# Biometric Data (Article 4(14) GDPR)

Biometric data are characteristics of a person resulting from specific technical processing (fingerprint, facial image, voice and others) that allow their unique identification and that, as a special category under Article 9 GDPR, are subject to a general prohibition of processing.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/begriffe-und-definitionen/1.2.14-biometrische-daten
> Sprache: en



Biometric data rank among the most sensitive categories of personal data, because they are inseparably linked to a person's physical identity. Article 4(14) GDPR defines them as personal data resulting from specific technical processing relating to the physical, physiological or behavioral characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data.

<Callout type="info">
  **Key takeaways**

  * Biometric data arise only through the use of **specific technical processing** that turns physical, physiological or behavioral characteristics into identifying information.
  * Photographs and images are biometric data only where they are processed by specific technical means allowing the unique identification or authentication of a person (Recital 51 GDPR).
  * Biometric data **for the purpose of uniquely identifying** a person belong to the special categories of personal data under [Article 9 GDPR](https://dsgvo-gesetz.de/art-9-dsgvo/) and are subject to a general prohibition of processing.
  * Processing is permitted only under the narrow conditions of Article 9(2) GDPR; Member States may introduce additional conditions (Article 9(4) GDPR).
</Callout>

## 1 Overview [#1-overview]

Biometric data are not a standalone data category in the sense that certain bodily characteristics would become biometric data merely by virtue of their existence. What is decisive is the technical processing: it is only the collection and processing by specific means aimed at unique identification or authentication that elevates a characteristic to the level of Article 4(14) GDPR. In doing so, the definition covers three groups of characteristics:

* **physical characteristics**: fingerprints, hand geometry, facial geometry, iris structure, vein patterns
* **physiological characteristics**: DNA profile, odor, heart rhythm
* **behavioral characteristics**: voice, writing dynamics when signing, gait

Biometric data for the purpose of uniquely identifying a person fall under the special categories of personal data pursuant to [Article 9(1) GDPR](https://dsgvo-gesetz.de/art-9-dsgvo/). Their processing is prohibited in principle and permitted only where one of the exhaustively regulated exceptions of Article 9(2) GDPR applies. For related term definitions, see [Genetic Data (Article 4(13) GDPR)](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.13-genetische-daten) and [Data Concerning Health (Article 4(15) GDPR)](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.15-gesundheitsdaten).

## 2 Elements of the Definition [#2-elements-of-the-definition]

### 2.1 Specific Technical Processing as a Prerequisite [#21-specific-technical-processing-as-a-prerequisite]

The central element is the use of **specific technical processing** during collection or processing. Without this technical step there is no biometric datum within the meaning of Article 4(14) GDPR, even if the underlying bodily characteristic would objectively be capable of identifying a person.

This has considerable practical significance for images: a passport photo that is simply stored and displayed is not yet a biometric datum. It becomes one only when it is processed with facial recognition software or similar biometric methods geared toward unique identification or authentication ([Recital 51 GDPR](https://dsgvo-gesetz.de/erwaegungsgruende/nr-51/)). Under this standard, images in passports, identity cards, driver's licenses, and residence permits are biometric data only where the processing is carried out by such specific technical means.

<Callout type="warn">
  The use of facial recognition software in public spaces or in access systems turns the processed image into a biometric datum and thereby triggers the prohibition of processing under Article 9(1) GDPR. Anyone operating a camera with facial recognition processes special categories of personal data, even if they only match the image briefly.
</Callout>

### 2.2 Physical, Physiological and Behavioral Characteristics [#22-physical-physiological-and-behavioral-characteristics]

The definition distinguishes three groups of characteristics without deriving different legal consequences from them. The group of behavioral characteristics is of practical importance because it is not confined to physically static properties. It includes in particular:

* **Signature with writing dynamics**: a mere copy or scan of a signature is not a biometric datum, because writing flow and writing pressure cannot be reconstructed from it. Where, by contrast, the signature is captured via a signature pad that records and analyzes speed, pressure, and movement pattern, a biometric datum exists.
* **Voice**: every person has a distinctive manner of speaking. Where the voice is processed for authentication purposes (for instance in voice biometrics systems), it constitutes a biometric datum.

### 2.3 Unique Identification or Confirmation [#23-unique-identification-or-confirmation]

The processing must allow or confirm the **unique identification** of the person. Biometric methods that merely permit a rough assignment to a group (e.g. age, sex) therefore do not produce biometric data within the meaning of the definition, provided that no individual identification is sought or made possible.

