Written evidence submitted by the Information Commissioner’s Office (BIO0009)
About the ICO
- The ICO’s mission is to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals.
- The ICO is the UK’s independent public authority set up to uphold information rights. We do this by promoting good practice, ruling on complaints, providing information to individuals and organisations and taking appropriate action where the law is broken.
- The ICO enforces and oversees the Freedom of Information Act 2000, the Environmental Information Regulations 2004, the Data Protection Act 1998 and the Privacy and Electronic Communication Regulations 2003.
Introduction
- Biometrics is a broad term referring to the use of individuals’ measurable biological properties. As a result, that data will more often than not “relate to” an individual and, when an individual can be identified from biometric data, it will be personal data with its use governed by the Data Protection Act (the DPA).
- Biometrics can give rise to a unique characteristic, e.g. a representation of a fingerprint, or one that is not unique within a population, such as gender. Biometric data that gives rise to unique characteristics has been used extensively in a broad range of identity–related tasks such as authentication (to verify that the individual presenting the fingerprint is the same individual that enrolled in the system: a one-to-one match) and identification (to search through a population of biometric samples to locate a match against a sample: a one-to-many match).
- Biometrics can also be used to perform classification, or segregation. Segregation is dividing a population into smaller groups based on one or more measurable biological properties. Simple examples of segregation will include classification based on predicting age or gender using measurements obtained from facial images. Many of the issues surrounding biometrics are applicable to the biometric data itself, the collection and retention of the source material and the processing of any biometric templates that have been generated.
- Biometrics are increasingly playing a role in the daily lives of adults and children alike:
- the administration of school meals or libraries;
- managing access to gyms and bank accounts; unlocking smartphones and laptops; and
- speeding up border controls.
- Whilst there are some very good justifications for the use of biometrics that would cause little public concern, the power of biometrics to identify and record details of individuals as they go about their daily lives may involve the surreptitious collection of information about individuals that they would not necessarily expect, whether that be from a fingerprint or genetic material left behind or facial recognition in live or recorded images. Even instances that might not cause immediate public concern, such as DNA profiling for law enforcement purposes, may stray into areas that go beyond acceptability as the ease of use increases and costs drop. For example the Protection of Freedoms Act (the PoFA) reined back the police use of DNA profiles to ensure that they are not held in inappropriate circumstances. The PoFA also established the Commissioner for the Retention and Use of Biometric Information (the Biometrics Commissioner) to keep under review the retention and use by the police of DNA samples, DNA profiles and fingerprints. The ICO works closely with the Biometrics Commissioner on issues that cut across both of our remits. A recent example is our discussions on shared concerns about the police service’s deployment of a facial recognition capability on the Police National Database to enable searching against all custody photographs, including those of persons never convicted of any offence. The ICO also has an oversight role in the early deletion of DNA records which were collected for law enforcement purposes.
- The Information Commissioner and his predecessors have all been concerned about the increasing surveillance of UK citizens in many different contexts. A report on ‘the surveillance society’ was commissioned in 2006[1] which led to two Parliamentary inquiries and a further update report[2]. The Information Commissioner has shown a keen interest in ensuring that the use of biometrics is well justified, clearly thought-out and deployed with appropriate safeguards; and not at the expense of simply increasing the level of surveillance in the UK.
- The ICO is also an active member of the Article 29 Working Party[3] and contributed to Opinion 03/2012 on developments in biometric technologies[4]. This paper provides additional insight into how the European data protection regulatory community more broadly views this area of data processing.
Specific questions
How might biometric data be applied in the future? Please give examples.
- As with many examples of data processing, recent technical advances have reduced the cost of the necessary hardware and computing power historically required for complex biometric systems. As a result, the use of biometric data is no longer an application of technology which should be considered as solely for the use of governments or law enforcement agencies. Biometric technologies are now in the hands of organisations both large and small, and also in the hands of individuals either in the form of smart-phones or made accessible to them via online services.
- The cost to the end user has diminished, biometric capability is now often a standard feature of systems:
- some mobile phones and laptops contain fingerprint sensors to authenticate the device’s owner in order to grant or deny access to the device;
- social networks use face recognition to identify users’ friends and
- in-store advertising displays use video feeds to predict the age and gender of the individual standing before the display in order to select the most suitable advert.
- New or upgraded CCTV systems may be equipped with high definition cameras simply because they are the most cost effective to install thereby requiring a small software upgrade to introduce facial recognition capabilities or for the system owner to upload high quality clips to an online service. Examples of the use of such a system may include:
- to grant or deny access to a physical location;
- to identify known or suspect trouble-makers; or
- to allow those with the correct access privileges to enter a particular place.
- Footage can also be easily shared with third-parties such as law enforcement, other branches of the same organisation or the public via the internet. In 2000 the Information Commissioner first published a CCTV Code of Practice, revising it in 2008[5] with some specific but limited guidance on deployment of automated recognition technologies. A further revision is due to be issued shortly[6] to help ensure the guidance keeps up with the swift pace of technological advances in this area.
