Data Protection HubConcepts and Definitions

Biometric Data (Article 4(14) GDPR)

Biometric data are characteristics of a person resulting from specific technical processing (fingerprint, facial image, voice and others) that allow their unique identification and that, as a special category under Article 9 GDPR, are subject to a general prohibition of processing.

Biometric data rank among the most sensitive categories of personal data, because they are inseparably linked to a person's physical identity. Article 4(14) GDPR defines them as personal data resulting from specific technical processing relating to the physical, physiological or behavioral characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data.

Key takeaways

  • Biometric data arise only through the use of specific technical processing that turns physical, physiological or behavioral characteristics into identifying information.
  • Photographs and images are biometric data only where they are processed by specific technical means allowing the unique identification or authentication of a person (Recital 51 GDPR).
  • Biometric data for the purpose of uniquely identifying a person belong to the special categories of personal data under Article 9 GDPR and are subject to a general prohibition of processing.
  • Processing is permitted only under the narrow conditions of Article 9(2) GDPR; Member States may introduce additional conditions (Article 9(4) GDPR).

1 Overview

Biometric data are not a standalone data category in the sense that certain bodily characteristics would become biometric data merely by virtue of their existence. What is decisive is the technical processing: it is only the collection and processing by specific means aimed at unique identification or authentication that elevates a characteristic to the level of Article 4(14) GDPR. In doing so, the definition covers three groups of characteristics:

  • physical characteristics: fingerprints, hand geometry, facial geometry, iris structure, vein patterns
  • physiological characteristics: DNA profile, odor, heart rhythm
  • behavioral characteristics: voice, writing dynamics when signing, gait

Biometric data for the purpose of uniquely identifying a person fall under the special categories of personal data pursuant to Article 9(1) GDPR. Their processing is prohibited in principle and permitted only where one of the exhaustively regulated exceptions of Article 9(2) GDPR applies. For related term definitions, see Genetic Data (Article 4(13) GDPR) and Data Concerning Health (Article 4(15) GDPR).

2 Elements of the Definition

2.1 Specific Technical Processing as a Prerequisite

The central element is the use of specific technical processing during collection or processing. Without this technical step there is no biometric datum within the meaning of Article 4(14) GDPR, even if the underlying bodily characteristic would objectively be capable of identifying a person.

This has considerable practical significance for images: a passport photo that is simply stored and displayed is not yet a biometric datum. It becomes one only when it is processed with facial recognition software or similar biometric methods geared toward unique identification or authentication (Recital 51 GDPR). Under this standard, images in passports, identity cards, driver's licenses, and residence permits are biometric data only where the processing is carried out by such specific technical means.

The use of facial recognition software in public spaces or in access systems turns the processed image into a biometric datum and thereby triggers the prohibition of processing under Article 9(1) GDPR. Anyone operating a camera with facial recognition processes special categories of personal data, even if they only match the image briefly.

2.2 Physical, Physiological and Behavioral Characteristics

The definition distinguishes three groups of characteristics without deriving different legal consequences from them. The group of behavioral characteristics is of practical importance because it is not confined to physically static properties. It includes in particular:

  • Signature with writing dynamics: a mere copy or scan of a signature is not a biometric datum, because writing flow and writing pressure cannot be reconstructed from it. Where, by contrast, the signature is captured via a signature pad that records and analyzes speed, pressure, and movement pattern, a biometric datum exists.
  • Voice: every person has a distinctive manner of speaking. Where the voice is processed for authentication purposes (for instance in voice biometrics systems), it constitutes a biometric datum.

2.3 Unique Identification or Confirmation

The processing must allow or confirm the unique identification of the person. Biometric methods that merely permit a rough assignment to a group (e.g. age, sex) therefore do not produce biometric data within the meaning of the definition, provided that no individual identification is sought or made possible.

3 Examples of Biometric Data at a Glance

The following table shows typical characteristics that are classified as biometric data under Article 4(14) GDPR as soon as they are processed by suitable technical methods.

CharacteristicCharacteristic categoryTypical methodPractical example
FingerprintPhysicalDactyloscopy, capacitive sensorTime recording, smartphone unlocking
Facial imagePhysicalFacial recognition (biometric analysis)Access control, video surveillance with analysis
Iris structurePhysicalIris scanBorder control, high-security area
Vein pattern (hand/finger/wrist)PhysiologicalVein scannerAccess system, payment system
VoiceBehavioralVoice biometricsTelephone authentication, voice assistant
Signature with writing dynamicsBehavioralSignature pad with pressure analysisDigital contract signing

4 Classification as a Special Data Category

4.1 General Prohibition of Processing

Biometric data used for the purpose of uniquely identifying a natural person fall under Article 9(1) GDPR. The processing of these data is prohibited in principle. It is permitted only where one of the exceptions exhaustively listed in Article 9(2) GDPR applies, such as explicit consent of the data subject (Article 9(2)(a) GDPR), a substantial public interest (Article 9(2)(g) GDPR), or a legitimate interest in the field of employment and social protection law (Article 9(2)(b) GDPR).

Details on the grounds for lawful processing under Article 9(2) GDPR can be found in the overview of sensitive data categories.

4.2 Opening Clause for Member States

Article 9(4) GDPR allows Member States to introduce or maintain additional conditions, including restrictions, with regard to genetic data, biometric data, and data concerning health. The German legislature has made use of this option, among other places, in the German Federal Data Protection Act (BDSG). On the scope of these national margins, see the page on the opening clause for Member State law.

4.3 Distinction: Biometric Data vs. Personal Data in General

Not every processing of bodily characteristics automatically leads to the applicability of Article 9 GDPR. What is decisive is whether the processing is aimed at unique identification. Where this purpose or the specific technical processing is absent, there is indeed a personal datum that must meet the general requirements of the GDPR, but not a biometric datum under Article 4(14) GDPR.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn