
Pull your finger out
Much as I hate these huge outsourcing companies, I think the ICO has to share some blame here. Not issuing clear guidance around the use of biometrics until 2024 is a dereliction of duty (In my not so humble opinion). The ICO have chosen not to fine Serco in this case because "the Commissioner considers that the resulting infringements are negligent [rather than deliberate]. Serco appears to have sought to comply with data protection legislation in its deployment of biometric technology, but its failure to meet these requirements indicates a lack of understanding of the UK GDPR" - https://ico.org.uk/media/action-weve-taken/enforcement-notices/4028590/20240219-serco-leisure-operating-limited-en.pdf
Serco stated: “Despite being aware of Serco Leisure’s use of this technology for some years, the ICO have only this week issued an enforcement notice and requested that we take action. We now understand this coincides with the publication of new guidance for organisations on processing of biometric data which we anticipate will provide greater clarity in this area."
I'd be curious if the ICO had been nudged to not issue guidance beforehand. Use of facial recognition in the UK seems to be on the basis that the government will look the other way for as long as it possibly can.