Many companies have a ‘meet the team’ page on their website which displays mugshots of their employees. Some even use employee photos in marketing materials such as brochures and reports. While these are great ways to show the human side of your business, it is crucial to understand that photos can constitute personal information (or even special personal information) and therefore be subject to data protection laws.
In this article, you will learn how to identify if your company is complying with data protection law when using photos of employees. The first question is aimed at finding out whether the photo in question is personal information as defined in data protection law. Since personal information is essentially any information that identifies a person, an employee’s photo will fall under this definition if it has identifiers such as a name associated with the image. The question is less clear when there are no identifiers. In these scenarios, you need to look at whether the employee’s face is in focus, and if it is, then it is likely personal information. If you have established that the photo is personal information, the next crucial step is to consider whether it is a biometric photo and therefore special personal information. We suggest looking at whether the photo in question meets the requirements of a passport photo. It is only once you have concluded that the photo is either personal information or special personal information that you then need to comply with relevant data protection laws. This means relying on a lawful justification for processing the photo. The relevant lawful justifications for processing your employee’s photo depends on whether it is a biometric photo or not. If it is not a biometric photo, you have the option of relying on either consent or legitimate interest, whereas a biometric photo can only be processed if you have obtained consent from your employee. We recommend relying on the consent justification in both instances and you can do this by putting in place an Employee Privacy Policy or sending your employee a consent form in niche use cases (like using their photo in a brochure or on a billboard).
How we can help
- We can help you lawfully process employee personal data by drafting an Employee Privacy Policy for you (or review your existing policy). We will review it, make suggested edits, and insert comments as necessary.
- Get consent from your employee to lawfully process their photo for a specific purpose in terms of POPI by asking us to draft a consent form for you (or review your existing form). We will review it, make suggested edits, and insert comments as necessary.
- Join our programme to find out more about protecting the personal information about employees and you can access our Personnel Privacy Policy template that you are able to use.
- Raise your level of awareness by getting our Consent and Disclosure Guide for POPI
Is your employee’s photo ‘personal information’?
As a point of departure, you need to establish whether the photo in question is indeed subject to data protection law. To establish this, you need to look closely at the definition of ‘personal data’ as defined in your relevant data protection law. For those of you situated in Europe, ‘personal data’ is defined in the GDPR as any information relating to an identified or identifiable natural person (‘data subject’). In other words, any information that is clearly about a particular person. For those in South Africa, the definition of ‘personal information’ in POPIA is very similar to that of the GDPR:
‘Personal information’ means information relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person.
In order to unpack this practically, we going to divide it into two scenarios:
Face in focus with identifiers
If your employees’ photos are accompanied by an identifier like their name and it is focused on their face, then there is a strong argument that they can be identified. This is a clear-cut case where the photo will be classed as personal information.
No identifiers
The question of whether photos of your employees is personal information becomes less clear when there are no identifiers. It is important to consider Recital 26 of the UK GDPR for guidance here, as it says that you should assume that you are not looking just at the means reasonably likely to be used by an ordinary person, but also by a determined person with a particular reason to want to identify individuals. So you need to consider the fact that people can do Google image searches and look on other platforms like LinkedIn.
Unnamed images of people will constitute personal information if there is other contextual information that would enable individuals to be identified.
The key question we recommend asking is whether the face of the employee is in focus. If your employee is looking down or away from the camera and there are no other identifiers attached to the photo, then in these instances, you could argue that it isn’t personal information. If the employee protests, then simply take down the photo. But if their face is in focus, we would recommend erring on the side of caution and treat the photo as personal information.
If your employee’s face is in focus, err on the side of caution and treat it as personal information
Is the employee’s photo special information?
Please note that when an employee is identifiable in a photo, sensitive personal information like ethnicity and biometric data is communicated and this adds further complexities under POPIA. In terms of ethnicity, “the UK’s Information Commissioner’s Office (ICO) has taken the view that the depiction of someone’s skin colour is not a clear indication of ethnicity and should not, by itself, be regarded as sensitive personal data.” On the other hand, when it comes to the question of what constitutes a biometric photo, the answer is still very unclear.
Biometric photos
- their face must be looking towards the camera
- their eyes are looking into the camera
- they must have a neutral facial expression (no smiling)
- it must be a monochrome background (light grey or grey are best)
- no shadows must be visible on their face or in the background
Considering the above, there is a strong argument that some employee mugshots on the ‘meet the team’ page of a company website do constitute a biometric photo. This is important in the context of POPIA because the processing of special personal information is prohibited unless you are authorised to do so (see section 27 of POPIA).
Facial recognition technology is improving at a drastic rate and we foresee that more and more photos that would previously not have been regarded as biometric photos will start being labelled as so.
What can you do under data protection law?
So if you have established that an employee’s photo is indeed personal or special information, then your processing of that photo will be governed by data protection law. In South Africa, this means complying with the POPIA’s 8 conditions.
There are only two relevant legal justifications for the processing of employee photos:
- Consent (which is voluntary, specific and informed); and
- legitimate interest.
Where it is a biometric photo of your employee, you will need to get authorisation by means of express consent. For non-biometric photos, The use of your employee’s photo for promotional purposes could be explored as a means of establishing legitimate interest as a lawful basis for using the photos. This is a tricky argument to rely on and we would suggest rather relying on consent in this instance as well.
Consent
The definition of consent in data protection law is very specific as it must be freely given, specific, informed and unambiguous (Recital 40 of the GDPR ).
POPIA defines consent as “any voluntary, specific and informed expression of will in terms of which permission if given for the processing of personal information”.
It is recommended in the light of these definitions that you secure specific consent for the use of your employee’s photo as general consent is unlikely to be adequate in this instance due to its lack of specificity. This can be done by means of a Human Resources Data Protection Policy (i.e. an internal employee privacy policy) for scenarios where it would be reasonably expected in the course of employment (e.g. an employee profile on your website). For more niche situations like reports and brochures, we recommend sending your employee a consent form for that specific purpose.
In many cases, an employee is likely to give consent for their photograph to be used, as it can help to raise an individual’s professional profile, but it is important to bear in mind that data protection law requires that you afford your employee the option to withdraw their consent at any time. The upshot of this is that you will need to remove their photograph which can cause a problem.
Quick tip
Going forward, we suggest that you map in which cases you process photos of employees, and, subsequently, determine which processing activities require consent. If you decide not to rely on consent, it is important to document reasoning prior to this decision, taking into account the accountability principle.