Why fingerprints and facial patterns should not be treated as passwords

An analysis of whether biometric unlocking (fingerprint, Face ID) of a device is covered by the right against self-incrimination (Arts. 17.3 and 24.2 of the Spanish Constitution), and when the judicial police need authorisation to access its contents.

For several years now there has been a doctrinal debate as to whether fingerprints, facial patterns or any other biometric recognition system fall within the right not to confess guilt and not to testify against oneself, derived from Articles 17.3 and 24.2 of the Spanish Constitution, as well as Article 14 of the International Covenant on Civil and Political Rights and Article 6 of the European Convention on Human Rights.

This question is especially relevant now that most phones and computers feature biometric recognition systems. On the one hand they make repeated access to the device easy; on the other, in certain situations they may allow the device’s contents to be examined by third parties acting within their state-conferred powers — for example, the security forces.

We will therefore distinguish two stages in the act of the judicial police accessing a device that is switched on and locked. First, the act of unlocking the device; second, examining its contents to obtain relevant information.

Unlocking

The mere fact that a subject can unlock a device can provide valuable information to the judicial police. From that moment the subject cannot claim to have no connection with the device, since they must previously have had access to it in order to identify themselves — via password — and register their own valid biometric pattern, whether or not they are the owner.

Among the unlocking systems — which use authentication factors — there are, broadly, four routes:

  • Something the user knows and expresses: PIN, password, drawn pattern.
  • Something the user does or solves: patterns combined with specific knowledge, a test, arithmetic calculations, solving a CAPTCHA, etc.
  • Something the user has: a token — usually a temporary code — for example, for banking transactions.
  • Something the user is, and cannot change: fingerprints, iris, facial patterns, DNA or brain waves.

An unlocking pattern can be based on anything, provided it can be reproduced without alteration (or imperceptibly to the device) over time, and ideally so that the device unlocks only for a single individual — the owner — or an authorised person. There are, therefore, certain human biometric patterns that indicate a human being is themselves and not another individual (so-called selfhood — the condition of being oneself) and that satisfy those two conditions: fingerprints, iris, facial patterns (such as Apple’s Face ID) and, in the not-too-distant future, those based on DNA or brain waves. So we have, on the one hand, biometric patterns that unlock the device by what you are, and on the other, patterns or passwords that require you to express what you know. By way of analogy: it is not the same to be asked to reveal your password as to be asked to hand over a piece of paper on which it is written.

To unlock a device using one of these biometric recognition systems, there is no need to express or externalise the subject’s will in any way. In other words, no act of will by the owner is required: the device unlocks by detecting that the biometric pattern matches the one previously stored.

Whereas unlocking a device by entering numbers (a PIN), drawing patterns on the screen or entering passwords does require an externalised expression of the subject’s will, in the case of biometric patterns it does not — and therefore they cannot be covered by Articles 17.3 and 24.2 of the Constitution, or the other provisions cited at the outset.

Here “absence of externalisation” refers to the concept found within the theory of the offence: ideas, thoughts or intentions are not treated as an act, however connected they may be with a legally relevant fact.

Accessing the device’s contents once unlocked

The reason a judicial authorisation is required is that these devices are treated as storage for a complex set of data affecting the suspect’s privacy in very different ways — files, photos, emails, conversations. Such authorisation is necessary where mobile phones are seized during a home search, or seized outside the suspect’s home. The diverse functionality of the data held on these devices creates an extreme weakness in the judicial protection of the suspect’s right to the privacy of their own virtual environment: once the device is accessed, past the barrier of the password or biometric pattern, all the data — including data covered by the secrecy of communications — is freely available to the investigator.

While case law establishes that the direct examination of a mobile phone’s contacts by judicial police officers is admissible — on the view that it affects not the secrecy of communications but the right to privacy (Art. 18 of the Constitution) — it also establishes that interference with that right requires that it be “justified according to the criteria of urgency and necessity, and that the requirement of proportionality be met when weighing the interests at stake in the specific case.”

There is therefore no single answer: the interference with the right to privacy through a direct police search of the device must be justified and reasoned case by case, always in accordance with the criteria of urgency and necessity. Failing that, the evidence may be rendered null, undermining a conviction. It is therefore important that police protocols provide for it and, in case of doubt, that the corresponding judicial authorisation be sought before examining the contents or extracting information — carried out under suitable conditions so as not to break the chain of custody, which could lead to a separate nullity.

This article, of my authorship, was originally published (in Spanish) in Legaltoday, Aranzadi–Thomson Reuters, on 30 July 2018. Original article in Spanish