Skip to content
Topic Contested in court

Identification

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Methods and processes for identifying individuals

584 linked items 46 Laws186 Case Law106 Guidance162 Enforcement27 News

Overview

28 sources · Sep 25, 2026

Legal Framework

Identification sits at the threshold of the GDPR: the entire regulation applies only where personal data — information linked to an identified or identifiable person — is processed. Article 4(1) GDPR defines the scope of identifiability broadly, encompassing direct and indirect identifiers including names, identification numbers, location data, and online identifiers. This definitional anchor determines whether the GDPR applies at all and triggers the full suite of obligations.

Article 11(1) GDPR provides a counterweight: if the controller's purposes do not require identifying the data subject, the controller need not acquire additional data solely to comply with the Regulation. Article 11(2) GDPR then suspends Articles 15 to 20 unless the data subject supplies supplementary information enabling identification. Article 5(1)(e) GDPR reinforces the temporal dimension — data may be kept in identifiable form no longer than necessary.

"‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person"
— GDPR Art. 4(1)

National identification numbers receive separate treatment under Article 87 GDPR, which permits Member States to set specific conditions for their processing, provided appropriate safeguards are in place.

Key Developments

The Hoge Raad's June 2026 ruling in the ICS credit card case (24/02161) crystallises the contested boundary between routine identity verification and biometric processing under Article 9(1) GDPR. The case centred on a cardholder who refused to submit a "selfie" and identity document copy for online verification under anti-money-laundering rules. The court examined whether storing a passport photograph constitutes processing of biometric data intended for unique identification — a question that determines whether the Article 9 prohibition and its narrow exceptions apply.

"Het gaat in deze zaak om een nieuwsbericht dat de rechtbank heeft gepubliceerd over een eindvonnis in een strafzaak."
— Hoge Raad, 19-12-2025 (25/02870) ¶4

The EDPB's Opinion 11/2024 draws a functional distinction between authentication (1-to-1 verification) and identification (1-to-many database search), both of which nonetheless constitute processing of special-category biometric data under Article 9 GDPR. This distinction matters for proportionality assessment but does not exempt authentication from the Article 9 framework.

Status of the Debate

This topic is actively contested in court. The Hoge Raad's 2026 ICS ruling directly addresses whether storing photographs for identity purposes triggers biometric-data protections — a question on which lower courts had diverged. The doctrinal fault line runs through Article 4(14) GDPR: whether a photograph constitutes biometric data only when technical processing enables recognition, or whether any storage of facial images for identification purposes suffices. CJEU guidance on this interpretive question would resolve the ambiguity. Until then, controllers face uncertainty when AML obligations push them toward photographic identification methods that may engage Article 9 protections.

Practical Guidance

  • Map identification methods against Article 9 thresholds. Determine whether any identification process involving facial images, fingerprints, or other biometric techniques constitutes processing "for the purpose of uniquely identifying a natural person" under Article 4(14) GDPR. If so, an Article 9(2) exception must be satisfied before processing.
  • Apply Article 11 where identification is unnecessary. Where processing purposes do not require identifying individuals — for example, pure statistical or pseudonymised research — invoke Article 11(1) GDPR and avoid acquiring supplementary data solely for compliance purposes.
  • Enforce storage limitation under Article 5(1)(e). Maintain identification data in identifiable form only for as long as genuinely necessary; implement automated retention schedules and deletion triggers tied to the original processing purpose.
  • Distinguish authentication from identification functionally but not legally. While the EDPB recognises a technical distinction, both uses fall within Article 9 GDPR. Ensure a lawful basis under Article 9(2) exists for either function.
  • Assess national ID number conditions under Article 87. Where processing involves national identification numbers, verify that Member State-specific conditions and appropriate safeguards are satisfied, as permitted by Article 87 GDPR.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 11 Processing which does not require identification Laws GDPR Apr 2016 conditions for identification necessity
why this is here
the controller shall not be obliged to maintain, acquire or process additional information in order to identify the data subject for the sole purpose of complying with this Regulation

The provision directly governs when identification is required or exempted for data-subject rights, defining the scope of the controller's obligations to identify individuals.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 05/2022 use of facial recognition technology in the area of law enforcement Guidelines ·EDPB Guidance EDPB May 2023 identification vs authentication
why this is here
It may be used to authenticate or to identify a person

The document's core focus is on identification and authentication using facial recognition.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 2/2023 Technical Scope of Art. 5(3) of ePrivacy Directive Guidelines ·EDPB Guidance EDPB Oct 2024 terminal equipment identifiers
why this is here
the fact that the receiving entity might not be the entity instructing the sending of information does not preclude the application of Article 5(3) ePD. This might concern routing identifiers such as the MAC or IP address

Identifies identifiers stored/accessed in terminal equipment as relevant to the scope.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Identification purposes
why this is here
biometric data for authentication or identification purposes

The document mentions identification as a purpose of biometric data processing in vehicles.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 3/2019 processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Identifiability
why this is here
Identity of these persons may be established on grounds of these details.

Discusses whether individuals are identifiable, but does not focus on identification methods or processes.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 01/2022 data subject rights - Right of access Guidelines ·EDPB Guidance EDPB Apr 2023 Identity verification for access requests
why this is here
if the controller has doubts about whether the data subject is who they claim to be, the controller may request additional information in order to confirm the identity of the data subject.

The document discusses identity verification as part of access request procedures, but it is not the main focus.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 8/2020 targeting of social media users Guidelines ·EDPB Guidance EDPB Apr 2021 Identifiability
why this is here
Both individuals that are and that are not registered with the social media providers may be considered ‘data subjects’ within the meaning of Article 4(1) GDPR insofar as the individual is directly or indirectly identified or identifiable.

Mentions identification but not central.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Greek SA fines Clearview AI for EUR 20M A rundown of the fine on IAPP: https://iapp.org/news/a/a-rundown-of-the-greek-dpas-clearview-ai-fine-findings News IAPP Oct 2022 Facial recognition identification
why this is here
facial recognition of natural persons through its online platform

The document discusses identifying individuals through facial recognition, which relates to identification methods, but the topic focuses on identifiers and identifiability in general.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

AEPD publishes GDPR Risk Assessment > GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the… News AEPD Oct 2022 Identifiers and unique identifiers
why this is here
Unique identifiers

Mentions unique identifiers as a type of data relevant to identification in processing.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

AEPD issues guidance for anonymization > Spain’s data protection authority, the Agencia Española de Protección de Datos, published guidance for anonymizing data. The guidance called for a trained professional to handle… News IAPP Feb 2023 Re-identification risk in anonymization
why this is here
experience in reidentification attacks. Even though "residual probability" of reidentification will always exist

The document discusses reidentification as a risk and the need for professional expertise to prevent it, connecting to identification processes but not as a central theme.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 46 Laws · all 106 Guidance · all 186 Case Law · all 162 Enforcement · all 57 Literature · all 27 News