Biometric Data
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Unique physical characteristics used for identification
Overview
24 sources · Jul 23, 2026Legal Framework
Biometric data occupies a uniquely restrictive position under EU data protection law. Article 9(1) GDPR establishes a general prohibition on processing special categories of personal data, including biometric data when used for unique identification. The provision states:
"Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited."
— GDPR Art. 9(1)
The definition of biometric data, found in Article 4(14) GDPR, is technical and specific. The EDPB has highlighted this definition in its guidance on virtual voice assistants, quoting it verbatim:
"persoonsgegevens die het resultaat zijn van een specifieke technische verwerking met betrekking tot de fysieke, fysiologische of gedragsgerelateerde kenmerken van een natuurlijke persoon op grond waarvan eenduidige identificatie van die natuurlijke persoon mogelijk is of wordt bevestigd, zoals gezichtsafbeeldingen of vingerafdrukgegevens"
— EDPB Guidelines 02/2021 §32
The critical threshold is purpose: biometric data processed not for unique identification falls outside Article 9's prohibition, though it remains personal data under Article 4(1). The primary lifeline for lawful processing is Article 9(2)(a), which permits processing where:
"the data subject has given explicit consent to the processing of those personal data for one or more specified purposes, except where Union or Member State law provide that the prohibition referred to in paragraph 1 may not be lifted by the data subject"
— GDPR Art. 9(2)(a)
The AI Act adds a further layer. Article 5 prohibits certain AI practices involving biometric categorisation and untargeted facial scraping, tightening the regulatory perimeter around biometric deployments in AI systems.
Key Developments
In Schwarz v. Bochum (CJEU, 2014), the Court upheld the use of fingerprint recognition for passport issuance under the EU Passport Regulation, noting that alternatives like iris recognition were not yet viable. The Court acknowledged centralisation risks but deferred their examination to national courts. This case established that biometric processing in law enforcement contexts can be justified by legislative mandate, but the proportionality analysis remains context-dependent.
Dutch administrative courts have actively enforced destruction obligations for biometric police data. In a 2024 ruling, a court ordered the destruction of biometric data after a suspect's case was dismissed:
"Op 12 juni 2024 heeft verweerder op verzoek van eiser alsnog de biometrische gegevens van eiser in de politiesystemen vernietigd (het aanvullende besluit)."
— Rectificatie en vernietiging politiegegeven ¶1.2
The underlying request was grounded in the absence of any legitimate basis for retention once prosecution was dropped — a principle with broad application beyond the police context.
Status of the Debate
This topic is actively contested. The boundary between biometric data processed for unique identification (Article 9) and biometric data processed for other purposes (e.g., authentication without storage of a biometric template) remains unsettled. Courts have not yet produced a definitive ruling on whether certain authentication architectures fall outside Article 9's scope. The EDPB's 2024 opinion on facial recognition at airports and its 2022 guidelines on facial recognition in law enforcement signal regulatory convergence toward strict scrutiny, but no court split has crystallised the doctrine. What would resolve the open question is a CJEU preliminary reference clarifying whether purpose-based exclusion from Article 9 requires that no biometric template be stored at all, or whether encrypted one-way matching suffices.
Practical Guidance
- Determine whether your processing falls under Article 9. If the biometric data is used to uniquely identify a person, the Article 9 prohibition applies. If used solely for access control without creating an identifiable template, argue the exclusion with documented technical evidence.
- Obtain explicit, granular consent under Article 9(2)(a). Consent must be freely given, specific, informed, and unambiguous. Bundling biometric consent with other terms invalidates it.
- Implement a data retention and destruction protocol. As the Dutch cases demonstrate, retaining biometric data after the legal basis expires triggers mandatory erasure obligations and potential cost awards against the controller.
- Conduct a DPIA before deployment. Biometric processing is high-risk under Article 35 GDPR; the DPIA must address proportionality, less invasive alternatives, and the technical measures preventing re-identification.
- Assess AI Act implications. If the biometric system qualifies as an AI system under Article 3 of the AI Act, verify that the use case does not fall within the prohibited practices of Article 5.