The Facts
Company introduces site attendance policy with biometric fingerprint scanning
A company introduced a biometric fingerprint scanning system as part of its new site attendance policy for all its employees. This measure was intended to provide security, safety and efficiency benefits for the company.
After the policy was announced during a floor meeting in October 2017, all company staff were directed to register their fingerprints over the following week. Once registered, employees would then check in and out of the company’s work sites by using scanners provided at the start and finish of each shift.
Employee refuses to provide fingerprints
One employee was a casual general hand who had worked at the company for more than three years. In November 2017 he was called in and attended a meeting, but did not provide his fingerprints when asked to do so.
The following day he met his supervisors, who provided him with further information about the site attendance policy and the scanning system. They provided reasons for the decision to introduce the scanners and the benefits the system would bring to the company.
Employee concerns regarding third party access to fingerprint data
The employee said he was not satisfied that the company could guarantee that third parties would not be able to access the electronically stored fingerprint data and there was no guarantee that the biometric information in his prints could not be used by any other persons.
The employee then wrote to the company, setting out his concerns about privacy and his objection to providing his fingerprints. The company responded with additional information about the nature of the fingerprint data collection.
The company provided the employee with documentation from the suppliers of the scanners, which said that the data collected could not be used “for any other purpose other than linking your payroll number to a clock in/out time”.
Company dismisses employee after discussions and warnings
The scanners were implemented in January 2018. Meanwhile, the employee continued to check in and out of work using the sign in and out book.
He was given a verbal warning and was subsequently warned in writing that if he continued to fail to comply with the policy, it would result in his employment being terminated.
The employee wrote to the company that he wished to be allowed to keep his job, but insisted on retaining ownership of his biometric data. Further discussions did not result in any resolution.
In February 2018 a show cause letter was issued to the employee, after which he was dismissed.
The employee brought an application in the Fair Work Commission for unfair dismissal. It was up to the commission to determine whether it was reasonable and lawful for the employer to require the employee to provide the biometric data and if so, whether the dismissal was harsh, unjust or unreasonable.
Expert commentary on the court's decision
Fair Work Commission initial decision in favour of employer
In the case Mr Jeremy Lee v Superior Wood Pty Ltd T/A Superior Wood [2018] FWC 4762, the Fair Work Commission at first instance determined that the dismissal of the employee, Mr Jeremy Lee, was valid. It said that the site attendance policy of the company, Superior Wood, was “reasonably necessary” to improve safety and payroll efficiency.
In considering the application of the Privacy Act, the commission said that despite the fact the company did not have a privacy policy, more weight should be given to the reasonable necessity of the site attendance policy. The commission found that there had been a valid reason for the dismissal.
Having regard to potential breaches of the Privacy Act, the commission concluded that the dismissal was not, in all the circumstances, harsh, unjust or unreasonable.
Successful appeal to Full Bench of Fair Work Commission
In Jeremy Lee v Superior Wood Pty Ltd [2019] FWCFB 2946, Mr Lee appealed the decision to the Full Bench of the Fair Work Commission on several grounds. The main argument centered on the key questions of whether failure to comply with the company’s policy was a valid reason for dismissal and whether the employer’s obligations under the privacy laws had been breached.
Overturning the initial decision, the Full Bench found that the company’s reasons for the dismissing Mr Lee were not valid, and that the dismissal had contravened Australian privacy laws.
Superior Wood had not complied with its privacy obligations. Mr Lee was within his rights to refuse to provide his fingerprint data. The company’s directions to him after he had refused consent were in breach of privacy laws.
Concerns related to confidentiality of fingerprint data found to be valid
The Full Bench also upheld Mr Lee’s concerns regarding management of the fingerprint data and its confidentiality, finding that the company was not aware of and did not comply with its obligations.
Prior to introducing the scanners, Superior Wood should have sought and provided employees with detailed information. It should have given notice to employees that it was seeking to collect what was in fact sensitive information. It should have had a privacy policy and a mechanism to manage and protect the fingerprint data after its collection.
