Biometrics BillA BILL to provide for proper privacy and security in the storage and gathering of biometric data, ban the use of biometric data for advertising purposes, ban the gathering of biometric data in public spaces without express written or verbal consent, classify neurological data as a type of human tissue, and for connected purposes.
|Author(s)||The Most Honourable Dame Sir Xanthe Orpheus Florence GCTL DOBC KOBC MR, 1st Marquess of Florence|
|First reading||2021 September 30|
Be it enacted by the Queen's most Excellent Majesty, by and with the advice and consent of the Lords Spiritual and Temporal, and Commons, in this present Parliament assembled, and by the authority of the same, as follows:—
biometric data refers to any data gathered by or a computer based on the distinguishing biological characteristics of one or more people, excluding fingerprints and neuro-data.
biometric data source refers to a person from whom biometric data is gathered
neuro-data refers to any data gathered from a person’s brain activity.
2 Biometric Data Licence
- Any person or organisation wishing to gather or store biometric data must apply for a Biometric Data Licence (hereafter ‘a BDL’) from the Information Commissioner’s Office (hereafter ‘the ICO’) before they can begin operations.
- A BDL expires after 5 years; a holder of a BDL may apply to the ICO to have it renewed.
3 Auditing and revocation of a BDL
- The ICO must conduct audits of each BDL holder’s privacy and security standards, with a gap of no more than three years between successive audits of a particular holder.
- If the ICO determines that the privacy or security of the holder’s biometric data sources is at risk, it may revoke the holder’s BDL.
4 Egregious violations of biometric privacy
- A person or corporation commits an offence if they —
- Gather biometric data without a BDL,
- Store biometric data on any device other than as a securely encrypted file on the biometric data source’s personal computer without a BDL,
- Use biometric data for advertising purposes, or
- Gather biometric data in a public space, or private outdoor space to which the public has open access, without express written or verbal consent from the biometric data source.
- A person or corporation guilty of committing an offence under this section, on summary conviction—
- Is liable to a fine not exceeding the statutory maximum;
- Must have their BDL revoked; and
- May not apply for another BDL or work for an organisation or person holding a BDL.
Neuro-data is to be treated as human tissue under the terms of the Human Tissue Act 2004.
6 Short title, commencement, and extent
- This Act may be cited as the Biometrics Act 2021.
- This Act comes into effect on 1 September 2023.
- This Act extends to England, Wales, and Northern Ireland.