{"id":2547,"date":"2020-05-24T09:56:34","date_gmt":"2020-05-24T09:56:34","guid":{"rendered":"http:\/\/www.bizlegal.eu\/?page_id=2547"},"modified":"2020-05-24T09:56:35","modified_gmt":"2020-05-24T09:56:35","slug":"newsletter-september-2019","status":"publish","type":"page","link":"https:\/\/www.bizlegal.eu\/?page_id=2547","title":{"rendered":"Newsletter September 2019"},"content":{"rendered":"\n<p><img loading=\"lazy\" src=\"\" width=\"189\" height=\"107\"><strong>Biometric Data processing.&nbsp;<\/strong><\/p>\n\n\n\n<p>To be legally compliant with data protection law, an employer must have a&nbsp; \u201clawful basis\u201d or justifiable reason to process an employee\u2019s personal data.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Ordinarily, under the GDPR, these reasons could include:&nbsp;&nbsp;<\/p>\n\n\n\n<p>a) employee consent;&nbsp;&nbsp;<\/p>\n\n\n\n<p>b) where the processing is necessary for the performance of&nbsp;<\/p>\n\n\n\n<p>a contract to which the data subject has agreed to;&nbsp;&nbsp;<br>c) for compliance with an employer&#8217;s legal obligation;&nbsp;&nbsp;<br>d) where the processing is necessary to protect to protect&nbsp;<\/p>\n\n\n\n<p>an individual\u2019s vital interests;&nbsp;<\/p>\n\n\n\n<p>e) where the processing is necessary in the public&nbsp;<br>interest;&nbsp;<\/p>\n\n\n\n<p>f) where the processing is necessary for the&nbsp;<br>purposes of legitimate interests pursued by the&nbsp;<\/p>\n\n\n\n<p>employer.&nbsp;<\/p>\n\n\n\n<p>Biometric data used to uniquely identify individuals is considered a \u2018special category\u2019 of personal data under the&nbsp;<br>GDPR. Processing of special categories of personal data is prohibited unless additional legal bases apply. Therefore, in&nbsp; addition to having one of the above legal bases for processing, the employer must ALSO have one of the following&nbsp;<br>legal bases:&nbsp;<\/p>\n\n\n\n<p>g) explicit consent;&nbsp;&nbsp;<\/p>\n\n\n\n<p>h) where the processing is necessary for the&nbsp;<\/p>\n\n\n\n<p>performance of specific rights or obligations in&nbsp;<br>employment\/social security\/social protection law&nbsp;<br>or a collective agreement;&nbsp;&nbsp;<\/p>\n\n\n\n<p>i) where the processing is necessary to protect to&nbsp;<br>protect an individual\u2019s vital interests where the&nbsp;<br>data subject is physically or legally incapable of&nbsp;<br>giving consent;&nbsp;&nbsp;<\/p>\n\n\n\n<p>j) where the processing is carried out by a non-profit&nbsp;<br>body in certain circumstances;&nbsp;<\/p>\n\n\n\n<p><img loading=\"lazy\" src=\"\" width=\"59\" height=\"50\"><strong>Consent&nbsp;<\/strong><\/p>\n\n\n\n<p>Explicit consent (i.e stated consent, or&nbsp;<\/p>\n\n\n\n<p>consent signified by some positive&nbsp;<\/p>\n\n\n\n<p>action such as ticking a box, not just consent which&nbsp;<\/p>\n\n\n\n<p>may be inferred from circumstances) given by the data&nbsp; subject to process their biometric data is one of these&nbsp; additional legal bases, however employee consent is&nbsp;<br>often not considered true consent due the&nbsp;<br>asymmetrical nature of the employer\/employee&nbsp;<br>relationship.&nbsp; Readers will also note from the list at g)- n) above that \u2018Legitimate interests\u2019 are not available&nbsp;<\/p>\n\n\n\n<p>as a legal basis to process biometric data.&nbsp;&nbsp;<\/p>\n\n\n\n<p>k) where the processing related to personal data&nbsp;<br>made public by the data subject themselves;&nbsp;&nbsp;<\/p>\n\n\n\n<p>l) where the processing is necessary for the&nbsp;<br>establishment, exercise or defence of legal claims;&nbsp;<\/p>\n\n\n\n<p>m) where the processing is necessary for reasons of&nbsp;<br>substantial public interest;&nbsp;<\/p>\n\n\n\n<p>n) where the processing is necessary in some limited&nbsp;<br>other circumstances as set out in Article 9 of the&nbsp;<br>GDPR.