Skip to main content
Category: Special Category Data

Biometric Data

Simply put

Biometric data is personal information about a person's physical, physiological, or behavioural characteristics, such as fingerprints, facial features, or voice patterns, that results from specific technical processing. It becomes subject to stricter protection under data protection law only when it is used for the purpose of uniquely identifying an individual, and not merely because it describes a physical trait.

Formal definition

Under Article 4(14) of the UK GDPR, biometric data is defined as personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that person. Importantly, biometric data is treated as special category data under Article 9 only where it is processed for the purpose of uniquely identifying a natural person; the same or similar data processed for other purposes may not attract Article 9 protections and should be assessed on the facts. The ICO notes that 'biometric recognition' is an industry-standard term describing the use of biometric data to uniquely identify someone and is not itself defined in data protection law. Practitioners should distinguish the EU GDPR and UK GDPR positions, verify against the current official text, and remain aware that regulator guidance in this area continues to develop.

Why it matters

Biometric data occupies a distinctive position in data protection law because whether it attracts heightened protection depends on how it is used, not simply on what it describes. A facial image or voice recording is personal data, but it becomes special category data under Article 9 of the UK GDPR only when it is processed for the purpose of uniquely identifying a natural person. This distinction matters greatly for compliance planning: organisations cannot assume that all handling of physical or behavioural characteristics triggers Article 9 conditions, nor can they assume it never does. Each processing activity should be assessed on its facts to determine whether the special category threshold is met.

The consequences of misclassification run in both directions. Treating biometric data as ordinary personal data when it is in fact being used for unique identification risks processing special category data without an Article 9 condition, which is a significant compliance gap. Conversely, over-applying Article 9 to data that is not being used to uniquely identify someone can impose unnecessary burdens. Because the ICO's guidance in this area continues to develop, and because the EU GDPR and UK GDPR positions should be verified separately against the current official text, practitioners should revisit their classifications as regulator guidance evolves.

Biometric recognition systems also raise elevated risk because the underlying characteristics are typically permanent and cannot be reissued in the way a password can. This makes the accuracy of legal classification, the selection of an appropriate lawful basis, and, where relevant, an Article 9 condition, central to any programme that deploys such technology.

Who it's relevant to

Data Protection Officers and compliance leads
DPOs and compliance teams must determine, on a case-by-case basis, whether a given processing activity uses biometric data for the purpose of unique identification and therefore engages Article 9 of the UK GDPR. This assessment drives whether an additional Article 9 condition is required alongside an Article 6 lawful basis, and should be revisited as ICO guidance in this developing area evolves.
Privacy lawyers and advisors
Legal advisors need to distinguish between biometric data as ordinary personal data and biometric data that qualifies as special category data because it is processed to uniquely identify a person. They should also separate the EU GDPR and UK GDPR positions rather than assuming they are identical, and verify definitions against the current official text.
Engineers and product teams building biometric systems
Teams designing systems that scan or process physical, physiological, or behavioural characteristics should understand that the technical processing step and the identification purpose are what shape the legal classification. Documenting whether a system's purpose is to uniquely identify individuals helps compliance colleagues determine the correct treatment under the framework.
Organisations deploying biometric recognition
Organisations using biometric recognition, which the ICO describes as using biometric data to uniquely identify someone, should recognise this term derives from industry standards and is not itself defined in data protection law. They should assess each use on its facts and remain aware that regulator guidance in this area continues to develop.

Inside Biometric Data

Definition under Article 4(14)
Biometric data is defined as personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that person. Examples referenced in the Regulation include facial images and dactyloscopic (fingerprint) data.
Technical processing requirement
The definition turns on 'specific technical processing.' A raw photograph or facial image is not automatically biometric data; it typically becomes biometric data only when subjected to technical processing that enables unique identification, such as the generation of a facial template. Practitioners should assess the processing applied, not merely the raw source material.
Special-category status is purpose-dependent
Biometric data is treated as a special category of data under Article 9(1) only when it is processed 'for the purpose of uniquely identifying a natural person.' Biometric data processed for other purposes may fall outside Article 9, though it generally remains personal data subject to the GDPR as a whole. The classification therefore depends on the purpose of processing, not on the nature of the data alone.
Physical, physiological, and behavioural characteristics
The concept spans several characteristic types: physical and physiological traits (for example facial geometry or fingerprints) and behavioural traits (for example characteristics derived from how a person acts). Whether a given behavioural signal constitutes biometric data depends on whether the technical processing allows or confirms unique identification.
Legal basis and additional condition
Where biometric data is processed for unique identification and thus falls under Article 9, an Article 6 legal basis is generally required together with a separate Article 9(2) condition (such as explicit consent or another applicable exception). Consent is one possible condition but is not a universal requirement; the appropriate condition is subject to assessment. Member state law may impose or vary conditions, so the position can differ by jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about Biometric Data.

