...
Skip to content

Biometric technology raises liability concerns

The use of biometric technology is expanding as businesses look beyond passwords to make financial transactions safer, to reduce fraud, and to better secure access to their premises.

In the era of COVID-19, biometrics companies are adding new features to detect illness and body temperature, for example, that could be deployed by organizations.

But as facial recognition, fingerprint, voice recognition and other biometric technologies become more commonplace, especially in customer-facing sectors such as retail and hospitality, there are growing concerns around data privacy and security, experts say.

Companies deploying the technologies are also seeing heightened exposure to litigation as more states enact laws to regulate the collection and use of biometric data, experts say. 

Biometrics use creates “an immediate intersection between very personal and private and sensitive things” that are the equivalent of health care records, said Chad Pinson, president of Stroz Friedberg LLC, an Aon PLC company in Dallas.

“This is a personal concern and a regulatory concern. There are laws around privacy and health care records and security,” Mr. Pinson said.

“In other words, some of the things that can work well for us and are convenient for us are intersecting right up against some of the things people hold most dear and sacred,” he said. 

Companies use biometric technologies for several reasons, the main purpose being identity verification, said Walker Taylor IV, Wilmington, North Carolina-based senior managing director of Arthur J. Gallagher & Co.’s life sciences practices group.

On the one hand, “it can be harder to steal biometric information than just a password, so companies can protect sensitive data and track the use of entries and exits,” Mr. Taylor said.

However, since biometrics are unique physical identifiers, there are associated risks, including possible hacking and theft of this information, and the potential for false positives in the employment context if an employee is terminated, harassed or discriminated against, he said.

Biometric privacy laws have become a big risk to companies, especially for larger firms that operate in multiple jurisdictions, said Laura Lapidus, New York-based risk control director for CNA’s management liability business.

While there is no federal law on biometric privacy, the 2008 Biometric Information Privacy Act in Illinois allows private actions by individuals and class-action lawsuits.

“You may not have your home office in Illinois, but if you operate in Illinois and have employees on a biometric time clock in Illinois you’d better make sure you are compliant with the Illinois law,” Ms. Lapidus said.

It’s not just Illinois’ BIPA that companies need to be concerned about, experts say.

Texas and Washington also have biometric privacy laws in place, while California includes biometric information within the California Consumer Privacy Act that went into effect Jan. 1, 2020.

A growing number of states have also introduced proposed legislation on biometrics regulation, including Arizona, Massachusetts, New York, South Carolina and West Virginia. 

As the laws catch up to biometrics, there has been an increase in claims associated with using these technologies, said Gamelah Palagonia, senior vice president for network security, data privacy and technology errors and omissions, at Willis Towers Watson PLC.

For example, BIPA’s private right of action allows for statutory damages of $1,000 per negligent violation and $5,000 if it’s egregious, she said.

Noncompliance fines are “a huge exposure for companies that may not have known they were exposed to these laws,” Ms. Palagonia said.

For this reason, it’s critical for companies that collect and use biometric data to follow protocols to gain the necessary consent for the collection of that information, she said.

“There are so many protocols around the collection of this data that you just can’t do it ad hoc. You have to establish protocol for gaining consent, and consent has to be specific to the use it’s being collected for,” Ms. Palagonia said.

From the perspective of a risk manager or treasurer, part of the challenge for businesses is that the adoption of biometric or other technologies can represent a “massive shift in their risk profile,” said Adam Peckman, New York-based director and global practice leader of Aon PLC’s cyber solutions practice.

“Their risk profile has shifted from one where traditionally they didn’t have any concerns around privacy or cyber liability, to now potentially holding or processing more of that data,” Mr. Peckman said.

“They are trying to get their heads around that and then stress test the traditional risk financing insurance programs to see how they handle the new reality they face,” he said.

Biometrics is making cyber insurance more relevant to non-traditional buyers, Mr. Peckman said.

“If you’re a manufacturer or a retailer and you’re looking to adopt this technology and haven’t been buying cyber (coverage), you need to have greater affirmative coverage around these exposures,” he said.

Policyholders should review their insurance coverages to determine how they apply to biometric technologies, experts say.

More insurance and risk management news on the coronavirus crisis here.