The Mayor of London has recently written to the owners of a 67 acre site in Kings Cross London regarding their use of facial recognition technology.

Live facial recognition (LFR) involves the processing of personal data; the biometric data of a large number of people is captured and screened against a database to identify people of interest.  It has significant data protection and privacy implications. This is a high priority area for the ICO; it is currently investigating its use by the police and has intervened in the case of R (Bridges) v Chief Constable of South Wales Police relating to whether the use of LFR by the police is lawful. The ICO has indicated that once judgment in this case is given it will report on the findings of its investigation and set out what action needs to be taken. This will also have implications for private companies.

It’s not just the police that are the subject of the ICO’s focus; it is also considering the use of LFR in public spaces by private companies, just as in Kings Cross. The Information Commissioner has given guidance for police forces considering LFR which includes carrying out data protection impact assessments and ensuring the algorithms within the software do not treat the race or sex of individuals unfairly. The same considerations apply to private companies who will also have to identify the lawful basis upon which they rely to process the personal data.  The ICO has stated that it will consider regulatory action where it finds non-compliance. With the ICO having power to fine companies up to 4% of their worldwide annual turnover and given that this is an area which is under scrutiny, private companies using LFR or considering its use must ensure that they meet their data protection compliance obligations.

Latest News

My Life in Law – Naomi Goldsmith - Pannone Corporate

In our latest My Life in Law blog, we speak to Naomi Goldsmith, who joined our employment team earlier this year as an Associate. After graduating from ...

Read more...
Pannone most highly recommended law firm in the North West – Legal 500 finds - Pannone Corporate

Pannone Corporate is the most highly recommended law firm in the North West, according to new data from Legal 500 – the global research and data platfo...

Read more...
Pannone Corporate strengthens team with raft of hires - Pannone Corporate

Pannone Corporate has bolstered its team with a raft of hires. The Manchester law firm has appointed five lawyers across employment and real estate. Nao...

Read more...

View all posts

The Information Commissioner’s Office (ICO) has recently demonstrated that it will take a hard line on data breaches announcing on 8 and 9 July 2019 that it intends to fine British Airways  £183.39 million and Marriot International £99.2 million.

Both fines relate to cyber incidents. In the British Airways incident the personal and financial details, including contact and payment card details, of approximately 500,000 customers were harvested. The ICO’s subsequent investigation found that information was compromised by poor security arrangements.

In the Marriot incident a variety of personal data, including email addresses, phone numbers, dates of birth and passport numbers, from approximately 339 million guest records globally were exposed. Whilst Marriott notified the breach to the ICO in November 2018, it is thought the vulnerability began in 2014 when the systems of the Starwood hotels group were compromised. The ICO found that Marriott failed to undertake sufficient due diligence when it bought Starwood in 2016 and should have done more to secure its systems.

Fines for a GDPR breach can be up €20 million or 4 per cent of annual global turnover, whichever is higher. The intended fines are two of the largest ever levied by the ICO amounting to 1.5 per cent of British Airway’s turnover and 2.4 per cent of Marriott International’s turnover reflecting the ICO’s view of the gravity of the breaches. Interestingly had Marriott International discovered and disclosed the data breach prior to 25 May 2018, it would have been fined under the previous Data Protection Act, which had an upper fine limit of £500,000.

British Airways and Marriott International now have the opportunity to make representations to the ICO regarding their intended fine before the ICO makes its final decision. However, these intended fines serve as a reminder that GDPR compliance is not optional and is underpinned by strong enforcement powers which the ICO is willing to exercise. Should you wish to discuss data breaches or GDPR compliance generally please contact Amy Chandler or Patricia Jones.

Latest News

My Life in Law – Naomi Goldsmith - Pannone Corporate

In our latest My Life in Law blog, we speak to Naomi Goldsmith, who joined our employment team earlier this year as an Associate. After graduating from ...

Read more...
Pannone most highly recommended law firm in the North West – Legal 500 finds - Pannone Corporate

Pannone Corporate is the most highly recommended law firm in the North West, according to new data from Legal 500 – the global research and data platfo...

Read more...
Pannone Corporate strengthens team with raft of hires - Pannone Corporate

Pannone Corporate has bolstered its team with a raft of hires. The Manchester law firm has appointed five lawyers across employment and real estate. Nao...

Read more...

View all posts