The Information Commissioner’s Office has ordered public service providers Serco Leisure Ltd, Serco Jersey Ltd and seven associated community leisure trusts to use facial recognition technology and fingerprint scanning to monitor employee attendance. ordered to stop.
An ICO investigation has revealed that Serco Leisure and Trusts illegally processed the biometric data of more than 2,000 employees at 38 leisure facilities for the purpose of RSVPs and subsequent payment of time worked. found.
The ICO said it had failed to demonstrate the necessity or propriety of using facial recognition technology or fingerprint scanning for this purpose, when less intrusive means such as ID cards and fobs were available.
The ICO said alternatives to face or finger scanning for time and attendance records were not actively offered to employees, but instead were presented as a requirement to receive pay.
“Due to the power imbalance between Serco Leisure and its employees, we do not believe they can say no to the collection and use of biometric data for attendance checks.”

The ICO has now directed Serco Leisure and Trusts to stop processing all biometric data to monitor employee attendance and to destroy all biometric data they are not legally required to retain. An enforcement notice has been issued. This must be done within three months of the enforcement notice being issued.
John Edwards, UK Information Commissioner, said: “Because biometric data is completely unique to an individual, the risk of harm in the event of inaccuracy or a security breach is much greater. You cannot reset your face or fingerprint.” password.
Diverse AI with a mission to diversify the world of AI
“Serco Leisure prioritized business interests over employee privacy and did not adequately consider the risks before implementing biometric technology to monitor employee attendance. Without a clear way to exit, the power imbalance in the workplace increases and people are put in situations where they feel they have to hand over their biometric data in order to work there.
“This is neither fair nor disproportionate under data protection law. As the UK regulator, we will scrutinize organizations and act decisively where we believe biometric data is being used unlawfully. Masu.”
This enforcement action will be carried out as follows ICO publishes new guidance for all organizations considering using people’s biometric data. This guidance outlines how organizations can comply with data protection laws when using biometric data to identify individuals.
Mr Edwards added: “This measure will help send a message to industry that biometric technology cannot be deployed lightly. We intervene and demand accountability and evidence that it is proportionate to the problems organizations are trying to solve. To do.
“Our latest guidance requires organizations to avoid potential risks associated with using biometric data, such as errors in accurately identifying people and bias when a system detects certain physical characteristics better than others. It is clear that we need to reduce this risk.”
Technology consultancy company Grayce expands into the US