- The smartphone has also kick-started a revolution in consumer health devices. A smartphone user can use a broad array of sensors to collect biological data such as heart rate, blood pressure, daily step count or even insulin levels. Such sensors will continue to develop, becoming smaller and more accurate, logging significant volumes of data that could potentially be shared with a number of online services: giving rise to a new generation of biometrics.
- The attraction of biometric systems in contexts such as fraud prevention or assessing entitlement to services is obvious. The same individual may have managed to obtain several national insurance numbers for use in benefit fraud. However the use of biometrics can make multiple claims easier to detect. Whilst this has not been the approach in the UK, some states have embarked on the collection of biometrics as part of registering for government services.
- The long-term nature of biometrics also means that source material or biometrics collected today or in the past may be used in the future for a range or purposes as yet unknown.
What are the key challenges facing both Government and industry in developing, implementing and regulating new technologies that rely on biometric data? How might these be addressed?
- The key challenge lies in the fact the biometric data is (generally) tightly linked to a specific individual. This is of course the single trait that makes biometrics attractive in the field of personal identification. Traditional methods of proving identity such as a passport or driving licence can be revoked by the issuing agency, or deleted or destroyed by the individual; but the source of biometric data cannot.
- A Privacy Impact Assessment[7] (PIA) should be conducted at the outset of a project involving the processing of biometric data in order to ensure that effective governance arrangements are in place. This will reduce the risks of harm to individuals through the misuse of their personal information because the nature of the harm has been addressed during the design phase of the project, and mitigating factors built-in. For example, in the event of a disclosure of biometric data, perhaps due to inappropriate technical or organisational security measures, an individual cannot simply reset or revoke their fingerprint in the same way they can a password or PIN. A PIA would therefore conclude that source material should not be retained unless it is strictly necessary (as may be the case in the lawful retention of forensic evidence). Biometric data must not only be transformed and stored in a non-reversible form (e.g. a hashed template) but must also be converted in such a way as to be unique to the system, and to be impossible to transfer to a different system without the user’s re-enrolment.
- In many of today’s identity systems an individual can provide unique usernames and passwords or choose which documents to present to assert their identity. In biometric systems, this choice is eroded as individuals are unlikely to be able to choose which source of biometric data to provide for enrolment or required to enrol a common feature in order to assert their identity. Therefore if biometric systems become more common place, individuals will be forced to enrol the same feature in multiple systems. For example, multiple border control agencies will hold the thumbprints of frequent travellers. In some applications, such as international cross-border enforcement, interoperability may be an important feature in order to support the original purpose. In other systems, however, it will be an important privacy-protecting mechanism that biometrics are effectively meaningless outside the system for which they were collected. However, again, the power of biometric systems in information security should not be underestimated – especially as consumers may suffer from increasing ‘password fatigue’.
- The ICO recently published a paper describing the issues surrounding privacy and big data[8]. Biometric data may contain a high level of additional detail, which - if analysed in different ways or combined with a multitude of other data sources - could give rise to powerful systems making decisions about individuals based solely on their facial markers, genetic data or other biometric detail in a manner which is incompatible with the original purpose. This demonstrates why – other than in certain specific applications – biometric data should not be readable across different information systems. The DPA gives individuals certain rights to prevent decisions being made about them that are based solely on automated processing of their personal data. As big data advances, there is a risk that the current human oversight in many applications is replaced. This could adversely affect a number of individuals, depending on the accuracy of the biometrics and the accuracy of the mapping of the biometrics to other classical identifiers such as a name or national insurance number.
- There are also issues surrounding the transparency of the use of biometrics, and the effective communication of the operation of the technology and its consequences to the public.
How effective is current legislation governing the ownership of biometric data and who can collect, store and use it?
- The DPA governs the use of “personal data”: data which relates to a living individual who can be identified from that data, either directly or indirectly. Given that biometric data is a measure of a biological property and that it can often be used to generate unique identifiers, it will often be classed as personal data. The DPA is technology-neutral and adequately flexible to ensure that biometric data can be processed in compliance with the essential legal obligations and safeguards: including a stated purpose, fairness of collection and the security that must protect the data.
- The first principle of the DPA is that the processing of personal data is fair and lawful. Central to this principle is the requirement that the individual is fully informed about the purposes of the processing.
- In a traditional CCTV system this will be achieved through the use of notices and the overt placement of cameras. However, the camera of a CCTV system capable of facial recognition will have no observable feature to differentiate it from one that does not perform such a task. A telephone helpline could perform voice recognition without any noticeable signal to the caller. On leaving a room, an individual will leave behind a number of physical traits and have no idea what may or may not happen to them. The DPA requires that individuals are informed about the purposes of the processing; data controllers would need to ensure that any enhancements remain compatible with the stated purposes.
