# Biometric Data — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/biometric-data
> Sources are cited per item. Verify against the official texts before relying on them.

Processing of biometric data for identification

## Overview

## Legal Framework

Biometric data processing for identification sits at the intersection of [Article 9 GDPR](/laws/gdpr/art-9) and the [AI Act Article 5](/laws/ai-act/art-5). Under [Article 9(1)](/laws/gdpr/art-9#par-1), biometric data processed for the purpose of uniquely identifying a natural person is categorised as a special category subject to a general prohibition. The only widely available lift for commercial controllers is [Article 9(2)(a)](/laws/gdpr/art-9#par-1): explicit consent.

> "processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited."
> — [GDPR Art. 9(1)](/laws/gdpr/art-9#par-1)

The consent must be explicit — a higher standard than Article 6(1)(a) — and freely given:

> "the data subject has given explicit consent to the processing of those personal data for one or more specified purposes, except where Union or Member State law provide that the prohibition referred to in paragraph 1 may not be lifted by the data subject"
> — [GDPR Art. 9(2)(a)](/laws/gdpr/art-9#par-1)

Where biometric identification is embedded in an AI system, Article 5 AI Act adds a further layer: certain real-time remote biometric identification practices in publicly accessible spaces are prohibited outright, while other biometric categorisation and evaluation uses may fall under high-risk classification.

## Key Developments

The CJEU's *Schwarz* ruling (C-291/12) upheld fingerprint processing under a specific legal basis but acknowledged that centralisation risks must be assessed separately. The court noted that alternative technologies were not yet equivalent:

> "iris-recognition technology is not yet as advanced as fingerprint-recognition technology. In addition, the procedure for iris recognition is currently significantly more expensive than the procedure for comparing fingerprints and is, for that reason, less suitable for general use."
> — [Schwarz ¶52](/posts/6167#seg-52)

Dutch courts have enforced data subjects' rights to destruction of biometric police data where retention lacked a basis:

> "Eiser heeft op 6 juli 2023 bij verweerder op grond van artikel 28, tweede lid, van de Wpg een verzoek ingediend tot vernietiging van zijn politiegegevens en zijn biometrische gegevens."
> — [Rectificatie en vernietiging politiegegeven ¶2](/posts/50705#seg-2)

The EDPB has actively scrutinised biometric use in both commercial and law-enforcement contexts, issuing guidance on facial recognition in airports (Opinion 11/2024) and in policing (Guidelines 05/2022), signalling that proportionality and necessity are assessed stringently.

## Status of the Debate

This area is actively contested. The core prohibition in Article 9(1) is settled, but the boundaries of its exceptions — particularly whether consent can ever be freely given in employment or service-provider contexts where biometric identification is functionally required — remain litigated. Courts diverge on whether biometric convenience features (e.g., fingerprint unlock) constitute processing "for the purpose of uniquely identifying" or merely authentication. The AI Act's interaction with GDPR Article 9 adds a further unresolved layer, as Member States transpose divergent national rules on biometric processing in employment and law enforcement. Resolution will likely come through CJEU preliminary references on whether consent-based biometric processing in imbalanced relationships satisfies the "freely given" requirement.

## Practical Guidance

- **Map the purpose precisely.** Only biometric data processed "for the purpose of uniquely identifying" triggers Article 9. Distinguish authentication (confirming a claimed identity) from identification (discovering identity) — the former may fall outside Article 9 if no template database is searched.
- **Obtain explicit, granular consent.** Under [Article 9(2)(a)](/laws/gdpr/art-9#par-1), consent must be explicit and separate from other consents. In employment contexts, assess whether power imbalances render consent non-freely-given; consider alternative legal bases or anonymised approaches.
- **Assess AI Act classification.** If biometric processing is embedded in an AI system, determine whether Article 5 prohibitions (e.g., real-time remote biometric identification in public spaces) or high-risk obligations apply.
- **Implement strict retention and destruction protocols.** As Dutch courts have ordered destruction of biometric police data when retention lacked justification, controllers should define purpose-specific retention periods and provide mechanisms for data subjects to request erasure.
- **Conduct a DPIA.** Biometric processing for identification always requires a data protection impact assessment under Article 35 GDPR, documenting necessity, proportionality, and safeguards against unauthorised access to biometric templates.

## Legislation (full text of key provisions)

### Recital 15 — biometric identification definition

*Source: AI Act, aiact-rec-15-en, 2024-06-12 — https://overview.legal/posts/93712*

The notion of ‘biometric identification’ referred to in this Regulation should be defined as the automated recognition of physical, physiological and behavioural human features such as the face, eye movement, body shape, voice, prosody, gait, posture, heart rate, blood pressure, odour, keystrokes characteristics, for the purpose of establishing an individual’s identity by comparing biometric data of that individual to stored biometric data of individuals in a reference database, irrespective of whether the individual has given its consent or not. This excludes AI systems intended to be used for biometric verification, which includes authentication, whose sole purpose is to confirm that a specific natural person is the person he or she claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having security access to premises.

### Recital 17 — remote biometric identification system definition

*Source: AI Act, aiact-rec-17-en, 2024-06-12 — https://overview.legal/posts/93716*

The notion of ‘remote biometric identification system’ referred to in this Regulation should be defined functionally, as an AI system intended for the identification of natural persons without their active involvement, typically at a distance, through the comparison of a person’s biometric data with the biometric data contained in a reference database, irrespectively of the particular technology, processes or types of biometric data used. Such remote biometric identification systems are typically used to perceive multiple persons or their behaviour simultaneously in order to facilitate significantly the identification of natural persons without their active involvement. This excludes AI systems intended to be used for biometric verification, which includes authentication, the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having security access to premises. That exclusion is justified by the fact that such systems are likely to have a minor impact on fundamental rights of natural persons compared to the remote biometric identification systems which may be used for the processing of the biometric data of a large number of persons without their active involvement. In the case of ‘real-time’ systems, the capturing of the biometric data, the comparison and the identification occur all instantaneously, near-instantaneously or in any event without a significant delay. In this regard, there should be no scope for circumventing the rules of this Regulation on the ‘real-time’ use of the AI systems concerned by providing for minor delays. ‘Real-time’ systems involve the use of ‘live’ or ‘near-live’ material, such as video footage, generated by a camera or other device with similar functionality. In the case of ‘post’ systems, in contrast, the biometric data has already been captured and the comparison and identification occur only after a significant delay. This involves material, such as pictures or video footage generated by closed circuit television cameras or private devices, which has been generated before the use of the system in respect of the natural persons concerned.

