Skip to main content
Category: Data Classification & Identifiers

Biometric Identification

Also known as: Biometric recognition, Biometric identification
Simply put

Biometric identification is the use of a person's physical or behavioural characteristics, such as fingerprints, face geometry, iris patterns, or voice, to recognise who they are or to confirm they are who they claim to be. In practice it typically relies on automated systems that measure these traits and match them against previously stored records. It should be distinguished from broader terms used in industry standards, and the underlying data may attract specific protections under data protection law depending on the purpose.

Formal definition

Biometric identification refers to the automated recognition of an individual based on measurable physical characteristics or behavioural traits (for example, fingerprints, iris scans, facial geometry, or voice patterns), used either to establish an identity from a set of enrolled records or to verify a claimed identity. Regulators and standards bodies distinguish related functions: identification (one-to-many matching to determine who a person is) and verification or authentication (one-to-one matching against a claimed identity). The ICO notes that 'biometric recognition' describes using biometric data to uniquely identify someone and is a term drawn from industry standards rather than one defined in data protection legislation; practitioners should therefore not assume that every use of biometric characteristics constitutes processing that meets the statutory definition of biometric data, as that assessment turns on whether the processing is for the purpose of uniquely identifying a natural person. The precise legal treatment, including whether special category conditions apply, is context-dependent and should be verified against the current UK GDPR and EU GDPR text and applicable regulatory guidance.

Why it matters

Biometric identification carries heightened significance because the characteristics it relies on, such as fingerprints, iris patterns, facial geometry, and voice, are intrinsic to a person and generally cannot be changed if compromised. Unlike a password or a token, a person cannot readily reset their face or fingerprints, so the consequences of misuse or a breach involving biometric records can be enduring. This makes accuracy, security, and purpose limitation central concerns whenever such systems are deployed.

Under data protection law, the treatment of biometric processing is context-dependent rather than automatic. As the ICO notes, 'biometric recognition' is a term drawn from industry standards and is not defined in data protection legislation. Whether a particular use meets the statutory definition of biometric data, and whether special category conditions therefore apply, generally turns on whether the processing is for the purpose of uniquely identifying a natural person. Practitioners should not assume that every use of biometric characteristics automatically constitutes processing of special category data; that assessment should be made against the current UK GDPR and EU GDPR text and applicable regulatory guidance.

Because the legal position depends on purpose and context, and because regulatory guidance in this area continues to develop, organisations deploying biometric systems typically need to document their analysis carefully. Getting the characterisation wrong, for example by treating a system that uniquely identifies individuals as if it did not, can affect the lawful basis relied upon and any additional conditions required.

Who it's relevant to

Data Protection Officers and compliance leads
DPOs and compliance teams need to assess whether a proposed biometric deployment is for the purpose of uniquely identifying individuals, since that assessment generally determines whether the statutory definition of biometric data is met and whether additional special category conditions apply. Because the term 'biometric recognition' comes from industry standards rather than legislation, this analysis should be documented and verified against current UK GDPR and EU GDPR text and regulatory guidance.
Privacy and technology lawyers
Lawyers advising on biometric systems typically need to distinguish identification (one-to-many matching) from verification or authentication (one-to-one matching), as the purpose of the processing bears on its legal characterisation. They should also flag that the precise legal treatment is context-dependent and that guidance in this area continues to evolve, rather than presenting a single interpretation as settled law.
Engineers and product teams
Those building or integrating biometric systems handle the enrolment, measurement, and matching processes that underpin identification and verification. Understanding how the system's purpose maps to legal categories helps them work with compliance colleagues on design decisions, including whether a deployment uniquely identifies individuals and what security and accuracy safeguards may be warranted given that biometric traits generally cannot be reset.

Inside Biometric Identification

Biometric Data (Definition)
Under the GDPR, biometric data means personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that person (for example facial images or fingerprint data). The definition is found in the GDPR's definitions provisions; readers should verify the exact article reference against the current official text.
Identification versus Verification
Biometric identification typically refers to a one-to-many comparison, where a sample is matched against a database to determine who someone is. This is generally distinguished from verification or authentication, which is a one-to-one comparison confirming a claimed identity. The distinction can affect the risk assessment and the applicable safeguards.
Special Category Status
Biometric data processed for the purpose of uniquely identifying a natural person is generally treated as a special category of personal data under Article 9. Not all processing of images or physiological measurements automatically qualifies; the special category treatment typically depends on whether the processing is for the purpose of unique identification. This should be assessed case by case.
Legal Basis and Article 9 Condition
Processing biometric data for identification generally requires both an Article 6 legal basis (such as consent, contract, legal obligation, vital interests, public task, or legitimate interests, as applicable) and a separate Article 9 condition for special category data. Consent is one possible condition but is not the only or a universal one; the appropriate condition is subject to assessment.
Scope Boundaries
The GDPR applies to biometric data of identifiable living individuals. Truly anonymous data falls outside its scope, and the position on the data of deceased persons is generally governed by member state law and can vary. Whether a given dataset is genuinely anonymised rather than pseudonymised is a fact-specific judgement.
Member State and Jurisdictional Variation
Member state derogations may vary the conditions applicable to biometric data, and the UK GDPR alongside UK national implementing law may diverge from the EU position. The applicable rules should be confirmed for each relevant jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about Biometric Identification.

