Rights and Digital Technology

Data Protection Authority and AI Act: more safeguards are needed for biometric data

With regard to career progression or the awarding of bonuses, the Data Protection Commissioner proposes to prohibit the use of automated AI systems alone for assessment purposes

An image shows the human eye with a grid representing biometric scanning technology used for security and identity verification. It represents the future of access control, cybersecurity and Khaisan - stock.adobe.com

2' min read

Translated by AI
Versione italiana

2' min read

Translated by AI
Versione italiana

It is prohibited to carry out assessments that may affect the employment relationship using artificial intelligence tools alone; the automated and blanket processing of biometric data of those accessing public places and events is also prohibited. These are some of the recommendations made by the Data Protection Authority regarding the draft legislative decree governing the implementation in Italia of EU Regulation 2024/1689. Known as the AI Act, the European Regulation governs the development and responsible use of artificial intelligence.

Guidance from the Data Protection Authority

The decree defines the national AI governance system and designates the Data Protection Authority as the market supervisory authority for high-risk systems, used in sectors most sensitive to fundamental rights. New rules are also envisaged for the financial and insurance sectors, as well as the promotion of digital literacy programmes and training in the responsible use of AI in schools and universities. According to the Data Protection Authority, however, it is necessary for the Authority to be granted the power to adopt guidelines, recommendations and best practices, and for the scope of application of the sanctions falling within its remit to be clarified.

Loading...

The Data Protection Authority also requests to be involved in the activities of the Italian Artificial Intelligence Testing Ground and that its role be defined within the procedures for assessing the compliance of high-risk systems. For decisions that may have a significant impact on employment relationship, such as career progression or the awarding of bonuses, the Data Protection Authority proposes prohibiting assessments from being carried out solely using automated AI systems.

Use by the police

As regards, however, the use of AI systems by the police, in particular the use of remote biometric identification technologies, the Data Protection Authority states that the role of human supervision must be clarified. Furthermore, responsibilities in research and experimental projects must be defined more precisely. The Data Protection Authority also requests to be involved in regulatory experimentation frameworks involving the processing of personal data. Furthermore, according to the Authority, greater safeguards are needed regarding the quality of the biometric databases used for identification.

However, the automated and blanket processing of biometric data of those accessing public places or events is not consistent with the AI Act: facial recognition, in fact, is permitted only for targeted ex post searches. The Data Protection Authority concludes that the processing of biometric data must take place only on data already collected and in the event of specific operational requirements, without any prior collection.

Finally, according to the Data Protection Authority, the provisions on biometric identification set out in Article 359-ter of the Code of Criminal Procedure should also include an explicit prohibition on the use of databases obtained through indiscriminate scraping or in breach of data protection legislation.

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti