Law note · European Union
GDPR Article 9, Special Categories of Personal Data Including Biometric Data
Article 9(1) prohibits processing special categories of personal data, including biometric data processed for the purpose of uniquely identifying a person, unless a listed Article 9(2) exception applies, most commonly explicit consent.
Article 4(14) defines biometric data as data from specific technical processing of physical, physiological or behavioural characteristics, with the statute's own examples (facial images, fingerprint data) stated as non-exhaustive, so the same definition reaches a voiceprint once a system derives an identification capable template from audio, even though the text never uses the word voice.
Recital 51 confirms an ordinary photograph is not itself biometric data and only becomes covered when processed through a specific technical means allowing unique identification, so a faceprint a controller derives from one, even from a publicly available photograph, is newly covered special category data; the General Data Protection Regulation (GDPR) text does not separately discuss audio recordings.
The Dutch data protection authority fined Clearview AI EUR 30.5 million (decision dated 16 May 2024, publicly announced 3 September 2024) for building a facial recognition database from photographs scraped off the public internet without an Article 9 basis, with parallel enforcement by the Greek, French and Italian authorities on the same facts.
What it asks of an app
- Obtain explicit consent, or establish another Article 9(2) basis, before capturing or storing a faceprint, voiceprint, or other biometric identifier derived from a photo, video, or audio recording, whether or not the source recording itself was publicly available.
- Treat any biometric identifier your system derives through its own technical processing as special category data, even where the underlying image or audio was lawfully public.
When LexLint raises it
Declared activities: processes_biometrics, processes_voice, high_risk_decisions
Primary source: Official Journal text, EUR-Lex, Regulation (EU) 2016/679