Biometric Data Is in Your Systems. Is Your Governance Program Ready?

Biometric data enters enterprise systems through more pathways than most privacy programs have mapped. Building access systems that use fingerprint or facial recognition.

RCDr. Richard Chingombe · Founder, Verisq·4 min read·Practitioner perspective, not legal advice

Time and attendance systems that use hand geometry. Employee monitoring systems that use voice recognition for authentication. Customer identity verification services that use facial matching. AI systems that process video content from which biometric characteristics can be extracted. Each of these creates a category of personal data that GDPR classifies as special category data, requiring explicit consent or another specific legal basis under Article 9, and that is subject to specific regulatory requirements under biometric privacy laws in an increasing number of US states. The data is in the systems. The governance programs that specifically address it are rarer than the data is.

What Makes Biometric Data Different

Biometric data is personal data with a characteristic that most personal data categories do not have: it is inherently linked to the individual and cannot be changed. A compromised password can be reset. A compromised biometric template cannot be replaced. The individual whose facial geometry has been exposed in a data breach is exposed permanently. This permanence characteristic is why biometric data receives special category treatment in GDPR and heightened protection in biometric-specific legislation — the risk to the individual from biometric data exposure persists indefinitely.

The definition of biometric data under GDPR is specific: biometric data means personal data resulting from specific technical processing relating to the physical, physiological, or behavioral characteristics of a natural person, which allow or confirm the unique identification of that natural person. This definition captures both raw biometric measurements and the processed templates derived from them. An organization that stores facial recognition templates rather than raw images is storing biometric data under this definition.

The distinction between collecting biometric data and collecting data from which biometric characteristics can be derived is narrower than most organizations assume. Video surveillance systems, photographs in personnel files, and audio recordings can be sources from which biometric data can be extracted through processing. The regulatory question is not only whether biometric data has been explicitly collected — it is whether the data collected can be used to produce biometric characteristics.

Where Biometric Data Is Entering Enterprise Systems

Physical Access and Time-Tracking Systems

Biometric authentication for building access and time-tracking is the most established enterprise use case. Fingerprint scanners and facial recognition systems in this context process biometric data for authentication purposes. In the EU, GDPR Article 9 requires either explicit consent from the individuals enrolled or another specific legal basis. In several EU member states, including Germany and France, biometric data processing in employment contexts has been specifically regulated with strict requirements. The organization that has deployed biometric access control without conducting a GDPR Article 9 legal basis assessment has a compliance gap that is common and significant.

AI Systems That Infer Biometric Characteristics

AI systems that process video, audio, or images may produce biometric data as a byproduct — facial recognition capabilities in video analysis tools, voice biometrics in customer service AI, emotion recognition in assessment tools. These systems create biometric data through processing even if their primary function is not biometric identification. The EU AI Act specifically addresses emotion recognition and biometric categorization systems, classifying some as high-risk or prohibited, creating additional governance obligations beyond GDPR Article 9.

Customer Identity Verification Services

Liveness detection and facial matching services used for customer identity verification process customer biometric data. The service provider processes the biometric data as a processor under GDPR, creating DPA requirements. The customer whose face is processed for identity verification has provided their biometric data in the context of the verification transaction. Whether they have provided the explicit consent required for biometric processing under Article 9, or whether another legal basis applies, requires specific legal basis analysis that many organizations implementing identity verification services have not conducted.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

The US Biometric Privacy Landscape

US state biometric privacy laws have created a patchwork of requirements that has produced significant litigation. Illinois's BIPA has produced hundreds of class action lawsuits against organizations that collected biometric data without adequate disclosure, consent, or data handling practices. Texas and Washington have enacted similar laws. California's CPRA includes specific provisions for sensitive personal information that encompasses biometric data.

BIPA's private right of action — allowing individuals to sue directly for statutory damages — has made biometric compliance failures expensive. Settlements in BIPA class actions have ranged from millions to hundreds of millions of dollars. The litigation risk from biometric data governance failures in Illinois is as significant as regulatory enforcement risk in any other jurisdiction.

The governance program that has addressed GDPR Article 9 for biometric data in EU operations but has not conducted a parallel assessment of US state biometric privacy law obligations has addressed half of its biometric governance obligation for organizations operating in both jurisdictions.

Inventory every system in your environment that collects, processes, or can derive biometric data. Apply the appropriate legal basis analysis for each jurisdiction where those systems operate.

Map the biometric data in your environment. Apply GDPR Article 9 legal basis analysis. Assess US state biometric law requirements. The litigation risk and regulatory risk are both material and both require attention.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.