### Recital 39 — biometric data processing compliance requirements

*Source: AI Act, aiact-rec-39-en, 2024-06-12 — https://overview.legal/posts/93760*

Any processing of biometric data and other personal data involved in the use of AI systems for biometric identification, other than in connection to the use of real-time remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement as regulated by this Regulation, should continue to comply with all requirements resulting from Article 10 of Directive (EU) 2016/680. For purposes other than law enforcement, Article 9(1) of Regulation (EU) 2016/679 and Article 10(1) of Regulation (EU) 2018/1725 prohibit the processing of biometric data subject to limited exceptions as provided in those Articles. In the application of Article 9(1) of Regulation (EU) 2016/679, the use of remote biometric identification for purposes other than law enforcement has already been subject to prohibition decisions by national data protection authorities.

### Recital 94 — law enforcement biometric data processing compliance

*Source: AI Act, aiact-rec-94-en, 2024-06-12 — https://overview.legal/posts/93870*

Any processing of biometric data involved in the use of AI systems for biometric identification for the purpose of law enforcement needs to comply with Article 10 of Directive (EU) 2016/680, that allows such processing only where strictly necessary, subject to appropriate safeguards for the rights and freedoms of the data subject, and where authorised by Union or Member State law. Such use, when authorised, also needs to respect the principles laid down in Article 4 (1) of Directive (EU) 2016/680 including lawfulness, fairness and transparency, purpose limitation, accuracy and storage limitation.

### Recital 38 — real-time biometric identification law enforcement

*Source: AI Act, aiact-rec-38-en, 2024-06-12 — https://overview.legal/posts/93758*

The use of AI systems for real-time remote biometric identification of natural persons in publicly accessible spaces for the purpose of law enforcement necessarily involves the processing of biometric data. The rules of this Regulation that prohibit, subject to certain exceptions, such use, which are based on Article 16 TFEU, should apply as lex specialis in respect of the rules on the processing of biometric data contained in Article 10 of Directive (EU) 2016/680, thus regulating such use and the processing of biometric data involved in an exhaustive manner. Therefore, such use and processing should be possible only in as far as it is compatible with the framework set by this Regulation, without there being scope, outside that framework, for the competent authorities, where they act for purpose of law enforcement, to use such systems and process such data in connection thereto on the grounds listed in Article 10 of Directive (EU) 2016/680. In that context, this Regulation is not intended to provide the legal basis for the processing of personal data under Article 8 of Directive (EU) 2016/680. However, the use of real-time remote biometric identification systems in publicly accessible spaces for purposes other than law enforcement, including by competent authorities, should not be covered by the specific framework regarding such use for the purpose of law enforcement set by this Regulation. Such use for purposes other than law enforcement should therefore not be subject to the requirement of an authorisation under this Regulation and the applicable detailed rules of national law that may give effect to that authorisation.

### Recital 95 — post remote biometric identification safeguards

*Source: AI Act, aiact-rec-95-en, 2024-06-12 — https://overview.legal/posts/93872*

Without prejudice to applicable Union law, in particular Regulation (EU) 2016/679 and Directive (EU) 2016/680, considering the intrusive nature of post-remote biometric identification systems, the use of post-remote biometric identification systems should be subject to safeguards. Post-remote biometric identification systems should always be used in a way that is proportionate, legitimate and strictly necessary, and thus targeted, in terms of the individuals to be identified, the location, temporal scope and based on a closed data set of legally acquired video footage. In any case, post-remote biometric identification systems should not be used in the framework of law enforcement to lead to indiscriminate surveillance. The conditions for post-remote biometric identification should in any case not provide a basis to circumvent the conditions of the prohibition and strict exceptions for real time remote biometric identification.

### Recital 34 — responsible use of real-time biometric identification

*Source: AI Act, aiact-rec-34-en, 2024-06-12 — https://overview.legal/posts/93750*

In order to ensure that those systems are used in a responsible and proportionate manner, it is also important to establish that, in each of those exhaustively listed and narrowly defined situations, certain elements should be taken into account, in particular as regards the nature of the situation giving rise to the request and the consequences of the use for the rights and freedoms of all persons concerned and the safeguards and conditions provided for with the use. In addition, the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement should be deployed only to confirm the specifically targeted individual’s identity and should be limited to what is strictly necessary concerning the period of time, as well as the geographic and personal scope, having regard in particular to the evidence or indications regarding the threats, the victims or perpetrator. The use of the real-time remote biometric identification system in publicly accessible spaces should be authorised only if the relevant law enforcement authority has completed a fundamental rights impact assessment and, unless provided otherwise in this Regulation, has registered the system in the database as set out in this Regulation. The reference database of persons should be appropriate for each use case in each of the situations mentioned above.

### Recital 33 — law enforcement biometric identification exceptions

*Source: AI Act, aiact-rec-33-en, 2024-06-12 — https://overview.legal/posts/93748*

The use of those systems for the purpose of law enforcement should therefore be prohibited, except in exhaustively listed and narrowly defined situations, where the use is strictly necessary to achieve a substantial public interest, the importance of which outweighs the risks. Those situations involve the search for certain victims of crime including missing persons; certain threats to the life or to the physical safety of natural persons or of a terrorist attack; and the localisation or identification of perpetrators or suspects of the criminal offences listed in an annex to this Regulation, where those criminal offences are punishable in the Member State concerned by a custodial sentence or a detention order for a maximum period of at least four years and as they are defined in the law of that Member State. Such a threshold for the custodial sentence or detention order in accordance with national law contributes to ensuring that the offence should be serious enough to potentially justify the use of ‘real-time’ remote biometric identification systems. Moreover, the list of criminal offences provided in an annex to this Regulation is based on the 32 criminal offences listed in the Council Framework Decision 2002/584/JHA (18), taking into account that some of those offences are, in practice, likely to be more relevant than others, in that the recourse to ‘real-time’ remote biometric identification could, foreseeably, be necessary and proportionate to highly varying degrees for the practical pursuit of the localisation or identification of a perpetrator or suspect of the different criminal offences listed and having regard to the likely differences in the seriousness, probability and scale of the harm or possible negative consequences. An imminent threat to life or the physical safety of natural persons could also result from a serious disruption of critical infrastructure, as defined in Article 2, point (4) of Directive (EU) 2022/2557 of the European Parliament and of the Council (19), where the disruption or destruction of such critical infrastructure would result in an imminent threat to life or the physical safety of a person, including through serious harm to the provision of basic supplies to the population or to the exercise of the core function of the State. In addition, this Regulation should preserve the ability for law enforcement, border control, immigration or asylum authorities to carry out identity checks in the presence of the person concerned in accordance with the conditions set out in Union and national law for such checks. In particular, law enforcement, border control, immigration or asylum authorities should be able to use information systems, in accordance with Union or national law, to identify persons who, during an identity check, either refuse to be identified or are unable to state or prove their identity, without being required by this Regulation to obtain prior authorisation. This could be, for example, a person involved in a crime, being unwilling, or unable due to an accident or a medical condition, to disclose their identity to law enforcement authorities.