Policies in force at commencement of employment contract
While Superior Wood maintained that Mr Lee’s failure to comply with its site attendance policy amounted to a breach of his employment contract and was a valid reason for his dismissal, the Full Bench determined that compliance with the site attendance policy was not a term covered by the contract:
Compliance with Privacy Act necessary for company’s conduct to be lawful
The Full Bench determined that the legality of Mr Lee’s obligation to comply with his employer’s site attendance policy depended on whether the company’s conduct in directing him to provide fingerprints for scanning by the biometric scanners amounted to “reasonable and lawful” conduct.
Superior Wood’s conduct would have been lawful if it had complied with the Privacy Act, which expressly prohibits acts and practices that breach the Australian Privacy Principles. Mr Lee submitted that Superior Wood’s direction to him to register his fingerprints was captured by prohibitions under the Privacy Act.
Relevance of Australian Privacy Principles
In determining Mr Lee’s appeal, the Full Bench provided considerable detail and invaluable analysis of the relevant sections of the Privacy Act. In particular it gave a detailed review of the relevant Australian Privacy Principles.
Australian Privacy Principle 1 requires the company or business entity to have an up-to-date and clearly expressed policy and about its management of personal information and how it manages storage of that personal information in an open and transparent way.
The Full Bench noted that at the time it was introducing its site attendance policy and directing employees to provide their fingerprints for scanning, Superior Wood did not have the necessary privacy policy, as required by this principle.
The direction to Mr Lee to provide his fingerprints for collection was issued in circumstances where Superior Wood had no privacy policy and no controls in place for the collection, use and storage of the information or data in question.
In addition, Superior Wood had provided no evidence that it or any related entities were able to protect and manage information collected according to privacy obligations.
Members of company management had made little effort to make themselves aware of privacy laws and their obligations. While it had the means to do so, Superior Wood had received no expert advice, nor had it engaged any human resources personnel to provide specialist knowledge about privacy protection and private information management.
Australian Privacy Principle 3 prohibits the collection of an individual’s sensitive information without consent, unless the information is “reasonably necessary” for the company’s activities or for the company’s functioning. Any collection of personal information can only occur by lawful and fair means.
The Full Bench found Superior Wood’s direction for Mr Lee to provide his fingerprints, after he had clearly refused consent, was not “reasonably necessary”, and therefore it was unlawful. Mr Lee was entitled to refuse to follow those directions.
Australian Privacy Principle 3 also defines “sensitive information” to include biometric information to be used for the purpose of automated biometric verification or biometric identification. The Full Bench noted that collection of fingerprint data by the scanners fits the description of sensitive information: “Fingerprint data is unique to the individual and it is derived from an individual’s biometric characteristics, both above and beneath the skin”.
A person is entitled to seek to protect private information if this type. The privacy principle in question applies not only to the collection, but also to the solicitation of sensitive information.
It was further asserted by legal counsel for Mr Lee that even if he had given his consent after being threatened with disciplinary action or dismissal, that consent would have been prompted by the threat and therefore would not have been a genuine consent.
Australian Privacy Principle 5 provides that before or as soon as practicable after collection of personal information, reasonable steps must be taken to notify individuals of a certain number of matters, some of which are to be included in the entity’s privacy policy.
Such notice to employees about the nature of the collection of personal information is to include details about who is doing the collecting, the purposes for which the private information is being collected, the consequences if the information is not collected, how the information may be accessed and corrected, how to make complaints about breaches of the Australian Privacy Principles, how complaints will be dealt with, whether it is likely the information would be disclosed to overseas recipients, and if so, in which countries those recipients may be located.
In addition, it was noted that Superior Wood had failed to issue a privacy collection notice. This fact had weighed considerably in Mr Lee’s favour in the appeal.
The Full Bench of the FWC found that Mr Lee was within his rights to refuse consent to having his fingerprints scanned and registered. Superior Wood had no valid reason to dismiss him.
It was found that the safety and convenience factors, asserted by Superior Wood, did not sufficiently establish that it was reasonably necessary for the employer to collect Mr Lee’s fingerprints, “particularly in circumstances where other options had been identified and had not yet been considered.”
Outcome a hollow victory for employee
Mr Lee’s dismissal was found to be unjust and procedurally unfair. However, it was also found that his reinstatement would be inappropriate. He received 26 weeks’ pay as compensation for unfair dismissal, but was out of a job.
For more information please see our July 2022 article Crackdown on facial recognition on social media.