&nbsp;<\/p>\n\n\n\n<p>Considering these stricter consent obligations under&nbsp; the GDPR and the Article 29 Working Party guidance&nbsp; (the Article 29 group is now effectively the European&nbsp; Data Protection Board, the overseeing body of the&nbsp;<\/p>\n\n\n\n<p>GDPR), an employer who is processing biometric data&nbsp; of employees used to uniquely identify individuals&nbsp;<br>should seek alternative bases to explicit consent or&nbsp;<br>\u2018legitimate interests\u2019 to process its employees\u2019&nbsp;<br>biometric data. Unless an employer can make an&nbsp;<br>argument that it is processing biometric data under a&nbsp; collective agreement, or is doing so in the public&nbsp;<br>interest, no other alternative basis is currently&nbsp;<br>available. &nbsp;&nbsp;<br><\/p>\n\n\n\n<p>In our opinion, employees should be offered&nbsp;<br>alternatives to biometric clock in systems used to&nbsp; uniquely identify individuals. This is based on a pre- existing pre-GDPR decision from the Irish Data&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><\/td><\/tr><tr><td><\/td><td><img loading=\"lazy\" src=\"\" width=\"199\" height=\"107\"><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Protection Commission to that effect, which has now&nbsp; been reinforced by a recent Swedish decision in which&nbsp; a school was fined 200,000 Krona (about \u20ac19,000) for&nbsp; processing biometric data.&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/www.biometricupdate.com\/201908\/swedish-data-protection-authority-issues-first-fine-for-biometrics-use-under-gdpr\">https:\/\/www.biometricupdate.com\/201908\/swedish-<\/a> <a href=\"https:\/\/www.biometricupdate.com\/201908\/swedish-data-protection-authority-issues-first-fine-for-biometrics-use-under-gdpr\">data-protection-authority-issues-first-fine-for-<\/a><br><a href=\"https:\/\/www.biometricupdate.com\/201908\/swedish-data-protection-authority-issues-first-fine-for-biometrics-use-under-gdpr\">biometrics-use-under-gdpr&nbsp;<\/a><\/p>\n\n\n\n<p>One potential solution is to use biometric data for&nbsp;<br>non-identification purposes. Biometric data which is&nbsp;<br>used to authorise entry without identifying an&nbsp;<br>individual, but only identifying the fact that they are&nbsp;<br>one of a class of people who are entitled to entry or&nbsp;<br>access is not \u2018biometric data for the purpose of&nbsp;<br>uniquely identifying a natural person\u2019 and is therefore&nbsp; not Special Category Data and therefore only subject&nbsp; the less onerous legal bases in the list at a)-f) above.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><\/td><\/tr><tr><td><\/td><td><img loading=\"lazy\" src=\"\" width=\"705\" height=\"2\"><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>When is a Data Protection Impact Assessment (\u2018DPIA\u2019) required in Ireland?&nbsp;<\/strong><\/p>\n\n\n\n<p>Following the EDPB\u2019s Opinion, the Irish Data Protection Commission (<strong>DPC<\/strong>) has published a non-exhaustive list of&nbsp;<br>processing activities which require a DPIA to be carried out. The list encompasses both national and cross-border&nbsp;<br>data processing operations. It should be read in conjunction with Article 35 of the GDPR and the Article 29 Working&nbsp; Group Guidelines&nbsp;&nbsp;<\/p>\n\n\n\n<p>The DPC has determined that a DPIA will be mandatory for the following types of processing operations:&nbsp;<\/p>\n\n\n\n<p>1. Use of personal data on a large-scale for a&nbsp;<br>purpose(s) other than that for which it was&nbsp;<\/p>\n\n\n\n<p>initially collected (a compatibility test must also&nbsp;<br>be carried out pursuant to Article 6(4) GDPR).&nbsp;<\/p>\n\n\n\n<p>2. Profiling vulnerable persons including children to&nbsp;<br>target marketing or online services at such&nbsp;<br>persons.&nbsp;<\/p>\n\n\n\n<p>3. Use of profiling or algorithmic means or special&nbsp;<br>category data as an element to determine access&nbsp;<\/p>\n\n\n\n<p>to services or that results in legal or similarly&nbsp;<br>significant effects;&nbsp;<\/p>\n\n\n\n<p>4. Systematically monitoring, tracking or observing&nbsp;<br>individuals\u2019 location or behaviour.