What happened
It was reported that the Data Protection Commission in Ireland announced on 4 October 2024 that it had opened an inquiry into an airline’s customer verification process under section 110 of the Data Protection Act 2018. The regulator said the verification methods included facial recognition technology using customers’ biometric data. The inquiry would examine whether the airline’s use of those verification methods complies with the General Data Protection Regulation.
It was reported that passengers who booked through third party websites or online travel agents were asked to complete extra verification, while those who booked directly were not. The reported options were facial recognition at booking for a 59 cent fee, which the airline says it does not benefit commercially from, a form taking up to seven days, or arriving at the airport two hours early. The airline said it welcomed the inquiry, that the process protects customers from non approved online travel agents, and that its methods comply with the regulation.
What an auditable version would have shown
The sources reviewed do not establish whether the processing was lawful. That is what the regulator is investigating. A privacy advocacy group complained about the same verification process to the Spanish data protection authority in July 2023. Its case record shows that the complaint was sent to the Irish regulator, as lead supervisory authority, on 29 September 2023, more than a year before the inquiry was announced. The sources reviewed did not identify how many passengers were asked to verify, how many chose facial recognition instead of another option, or how long their biometric data was kept.
For each verification, the airline could keep a record of the lawful basis it relied on, the alternatives offered and which option the passenger chose. It could also record what data was collected, where it went and when it was deleted. Those records would allow the airline to say how many passengers used facial recognition and how many completed the same booking without it.
Where the gap was
The regulator said the verification process included facial recognition using customers’ biometric data. It also noted the European Data Protection Board’s position that biometric data and facial recognition entail heightened risks to the rights and freedoms of data subjects.
A ConstraintGate is designed to check the standing rule for this type of data before it is collected, and require an explicit recorded approval when the rule is not satisfied. A ConductRecord keeps the basis relied on, the alternatives offered, what data was collected and how long it was kept. This gives the organisation a record of what happened if the regulator asks. Neither decides whether the processing was lawful. That remains with the regulator.
What governance should have looked like
The airline’s position is that its verification process protects customers from non approved online travel agents and fully complies with the regulation. The regulator has not published a decision, and the sources reviewed do not establish that any part of the process was unlawful.
Where an organisation asks people for biometric data as part of a transaction, best practice would be to record why it is legally entitled to collect that data before collecting it. It should also record what other options the person was offered, which one they chose, how long the biometric data was kept and when it was deleted.
Failure Pattern: it was reported that customers booking through third parties faced an extra verification process that could involve handing over biometric data. Whether that processing was lawful later became the subject of a regulatory inquiry.
Governance Principle: an organisation collecting biometric data should be able to show why it was entitled to collect it, what other option the person was given, what data was collected, where it went and how long it was kept.
The reference implementation of ConstraintGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.
Sources
- Data Protection Commission launches inquiry into Ryanair’s Customer Verification Process (Data Protection Commission, 4 October 2024)
- Report carrying the airline’s statement in response (The Irish Times, 4 October 2024)
- Data watchdog probes Ryanair’s use of facial recognition (RTE, 4 October 2024)
- Booking a Ryanair flight through an online travel agent might hold a nasty surprise, the complaint filed with the Spanish authority (noyb, 27 July 2023)
- Case C065, Ryanair DAC, recording the filing authority, the lead supervisory authority and the pending status (noyb case page)
- Analysis of the inquiry and its implications for airline verification (Pinsent Masons Out-Law)
- Report on the inquiry and the verification options (Irish Legal News, October 2024)