{"id":16587,"date":"2024-04-05T16:42:41","date_gmt":"2024-04-05T16:42:41","guid":{"rendered":"https:\/\/businessadapter.es\/more-reasons-not-to-use-biometrics\/"},"modified":"2024-12-11T10:44:44","modified_gmt":"2024-12-11T10:44:44","slug":"more-reasons-not-to-use-biometrics","status":"publish","type":"post","link":"https:\/\/businessadapter.es\/en\/more-reasons-not-to-use-biometrics\/","title":{"rendered":"More reasons not to use Biometrics"},"content":{"rendered":"\n<p><strong style=\"color: #800000; font-size: 45px; letter-spacing: -0.06em;\">More reasons not to use Biometrics<\/strong><\/p>\n<p style=\"text-align: justify;\">Again with <strong>biometric<\/strong> data, since November 23, 2023, the Spanish Data Protection Agency<a href=\"https:\/\/www.aepd.es\/informes-y-resoluciones\/resoluciones\" target=\"_blank\" rel=\"noopener\">(AEPD<\/a>) published the <a href=\"https:\/\/www.aepd.es\/guias\/guia-control-presencia-biometrico.pdf\" target=\"_blank\" rel=\"noopener\">Guide on the use of biometric data<\/a> (e.g. fingerprint) to carry out the <a href=\"https:\/\/www.boe.es\/buscar\/doc.php?id=BOE-A-2019-3481\" target=\"_blank\" rel=\"noopener\">registration of working hours<\/a> or access control to facilities, many doubts have arisen around the use of biometric data by companies as they have been using these data.<\/p>\n<p style=\"text-align: justify;\">On December 1st Business Adapter\u00ae <a href=\"https:\/\/businessadapter.es\/en\/biometrics-for-workday-and-safety-registration\/\">wrote about this issue<\/a>, in order to shed light on <a href=\"https:\/\/businessadapter.es\/en\/biometrics-for-workday-and-safety-registration\/\">this matter<\/a> for our clients and readers, resolving in parallel numerous queries, given the different interpretations that clients gave to the Guide, detecting a logical disillusionment and even impotence for the answers given by our legal and consulting department.<a href=\"https:\/\/businessadapter.es\/en\/\"><img decoding=\"async\" class=\" wp-image-5136 alignright\" src=\"https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/08\/flat-3252983_1280-300x250.png\" alt=\"\" width=\"470\" height=\"392\" srcset=\"https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/08\/flat-3252983_1280-300x250.png 300w, https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/08\/flat-3252983_1280-1024x853.png 1024w, https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/08\/flat-3252983_1280-768x640.png 768w, https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/08\/flat-3252983_1280.png 1280w\" sizes=\"(max-width: 470px) 100vw, 470px\" \/><\/a> different interpretations that clients gave to this <a href=\"https:\/\/www.aepd.es\/guias\/guia-control-presencia-biometrico.pdf\" target=\"_blank\" rel=\"noopener\">Guide<\/a>, detecting a logical disappointment and even impotence for the answers given by our legal and consulting department.<\/p>\n<p style=\"text-align: justify;\">We say logical and understandable, because in November 2023 the <a href=\"https:\/\/www.aepd.es\/informes-y-resoluciones\/resoluciones\" target=\"_blank\" rel=\"noopener\">AEPD<\/a> changed its interpretation, since in a previous publication, specifically the <a href=\"https:\/\/www.aepd.es\/prensa-y-comunicacion\/notas-de-prensa\/aepd-publica-guia-pd-y-relaciones-laborales\" target=\"_blank\" rel=\"noopener\">Guide on labor relations<\/a> of May 2021, the AEPD supported the lawfulness of processing biometric data in articles 20.3 and 34.9 of the Workers&#8217; Statute. In other words, it legitimized companies to process biometric data on a very specific legal basis. <\/p>\n<p style=\"text-align: justify;\">Once again, we return to this issue to reconfirm our advice, after a new Resolution of the AEPD (<a href=\"https:\/\/www.aepd.es\/documento\/ps-00170-2023.pdf\" target=\"_blank\" rel=\"noopener\">PS\/00170\/2023<\/a>) where the Agency makes a meticulous analysis of the requirements that must be met to carry out the processing of biometric data, in this particular case, to carry out the <a href=\"https:\/\/www.boe.es\/buscar\/doc.php?id=BOE-A-2019-3481\" target=\"_blank\" rel=\"noopener\">registration of working hours.