So who is holding them? And are they complying with GDPR?
Not sure you can abrogate your responsibility by saying someone else holds the data
As LongsightM13 said, you can't entirely abrogate your responsibilities, but GDPR is primarily concerned with the data stored on your systems. If it's not stored on your systems, the company that does store it must demonstrate that they can meet these legal requirements.
If you don't want a picture taken and stored of your face, can you legally request that?
Presume so - understand there were a couple of people who objected to the system and have been allowed to clock in in a manual way. How this would work if City changed the terms and conditions of entry into the ground, I don't know.
Yes but what about if and when your company or City gets hacked (are M&S back online yet?) and all these images end up on some Russian rag's AI generated fake porn site?
Well clearly as a fan base, we're all beautiful enough for that, but its hard to explain all of the precautions behind such schemes to limit the chances of that happening. Of course, its impossible to limit it to zero. Then again, the chances of someone nicking your phone and getting in to watch City on your card is now reduced. Swings and roundabouts...



