The legal answer can depend on how a system is implemented, and we do not claim it is never biometric processing. What matters are the safeguards:
- whether the image is processed transiently,
- whether any biometric template is created,
- whether the system is capable of subsequently identifying the person and
- whether any image or template is retained.
In implementations designed by our members, the answers are transient, no, no and no.
The UK Information Commissioner’s Office accepted that personal data is not used for the estimation process because any image is first transformed into a mathematical map of the face that is no longer sufficiently detailed to re-identify the user. Lawful deployment still requires a data protection impact assessment, transparency with users, strict minimisation and often, regulators insist there are alternative methods for anyone who prefers not to use biometrics.