### Recital 14 — biometric data definition interpretation

*Source: AI Act, aiact-rec-14-en, 2024-06-12 — https://overview.legal/posts/93710*

The notion of ‘biometric data’ used in this Regulation should be interpreted in light of the notion of biometric data as defined in Article 4, point (14) of Regulation (EU) 2016/679, Article 3, point (18) of Regulation (EU) 2018/1725 and Article 3, point (13) of Directive (EU) 2016/680. Biometric data can allow for the authentication, identification or categorisation of natural persons and for the recognition of emotions of natural persons.

### Recital 35 — real-time biometric identification law enforcement authorisation

*Source: AI Act, aiact-rec-35-en, 2024-06-12 — https://overview.legal/posts/93752*

Each use of a ‘real-time’ remote biometric identification system in publicly accessible spaces for the purpose of law enforcement should be subject to an express and specific authorisation by a judicial authority or by an independent administrative authority of a Member State whose decision is binding. Such authorisation should, in principle, be obtained prior to the use of the AI system with a view to identifying a person or persons. Exceptions to that rule should be allowed in duly justified situations on grounds of urgency, namely in situations where the need to use the systems concerned is such as to make it effectively and objectively impossible to obtain an authorisation before commencing the use of the AI system. In such situations of urgency, the use of the AI system should be restricted to the absolute minimum necessary and should be subject to appropriate safeguards and conditions, as determined in national law and specified in the context of each individual urgent use case by the law enforcement authority itself. In addition, the law enforcement authority should in such situations request such authorisation while providing the reasons for not having been able to request it earlier, without undue delay and at the latest within 24 hours. If such an authorisation is rejected, the use of real-time biometric identification systems linked to that authorisation should cease with immediate effect and all the data related to such use should be discarded and deleted. Such data includes input data directly acquired by an AI system in the course of the use of such system as well as the results and outputs of the use linked to that authorisation. It should not include input that is legally acquired in accordance with another Union or national law. In any case, no decision producing an adverse legal effect on a person should be taken based solely on the output of the remote biometric identification system.

## Case law

### CJEU - C‑371/24 - Comdribus

*Source: GDPRhub, 2026-03-19 — https://overview.legal/posts/125595 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑371/24_-_Comdribus*

Facts — In 2020, law enforcement officers arrested several people from a climate protest. One of the individuals detained (the data subject) provided their identity, but refused to be fingerprinted and photographed, as well as to provide the code to their phone (or unlock it themselves). The data subject was later accused before the Paris Criminal Court of unlawfully organising a protest, as well as refusing to provide their data for identification and investigation purposes in accordance with national law . The court found them guilty of not providing their biometric data and fined the data subject €300. Both the data subject and Public Prosecutor appealed the decision to the Paris Court of Appeal. The court requested a preliminary ruling from the CJEU, regarding the compatibility of national law with provisions of the Law Enforcement Directive (LED), taking into consideration previous case law . Specifically, the court had questions regarding the systematic processing of biometric data of a data subject reasonably suspected of having committed or attempted to commit an offense in the context of an investigation, when the data subject has not necessarily been accused of committing an offense. The court referred the following questions: 1. Does the Law Enforcement Directive 2016/680 preclude national legislation from systematically processing identification data from data subjects who are suspected of having committed or attempted to commit an offense? 2. Does the Law Enforcement Directive 2016/680 require national legislation to oblige a competent authority to sufficiently explain why it is strictly necessary to process this data on an individual basis? 3. Does the Law Enforcement Directive 2016/680 preclude national legislation from allowing data subjects to be prosecuted on the basis of refusing to provide identification data, even if they are not prosecuted for or convicted of the offense under which said data was processed? The French Government argued that the national law complies with the strict necessity requirements of the LED. For example, the wording of the law leaves the competent authority the discretion to process non-sensitive data for the purposes of the investigation. In addition, national law provisions strictly limit the processing of biometric data for investigation purposes. Finally, the government questioned the admissibility of the second and third questions, arguing that both concerned matters outside the scope of EU law. Holding — Question 1: systematic collection of biometric data under national law — The court first noted that Article 10 Law Enforcement Directive 2016/680 aims to ensure a higher level of protection for personal data that is considered sensitive by nature (e.g. biometric data), as its processing can create significant risks for data subjects’ fundamental rights. Under Article 10 Law Enforcement Directive 2016/680, processing activities allowed under national law must also be strictly necessary in relation to the purposes of processing this data. This also requires the purposes to be sufficiently precise, and the processing activities to be relevant and respects the principle of data minimisation (Article 4(1)(c) Law Enforcement Directive 2016/680). Therefore, Member States must either delegate the responsibility of complying with these requirements to a competent authority, or include assessment criteria in national law for authorities to follow. In this case, the court found that national law is not compatible with the LED in terms of collecting biometric data in an indiscriminate and generalised manner. This is because it provided for the systematic collection of biometric and genetic data of any person accused of an intentional offense with the purpose of entering them in a record, without also obliging competent authorities to demonstrate first that this data processing is strictly necessary. The court stated that the scope of processing biometric data was particularly broad, as it concerned all data subjects reasonably suspected of having committed or attempted to commit a criminal offense. The court took into consideration the possible interferences with data subjects’ fundamental rights . The court concluded that it was for the referring court to determine whether national law required the police authority to carry out a systematic collection of biometric data, and to verify the data subject’s claim of an automated database containing the fingerprints of 6.5 million data subjects. Question 2: obligation of a competent authority to explain the necessity of the data processing — The court first stated that this question was admissible, as it concerned the obligations of a national competent authority in relation to EU law (Article 10 of the LED). The court then noted that the obligation to implement appropriate safeguards when processing biometric data is connected to data subjects’ fundamental right to an effective judicial remedy (Article 47 CFR). Therefore, a competent authority must provide data subjects with information on why it is “strictly necessary” to process their biometric data to allow them to exercise this right. The court stated that this information could be succinct in order to not compromise the investigation. However, the information must also be sufficiently clear. Furthermore, this obligation was essential in ensuring that a competent authority carries a case by case assessment on whether it is “strictly necessary” to process a data subject’s biometric data, as well as allowing national courts to review the competent authority’s decision. This is especially relevant in relation to the competent authority’s obligation to demonstrate compliance with Articles 4(1)(a) to (c) Law Enforcement Directive 2016/680, as it acts as a controller in accordance with Article 3(8) Law Enforcement Directive 2016/680. In any event, this judicial review cannot compensate for cases where the competent authority is not obliged to state the reasons why the data processing is strictly necessary. Finally, the court noted that this obligation is not an excessive burden for the authority, since it was clear that it may not systematically process biometric data of data subjects reasonably suspected of having committed or attempted to commit an offense. Question 3: refusal to provide biometric data as an offense — The court first stated that this question was admissible, as it was not obvious that the facts in dispute bear no relation to EU law. The court clarified that the LED was also applicable to situations in which a competent authority attempts to process personal data. Therefore, if national law imposes a criminal penalty for refusing to provide this data, this penalty is lawful if it complies with the LED (in essence, the processing must meet the conditions of strict necessity in accordance with Article 10 Law Enforcement Directive 2016/680 and Articles 4(1)(a) to (c) Law Enforcement Directive 2016/680 and 8 Law Enforcement Directive 2016/680). The court stated that the LED does not preclude national law allowing data subjects to be prosecuted on the basis of refusing to provide identification data, even if they are not prosecuted for or convicted of the offense under which said data was processed. However, national law must meet the strict necessity requirement under Article 10 Law Enforcement Directive 2016/680, and the criminal penalty must be proportionate. The court noted that fact that a data subject is reasonably suspected of committing an offense or attempted to commit an offense is not in itself decisive to determine whether the data processing is strictly necessary. In addition, the criminal penalty must be proportionate to the offense, and take into account the individual circumstances of each case. The court concluded that it was for the referring court having jurisdiction to impose a criminal penalty to take into consideration the individual circumstances of the case.

### Dutch Supreme Court: Bank may require online ID copy and selfie for AMLD compliance

*Source: Supreme Court of the Netherlands, 2025-02-21 — https://overview.legal/posts/108994 — original: https://gdprhub.eu/index.php?title=Hoge_Raad_-_24/02161*

Facts — The data subject applied for a credit card in 2008 and was granted it. In July 2020, the bank (controller) requested that the data subject identify themselves online by providing a copy of their ID and a digital selfie. A bank employee would then compare the two images and approve it. The data subject was informed that this was necessary to comply with the provisions of the Fourth Anti-Money Laundering Directive (AMLD) and failure to do this would result in their card being terminated. In late July and early August, the controller contacted the data subject, again requesting that they verify their identity through the online portal. On 17 August 2020, the data subject was informed that their credit card agreement would be cancelled in November 2020, unless they verified their identity before then. In September 2020, the data subject sued the controller in the Subdistrict Court of Amsterdam, which declared some of her claims as inadmissible and dismissed others. In August 2021, the data subject appealed to the Amsterdam Court of Appeal. The data subject sought, inter alia, the restoration of their credit card, the payment of compensation, and a declaration that the bank’s proposed method of identification is unlawful. In March 2024, the Amsterdam Court of Appeal upheld the decision of the lower Court. The data subject then appealed to the Supreme Court. The data subject argued that the processing of biometric data in the identity verification procedure is unlawful under Article 9(1) GDPR and that the appellate court had erred in finding that the controller could retain copies of their ID after the verification had been performed. Holding — The Parket opined that the verification of the data subject’s identity in this method did not constitute biometric processing, falling under Article 9 GDPR. The Parket reasoned that the identification of the individual in this process is performed by an employee of the controller, not by software. The processing operation was therefore not performed by “technical means” as required in the definition of biometric data. The court noted that this was sufficiently clear so as to not require any questions to be referred to the Court of Justice. In relation to the question of the legitimacy of the retention of the ID by the bank, the Parket ruled that this practice was lawful. The Parket referenced the obligation to perform customer due diligence under the ALMD and to store the documents and data used to comply with this provision “in a retrievable manner”. The Parket therefore ruled that a directive-compliant interpretation of this provision means that institutions are obliged to retain copies of IDs used for verification. Accordingly, the Parket recommended that the Supreme Court dismiss the applicant’s appeal.

### CJEU - C-205/21 - Ministerstvo na vatreshnite raboti

*Source: GDPRhub, 2023-01-26 — https://overview.legal/posts/158437 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-205/21_-_Ministerstvo_na_vatreshnite_raboti*

Facts — A data subject was accused of a criminal offence and refused to consent to the collection of her genetic and biometric data (Photographs and fingerprints), which the Bulgarian Police required to create a record. The data subject also refused to let the police take a sample for the purpose of creating a DNA profile. In the end, the police did not collect this data. The police went to a Bulgarian Criminal court (Spetsializiran nakazatelen sad), which was also the referring court in this case. Here, the police asked the court to authorise the forced collection of the genetic and biometric data, considering there was enough evidence to convict the data subject of the crime. The police position was mostly based on Bulgatian law (ZMVR, Law of the ministry of Home affairs) authorising the collection of biometric and genetic data for, among the others, law and order purposes. However, the referring court had doubts whether the such law was actually compliant with EU law. This Bulgarian law did refer to Article 9 GDPR, but did not refer to EU directive 2016/680. The latter is an EU directive which concerns the protection of personal data regarding processing of competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties. This directive states that the processing of certain special category data, including genetic and biometric data, can be lawful if this is compliant with EU law or national law. The Bulgarian law had even taken over some of the wording from Article 10(a) of this directive for its national provision. The court determined that there were two problems resulting from the fact that this national law contained a reference to the GDPR, but did not mention the aforementioned directive. The first problem was the fact that the GDPR was not applicable to the processing of personal data with regard to criminal investigations, pursuant to Article 2(2)(d) GDPR. The second problem was the fact that Article 9 GDPR prohibited the processing of genetic and biometric data. The court also reiterated that a law enforcement purpose could not fall under one of the exceptions under Article 9(2) GDPR. The referring court referred several questions to the CJEU. The main issue was to know whether the processing of genetic and biometric data for purposes of criminal investigations in this case was permissible under the national law, despite the mention of Article 9 GDPR, and despite the fact that EU directive 2016/680 was not mentioned in the national law. Holding — First, The CJEU determined that both Article 9 GDPR and Article 10 of the directive contain provisions regarding the processing of special categories of personal data, including biometric en genetic data. Second, The CJEU determined that processing of biometric and genetic data by the police authorities could be permissible, as long as this processing fell under Article 10(a) of the directive. This meant that the processing had to be strictly necessary, with adequate safeguards and was provided for in national / EU law, pursuant to Article 52 CFR. However, it could still be unlawful to process this data, when this processing also fell within the scope of the GDPR. Third, The court stated that the requirement of authorised by Union or Member State' law in Article 10a of the directive must be interpreted pursuant to Article 52(1) CFR, which states that any limitation on the exercise of a fundamental right "must be ‘provided for by law". The legal basis which is used for this limitation (in this case, the legal basis was the Bulgarian law), must define the scope of the limitation sufficiently clearly and precisely. This meant that there should not be any uncertainty about the laws concerning - or the conditions of the processing of genetic and biometric data. However, The CJEU also noted that these conditions of processing could vary between the GDPR and the directive. In this context, The CJEU determined that the member states were free to organise their processing operations under either the GDPR or the aforementioned directive. However, member states would have to make sure that there would be no uncertainty about the fact which law would be applicable to different kinds of processing of biometric/genetic data. Fourth, The court also determined that member states were not obligated to cite the directive in the national law itself when they were transposing this directive into national law. It was therefore not necessary for the Bulgarian legislature to mention directive 2016/680 in its transposed national provisions. Fifth, the CJEU noted that national courts had the obligation to explain the national law. For this explanation, the national court had to consider the wording of the directive and the context of the directive. This was an obligation pursuant to Article 288 TFEU, which was applicable to all public bodies of a member state, including national courts. In the present case, where there was an obvious conflict between the GDPR and the directive, the national court had to provide an explanation which would keep the useful working of the directive intact. The CJEU stated that it was up to the national court to determine if the reference to Article 9 GDPR in the Bulgarian law was even correct. The court concluded that it was up to the national court to assess the case. In summary, the Court noted that the processing of the biometric and genetic data by the police could be lawful in this case if it fell under Article 10(a) of the directive. Also, the national implementation of the directive needed to have a sufficiently clear and precise legal basis for the processing of biometric/genetic data by the Bulgarian police. The fact that Article 9 GDPR was mentioned in this law was of no consequence for the legality of this processing, nor was the fact that the directive was not mentioned in the national implementation. However, the explanation by the national court of this Bulgarian law had to be sufficiently precise and clear. Also, this explanation of the national court should state in an unequivocal manner whether certain processing of biometric and genetic data would fall under the directive, or would fall under the GDPR.

