Popular Post Ditto Posted September 4, 2024 Popular Post Posted September 4, 2024 https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2024/07/essex-school-reprimanded-after-using-facial-recognition-technology-for-canteen-payments The school in Essex introduce facial recognition software for cashless payments for meals. There were some pretty basic failings. not consulting DPO opt out option only, not affirmative opt-in no consultation with pupils/parents age of consent ignored and relied on parents permissions The reprimand is at https://ico.org.uk/action-weve-taken/enforcement/chelmer-valley-high-school/ In the light of this, other school maybe want to check if they are following the ICO guidance, in particular in relation to biometric data. 5
synaesthesia Posted September 4, 2024 Posted September 4, 2024 Yeah, saw that as soon as it come up the first time round after Cunninghams introduced that tech. Alarms bells should have been ringing the moment "opt-out" was mentioned but clearly the school didn't have the staff, expertise or support required to make an informed decision. I don't think FRT is available any more possibly as a direct result - it'd be a hard sell for any DPIA to show it has benefits that balance out the risks.
Rob_D Posted September 4, 2024 Posted September 4, 2024 AFAIK Cunninghams still offer facial recognition, and I don't see why it would be that hard a sell. You're storing it in an on-site server behind your firewalls, facial rec data never leaves the cashless VLAN. From a DP standpoint, I don't see it's any more of a risk than fingerprints which has been pretty common in schools. If done right, with the DPI and opt-in consent, I don't see why it should be a problem. The main benefits would be speed, contactless, and (over a card) the inability to loose one's face. 1
synaesthesia Posted September 5, 2024 Posted September 5, 2024 AFAIK Cunninghams still offer facial recognition, and I don't see why it would be that hard a sell. You're storing it in an on-site server behind your firewalls, facial rec data never leaves the cashless VLAN. From a DP standpoint, I don't see it's any more of a risk than fingerprints which has been pretty common in schools. If done right, with the DPI and opt-in consent, I don't see why it should be a problem. The main benefits would be speed, contactless, and (over a card) the inability to loose one's face. Agreed to a point, however that may be all moot until you can translate that into Tin Foil Hat Parent. There's your hard sell! It's not really any different to finger printing in how it works and how the data is stored but the DPIA still needs to consider it as "higher risk" than fingerprinting because of the connotations involved with facial recognition. Cunninghams didn't even mention it to us when installing over the summer - we did ask about it in passing and it appears as if they've been suggested to not give it the hard sell at the moment! 1
Rob_D Posted September 5, 2024 Posted September 5, 2024 True. It got talked about during our Cunninghams sales pitch back in May, but they weren't pushing it super hard.
ass17 Posted September 6, 2024 Posted September 6, 2024 the ICO article suggested: "Our reprimand also notes most students were old enough to provide their own consent. Therefore, parental opt-out deprived students of the ability to exercise their rights and freedoms." Is it not the current law that parental consent must be given by a parent for any child under the age of 18, therefore most students would not be old enough to give consent themselves. A child can only refuse if consent is given by a parent. The Protection of Freedoms Act 2012 https://www.legislation.gov.uk/ukpga/2012/9/part/1/chapter/2 Notification and Parental Consent What the law says: 1) Schools and colleges must notify each parent of a pupil under the age of 18 if they wish to take and subsequently use the child’s biometric data as part of an automated biometric recognition system. Seems like the ICO got this bit wrong? Thoughts?
Ditto Posted September 7, 2024 Author Posted September 7, 2024 I don't think ICO got it wrong. For me, the school needs to comply with both the PofFA as well as DPA/GDPR regulations. 26(5) shows the child can object even if the parent gives consent. Perhaps ICO should also be quoting Protection of Freedom Act in addition to what they have. 1
ass17 Posted September 7, 2024 Posted September 7, 2024 They have more knowledge than most of us do but why say the child can give consent without parents when under the rule I quoted suggests they can’t and can only refuse, not give. I wish they would clarify more what they meant by this.. at least this school being made an example of will help other schools not to fall in the same trap. I still think GDPR is a massive mine field and long gone are those days we just did it without red tape. Whether it be for the better or not that’s another debate.
Ditto Posted September 7, 2024 Author Posted September 7, 2024 It's worth noting that the letter does refer the school to the case study on North Ayrshire Council schools. That study does highlight the Protection of Freedom Act.
ass17 Posted September 7, 2024 Posted September 7, 2024 It's worth noting that the letter does refer the school to the case study on North Ayrshire Council schools. That study does highlight the Protection of Freedom Act. Yes indeed, hence my confusion to their findings. For me if the ICO say jump, I’m asking how far :-) 1
Ditto Posted September 7, 2024 Author Posted September 7, 2024 They have more knowledge than most of us do but why say the child can give consent without parents when under the rule I quoted suggests they can’t and can only refuse, not give. I wish they would clarify more what they meant by this.. at least this school being made an example of will help other schools not to fall in the same trap. I still think GDPR is a massive mine field and long gone are those days we just did it without red tape. Whether it be for the better or not that’s another debate. I agree it's a minefield! My work overlaps with Health and Social Care regulations and many other bits of legislation and it gets a lot more challenging. It's why after joining my charity, I got them to recruit and external DPO very quickly. Small charities are not required by law to have a DPO. We are now at least a medium sized charity, besides small or large, there is still a need to be compliant. Our outsourced DPO has proved invaluable on several occasions. One of the points of the reprimand is the school did not consult with their DPO and it's something I recommend to all schools. Some schools do give the role to someone internal but I think that's not best practice. In fact I remember a job interview in the last years when I asked about the DPO, it was the deputy head. When I suggested that there could be a conflict of interest and was not best practice, I don't think it went down well. I didn't get an offer but clearly was the most qualified for the role. Probably for the best, as if my line manager can not take constructive, it's unlikely to work out well. 3
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now