Law note · Netherlands
UAVG Article 29, Biometric-Data Exception for Authentication or Security
UAVG Article 29 is a genuine Dutch national addition beyond the General Data Protection Regulation (GDPR) Article 9 baseline, confirmed verbatim by direct fetch: it exercises the GDPR Article 9(2)(g) substantial public-interest derogation to permit processing biometric data for unique identification specifically where necessary for authentication or security purposes.
The provision does not itself enumerate safeguards, a retention limit, or qualifying use cases beyond authentication or security, and no further AP guidance elaborating its boundaries was found. The exception applies equally to a voiceprint and a faceprint; UAVG Article 29's own text does not distinguish by modality, and no AP guidance specifically addressing voiceprint biometrics as distinct from facial biometrics was found.
What it asks of an app
- Rely only on an authentication-or-security purpose, or another General Data Protection Regulation (GDPR) Article 9(2) basis, before processing biometric data of a person in the Netherlands for unique identification; UAVG Article 29's exception reaches no broader purpose on its face.
When LexLint raises it
Declared activities: processes_biometrics, processes_voice, high_risk_decisions
Primary source: wetten.overheid.nl, UAVG Art. 29 (direct fetch, verbatim, confirmed twice)