## 3 Examples of Biometric Data at a Glance [#3-examples-of-biometric-data-at-a-glance]

The following table shows typical characteristics that are classified as biometric data under Article 4(14) GDPR as soon as they are processed by suitable technical methods.

| Characteristic                   | Characteristic category | Typical method                          | Practical example                                |
| -------------------------------- | ----------------------- | --------------------------------------- | ------------------------------------------------ |
| Fingerprint                      | Physical                | Dactyloscopy, capacitive sensor         | Time recording, smartphone unlocking             |
| Facial image                     | Physical                | Facial recognition (biometric analysis) | Access control, video surveillance with analysis |
| Iris structure                   | Physical                | Iris scan                               | Border control, high-security area               |
| Vein pattern (hand/finger/wrist) | Physiological           | Vein scanner                            | Access system, payment system                    |
| Voice                            | Behavioral              | Voice biometrics                        | Telephone authentication, voice assistant        |
| Signature with writing dynamics  | Behavioral              | Signature pad with pressure analysis    | Digital contract signing                         |

## 4 Classification as a Special Data Category [#4-classification-as-a-special-data-category]

### 4.1 General Prohibition of Processing [#41-general-prohibition-of-processing]

Biometric data used for the purpose of uniquely identifying a natural person fall under [Article 9(1) GDPR](https://dsgvo-gesetz.de/art-9-dsgvo/). The processing of these data is prohibited in principle. It is permitted only where one of the exceptions exhaustively listed in Article 9(2) GDPR applies, such as explicit consent of the data subject (Article 9(2)(a) GDPR), a substantial public interest (Article 9(2)(g) GDPR), or a legitimate interest in the field of employment and social protection law (Article 9(2)(b) GDPR).

Details on the grounds for lawful processing under Article 9(2) GDPR can be found in the overview of [sensitive data categories](/docs/dsgvo-hub/einzelthemen/besondere-kategorien-personenbezogener-daten/1.3.12.1-sensible-datenkategorien).

### 4.2 Opening Clause for Member States [#42-opening-clause-for-member-states]

Article 9(4) GDPR allows Member States to introduce or maintain additional conditions, including restrictions, with regard to genetic data, biometric data, and data concerning health. The German legislature has made use of this option, among other places, in the German Federal Data Protection Act (BDSG). On the scope of these national margins, see the page on the [opening clause for Member State law](/docs/dsgvo-hub/einzelthemen/besondere-kategorien-personenbezogener-daten/1.3.12.3-oeffnungsklausel-fuer-mitgliedstaatliches-recht).

### 4.3 Distinction: Biometric Data vs. Personal Data in General [#43-distinction-biometric-data-vs-personal-data-in-general]

Not every processing of bodily characteristics automatically leads to the applicability of Article 9 GDPR. What is decisive is whether the processing is aimed at unique identification. Where this purpose or the specific technical processing is absent, there is indeed a [personal datum](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.1-personenbezogene-daten) that must meet the general requirements of the GDPR, but not a biometric datum under Article 4(14) GDPR.

<Cards>
  <Card title="Article 4(14) GDPR" href="https://dsgvo-gesetz.de/art-4-dsgvo/" description="Legal definition of biometric data in full text." />

  <Card title="Article 9 GDPR" href="https://dsgvo-gesetz.de/art-9-dsgvo/" description="Prohibition of processing and exceptions for special data categories." />

  <Card title="Recital 51 GDPR" href="https://dsgvo-gesetz.de/erwaegungsgruende/nr-51/" description="Images as biometric data only where specific technical means are used." />

  <Card title="Genetic Data" href="/docs/dsgvo-hub/begriffe-und-definitionen/1.2.13-genetische-daten" description="Article 4(13) GDPR: related special data category." />

  <Card title="Data Concerning Health" href="/docs/dsgvo-hub/begriffe-und-definitionen/1.2.15-gesundheitsdaten" description="Article 4(15) GDPR: further special data category." />

  <Card title="Sensitive Data Categories" href="/docs/dsgvo-hub/einzelthemen/besondere-kategorien-personenbezogener-daten/1.3.12.1-sensible-datenkategorien" description="Overview of Article 9 GDPR and the grounds for lawful processing." />

  <Card title="Opening Clause for Member States" href="/docs/dsgvo-hub/einzelthemen/besondere-kategorien-personenbezogener-daten/1.3.12.3-oeffnungsklausel-fuer-mitgliedstaatliches-recht" description="National additions and stricter rules for biometric data." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.