&nbsp;<\/p>\n\n\n\n<p>5. Profiling individuals on a large-scale.&nbsp;<\/p>\n\n\n\n<p>6. Processing biometric data to uniquely identify an&nbsp;<\/p>\n\n\n\n<p>individual or enable the identification or&nbsp;<br>authentication of an individual in combination&nbsp;<br>with any of the other criteria set out in the WP29&nbsp;<br>DPIA Guidelines.&nbsp;<\/p>\n\n\n\n<p>7. Processing genetic data in combination with any&nbsp;<br>of the other criteria set out in WP29 DPIA&nbsp;<br>Guidelines.&nbsp;<\/p>\n\n\n\n<p>8. &nbsp;&nbsp; Indirectly sourcing personal data where GDPR&nbsp;<br>transparency requirements are not being met,&nbsp;<br>including when relying on exemptions based on&nbsp;<\/p>\n\n\n\n<p>impossibility or disproportionate effort.&nbsp;<\/p>\n\n\n\n<p>9. Combining, linking or cross-referencing separate&nbsp;<\/p>\n\n\n\n<p>datasets where such linking significantly&nbsp;<br>contributes to or is used for profiling or&nbsp;<br>behavioural analysis of individuals, particularly&nbsp;<br>where the data sets are combined from different&nbsp;<br>sources where processing was\/is carried out for&nbsp;<br>different purposes or by different controllers.&nbsp;<\/p>\n\n\n\n<p>10. Large scale processing of personal data where the&nbsp;<br>Data Protection Act 2018 requires \u201csuitable and&nbsp;<br>specific measures\u201d to be taken in order to&nbsp;<br>safeguard the fundamental rights and freedoms&nbsp;<\/p>\n\n\n\n<p>of individuals.&nbsp;<\/p>\n\n\n\n<p>You will see that biometric data processing is at number 6. In our opinion that DPIA should conclude that you should&nbsp; offer an alternative to its employees. There is no requirement that such alternative be more convenient for the&nbsp;<br>employees&nbsp;<\/p>\n\n\n\n<p><img loading=\"lazy\" src=\"\" width=\"177\" height=\"114\"><strong>Brexit : this advice from August is worth repeating.&nbsp;&nbsp;<\/strong><\/p>\n\n\n\n<p>Are you an Irish company that transfers personal data to the UK?&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p><img loading=\"lazy\" src=\"\" width=\"265\" height=\"12\"><img loading=\"lazy\" src=\"\" alt=\"Reserved: This Photo by Unknown Author is licensed  under CC BY-SA  \" width=\"38702136\" height=\"6689263\">The proposed withdrawal agreement would have preserved the status quo in data&nbsp; protection terms, at least until the end of the transition period in December 2020.&nbsp; However, if the U.K. leaves the EU without a deal, the implications for&nbsp;<\/p>\n\n\n\n<p>international data flows and privacy compliance generally will be severe.&nbsp; Without&nbsp; additional actions, UK based processing of EU personal data will be illegal.&nbsp;<\/p>\n\n\n\n<p><strong>How to ascertain ways you might be transferring data to a UK-based company&nbsp;<\/strong><\/p>\n\n\n\n<p>\u2022 Are you outsourcing your HR, IT or Payroll function&nbsp;<br>to a UK based organisation?&nbsp;&nbsp;<\/p>\n\n\n\n<p>\u2022 Are you using a UK based marketing company to&nbsp;<br>send marketing communications to your customer&nbsp;<\/p>\n\n\n\n<p>database?&nbsp;<\/p>\n\n\n\n<p>\u2022 Is your pension scheme based in the UK?&nbsp;<\/p>\n\n\n\n<p>\u2022 Are you using a UK based company to analyse data&nbsp;<br>on visitors to your website?&nbsp;&nbsp;<\/p>\n\n\n\n<p>In a &#8216;No Deal&#8217; Brexit scenario you will need to put extra&nbsp;<br>measures in place to legally transfer this data.&nbsp; EU based&nbsp;<br>data controllers are not permitted to transfer personal data&nbsp; outside the EU\/EEA unless those standards are maintained.&nbsp; In a \u201cno-deal\u201d Brexit scenario, the UK will no longer be&nbsp;<\/p>\n\n\n\n<p>a member of the EU; instead, it will become a \u2018Third&nbsp;<br>Country\u2019.