- The DPA also requires that personal data is accurate and not excessive. The sensors recording biometric data will have a natural level of sensitivity and error, but biometrics also rely heavily on probabilities and “best matches”. It is difficult to produce error-free results. Searching for a potential suspect within a bank of images will merely return a list of those that most closely resemble the suspect. The opening of an automatic ePassport gate will occur if the facial recognition algorithm deems that the individual matches the image in the photograph closely enough. Whilst systems can be tuned to give the most accurate results, both an incorrect identification (a false positive) and a failure to identify (a false negative) may have significant consequences on individuals and these must be taken into account by the system designer or operator. A Privacy Impact Assessment[9] (PIA) can be a useful tool to identify such privacy risks and the need for the involvement of human intervention and oversight. It is critical that the threshold for a positive match is set correctly. Biometric data, especially if derived from source material such as genetic data, is likely to contain significant amounts of information which is not required for the original purpose. There is therefore a risk that a data controller will be processing an amount of information that is excessive in relation to that required for the original purposes.
- Furthermore, biometric data might reveal so-called “sensitive personal data”, a category of personal data which may require the data subject’s explicit consent for processing. Such categories of data include an individual’s race, ethnic origin or health condition. It is debatable though whether information with the mere potential to reveal somebody’s race, for example, is in itself sensitive personal data.
- The DPA also governs the sharing of personal data between organisations. This means that the sharing of data (the disclosure of personal data from one organisation to another) must be in accordance with the DPA. To assist data controllers in this area, the ICO has published the Data Sharing Code of Practice[10]. In the event that organisations build up biometric datasets (e.g. templates from photos, video or voice recordings) which are of potential use to third-party organisations, such as law enforcement, then any request to access data and the subsequent sharing of data must be done with lawful authority.
- The DPA does not apply to anonymous datasets: personal data processed in such a way that the individual is no longer identifiable. The ICO has recently published a Code of Practice on Anonymisation[11] to explain the issues surrounding the anonymisation of personal data, and the disclosure of data once it has been anonymised. The ICO has also set up the UK Anonymisation Network[12] to establish best practice in anonymisation and to offer practical advice and information to data controllers considering the release of anonymous data sets.
- The risk of re-identification increases when there is a higher level of information in the dataset. Biometric data such as genetic data may have an extremely high level of information, and in such circumstances it becomes more difficult to ensure that the risk of re-identification remains at an acceptable level.
- The DPA also gives a strong right to individuals to access copies of their personal data held and processed by organisations. Biometric data would not immediately be excluded from such a right.
- The PoFA introduced a range of provisions relating to biometric data, specifically DNA and fingerprints, and outlines how long this data can be retained in certain circumstances. There are also restrictions on how long samples can be retained by the police. Any extension of the retention period needs to be approved by the Biometrics Commissioner. This has resulted in stringent safeguards being in place in relation to biometric information held by the police; however this does not cover photographs. There is a clear gap here, since other data such as photographs can be used in the context of facial recognition, but there is currently no specific legislation covering their retention or their use.
Should the Government be identifying priorities for research and development in biometric technologies? Why?
- The ICO would encourage the research into privacy enhancing technologies in biometric contexts as a priority area so that the issues raised in this consultation response can be appropriately managed by data controllers.
- Privacy enhancing technologies (PETs) encompass a wide range of mechanisms which allow data controllers to provide a particular product or service in a manner that protects the personal data and privacy of the users. PETs include features which reduce or eliminate the possibility of function creep or promote data minimisation.
- Being able to consider a wide range of privacy enhancing technologies during a Privacy Impact Assessment would enable data controllers to deliver a system built with a higher degree of privacy-by-default from the outset than may currently be the case at present.
September 2014
[1] http://ico.org.uk/about_us/research/~/media/documents/library/Data_Protection/Practical_application/SURVEILLANCE_SOCIETY_FULL_REPORT_2006.ashx
[2] http://ico.org.uk/about_us/research/~/media/documents/library/Corporate/Research_and_reports/surveillance_report_for_home_select_committee.ashx
[3] http://ec.europa.eu/justice/data-protection/article-29/index_en.htm
[4] http://ec.europa.eu/justice/data-protection/article-29/documentation/opinion-recommendation/files/2012/wp193_en.pdf
[5] http://ico.org.uk/~/media/documents/library/Data_Protection/Detailed_specialist_guides/ICO_CCTVFINAL_2301.pdf
[6] http://ico.org.uk/about_us/consultations/~/media/documents/library/Data_Protection/Research_and_reports/draft-cctv-cop.pdf
[7] http://ico.org.uk/for_organisations/data_protection/topic_guides/privacy_impact_assessment
[8] http://ico.org.uk/for_organisations/data_protection/topic_guides/~/media/documents/library/Data_Protection/Practical_application/big-data-and-data-protection.pdf
[9] http://ico.org.uk/for_organisations/data_protection/topic_guides/privacy_impact_assessment
[10] http://ico.org.uk/for_organisations/data_protection/topic_guides/~/media/documents/library/Data_Protection/Detailed_specialist_guides/data_sharing_code_of_practice.ashx
[11] http://ico.org.uk/for_organisations/data_protection/topic_guides/anonymisation
[12] http://ukanon.net/