[ad_1]

The Information Commissioner’s Office (ICO) has issued an order against Serco, demanding the cessation of facial recognition technology in monitoring its workforce, citing a violation of privacy rights.
A particular branch of Serco, known as Serco Leisure, and affiliated community leisure trusts were found by the ICO to be engaged in unlawful activities by processing the biometric data of employees at 38 UK leisure centers.
According to the ICO’s investigations, the abovementioned centers employed facial recognition and fingerprint scanning technologies to track employee attendance, which then influenced their pay.
The regulatory body highlighted Serco Leisure’s failure in demonstrating the necessity for such intrusive methods when compared to alternatives like ID cards, which are seen as less invasive. Furthermore, it was noted that no explicit opt-out was provided for employees who did not wish to consent to biometric data collection.
Aligning with its recent publication of new guidelines on biometric data usage, the ICO’s action underscores the imperatives for companies to abide by data protection laws.
John Edwards, UK Information Commissioner, elaborated on the matter, stating that biometric data personalization means higher risks, making it crucial that employees are not forced to exchange their biometric information for employment.
The ICO will maintain vigilant oversight to ensure organisations do not misuse biometric data.
In response to the enforcement notice, a Serco Leisure representative clarified that the biometric technology was embraced five years prior to simplify timekeeping processes and was initially well-received. They also mentioned the advisory they received which had confirmed the legality of the technology usage.
Despite the past knowledge of Serco Leisure’s practices, the ICO only issued the enforcement notice in tandem with their new guidance, though Serco has vowed to comply fully.
[ad_2]
FAQ Section
- Why was Serco ordered to stop using facial recognition technology?
The ICO found that Serco was unlawfully processing biometric data of its employees by using facial recognition and fingerprint scanning to monitor their attendance and pay, prioritizing business interests over employee privacy without offering a less intrusive alternative. - What are the risks of using biometric data according to the ICO?
Biometric data is unique and cannot be reset like a password, so inaccuracies or a security breach pose greater risks of harm. - How did Serco Leisure respond to the ICO’s order?
Serco Leisure acknowledged the introduction of biometric technology, claiming it was well-received and legal according to external advice. They have agreed to fully comply with the ICO’s enforcement notice. - Did the ICO release any new guidelines regarding biometric data?
Yes, the ICO published new guidance for organizations on the processing of biometric data, which coincided with the enforcement notice issued to Serco.
Conclusion
The enforcement notice served to Serco by the ICO serves as a significant reminder of the legal and ethical responsibilities companies have when dealing with the personal biometric data of their employees. With technological advancements coming to the forefront of daily operations, companies must ensure compliance with data protection laws and respect for employee privacy. Serco’s compliance with the ICO’s recent notice and the release of new guidelines on biometric data usage may lead to a broader industry shift towards more careful consideration of privacy issues related to biometric technologies.










