&nbsp; It will have to look for an Adequacy Ruling&nbsp;<\/p>\n\n\n\n<p>like Japan in time. This means that transfer of personal&nbsp;<\/p>\n\n\n\n<p>data from Ireland to the UK will be treated in the same&nbsp;<\/p>\n\n\n\n<p>way as transfers of personal data to countries like&nbsp;<\/p>\n\n\n\n<p>Australia or India etc.&nbsp;<\/p>\n\n\n\n<p>What this means in practice is that, in order to comply&nbsp;<\/p>\n\n\n\n<p>with GDPR rules, an Irish company intending to&nbsp;<\/p>\n\n\n\n<p>transfer personal data to the UK will need to put in&nbsp;<\/p>\n\n\n\n<p>place specific safeguards to protect the data in the&nbsp;<\/p>\n\n\n\n<p>context of its transfer and subsequent processing.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><\/td><\/tr><tr><td><\/td><td><img loading=\"lazy\" src=\"\" width=\"705\" height=\"2\"><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><img loading=\"lazy\" src=\"\" width=\"197\" height=\"131\"><strong>Recent Cases from around the world&nbsp;<\/strong><\/p>\n\n\n\n<p>\u2022 Are you storing or processing data in the UK on a&nbsp;<br>server or in the cloud?&nbsp;<\/p>\n\n\n\n<p>\u2022 Are you using web-based tools provided by or via&nbsp;<br>UK resources?&nbsp;<\/p>\n\n\n\n<p>This can be done in a number of different ways,&nbsp;<br>depending on the circumstances in which the data is&nbsp;<br>to be transferred. One such way is the use of&nbsp;<br>\u201cStandard Contractual Clauses\u201d or \u201cSCCs\u201d&nbsp; or\u201d Model&nbsp;<br>Clause Agreements \u201cand this is likely to be relevant to&nbsp; most Irish businesses that transfer personal data to&nbsp;<br>the UK.&nbsp;&nbsp;<\/p>\n\n\n\n<p>The Model Clause Agreements consist of standard or&nbsp; template sets of contractual terms and conditions that&nbsp; the Irish-based controller and the UK-based recipient&nbsp; both sign up to. The basic idea is that each of the&nbsp;<br>parties to the contract gives contractually binding&nbsp;<br>commitments to protect personal data in the context&nbsp; of its transfer from the EU\/EEA to the Third Country.&nbsp;<br>Importantly, the data subject is also given certain&nbsp;<br>specific rights under the SCCs even though he or she is&nbsp; not party to the relevant contract.<\/p>\n\n\n\n<p>Recently the data protection authority of North Rhine \u2013 Westphalia in Germany&nbsp;<br>has brought the matter into sharp focus into an investigation into the car industry.&nbsp;<\/p>\n\n\n\n<p>It pointed at the following: \u2013&nbsp;<\/p>\n\n\n\n<p>1. Vehicle data can be considered personal data if it can be linked to the&nbsp;<br>customer\u2019s name, or to a vehicle identification number;&nbsp;<br><\/p>\n\n\n\n<p>2. Data processing by a garage necessary for repair, service and maintenance including data transmission to the&nbsp;<br>manufacturer is legitimate where that is necessary for the purpose of fulfilling a contract to which the data&nbsp;<br>subject is party, but even in such circumstances the exact nature of the processing must be made clear to the&nbsp;<br>data subject.&nbsp; The recommendation was that this be done at the time of the order, in an addendum to order&nbsp;<br>documents;&nbsp;<\/p>\n\n\n\n<p>3. The data protection authority was more sceptical of transmission of personal data to manufacturers.&nbsp; In&nbsp;<br>particular, it formed the view that the garages and manufacturers were possibly both joint controllers of the&nbsp;<\/p>\n\n\n\n<p>personal data;&nbsp;<\/p>\n\n\n\n<p>It seems that the automotive industry is now becoming a focus for data protection, and that the data protection &nbsp;<br>commission here will be aware of this German investigation, as there is a regular formal coordination process&nbsp;<br>between all of the data protection authorities in the EU.&nbsp; We can expect that the DPC will be considering launching its&nbsp; own investigation, now that a large proportion of the work involved has already been done in Germany.