Case ruling
Shoe shop Manfield recently installed a fingerprint scanner on its checkout system. Employees must now first identify themselves with their fingerprint before they can use the till. One employee who objects to this is resisting it and wants clarity from the court. May Manfield require its employees to log in with their fingerprint?
Many people know it from their smartphone or tablet: you place your finger on a scanning surface and the device unlocks. Store employees at Manfield have recently had to do the same to be able to use the till. Without a fingerprint they can no longer carry out their till duties. In addition, the hours of Manfield’s employees are also recorded via a fingerprint system.
The special status of the fingerprint
Despite the fact that the fingerprint scan has by now become commonplace, the fingerprint has a special legal status. Under the General Data Protection Regulation (GDPR), the fingerprint is in fact biometric data: it can be used to directly identify a person. Other biometric data includes, for example, a facial image or an iris scan. In principle, the collection of biometric data is prohibited. This is different if the person concerned has given consent for its use. But even if consent has been given, the use of a fingerprint must still be necessary for security and proportionate to the purpose for which it is used.
Special relationship between employer and employee
In this case it is relevant that we are dealing with the employer-employee relationship. The employee is never fully free to refuse consent, since he is dependent on his employer. The court therefore also considers the question of whether Manfield may require its store employees to use the fingerprint scan.
Manfield’s position
According to Manfield, the introduction of a fingerprint scan is necessary for security. Manfield regularly deals with theft and fraud by personnel. In the past, cards and login codes were used to open the till, but these were passed around among staff, so that in the event of theft the perpetrator could no longer be traced. The fingerprint scan solves this problem, because a fingerprint cannot be passed on.
In addition, Manfield argues that it is legally obliged to secure the data in its checkout system as well as possible. The checkout system contains sensitive information about customers and about the company’s finances. The use of the fingerprint scan is therefore a logical choice: the fingerprint cannot be copied and ensures that it is not possible to log in remotely.
The court: use of the fingerprint scan in breach of the GDPR
The court, however, ruled that the introduction of the fingerprint scan is too far-reaching a measure. The court considers the use of the fingerprint scan not to be necessary for security. It is also relevant that Manfield did not take any less far-reaching measures, such as camera surveillance or access gates. In addition, Manfield did too little research into less far-reaching alternatives, such as an access card combined with a numeric code. In this way the system can also be properly secured, without having to use biometric data such as a fingerprint scan.
Ultimately, the court ruled that Manfield may not require its employees to use the fingerprint scan, because in these circumstances that is in breach of the GDPR.
Advice
A fingerprint scan or facial recognition may seem like a convenient solution for your company, for example if you face challenges in security or accurate time registration. We increasingly see companies in, for example, cleaning, hospitality or retail using such a system. However, be aware that such a system is likely to infringe your employees’ privacy too much.
If you want to require your employees to use a fingerprint scan or facial recognition, you will have to demonstrate that this is truly necessary for the security of personal data and that no other options are available. That can be difficult: as an example situation in which a fingerprint scan is indeed necessary, the legislator cites the security of a nuclear power plant.
Have a Privacy Impact Assessment (PIA) carried out
Do you want to introduce new measures that may have an impact on your employees’ privacy? We recommend that you always have a so-called “privacy impact assessment” carried out by an objective privacy expert and have this recorded in writing. In this you can weigh up the pros and cons of different systems and consider which form of security is necessary and suitable for your company. You also record that you have checked and weighed all of this, which is an important requirement of the GDPR if you make a conscious and considered intrusion on privacy. You preferably choose a system that infringes as little as possible on your employees’ privacy, but still provides sufficient security, for example dual security by means of a card and a code.
For help with PIAs and for more information on help with GDPR compliance, visit our website. Of course you can also email info@thelegalprivacycompany.com or call 020-3450152.
Do you have a legal question in the field of employment law, contract law and/or corporate law? Visit our website for more information.