Biometric Data
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing of biometric data for identification
Overview
24 sources · Jul 23, 2026Legal Framework
Biometric data processing for identification sits at the intersection of Article 9 GDPR and the AI Act Article 5. Under Article 9(1), biometric data processed for the purpose of uniquely identifying a natural person is categorised as a special category subject to a general prohibition. The only widely available lift for commercial controllers is Article 9(2)(a): explicit consent.
"processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited."
— GDPR Art. 9(1)
The consent must be explicit — a higher standard than Article 6(1)(a) — and freely given:
"the data subject has given explicit consent to the processing of those personal data for one or more specified purposes, except where Union or Member State law provide that the prohibition referred to in paragraph 1 may not be lifted by the data subject"
— GDPR Art. 9(2)(a)
Where biometric identification is embedded in an AI system, Article 5 AI Act adds a further layer: certain real-time remote biometric identification practices in publicly accessible spaces are prohibited outright, while other biometric categorisation and evaluation uses may fall under high-risk classification.
Key Developments
The CJEU's Schwarz ruling (C-291/12) upheld fingerprint processing under a specific legal basis but acknowledged that centralisation risks must be assessed separately. The court noted that alternative technologies were not yet equivalent:
"iris-recognition technology is not yet as advanced as fingerprint-recognition technology. In addition, the procedure for iris recognition is currently significantly more expensive than the procedure for comparing fingerprints and is, for that reason, less suitable for general use."
— Schwarz ¶52
Dutch courts have enforced data subjects' rights to destruction of biometric police data where retention lacked a basis:
"Eiser heeft op 6 juli 2023 bij verweerder op grond van artikel 28, tweede lid, van de Wpg een verzoek ingediend tot vernietiging van zijn politiegegevens en zijn biometrische gegevens."
— Rectificatie en vernietiging politiegegeven ¶2
The EDPB has actively scrutinised biometric use in both commercial and law-enforcement contexts, issuing guidance on facial recognition in airports (Opinion 11/2024) and in policing (Guidelines 05/2022), signalling that proportionality and necessity are assessed stringently.
Status of the Debate
This area is actively contested. The core prohibition in Article 9(1) is settled, but the boundaries of its exceptions — particularly whether consent can ever be freely given in employment or service-provider contexts where biometric identification is functionally required — remain litigated. Courts diverge on whether biometric convenience features (e.g., fingerprint unlock) constitute processing "for the purpose of uniquely identifying" or merely authentication. The AI Act's interaction with GDPR Article 9 adds a further unresolved layer, as Member States transpose divergent national rules on biometric processing in employment and law enforcement. Resolution will likely come through CJEU preliminary references on whether consent-based biometric processing in imbalanced relationships satisfies the "freely given" requirement.
Practical Guidance
- Map the purpose precisely. Only biometric data processed "for the purpose of uniquely identifying" triggers Article 9. Distinguish authentication (confirming a claimed identity) from identification (discovering identity) — the former may fall outside Article 9 if no template database is searched.
- Obtain explicit, granular consent. Under Article 9(2)(a), consent must be explicit and separate from other consents. In employment contexts, assess whether power imbalances render consent non-freely-given; consider alternative legal bases or anonymised approaches.
- Assess AI Act classification. If biometric processing is embedded in an AI system, determine whether Article 5 prohibitions (e.g., real-time remote biometric identification in public spaces) or high-risk obligations apply.
- Implement strict retention and destruction protocols. As Dutch courts have ordered destruction of biometric police data when retention lacked justification, controllers should define purpose-specific retention periods and provide mechanisms for data subjects to request erasure.
- Conduct a DPIA. Biometric processing for identification always requires a data protection impact assessment under Article 35 GDPR, documenting necessity, proportionality, and safeguards against unauthorised access to biometric templates.