<\/a><\/p>\n<h2><span style=\"color: #800000;\"><strong>Analysis of the Resolution for the use of biometrics<\/strong><\/span><\/h2>\n<p style=\"text-align: justify;\">The case deals with a complaint filed before the <a href=\"https:\/\/www.aepd.es\/informes-y-resoluciones\/resoluciones\" target=\"_blank\" rel=\"noopener\">AEPD<\/a> by an employee against his company, due to the fact that he was asked to register his fingerprint for a clocking system.<\/p>\n<p>Faced with the employee&#8217;s complaint, the <a href=\"https:\/\/www.aepd.es\/informes-y-resoluciones\/resoluciones\" target=\"_blank\" rel=\"noopener\">AEPD <\/a>requires the company to provide the corresponding allegations and the company defends itself as follows:<\/p>\n<h3><strong>Biometric system used<\/strong><\/h3>\n<p>The system implemented is not for identification, but for authentication\/verification, as the system is configured to perform a 1:N fingerprint comparison.<\/p>\n<p>There is no storage of the fingerprint, but a hash code is created.<\/p>\n<h3><strong>Result of the Impact Assessment<\/strong><\/h3>\n<p>The Impact Assessment<a href=\"https:\/\/businessadapter.es\/evaluacion-de-impacto-de-proteccion-de-datos-eipd-valencia\/\">(EIPD<\/a>) states that the judgment of suitability, necessity and proportionality is overcome because there is no other way of recording working hours that is 100% reliable, since with the use of cards, anomalies had been observed in their use (they were lent to persons other than the cardholders) and since the fingerprints were not stored, there was no risk to the rights and freedoms of employees.<\/p>\n<h3><strong>Information to employees<\/strong><\/h3>\n<p>Regarding the information provided to employees about this fingerprinting system, an email was sent indicating that there was an update of the Data Protection Clause, which they had to accept. In this clause the only reference to the treatment of biometric data is the following: &#8220;<em>A fingerprint reader is installed for access to offices&#8221;.<\/em> <\/p>\n<h2><span style=\"color: #800000;\"><strong>AEPD&#8217;s position <\/strong><\/span><span style=\"color: #800000;\"><strong>on the use of biometrics<\/strong><\/span><\/h2>\n<p>Following the allegations presented by the company complained against to the <a href=\"https:\/\/www.aepd.es\/informes-y-resoluciones\/resoluciones\" target=\"_blank\" rel=\"noopener\">AEPD<\/a>, the latter refutes them with the following arguments:<\/p>\n<h3><strong>Biometric system used<\/strong><\/h3>\n<p>Regarding whether the system used is for authentication or identification, from the <a href=\"https:\/\/www.edpb.europa.eu\/our-work-tools\/our-documents\/guidelines\/guidelines-052022-use-facial-recognition-technology-area_es\" target=\"_blank\" rel=\"noopener\">CEPD Guidelines 05\/2022,<\/a> on Facial Recognition Technologies, it is made clear that both systems (identification and authentication) constitute a <a href=\"https:\/\/businessadapter.es\/datos-especiales-es-proteccion-de-dato\/\">special category<\/a> processing of <a href=\"https:\/\/businessadapter.es\/datos-especiales-es-proteccion-de-dato\/\">personal data<\/a>, therefore, the regime established for special category data in the RGPD and LOPDGDD applies to the present case.<\/p>\n<p>Regarding compliance with security measures, it is not noted that the process for deleting fingerprints after fingerprint capture, as well as the separation of the personal data of workers and the hash of the fingerprint.<\/p>\n<h3><strong>Result of the Impact Assessment<\/strong><\/h3>\n<p>Effectively there is no PIDD performed, as the respondent claims that no special category data was being processed, since the fingerprint was not stored. Therefore, the document prepared by the respondent cannot be accepted since it does not contain the analysis of the processing of special category data. Nor does it pass the triple test of necessity, suitability and proportionality.  <\/p>\n<h3><strong>Information to employees<\/strong><\/h3>\n<p>With respect to compliance with art. 13 RGPD, the information provided to workers initially did not meet the requirements of the regulation; so much so that the entity itself, after the requirement of the AEPD, modified and expanded it to include more information on the processing of the fingerprint, a basis of legitimacy different from the initial one (previously it was based on the employment contract, but later it was based on a legal obligation), conservation period (4 years) and the right to file a complaint with the supervisory authority.<\/p>\n<h2><span style=\"color: #800000;\"><strong>The AEPD resolves with sanction for the use of biometrics<\/strong><\/span><\/h2>\n<p>In the Resolution published by the AEPD<a href=\"https:\/\/www.aepd.es\/documento\/ps-00170-2023.pdf\" target=\"_blank\" rel=\"noopener\">(PS\/00170\/2023<\/a>) the following sanctions were imposed on the company:<\/p>\n<h3><strong>100.000\u20ac<\/strong><\/h3>\n<p>For not preparing a real Impact Assessment prior to the processing, which determines the technical and organizational measures to be implemented and that guarantee the rights and freedoms of workers, in breach of art. 35 of the <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">RGPD<\/a>.<\/p>\n<h3><strong>75.000\u20ac<\/strong><\/h3>\n<p>For not applying the necessary technical and organizational measures to guarantee the rights and freedoms of employees, in breach of art. 32 of the <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">RGPD<\/a>.<\/p>\n<h3><strong>200.000\u20ac<\/strong><\/h3>\n<p>For not applying the fundamental criteria on the information to be provided to employees, in breach of art. 13 of the <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">GDPR<\/a>.  <\/p>\n<h3><strong>As a consequence of all these circumstances, the supervisory body sanctioned the company with 365,000 euros.<\/strong><\/h3>\n<h2><span style=\"color: #800000;\"><strong>Business Adapter\u00ae at your service  <\/strong><\/span><\/h2>\n<p>If you need help, contact us by email: <a href=\"mailto:info@businessadapter.es,%20\">info@businessadapter.es, <\/a> you can also call <a href=\"http:\/\/tel.961318804\">96 131 88 04<\/a>, or leave your message in this form:<\/p>\n<p> <\/p>\n<p><strong>[su_button url=&#8221;https:\/\/businessadapter.es\/contacto&#8221; target=&#8221;blank&#8221; background=&#8221;#f6f903&#8243; color=&#8221;#181818&#8243; size=&#8221;7&#8243; center=&#8221;yes&#8221; icon_color=&#8221;#000000&#8243;]Contact us, we will be pleased to help you.[\/su_button]<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>More reasons not to use Biometrics Again with biometric data, since November 23, 2023, the Spanish Data Protection Agency(AEPD) published [&hellip;]<\/p>\n","protected":false},"author":1373,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[75],"tags":[93,82,86,83,94],"class_list":["post-16587","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-biometrics","tag-compliance-with-lopd-and-rgpd","tag-data-protection-penalties","tag-security-measures","tag-workers"],"_links":{"self":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16587","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/users\/1373"}],"replies":[{"embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/comments?post=16587"}],"version-history":[{"count":1,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16587\/revisions"}],"predecessor-version":[{"id":16589,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16587\/revisions\/16589"}],"wp:attachment":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/media?parent=16587"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/categories?post=16587"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/tags?post=16587"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}