Is all biometric data automatically treated as a special category of personal data under the GDPR?
Not automatically. Biometric data attracts the enhanced protections of Article 9 only when it is processed 'for the purpose of uniquely identifying a natural person'. Biometric characteristics processed for other purposes may still be personal data under Article 4 and require an Article 6 legal basis, but they do not necessarily engage the additional Article 9 conditions. The distinction turns on the purpose of processing, and its application to specific technologies can be subject to regulatory assessment and evolving guidance.
Does using biometric identification always require the individual's consent?
No. Consent is one route, but Article 9 sets out several conditions that can permit processing of special category data, and Article 6 provides distinct legal bases for the underlying processing. Whether consent is the appropriate or only viable condition depends on the context, including power imbalances that may affect whether consent is freely given, and on any relevant member state derogations. Each deployment should be assessed on its facts rather than assuming consent is a universal requirement.
When should we carry out a Data Protection Impact Assessment before deploying biometric identification?
A DPIA under Article 35 is generally expected where processing is likely to result in a high risk to individuals, and large-scale or systematic biometric identification frequently falls within that category. Supervisory authorities also publish lists of processing operations for which a DPIA is required, and these can vary by member state. In most cases it is prudent to conduct the DPIA before processing begins and to keep it under review; consult your applicable authority's current list to confirm the position.
How should we identify a lawful basis and condition for a biometric identification project?
Typically this involves two linked steps: selecting an appropriate Article 6 legal basis for the processing generally, and, where the data is processed to uniquely identify a person, identifying a separate Article 9 condition. These should be documented and justified as part of your accountability records. The correct combination is context dependent and may be affected by national implementing law, so the analysis should be tailored to the specific use case rather than copied from another deployment.
What technical and organisational measures are typically expected for biometric systems?
Measures are risk-based and should be proportionate to the sensitivity of the data. Commonly considered safeguards include data minimisation, storing templates rather than raw images where feasible, encryption, strict access controls, retention limits, and clear procedures for handling enrolment and deletion. The specific measures appropriate to a given system should be determined through assessment, and this entry does not prescribe a fixed checklist because expectations evolve with technology and guidance.
How should we handle individuals who cannot or will not use biometric identification?
Offering a genuine alternative is often important, particularly where consent is relied upon, because the ability to refuse without detriment can bear on whether consent is freely given and whether the processing is fair. The availability and design of alternatives should be considered as part of the DPIA and the necessity and proportionality analysis. The appropriate approach is context specific and may be shaped by regulator expectations and applicable national law.

Common misconceptions

All biometric data is automatically special category data requiring explicit consent.
Biometric data is generally treated as special category data only when processed for the purpose of uniquely identifying a natural person. Even where Article 9 applies, consent is one of several possible conditions, not a universal requirement; the appropriate Article 9 condition and Article 6 basis are subject to assessment.
Biometric identification and biometric verification are the same thing under the law.
Identification typically involves a one-to-many search to establish who someone is, while verification typically involves a one-to-one confirmation of a claimed identity. This distinction can materially affect the risk profile and the safeguards expected, so the two should not be conflated.
Anonymising or blurring biometric records removes all GDPR obligations.
The GDPR ceases to apply only to genuinely anonymous data. Many measures produce pseudonymised rather than anonymised data, which remains personal data. Whether a dataset is truly anonymised is a fact-specific assessment, and getting this wrong can leave the processing within scope.

Best practices

Determine at the outset whether the processing is for the purpose of uniquely identifying a natural person, since this generally drives whether Article 9 special category treatment applies.
Identify and document both an Article 6 legal basis and, where applicable, a separate Article 9 condition before processing, rather than assuming consent is the default.
Distinguish clearly in your documentation between identification (one-to-many) and verification (one-to-one) use cases, as the risk and safeguards may differ.
Consider whether a Data Protection Impact Assessment is warranted given the typically higher-risk nature of biometric identification, and verify the applicable requirements against the current official text.
Confirm the position under each relevant jurisdiction, including possible member state derogations and any divergence under the UK GDPR and national implementing law.
Critically assess claims that data has been anonymised, treating pseudonymised biometric records as personal data still within scope until genuine anonymisation is demonstrated.