Biometric Data
Biometric data is personal information about a person's physical, physiological, or behavioural characteristics, such as fingerprints, facial features, or voice patterns, that results from specific technical processing. It becomes subject to stricter protection under data protection law only when it is used for the purpose of uniquely identifying an individual, and not merely because it describes a physical trait.
Under Article 4(14) of the UK GDPR, biometric data is defined as personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that person. Importantly, biometric data is treated as special category data under Article 9 only where it is processed for the purpose of uniquely identifying a natural person; the same or similar data processed for other purposes may not attract Article 9 protections and should be assessed on the facts. The ICO notes that 'biometric recognition' is an industry-standard term describing the use of biometric data to uniquely identify someone and is not itself defined in data protection law. Practitioners should distinguish the EU GDPR and UK GDPR positions, verify against the current official text, and remain aware that regulator guidance in this area continues to develop.
Why it matters
Biometric data occupies a distinctive position in data protection law because whether it attracts heightened protection depends on how it is used, not simply on what it describes. A facial image or voice recording is personal data, but it becomes special category data under Article 9 of the UK GDPR only when it is processed for the purpose of uniquely identifying a natural person. This distinction matters greatly for compliance planning: organisations cannot assume that all handling of physical or behavioural characteristics triggers Article 9 conditions, nor can they assume it never does. Each processing activity should be assessed on its facts to determine whether the special category threshold is met.
The consequences of misclassification run in both directions. Treating biometric data as ordinary personal data when it is in fact being used for unique identification risks processing special category data without an Article 9 condition, which is a significant compliance gap. Conversely, over-applying Article 9 to data that is not being used to uniquely identify someone can impose unnecessary burdens. Because the ICO's guidance in this area continues to develop, and because the EU GDPR and UK GDPR positions should be verified separately against the current official text, practitioners should revisit their classifications as regulator guidance evolves.
Biometric recognition systems also raise elevated risk because the underlying characteristics are typically permanent and cannot be reissued in the way a password can. This makes the accuracy of legal classification, the selection of an appropriate lawful basis, and, where relevant, an Article 9 condition, central to any programme that deploys such technology.
Who it's relevant to
Inside Biometric Data
Common questions
Answers to the questions practitioners most commonly ask about Biometric Data.