Is all biometric data automatically special category data under the GDPR?
No. Biometric data is treated as a special category of personal data under Article 9(1) only when it is processed for the purpose of uniquely identifying a natural person. Biometric-type data processed for other purposes may still be personal data subject to the general GDPR rules, but it does not automatically attract the additional Article 9 conditions. The purpose of the processing is decisive, so the same underlying data may or may not fall within the special category depending on how it is used. You should assess each processing activity against this purpose test rather than assuming the category applies universally.
Does processing biometric data always require the individual's consent?
Not necessarily. Where biometric data is processed for the purpose of uniquely identifying a natural person, Article 9 requires an applicable condition from Article 9(2), of which explicit consent is only one option. Other Article 9(2) conditions may apply depending on the context, and member state law can provide or narrow certain grounds. In addition, an Article 6 legal basis is also required. Consent is therefore a common but not universal route, and its suitability should be assessed against the specific processing, the power balance between the parties, and any relevant national derogations.
How do we determine whether our use of biometric data engages Article 9?
Focus on the purpose of the processing and whether it aims to uniquely identify or verify a specific individual. If identification or verification of a natural person is the objective, the Article 9 regime generally applies and you should identify both an Article 6 basis and an Article 9(2) condition. Where the purpose is different, document that assessment. Because this turns on facts and can be subject to regulator and national-law interpretation, record your reasoning and revisit it if the purpose changes.
Do we need a Data Protection Impact Assessment before deploying a biometric system?
In many cases a DPIA under Article 35 will be appropriate, particularly where processing is likely to result in a high risk to individuals, and large-scale processing of special category data is a relevant factor. Some supervisory authorities publish lists of processing that require a DPIA, and these can vary between member states. You should check the applicable national list and conduct the DPIA before processing begins where required, treating it as an ongoing document rather than a one-off exercise.
What should we consider when relying on consent for a biometric identification system?
Where consent is the chosen condition, it generally needs to meet the standard for explicit consent and be freely given, specific, informed, and unambiguous. Consider whether individuals have a genuine free choice, especially in employment or other imbalanced relationships where consent may be difficult to rely on, and whether a non-biometric alternative is offered. Document how consent is obtained and how it can be withdrawn, and reassess if the processing purpose or context changes.
How should we handle data minimisation and retention for biometric processing?
Apply the general principles, so collect and retain biometric data only to the extent necessary for the identified purpose and for no longer than needed. Consider whether verification (one-to-one matching) is sufficient rather than identification (one-to-many), and whether templates or other measures can reduce the data held. Define and document retention periods tied to the purpose, and put in place deletion processes. The specific safeguards that are appropriate should be determined through your risk assessment and any applicable national requirements.

Common misconceptions

All biometric data is automatically special-category data requiring the highest safeguards.
Under the GDPR, biometric data is special-category data under Article 9(1) only when processed for the purpose of uniquely identifying a natural person. Biometric data processed for other purposes may not attract Article 9, although it generally remains personal data governed by the rest of the Regulation. Classification depends on the purpose of processing and should be assessed case by case.
Any photograph or image of a person is biometric data.
A photograph or facial image is generally not biometric data on its own. It typically becomes biometric data only after specific technical processing capable of allowing or confirming unique identification, such as producing a biometric template. The presence and nature of that technical processing is the determining factor.
Consent is always the required legal basis for processing biometric data.
Consent is not a universal requirement. Where biometric data falls under Article 9, an Article 9(2) condition is needed in addition to an Article 6 legal basis; explicit consent is one such condition, but other conditions may apply, and member state law can vary the position. The appropriate basis and condition are subject to assessment.

Best practices

Assess the purpose of processing before classifying data: determine whether biometric data is being processed for the purpose of uniquely identifying a natural person, as this drives whether Article 9(1) applies.
Examine the specific technical processing applied to source material, since a raw image or photograph generally becomes biometric data only when processing enables or confirms unique identification.
Where Article 9 applies, identify and document both an Article 6 legal basis and a separate Article 9(2) condition, rather than assuming consent is the only or default option.
Check for member state derogations and national implementing law, which can vary the conditions and safeguards applicable to biometric data processing in a given jurisdiction.
Document the classification reasoning and the assessment of purpose, technical processing, and legal basis, so the basis for treating (or not treating) data as special-category is defensible.
Verify terminology, article references, and any applicable conditions against the current official text and up-to-date regulator guidance, as interpretations and guidance in this area continue to evolve.