### Judgment of the Court (Fourth Chamber) of 16 April 2015.#W. P. Willems and Others v Burgemeester van Nuth and Others.#Requests for a preliminary ruling from the Raad van State.#Reference for a preliminary ruling — Area of freedom, security and justice — Biometric passport — Biometric data — Regulation (EC) No 2252/2004 — Article 1(3) — Article 4(3) — Use of data collected for purposes other than the issue of passports and travel documents — Establishment and use of databases containing biometric

*Source: Court of Justice of the European Union, C-446/12, 2015-04-16 — https://overview.legal/posts/132363 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0446*

In Joined Cases C-446/12 to C-449/12, the Court of Justice of the European Union (Fourth Chamber) ruled on a preliminary reference from the Dutch Raad van State regarding whether biometric data collected for passport issuance under Regulation (EC) No 2252/2004 may be stored in and used from central national databases for purposes beyond document issuance. The Court held that while the Regulation does not itself regulate the establishment or use of such databases—leaving that to national law—any secondary storage or use of biometric data must comply with the data protection principles of Directive 95/46/EC and the fundamental rights to privacy and data protection under Articles 7 and 8 of the EU Charter, including requirements of necessity, proportionality, and purpose limitation. No fine was imposed.

### Judgment of the Court (First Chamber) of 3 October 2019.#Staatssecretaris van Justitie en Veiligheid v A and Others.#Request for a preliminary ruling from the Raad van State.#Reference for a preliminary ruling — EEC-Turkey Association Agreement — Decision No 2/76 — Article 7 — Decision No 1/80 — Article 13 — ‘Standstill’ clauses — New restriction — Collection, registration and retention of biometric data of Turkish nationals in a central filing system — Overriding reasons of public interest — Ob

*Source: Court of Justice of the European Union, C-70/18, 2019-10-03 — https://overview.legal/posts/132337 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0070*

The CJEU ruled on a preliminary reference from the Dutch Council of State in Case C-70/18, Staatssecretaris van Justitie en Veiligheid v. A, B, and P, addressing whether the Netherlands' obligation for Turkish nationals to provide biometric data for residence permits constitutes a "new restriction" under the standstill clauses of Article 7 of Decision No. 2/76 and Article 13 of Decision No. 1/80 of the EEC-Turkey Association Agreement. The Court held that requiring the collection, registration, and retention of biometric data in a central filing system does amount to a new restriction within the meaning of those provisions, but may be justified by the overriding public interest objective of preventing identity and document fraud, provided the measure is proportionate and complies with Articles 7 and 8 of the Charter of Fundamental Rights regarding respect for private life and protection of personal data. No fine was imposed, as the ruling was limited to interpretive guidance for the referring national court.

### Judgment of the Court (Grand Chamber) of 21 March 2024.#RL v Landeshauptstadt Wiesbaden.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Regulation (EU) 2019/1157 – Strengthening the security of identity cards of EU citizens – Validity – Legal basis – Article 21(2) TFEU – Article 77(3) TFEU – Regulation (EU) 2019/1157 – Article 3(5) – Obligation for Member States to include two fingerprints in interoperable digital formats in the stora

*Source: Court of Justice of the European Union, C-61/22, 2024-03-21 — https://overview.legal/posts/132266 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0061*

The Court of Justice of the European Union (Grand Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden in proceedings between RL and the Landeshauptstadt Wiesbaden concerning RL's request for an identity card without fingerprints, which the city rejected. The core issue was the validity of Regulation (EU) 2019/1157, particularly Article 3(5), which obliges Member States to include two fingerprints in the storage medium of EU citizens' identity cards, and whether the regulation was validly adopted under Articles 21(2) and 77(3) TFEU and complies with Articles 7 and 8 of the Charter of Fundamental Rights. The Court upheld the regulation's validity, finding the legal basis appropriate and the fingerprint storage requirement a proportionate interference with fundamental rights that is justified by the objective of strengthening identity document security and preventing fraud, while also clarifying Member States' obligation to conduct data protection impact assessments under Article 35 of GDPR for the national implementing measures.

### SCHWARZ V. BOCHUM, 17.10.2014 (“SCHWARZ”)

*Source: CJEU, 2013-10-17 — https://overview.legal/posts/6167 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0291&ref=6167*

No sufficiently effective yet less invasive alternative exist as taking fingerprints/pictures is causes no physical or mental discomfort and the technology for the only alternative (iris scan) is not advance enough. (¶¶ 48-53).

### SCHWARZ V. BOCHUM, 17.10.2014 (“SCHWARZ”)

*Source: CJEU, 2013-10-17 — https://overview.legal/posts/6165 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0291&ref=6165*

Processing: Taking and storing fingerprints constitute processing. (¶¶ 28–29)

### SCHWARZ V. BOCHUM, 17.10.2014 (“SCHWARZ”)

*Source: CJEU, 2013-10-17 — https://overview.legal/posts/6166 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0291&ref=6166*

Necessity/proportionality: Secure storage of fingerprints reduces risk of passports falsification and to facilitates EU borders control and,thus, it is appropriate.(¶¶ 41-45).

