How the GDPR defines biometric data
Article 4(14) of the GDPR defines biometric data as personal data resulting from specific technical processing relating to a person's physical, physiological or behavioural characteristics, where that processing allows or confirms unique identification. The legal definition expressly mentions dactyloscopic data, which means fingerprint data.
Why the purpose of processing matters
Article 9 treats biometric data used for the purpose of uniquely identifying a person as a special category of personal data. Its processing is generally prohibited unless one of the conditions set out in Article 9 applies.
This does not mean that every use of a fingerprint is governed in exactly the same way. The purpose, the technical processing, the organisation involved and the applicable legal basis all matter. A competent data protection professional should be consulted for advice on a specific processing operation.
Core data protection principles
Article 5 sets out principles that apply to personal data processing. They include purpose limitation, data minimisation, storage limitation and appropriate security. These principles are particularly relevant when information can be used to confirm a person's identity.
Fingerprint cards and administrative procedures
An authority requesting fingerprints sets the purpose and requirements of its own procedure. A fingerprinting service should not replace those official instructions or decide the legal basis for the authority receiving the data.
Groupe AS Detectives provides ink fingerprinting in Paris. This article explains the general European legal framework and is not legal advice about a particular application or authority.
Official source
- Regulation (EU) 2016/679 on EUR-Lex, particularly Articles 4, 5 and 9