&nbsp;<\/p>\n\n\n\n<p>Department of Social Protection, the DPC has directed&nbsp; that the department cease processing applications for&nbsp;<\/p>\n\n\n\n<p><strong>Breaking news in Ireland&nbsp;<\/strong><\/p>\n\n\n\n<p>We explained in our August Newsletter that the State&nbsp; has been told it must delete data held on 3.2 million&nbsp;<br>citizens, which was gathered as part of the roll-out of&nbsp; the Public Services Card, as there is no lawful basis for&nbsp; retaining it.&nbsp;<\/p>\n\n\n\n<p>In a report on its investigation into the card, the Data&nbsp; Protection Commission found there was no legal&nbsp;<br>reason to make individuals obtain the card in order to&nbsp; access State services such as renewing a driving&nbsp;<br>licence or applying for a college grant.&nbsp;<\/p>\n\n\n\n<p>While the card will still be sought from people&nbsp;<br>accessing some services directly administered by the&nbsp;<\/p>\n\n\n\n<p>cards needed for such functions.&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/www.dataprotection.ie\/en\/dpc-statement-matters-pertaining-public-services-card\">https:\/\/www.dataprotection.ie\/en\/dpc-statement-<\/a> <a href=\"https:\/\/www.dataprotection.ie\/en\/dpc-statement-matters-pertaining-public-services-card\">matters-pertaining-public-services-card&nbsp;<\/a><\/p>\n\n\n\n<p>The Minister has now said she is going to challenge&nbsp; any outcome arising from the findings. The report is&nbsp; below:&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-embed\"><div class=\"wp-block-embed__wrapper\">\nhttps:\/\/www.welfare.ie\/en\/pdf\/pr170919.pdf\n<\/div><\/figure>\n\n\n\n<p>It seems that the government is waiting for the DPC to&nbsp; issue a prosecution or fine, before reacting, so we will&nbsp; have to await any such prosecution or fine and the&nbsp;<br>inevitable Appeal\/Judicial Review.&nbsp;&nbsp;<br><\/p>\n\n\n\n<p><strong>Polish DPA imposes \u20ac645,000 fine for insufficient organisational and technical safeguards which led to personal&nbsp; data of 2.2 million data subjects being breached.&nbsp;<\/strong><\/p>\n\n\n\n<p>In the decision imposing the fine, the Polish DPA concluded that the company by&nbsp; failing to comply with the required technical means of data protection, had&nbsp;<br>breached, inter alia, the principle of confidentiality, as set out in Article 5 (1)(f) of&nbsp; the GDPR. Therefore, there had been unauthorised access to and obtaining of&nbsp;<br>customers\u2019 data. The authority considered that unsuccessful measures for the&nbsp;<br>authentication of data access were put in place. The company had implemented&nbsp; additional technical security measures after the breach.&nbsp;<br><\/p>\n\n\n\n<p>The investigation revealed that the infringement occurred also because of ineffective monitoring of potential risks.&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/edpb.europa.eu\/news\/national-news\/2019\/polish-dpa-imposes-eu645000-fine-insufficient-organisational-and-technical_en\">https:\/\/edpb.europa.eu\/news\/national-news\/2019\/polish-dpa-imposes-eu645000-fine-insufficient-organisational-<\/a> <a href=\"https:\/\/edpb.europa.eu\/news\/national-news\/2019\/polish-dpa-imposes-eu645000-fine-insufficient-organisational-and-technical_en\">and-technical_en&nbsp;<\/a><\/p>\n\n\n\n<p><strong>Google wins landmark right to be forgotten case&nbsp;<\/strong><\/p>\n\n\n\n<p>The Court of Justice of European Union on 24 September 2019 has agreed with the earlier decision of the Advocate&nbsp;<br>General (on 10 January 2019) in its ruling on this landmark case and found that the &#8220;Right to be Forgotten&#8221; as applied&nbsp; to Google search results only applies within the EU. Therefore, only domain names corresponding to EU Member&nbsp;<br>States may be dereferenced TOGETHER WITH geo-blocking preventing all access to that partially dereferenced&nbsp;<br>material from within the EU.