### SCHWARZ V. BOCHUM, 17.10.2014 (“SCHWARZ”)

*Source: CJEU, 2013-10-17 — https://overview.legal/posts/6163 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0291&ref=6163*

Centralized storage of the data and used for other purposes does not affect the validity of the Regulation, which provides only for preventing illegal entry into the EU. (¶¶ 61-62)

### Judgment of the Court (Fourth Chamber) of 4 October 2024.#Maximilian Schrems v Meta Platforms Ireland Limited.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Online social networks – General terms of use relating to contracts concluded between a digital platform and a user – Personalised advertising – Article 5(1)(b) – Principle of purpos

*Source: Court of Justice of the European Union, C-446/21, 2024-10-04 — https://overview.legal/posts/132159 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0446*

In a preliminary ruling arising from proceedings between Maximilian Schrems and Meta Platforms Ireland Limited, the Court of Justice of the European Union interpreted GDPR Articles 5(1)(b), 5(1)(c), 6(1), and 9 concerning the lawfulness of processing user personal data for personalised advertising on online social networks. The Court addressed whether such processing can be deemed compatible with the original purpose of data collection under a platform's terms of use, the applicability of the data minimisation principle, and the conditions under which special categories of personal data, including data concerning sexual orientation made public by the data subject, may be processed. No fine was imposed, as the ruling provides interpretative guidance to the Austrian Supreme Court for resolution of the underlying dispute.

### Judgment of the Court (First Chamber) of 7 December 2023.#OQ v Land Hessen.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 22 – Automated individual decision-making – Credit information agencies – Automated establishment of a probability value concerning the ability of a person to meet payment commitments in the future (‘s

*Source: Court of Justice of the European Union, C-634/21, 2023-12-07 — https://overview.legal/posts/132279 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0634*

In Case C-634/21, the CJEU addressed a preliminary ruling from the Verwaltungsgericht Wiesbaden concerning OQ's challenge against Land Hessen's refusal to order SCHUFA Holding AG to grant access to and erase personal data, including a credit score. The core issue was whether the automated calculation of a probability value ("scoring") by a credit information agency regarding a person's future ability to meet payment commitments constitutes an automated individual decision-making under Article 22(1) of the GDPR when third parties use that score for their own decisions. The Court held that such scoring does not itself amount to a decision producing legal effects under Article 22(1), as it is the third party, not the credit agency, that makes the decision based on the score.

## Guidance

### Opinion 11/2024 on the use of facial recognition to streamline airport passengers’ flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR)

*Source: EDPB, opinion-112024-on-the-use-of-facial-recognition-to-streamline-en, 2024-05-24 — https://overview.legal/posts/125750 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-112024-on-the-use-of-facial-recognition-to-streamline_en*

A dopted Opinion 11/2024 on the use of facial recognition to streamline airport passengers’ flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR Version 1.1 Adopted on 23 May 20 24 Adopted 1 Version 1.1 28 May 2024 Grammatical correction in the E xecutive summary (pages 3 and 4) and paragraphs 77 and 90 of the Opinion Version 1.0 23 May 2024 Adoption of the Opinion Adopted 2 Executive summary The French Supervisory Authority requested the European Data Protection Board to issue an…

### Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement

*Source: EDPB, edpb-guidelines-on-the-use-of-facial-recognition technology-in-the-area-of-law-enforcement, 2023-05-17 — https://overview.legal/posts/38075 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-052022-on-the-use-of-facial-recognition-technology-in-the-area-of_en*

More  and  more  law  enforcement  authorities  (LEAs)  apply  or  intend  to  apply  facial  recognition technology (FRT). It may be used to authenticate or to identify a person and can be applied on videos (e.g. CCTV) or  photographs. It may be used for various purposes, including to search for persons  in police watch lists or to monitor a person's movements in the public space. FRT is  built on the processing of biometric data , therefore, it encompasses the processing of special categories ...

### EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

*Source: EDPB, edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the-en, 2021-06-18 — https://overview.legal/posts/126016 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the_en*

1 Adopted EDPB - EDPS Joint Opinion 5 /2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmo nised rules on artificial i ntelligence (Artificial Intelligence Act) 18 June 2021 2 Adopted Executive Summary On 2 1 April 2021, the European Commission presented its Proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (hereinafter “the Proposal”) . The EDPB and the EDPS welcome…

### Guidelines 3/2019 on processing of personal data through video devices

*Source: EDPB, edpb-guidelines-on-processing-of-personal-data-through-video-devices, 2020-01-30 — https://overview.legal/posts/38059 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-32019-on-processing-of-personal-data-through-video-devices_en*

The European Data Protection Board (EDPB) adopted Guidelines 3/2019 to provide comprehensive guidance on the processing of personal data through video devices,including CCTV and smart camera systems, under the GDPR. The guidelines address key issues such as the scope of application, the household exemption, lawfulness of processing under Article 6(1)(f) GDPR (legitimate interests), data subjects' rights, and obligations of controllers, while also clarifying the boundary with the Law Enforcement Directive (EU 2016/680). The guidelines were adopted on 29 January 2020 following public consultation and do not impose fines but serve as interpretative guidance for controllers and supervisory authorities.

### Opinion 26/2018 on the draft list of the competent supervisory authority of Luxembourg regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-262018-on-the-draft-list-of-the-competent-supervisory-en, 2018-12-04 — https://overview.legal/posts/126264 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-262018-on-the-draft-list-of-the-competent-supervisory_en*

1 Adopted EDPB Plenary meeting, 04/05.12.2018 Opinion 26 /2018 on the draft list of the competent supervisory authority of Luxembourg regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 4 December 2018 2 Adopted TABLE OF C ONTENTS 1 Summary of the Facts ................................ ................................ ................................ ..................... 4 2 Assessment…

### Opinion 3/2018 on the draft list of the competent supervisory authority of Bulgaria regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-32018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126291 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-32018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 3 /2018 on the draft list of the competent supervisory authority of Bulgaria regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 21/2018 on the draft list of the competent supervisory authority of Slovakia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-212018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126305 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-212018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 21 /2018 on the draft list of the competent supervisory authority of Slovakia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 10/2018 on the draft list of the competent supervisory authority of Hungary regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-102018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126282 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-102018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 10 /2018 on the draft list of the competent supervisory authority of Hungary regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

## Enforcement decisions

### School in Skellefteå: Insufficient legal basis for data processing

*Source: Data Protection Authority of Sweden, 2019-08-20 — https://overview.legal/posts/46182 — original: https://www.enforcementtracker.com/ETid-67*

A school in Skellefteå made a trial to use facial recognition technology. The fine was imposed against the school which had used facial recognition technology to monitor the attendance of students. Even though, in general, data processing for the purpose of monitoring attendance is possible doing so with facial recognition is disproportioned to the goal to monitor attendance. The supervisory authority is of the opinion that biometric data of students was processed which is why Art. 9 GDPR is app

