Identification
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Methods and processes for identifying individuals
Overview
28 sources · Sep 25, 2026Legal Framework
Identification sits at the threshold of the GDPR: the entire regulation applies only where personal data — information linked to an identified or identifiable person — is processed. Article 4(1) GDPR defines the scope of identifiability broadly, encompassing direct and indirect identifiers including names, identification numbers, location data, and online identifiers. This definitional anchor determines whether the GDPR applies at all and triggers the full suite of obligations.
Article 11(1) GDPR provides a counterweight: if the controller's purposes do not require identifying the data subject, the controller need not acquire additional data solely to comply with the Regulation. Article 11(2) GDPR then suspends Articles 15 to 20 unless the data subject supplies supplementary information enabling identification. Article 5(1)(e) GDPR reinforces the temporal dimension — data may be kept in identifiable form no longer than necessary.
"‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person"
— GDPR Art. 4(1)
National identification numbers receive separate treatment under Article 87 GDPR, which permits Member States to set specific conditions for their processing, provided appropriate safeguards are in place.
Key Developments
The Hoge Raad's June 2026 ruling in the ICS credit card case (24/02161) crystallises the contested boundary between routine identity verification and biometric processing under Article 9(1) GDPR. The case centred on a cardholder who refused to submit a "selfie" and identity document copy for online verification under anti-money-laundering rules. The court examined whether storing a passport photograph constitutes processing of biometric data intended for unique identification — a question that determines whether the Article 9 prohibition and its narrow exceptions apply.
"Het gaat in deze zaak om een nieuwsbericht dat de rechtbank heeft gepubliceerd over een eindvonnis in een strafzaak."
— Hoge Raad, 19-12-2025 (25/02870) ¶4
The EDPB's Opinion 11/2024 draws a functional distinction between authentication (1-to-1 verification) and identification (1-to-many database search), both of which nonetheless constitute processing of special-category biometric data under Article 9 GDPR. This distinction matters for proportionality assessment but does not exempt authentication from the Article 9 framework.
Status of the Debate
This topic is actively contested in court. The Hoge Raad's 2026 ICS ruling directly addresses whether storing photographs for identity purposes triggers biometric-data protections — a question on which lower courts had diverged. The doctrinal fault line runs through Article 4(14) GDPR: whether a photograph constitutes biometric data only when technical processing enables recognition, or whether any storage of facial images for identification purposes suffices. CJEU guidance on this interpretive question would resolve the ambiguity. Until then, controllers face uncertainty when AML obligations push them toward photographic identification methods that may engage Article 9 protections.
Practical Guidance
- Map identification methods against Article 9 thresholds. Determine whether any identification process involving facial images, fingerprints, or other biometric techniques constitutes processing "for the purpose of uniquely identifying a natural person" under Article 4(14) GDPR. If so, an Article 9(2) exception must be satisfied before processing.
- Apply Article 11 where identification is unnecessary. Where processing purposes do not require identifying individuals — for example, pure statistical or pseudonymised research — invoke Article 11(1) GDPR and avoid acquiring supplementary data solely for compliance purposes.
- Enforce storage limitation under Article 5(1)(e). Maintain identification data in identifiable form only for as long as genuinely necessary; implement automated retention schedules and deletion triggers tied to the original processing purpose.
- Distinguish authentication from identification functionally but not legally. While the EDPB recognises a technical distinction, both uses fall within Article 9 GDPR. Ensure a lawful basis under Article 9(2) exists for either function.
- Assess national ID number conditions under Article 87. Where processing involves national identification numbers, verify that Member State-specific conditions and appropriate safeguards are satisfied, as permitted by Article 87 GDPR.
why this is here
the controller shall not be obliged to maintain, acquire or process additional information in order to identify the data subject for the sole purpose of complying with this Regulation
The provision directly governs when identification is required or exempted for data-subject rights, defining the scope of the controller's obligations to identify individuals.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
It may be used to authenticate or to identify a person
The document's core focus is on identification and authentication using facial recognition.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the fact that the receiving entity might not be the entity instructing the sending of information does not preclude the application of Article 5(3) ePD. This might concern routing identifiers such as the MAC or IP address
Identifies identifiers stored/accessed in terminal equipment as relevant to the scope.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
biometric data for authentication or identification purposes
The document mentions identification as a purpose of biometric data processing in vehicles.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
Identity of these persons may be established on grounds of these details.
Discusses whether individuals are identifiable, but does not focus on identification methods or processes.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
if the controller has doubts about whether the data subject is who they claim to be, the controller may request additional information in order to confirm the identity of the data subject.
The document discusses identity verification as part of access request procedures, but it is not the main focus.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
Both individuals that are and that are not registered with the social media providers may be considered ‘data subjects’ within the meaning of Article 4(1) GDPR insofar as the individual is directly or indirectly identified or identifiable.
Mentions identification but not central.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
facial recognition of natural persons through its online platform
The document discusses identifying individuals through facial recognition, which relates to identification methods, but the topic focuses on identifiers and identifiability in general.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
Unique identifiers
Mentions unique identifiers as a type of data relevant to identification in processing.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
experience in reidentification attacks. Even though "residual probability" of reidentification will always exist
The document discusses reidentification as a risk and the need for professional expertise to prevent it, connecting to identification processes but not as a central theme.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 46 Laws · all 106 Guidance · all 186 Case Law · all 162 Enforcement · all 57 Literature · all 27 News