&nbsp;&nbsp;<\/p>\n\n\n\n<p>This case was decided on jurisdictional grounds. It can just about be distinguished from Article 3.2 which does confer&nbsp; extra-territorial jurisdiction, as that extra-territorial jurisdiction is only in the context of the sale of goods or services,&nbsp; or of the monitoring of the behaviour of data subjects.&nbsp;<\/p>\n\n\n\n<p>It does make the Right to be Forgotten of only very limited use, as the information can now be accessed by technical&nbsp; means or simply by accessing the information from outside the EU.&nbsp;<\/p>\n\n\n\n<p>ECJ Decision 24 September 2019&nbsp;<\/p>\n\n\n\n<p><a href=\"http:\/\/curia.europa.eu\/juris\/document\/document.jsf?text=&amp;amp;docid=218105&amp;amp;pageIndex=0&amp;amp;doclang=EN&amp;amp;mode=req&amp;amp;dir=&amp;amp;occ=first&amp;amp;part=1&amp;amp;cid=1162593\">http:\/\/curia.europa.eu\/juris\/document\/document.j<\/a> <a href=\"http:\/\/curia.europa.eu\/juris\/document\/document.jsf?text=&amp;amp;docid=218105&amp;amp;pageIndex=0&amp;amp;doclang=EN&amp;amp;mode=req&amp;amp;dir=&amp;amp;occ=first&amp;amp;part=1&amp;amp;cid=1162593\">sf?text=&amp;docid=218105&amp;pageIndex=0&amp;doclang=EN<\/a> <a href=\"http:\/\/curia.europa.eu\/juris\/document\/document.jsf?text=&amp;amp;docid=218105&amp;amp;pageIndex=0&amp;amp;doclang=EN&amp;amp;mode=req&amp;amp;dir=&amp;amp;occ=first&amp;amp;part=1&amp;amp;cid=1162593\">&amp;mode=req&amp;dir=&amp;occ=first&amp;part=1&amp;cid=1162593&nbsp;<\/a><\/p>\n\n\n\n<p>Advocate General\u2019s Decision 10 January 2019&nbsp;<\/p>\n\n\n\n<p><a href=\"http:\/\/curia.europa.eu\/juris\/document\/document.jsf?docid=209688&amp;amp;mode=req&amp;amp;pageIndex=1&amp;amp;dir=&amp;amp;occ=first&amp;amp;part=1&amp;amp;text=&amp;amp;doclang=EN&amp;amp;cid=1162593\">http:\/\/curia.europa.eu\/juris\/document\/document.j<\/a> <a href=\"http:\/\/curia.europa.eu\/juris\/document\/document.jsf?docid=209688&amp;amp;mode=req&amp;amp;pageIndex=1&amp;amp;dir=&amp;amp;occ=first&amp;amp;part=1&amp;amp;text=&amp;amp;doclang=EN&amp;amp;cid=1162593\">sf?docid=209688&amp;mode=req&amp;pageIndex=1&amp;dir=&amp;o<\/a> <a href=\"http:\/\/curia.europa.eu\/juris\/document\/document.jsf?docid=209688&amp;amp;mode=req&amp;amp;pageIndex=1&amp;amp;dir=&amp;amp;occ=first&amp;amp;part=1&amp;amp;text=&amp;amp;doclang=EN&amp;amp;cid=1162593\">cc=first&amp;part=1&amp;text=&amp;doclang=EN&amp;cid=1162593<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Biometric Data processing.&nbsp; To be legally compliant with data protection law, an employer must have a&nbsp; \u201clawful basis\u201d or justifiable reason to process an employee\u2019s personal data.&nbsp;&nbsp; Ordinarily, under the GDPR, these reasons could include:&nbsp;&nbsp; a) employee consent;&nbsp;&nbsp; b) where the processing is necessary for the performance of&nbsp; a contract to which the data subject &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/www.bizlegal.eu\/?page_id=2547\"> <span class=\"screen-reader-text\">Newsletter September 2019<\/span> Read More &raquo;<\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":""},"coauthors":[],"author_meta":{"author_link":"https:\/\/www.bizlegal.eu\/?author=3","display_name":"Sharon McGauley"},"relative_dates":{"created":"Posted 6 years ago","modified":"Updated 6 years ago"},"absolute_dates":{"created":"Posted on 24\/05\/2020","modified":"Updated on 24\/05\/2020"},"absolute_dates_time":{"created":"Posted on 24\/05\/2020 9:56 am","modified":"Updated on 24\/05\/2020 9:56 am"},"featured_img_caption":"","featured_img":false,"series_order":"","_links":{"self":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2547"}],"collection":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2547"}],"version-history":[{"count":1,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2547\/revisions"}],"predecessor-version":[{"id":2548,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2547\/revisions\/2548"}],"wp:attachment":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2547"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}