### HmbBfDI (Hamburg) - Einstellung Gerichtsverfahren in Sachen Videmo 360

*Source: HmbBfDI (Hamburg), 2026-07-24 — https://overview.legal/posts/158442 — original: https://gdprhub.eu/index.php?title=HmbBfDI_(Hamburg)_-_Einstellung_Gerichtsverfahren_in_Sachen_Videmo_360*

Facts — Following the 2017 G20 summit in Hamburg, the Hamburg Police used automated facial recognition software to analyze video footage. A template database containing mathematical models of faces was created which includes data from private citizen uploads, police surveillance, public transport, and media sources (~32,000 video and image files). The Hamburg DPA (HmbBfDI) determined that there was no sufficient legal basis for this processing and ordered the deletion of the database. The Hamburg Ministry of Interior and Sports, responsible for the police, contested the deletion order in court and won before the Hamburg Administrative Court (VG Hamburg) in 2019. The Hamburg DPA appealed the ruling to the Higher Administrative Court (OVG Hamburg). Holding — Before the appeal was decided, the police deleted the database, stating that the investigation had been completed. Due to this deletion, the OVG Hamburg declared the case moot on May 17, 2023. The court ruled that a retrospective determination of the lawfulness of the data processing was inadmissible, as it was a one-time decision with no recognized risk of recurrence.

### School in Gdansk (Danzig) (fine imposed against town of Gdansk): Insufficient legal basis for data processing

*Source: Polish National Personal Data Protection Office (UODO), 2020-03-04 — https://overview.legal/posts/46339 — original: https://www.enforcementtracker.com/ETid-224*

Original summary: A school in Gdansk used biometric fingerprint scanners to authenticate students for the payment process in the school canteen. Although the parents had given their written consent to such data processing, the data protection authority considered the processing of the student data to be unlawful, as the consent to data processing was not given voluntarily. Update: Update: On August 7, 2020, the Provincial Administrative Court in Warsaw overturned the decision of the Polish DPA i

### IMY reprimands Swedish Police for inadequate GDPR Article 13 info at Arlanda border

*Source: IMY (Sweden), 2026-07-03 — https://overview.legal/posts/57263 — original: https://gdprhub.eu/index.php?title=IMY_(Sweden)_-_IMY-2024-2904*

Facts — The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of the personal data of travellers arriving from third countries (the data subjects). During border control, the controller scanned the data subjects’ passports, and some travellers were required to provide fingerprints. The data collected was then possibly checked against various border control systems, such as the Schengen Information System (SIS) and the Visa Information System (VIS). There were no signs, brochures, or other written information on the processing of personal data available directly in the arrival hall. The only information available could be found on the controller’s website. Holding — The DPA issued the controller a reprimand for the infringement of Article 13 GDPR. It held that the controller had not provided the data subjects sufficient information about the processing of personal data during border controls. According to the DPA, the data subjects had not been able to easily access information regarding, among other things, what personal data is collected, how it is processed, and what rights data subjects have. The DPA took into account that not all travellers arriving from third countries could be expected to know which national authority is responsible for border controls, let alone be able to find and understand the information on the controller’s website without any guidance in the arrivals hall. It concluded that the lack of easily accessible information on this matter constituted a significant shortcoming: the border control operations included the processing of sensitive data, including biometric data, of a large number of travellers on a daily basis. On the other hand, the investigation was limited to one arrivals hall. The controller had also obtained signs with tailored information regarding the processing of personal data during border control since the beginning of the investigation. Based on an overall assessment, the DPA held that the lack of information required by Article 13 in the arrivals hall constituted a minor GDPR violation.

### Departement of Social Security: Insufficient legal basis for data processing

*Source: Data Protection Authority of Ireland, 2025-06-12 — https://overview.legal/posts/48772 — original: https://www.enforcementtracker.com/ETid-2657*

The Irish DPA imposed a fine of EUR 550,000 on the Departement of Social Security. The controller uses the so called SAFE 2 registration process for anyone applying for a Public Services Card. The SAFE 2 registration, which is mandatory, processes biometric data without a sufficient legal basis. The controller also failed to adequately inform data subjects in regards to the processing and to conduct a data protection impact assessment.

### Comune di Borgia: Insufficient legal basis for data processing

*Source: Italian Data Protection Authority (Garante), 2022-12-15 — https://overview.legal/posts/47749 — original: https://www.enforcementtracker.com/ETid-1634*

The Italian DPA (Garante) imposed a fine of EUR 5,000 on Comune di Borgia. The municipality processed biometric data of employees for the purpose of registering their attendance. Garante found that such processing was not proportionate and therefore constituted an unjustified infringement of the rights of the data subjects. Subsequently, Garante determined that the processing of biometric data had taken place without a legal basis. Also the Garante found that the municipality failed to provide t

### UAB VS FITNESS: Non-compliance with general data processing principles

*Source: Lithuanian Data Protection Authority (VDAI), 2021-06-21 — https://overview.legal/posts/46847 — original: https://www.enforcementtracker.com/ETid-732*

The Lithuanian DPA (VDAI) has imposed a fine of EUR 20,000 on UAB VS FITNESS. After receiving a notification from an individual stating that scanning a fingerprint was necessary to use the services of a sports club owned by the controller, the DPA started an investigation against the controller. The DPA's review found that the consent given by customers to have their fingerprint patterns processed was not voluntary as there were no other identification measures. In addition, the DPA found that t

### SIDECU, S.A.: Niet-naleving van de algemene principes voor gegevensverwerking.

*Source: Spanish Data Protection Authority (aepd), 2025-06-26 — https://overview.legal/posts/52225*

De Spaanse autoriteit voor gegevensbescherming (DPA) heeft een boete van 96.000 euro opgelegd aan SIDECU, S.A. De verantwoordelijke partij heeft een gezichtsherkenningssysteem geïntroduceerd als de enige manier om toegang te krijgen tot hun faciliteiten, zonder alternatieve toegangsmethoden aan te bieden. De verantwoordelijke partij had geen voldoende juridische basis voor de verwerking van de gegevens, heeft de betrokkenen niet voldoende geïnformeerd over de verwerking en heeft geen beoordeling van de impact op de privacy uitgevoerd. De oorspronkelijke boete van 160.000 euro is verlaagd tot 96.000 euro vanwege een onmiddellijke betaling.

