Skip to main content
Category: Special Category Data

Biometric Data for Unique Identification

Also known as: Biometric recognition, Biometric identification
Simply put

Biometric data for unique identification refers to information about a person's physical, physiological, or behavioural characteristics that is processed specifically to recognise or single out that individual. Common examples include fingerprints, iris scans, facial images, and palm vein patterns when used to identify a particular person. When biometric data is used in this way to uniquely identify someone, it generally attracts heightened protection under data protection law.

Formal definition

Biometric data for unique identification denotes the processing of biometric data (data resulting from specific technical processing relating to physical, physiological, or behavioural characteristics of a natural person) for the purpose of uniquely identifying that person. The ICO notes that 'biometric recognition' is an industry-standard term describing the use of biometric data to uniquely identify someone and is not itself defined in data protection legislation; practitioners should distinguish it from the underlying statutory definition of biometric data. Not all processing of biometric data amounts to processing for unique identification: where biometric data is processed specifically to uniquely identify an individual, it is generally treated as special category data requiring an additional Article 9 condition in addition to an Article 6 lawful basis. The technical process typically involves automated recognition based on distinguishing biological or behavioural characteristics, and may include duplicate-enrolment (deduplication) checks in identity systems. Readers should verify the current statutory definitions and conditions against the applicable EU GDPR or UK GDPR text, as national implementing law and regulatory guidance may vary the position.

Why it matters

Biometric characteristics such as fingerprints, iris patterns, and facial images are intrinsically tied to a person and generally cannot be changed if compromised, unlike a password or an account number. When biometric data is processed specifically to uniquely identify an individual, it is generally treated as special category data, which means it attracts heightened protection and typically requires an additional condition under Article 9 alongside a lawful basis under Article 6. Organisations that deploy biometric recognition therefore face a more demanding compliance threshold than they would for many other categories of personal data.

The distinction between processing biometric data and processing it for unique identification is central and easily misunderstood. As the ICO notes, 'biometric recognition' is an industry-standard term describing the use of biometric data to uniquely identify someone, and it is not itself defined in data protection legislation; not all processing of biometric data amounts to processing for unique identification. Getting this classification wrong can lead an organisation to under-protect data that qualifies as special category, or to apply heightened controls where they may not be strictly required. Because the position can turn on the specific purpose of the processing, each use case generally warrants its own assessment.

Biometric recognition is increasingly used in identity systems, access control, and deduplication checks, which raises the stakes for accurate governance. The applicable conditions and the precise statutory definitions can differ between the EU GDPR and the UK GDPR, and national implementing law and regulatory guidance may vary the position. Readers should verify the current requirements against the applicable text rather than rely on a single snapshot, as guidance in this area continues to evolve.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads need to determine whether a given use of biometric data amounts to processing for unique identification, because that classification generally triggers special category treatment and the need for an Article 9 condition alongside an Article 6 lawful basis. They should assess each use case on its facts rather than assume all biometric processing is equivalent, and should confirm the applicable requirements under the relevant EU GDPR or UK GDPR text and any national implementing law.
Privacy and Technology Lawyers
Lawyers advising on biometric deployments should distinguish the industry term 'biometric recognition' from the statutory definition of biometric data, noting that the former is not itself defined in data protection legislation. They should advise clients on the additional conditions that generally apply where processing is for unique identification, and flag that the position may diverge between the EU and UK regimes and may be subject to member state derogations and evolving regulatory guidance.
Engineers and Product Teams Building Identity Systems
Teams designing access control, authentication, or identity systems that use fingerprints, iris scans, facial images, or palm vein patterns should recognise that deduplication and duplicate-enrolment checks can constitute processing for unique identification. Because such processing generally attracts heightened protection, product and engineering decisions on data collection, storage, and matching should be made in consultation with compliance colleagues and assessed against the current applicable requirements.
Organisations Deploying Biometric Recognition
Employers and service providers considering biometric recognition for staff or customers should understand that where biometric data is used to uniquely identify individuals it is generally special category data requiring an additional Article 9 condition. The appropriate condition and the overall lawfulness of the processing are context and risk dependent and should be assessed before deployment, with verification against the applicable statutory text and current regulatory guidance.

Inside Biometric Data for Unique Identification

Biometric data (definition)
Under the GDPR, biometric data generally means personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that person. Examples typically include facial images and fingerprint data, though a facial image is not automatically biometric data unless processed through such specific technical means.
Purpose of unique identification
The GDPR elevates biometric data to a special category only when it is processed for the purpose of uniquely identifying a natural person. The processing purpose, not merely the nature of the data, is decisive. Biometric characteristics processed for other purposes may fall outside the special category classification, subject to assessment.
Special category status (Article 9)
Biometric data processed for unique identification is treated as a special category of personal data. This means, in addition to identifying a lawful basis under Article 6, the controller must generally satisfy a separate condition under Article 9(2) before the processing is permitted.
Distinction between identification and verification
Regulators have discussed the difference between one-to-many identification (matching an individual against a database) and one-to-one verification or authentication (confirming a claimed identity). Whether both scenarios fall within 'unique identification' can depend on context and guidance; practitioners should assess this rather than assume a single answer.
Role of member state law
The GDPR permits member states to introduce or maintain further conditions, including limitations, with regard to the processing of biometric data. As a result, the lawful position can vary between jurisdictions and between the EU GDPR and the UK GDPR, so national implementing law should be checked.

Common questions

Answers to the questions practitioners most commonly ask about Biometric Data for Unique Identification.

Is all biometric data automatically treated as a special category of data under the GDPR?
No. Biometric data is only treated as a special category under Article 9 when it is processed for the purpose of uniquely identifying a natural person. Biometric data processed for other purposes may still be personal data subject to the general GDPR requirements, but it does not automatically attract the additional Article 9 conditions unless the unique-identification purpose is present. The distinction turns on the purpose of processing, so the same underlying data can fall in or out of Article 9 depending on how it is used. This is a nuanced area, and you should assess each processing operation against the current official text and applicable regulatory guidance.
Does consent always have to be the legal basis for processing biometric data used to identify someone?
No. Processing biometric data for unique identification requires both an Article 6 legal basis and a separate Article 9 condition; these are distinct requirements and should not be collapsed into one. Explicit consent is one available Article 9 condition, but it is not the only one, and it is not automatically required in every case. Other Article 9 conditions may apply depending on context, and member state law can add or vary conditions in certain areas. The appropriate basis and condition depend on the specific processing, the actors involved, and any applicable national implementing law, so this generally calls for a case-by-case assessment.
How should an organisation document its legal basis and Article 9 condition for a biometric identification system?
In most cases you should record, before processing begins, both the identified Article 6 legal basis and the separate Article 9 condition relied upon, along with the reasoning that supports each. This documentation typically forms part of the organisation's accountability records and should reflect the specific purpose of unique identification. Where explicit consent is relied on, the mechanism for obtaining and evidencing it would generally be documented as well. Because national implementing law can affect the available conditions, you should verify your analysis against the applicable law in each relevant jurisdiction rather than assuming a single approach applies everywhere.
When is a Data Protection Impact Assessment likely to be needed for biometric identification?
A DPIA under Article 35 is generally expected where processing is likely to result in a high risk to individuals' rights and freedoms, and processing special category biometric data for unique identification, particularly at scale or involving systematic monitoring, is often treated as a strong indicator of such risk. Whether a DPIA is required in a specific deployment is subject to assessment against the criteria in the Regulation and the relevant supervisory authority's published lists, which can differ between member states. Where a DPIA is carried out, it should address the necessity and proportionality of the biometric processing and the measures used to mitigate identified risks.
How should the necessity and proportionality of using biometrics for identification be evaluated?
You should typically assess whether the identification purpose could reasonably be achieved through less intrusive means before relying on biometric identification, since biometric data is generally regarded as sensitive and its use for unique identification carries heightened risk. This assessment usually considers the specific purpose, the availability of alternatives, the categories of individuals affected, and the safeguards applied. Proportionality is context and risk dependent, so a conclusion reached for one deployment does not automatically transfer to another. Regulatory expectations in this area continue to develop, and you should check current guidance from the relevant supervisory authority.
What safeguards and data subject rights considerations apply to biometric identification systems?
Organisations generally need to provide transparent information about the biometric processing, apply appropriate technical and organisational security measures given the sensitivity of the data, and enable individuals to exercise their applicable rights, which may include access, erasure, and objection depending on the legal basis and Article 9 condition relied upon. Where explicit consent is the condition, individuals would typically be able to withdraw it, and the organisation should be prepared to handle the consequences of withdrawal. The precise scope of available rights can vary with the chosen basis, condition, and any national derogations, so the position should be confirmed against the applicable law and current guidance.

Common misconceptions

Any photograph or facial image is automatically biometric data under the GDPR.
A photograph or facial image is generally not biometric data merely because it exists. It typically becomes biometric data only when subjected to specific technical processing that allows or confirms unique identification. The classification depends on how the data is processed, not on the image alone.
Consent is always required to process biometric data.
Consent is one possible condition under Article 9 and one possible lawful basis under Article 6, but it is not the only route. Other Article 9 conditions may apply depending on context, and member state law may add further requirements. The appropriate basis and condition should be determined by assessment rather than defaulting to consent.
All biometric processing is special category data.
Biometric data is treated as a special category under Article 9 specifically when processed for the purpose of uniquely identifying a natural person. Biometric characteristics processed for other purposes may not attract special category status, though this should be assessed carefully in each case.

Best practices

Determine and document whether the processing purpose is unique identification, since this typically decides whether Article 9 special category obligations apply.
Identify both an Article 6 lawful basis and a separate Article 9 condition before processing, and record the reasoning rather than assuming consent is required or sufficient.
Assess whether your use case is one-to-many identification or one-to-one verification, and consider current regulator guidance on how each is treated in your jurisdiction.
Check applicable member state or UK implementing law for additional conditions or limitations, as the position on biometric data can diverge from the baseline GDPR text.
Consider whether a Data Protection Impact Assessment under Article 35 is required, as biometric processing for identification is often higher risk and may trigger this obligation subject to assessment.
Verify the specific article references, conditions, and any evolving regulatory guidance against the current official text before relying on them in a compliance program.