European data protection law

Fingerprints and biometric data under the GDPR

A reading of Articles 4, 5 and 9 of Regulation (EU) 2016/679.

How the GDPR defines biometric data

Article 4(14) of the GDPR defines biometric data as personal data resulting from specific technical processing relating to a person's physical, physiological or behavioural characteristics, where that processing allows or confirms unique identification. The legal definition expressly mentions dactyloscopic data, which means fingerprint data.

Why the purpose of processing matters

Article 9 treats biometric data used for the purpose of uniquely identifying a person as a special category of personal data. Its processing is generally prohibited unless one of the conditions set out in Article 9 applies.

This does not mean that every use of a fingerprint is governed in exactly the same way. The purpose, the technical processing, the organisation involved and the applicable legal basis all matter. A competent data protection professional should be consulted for advice on a specific processing operation.

Core data protection principles

Article 5 sets out principles that apply to personal data processing. They include purpose limitation, data minimisation, storage limitation and appropriate security. These principles are particularly relevant when information can be used to confirm a person's identity.

Fingerprint cards and administrative procedures

An authority requesting fingerprints sets the purpose and requirements of its own procedure. A fingerprinting service should not replace those official instructions or decide the legal basis for the authority receiving the data.

Groupe AS Detectives provides ink fingerprinting in Paris. This article explains the general European legal framework and is not legal advice about a particular application or authority.

Official source