## Recent developments

### No action taken against PimEyes: noyb lawsuit against Hamburg DPA

*Source: noyb - European Center for Digital Rights, 2026-04-30 — https://overview.legal/posts/53128 — original: https://noyb.eu/en/no-action-taken-against-pimeyes-noyb-lawsuit-against-hamburg-dpa*

National Administrative Procedures and DPA inactivity Today, noyb has filed a lawsuit against the Hamburg data protection authority (DPA). While the authority considers the practices of the facial recognition search engine PimEyes to be illegal, it refuses to take effective action because the company seems to be based in Dubai. PimEyes systematically extracts biometric data from images on the internet and uses it to build up a database. Users can upload photos of people to this website to find f

### Criminal complaint against facial recognition company Clearview AI

*Source: noyb - European Center for Digital Rights, 2025-10-28 — https://overview.legal/posts/53133 — original: https://noyb.eu/en/criminal-complaint-against-facial-recognition-company-clearview-ai*

Biometric Data Today, noyb has filed a criminal complaint against Clearview AI and its managers. The facial recognition company is known for scraping billions of photos of Europeans and people around the world on the internet – and selling its facial recognition system to law enforcement and state actors. Several EU data protection authorities have already imposed fines and bans on Clearview AI. But the US company simply ignores these actions – given the lack of enforcement. Original Complaints

### Want to book a Ryanair flight? Prepare for a face scan!

*Source: noyb - European Center for Digital Rights, 2024-12-19 — https://overview.legal/posts/53168 — original: https://noyb.eu/en/want-book-ryanair-flight-prepare-face-scan*

Biometric Data Today, noyb filed a GDPR complaint against Ryanair. Booking a flight on the airline’s website not only requires a mandatory account. New customers must also go through a verification process which, for many people, involves invasive biometrics. There is no reasonable justification for such a system. Instead, it appears that Ryanair is willingly violating its customers’ right to data protection in order to increase its market power. This is already the second noyb complaint against

### Clearview AI data use deemed illegal in Austria, however no fine issued

*Source: noyb - European Center for Digital Rights, 2023-05-10 — https://overview.legal/posts/53239 — original: https://noyb.eu/en/clearview-ai-data-use-deemed-illegal-austria-however-no-fine-issued*

The Austrian data protection authority has decided: Clearview AI, the company that sells facial recognition software to law enforcement agencies in the U.S. is no longer allowed to process biometric data of the complainant and must delete their existing data. The US based company scrapes photos from websites to create a permanent searchable database of biometric profiles. The decision follows similar decisions in Italy, the UK, France and Greece, however no fine was issued. Decision by the Austr

### Climate justice action repression vs EU data protection law: the Advocate General’s opinion

*Source: European Digital Rights, 2025-11-13 — https://overview.legal/posts/49202 — original: https://edri.org/our-work/climate-justice-action-repression-vs-eu-data-protection-law-the-advocate-generals-opinion/*

In his opinion, the Court’s Advocate General assesses the compliance of the French law regulating the collection of biometric data by police with EU data protection criteria. Although his interpretation remains strictly theoretical and fails to account for the reality of police practices in France, one of his proposals might become handy for people when seeking redress after abusive data collection. The post Climate justice action repression vs EU data protection law: the Advocate General’s opin

## Literature

### Use of Artificial Intelligence Tools by Law Enforcement Services in Light of the Artificial Intelligence Act

*Source: Zeszyt Prawniczy UAM, 2025-12-22 — https://overview.legal/posts/132565 — original: https://doi.org/10.14746/zpuam.2025.15.4*

Celem artykułu jest wskazanie przestępstw, w przypadku których służby państwowe mogą korzystać z systemów zdalnej identyfikacji biometrycznej w czasie rzeczywistym w przestrzeni publicznej. Zostanie to uczynione przez analizę przesłanek umożliwiających posługiwanie się tą technologią oraz przyrównanie ich do czynów zabronionych przez polski kodeks karny. Rezultatem powyższego jest stworzenie katalogu przestępstw, odnośnie do których służby mogą zastosować system zdalnej identyfikacji biometryczn

### Comparative Analysis of Passkeys (FIDO2 Authentication) on Android and iOS for GDPR Compliance in Biometric Data Protection

*Source: Electronics, 2025-10-13 — https://overview.legal/posts/132630 — original: https://doi.org/10.3390/electronics14204018*

Biometric authentication, such as facial recognition and fingerprint scanning, is now standard on mobile devices, offering secure and convenient access. However, the processing of biometric data is tightly regulated under the European Union’s General Data Protection Regulation (GDPR), where such data qualifies as “special category” personal data when used for uniquely identifying individuals. Compliance requires meeting strict conditions, including explicit consent and data protection by design.

### The Artificial Intelligence Act (AI Act) as the basis for legal regulation of artificial intelligence in the EU: review of the main provisions

*Source: Analytical and Comparative Jurisprudence, 2025-07-12 — https://overview.legal/posts/132431 — original: https://doi.org/10.24144/2788-6018.2025.03.3.44*

This article reviews the main provisions of the Artificial Intelligence Act (AI Act), which entered into force as an EU Regulation in 2014. It is indicated that one of the main global trends in recent years is the active development of artificial intelligence and its application, and it is argued that since the AI Act is one of the first legal acts in the world designed to regulate artificial intelligence, and also taking into account Ukraine’s course towards European integration, it is importan

### Artificial Intelligence in Decision-making: A Test of Consistency between the “EU AI Act” and the “General Data Protection Regulation”

*Source: Athens Journal of Law, 2025-01-02 — https://overview.legal/posts/132443 — original: https://doi.org/10.30958/ajl.11-1-3*

The recent Regulation that sets down harmonised rules on Artificial Intelligence in the European Union, known as the "AI Act," includes a significant requirement for human oversight in high-risk AI systems during their use (art. 14). This requirement embodies the "human-in-command" approach, ensuring both legal and ethical compliance. The AI Act is intended to complement the General Data Protection Regulation (hereinafter GDPR), thereby forming a consistent and comprehensive legal framework. Thi

### GDPR Enforcement Beyond EU-Borders — The Dutch Data Protection Authority’s Fine on Clearview AI and the Future of AI Regulation Enforcement

*Source: Computer Law Review International, 2025-03-01 — https://overview.legal/posts/132514 — original: https://doi.org/10.9785/cri-2025-260103*

Abstract After a brief introduction (I.), the article summarises the reasoning of the Dutch Data Protection Authority (II.) and examines the challenges of enforcing GDPR against companies outside the EU (III.) as well as the potential future impact of the upcoming European Union Artificial Intelligence (AI) Act on such cases (IV.). A particular emphasis is placed on how the AI Act’s provisions may influence future regulatory decisions and enforcement actions involving AI technologies such as fac

## Related topics

- **Biometric Data** — https://overview.legal/topics/biometrie
  Unique physical characteristics used for identification
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Special Categories of Data** — https://overview.legal/topics/bijzondere-persoonsgegevens
  Sensitive data requiring enhanced protection (health, biometric, etc.)
- **Types of Special Categories of Personal Data** — https://overview.legal/topics/special-categories-data-types
  A dedicated topic is needed to comprehensively cover the specific types and definitions of special categories of personal data, including racial/ethnic origin, 
- **Identification** — https://overview.legal/topics/identificatie
  Methods and processes for identifying individuals
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data

---
Generated by overview.legal · https://overview.legal/topics/biometric-data · 2026-08-22
