Data Protection Commission issues a €550,000 Fine to the Department of Social Protection for Failing to Ensure Facial Recognition Technology is Operated in Compliance with GDPR
The Data Protection Commission (DPC) has published its final decision regarding an inquiry into the Department of Social Protection’s (DSP) use of biometric facial recognition technology as part of the Public Services Card registration process, known as “SAFE 2 registration”.
This inquiry, launched in July 2021, focused on the DSP’s processing of biometric facial data, specifically the creation and use of facial templates for identity verification. The SAFE 2 registration process is a requirement for anyone applying for a Public Service Card, which is needed to access a wide range of public services, including social welfare payments.
Background
This investigation builds upon a former DPC inquiry into the Public Services Card system, which concluded in 2019. Although the DSP initially appealed that decision, it later withdrew the appeal, and a final investigation report was released in December 2021. That report signalled that the DPC would conduct a separate review focused specifically on biometric data. This announcement marks the conclusion of that process.
Key Issues Examined
The inquiry examined whether the DSP:
- Had a valid legal basis for collecting and using biometric data for facial recognition
- Lawfully retained such data
- Provided adequate transparency to individuals undergoing SAFE 2 registration, and
- Conducted a proper Data Protection Impact Assessment
Biometric data, due to its highly personal nature, is subject to additional protections under Article 9 of the General Data Protection Regulation (GDPR) and is considered a “special category” of personal data alongside political opinion, religious or philosophical beliefs, and trade union membership to name a few. As of 2021, the DSP was storing facial templates for approximately 70% of the Irish population, making the scale of data collection and processing a significant concern. Joe O’Brien, Executive Director of The Irish Council for Civil Liberties, an organisation which has long been critical of the SAFE 2 registration system, stated the following in response to the DPC’s decision:
“The Department effectively created a de facto national biometric ID system by stealth over 15 plus years without a proper legal foundation. This illegal database of millions of Irish people’s biometric data must be deleted.”
Findings and Enforcement Actions
The DPC, led in this inquiry by Commissioner Dale Sunderland, found that the DSP had:
- No valid legal basis for collecting and processing biometric data under Articles 5(1)(a), 6(1), and 9(1) of the GDPR
- Unlawfully retained biometric data in breach of Article 5(1)(e)
- Failed to meet transparency obligations under Articles 13(1)(c) and 13(2)(a), and
- Did not fully meet the GDPR’s requirements for a Data Protection Impact Assessment under Articles 35(7)(b) and (c)
As a result, the DPC has issued:
- A formal reprimand
- Administrative fines totalling €550,000, and
- An order requiring the DSP to cease processing biometric data in connection with SAFE 2 registration within nine months, unless it can establish a valid legal basis.
Context and Next Steps
The DPC’s Deputy Commissioner, Graham Doyle, emphasised that the decision does not call into question the SAFE 2 process itself as a public policy tool, nor did the inquiry find any security failings in how the DSP protects biometric data. Rather, the DPC found that in accordance with EU law (presumably the principle of Legality although this was not specified), legislation which is precise and foreseeable is required to ground the arrangements for the underlying processing of biometric data in light of the scale and intrusive nature of the DSP’s data processing. As the DPC was not able to cite any such legislation, they concluded that the legislative framework presently in place is inadequate in this regard. Furthermore, failure on the part of the DSP to inform data subjects as to the reason their data was being collected and on what grounds also constituted a breach of the GDPR.
The DPC has indicated it will publish the full decision and related documents in due course.
How We Can Help
If you are subject to a DPC investigation or if you have a query regarding your company’s compliance with GDPR / Privacy laws more broadly, then please do not hesitate to contact Sarah O’Toole (sotoole@bhsm.ie) or Seamus Ennis (sennis@bhsm.ie)
This article is for general information purposes. Legal advice must be obtained for individual circumstances. Whilst every effort has been made to ensure the accuracy of this article, no liability is accepted by the author for any inaccuracies.