Glossary Terms

Biometric Data

Personal data derived from physical or behavioural characteristics and used to uniquely identify or authenticate a person.
On this page

What is biometric data?

Biometric data is information produced through technical processing of a person’s physical, physiological or behavioural characteristics. It can include facial templates, fingerprints, iris patterns, voiceprints, vein patterns, gait, keystroke dynamics and other measurements. The information becomes especially sensitive when it is used to identify a person uniquely or verify that someone is who they claim to be.

A photograph is not automatically biometric data in every context. It may become biometric when a system extracts a template or measurements and compares them for identification or authentication. The legal classification depends on the applicable framework and the purpose of the processing.

Why is biometric data sensitive?

Biometric identifiers are closely connected to a person and are difficult or impossible to replace if compromised. A password can be changed; a fingerprint or face cannot. Biometric systems may also enable persistent tracking across locations or services, particularly when identification occurs at a distance without active participation by the individual.

Accuracy can vary across populations, environments and devices. False matches may lead to exclusion, investigation or denial of access, while false non-matches can prevent legitimate users from using a service. These risks make testing, transparency and challenge procedures essential.

How should biometric processing be assessed?

The organisation should begin by defining the exact purpose and considering whether a less intrusive alternative is available. It should identify which biometric characteristic is used, how templates are created, where they are stored, who can access them, whether matching is one-to-one or one-to-many and how long the data will be retained.

A privacy or data-protection impact assessment is often appropriate because biometric processing can create high risk. The assessment should consider lawful basis, additional legal conditions, consent where relevant, security, accuracy, discrimination, children or vulnerable people, vendor arrangements and international transfers.

What controls protect biometric data?

Strong controls include encryption, template protection, segregation, access restrictions, short retention, deletion procedures, liveness detection, rate limiting and monitoring for misuse. Organisations should avoid storing raw biometric images when a protected template is sufficient and should limit the ability to reuse templates across unrelated purposes.

People should receive clear information about what is collected, why it is needed, how long it is kept and what alternatives or rights are available. Testing should examine both security and performance across relevant groups.

Frequently asked questions

Is facial recognition the same as face verification?

No. Verification usually compares a face with one claimed identity, while identification searches for a match among many identities. Identification generally creates broader privacy risk.

Are voice recordings biometric data?

A recording may become biometric when technical features are extracted and used to identify or authenticate a speaker. Ordinary audio is not automatically biometric.

Can consent make every biometric use acceptable?

No. Consent must be valid and the processing must still be necessary, proportionate, secure and lawful. In some relationships, consent may not be freely given.

Should biometric templates be retained indefinitely?

No. Retention should be tied to the defined purpose and legal requirements. Templates should be deleted when they are no longer necessary.

What happens if biometric data is breached?

The organisation should contain the incident, assess potential harm, determine notification duties and consider whether affected templates or authentication methods can be revoked or replaced.

Book your personalised demo!
And see how leading organisations are already powering their Privacy and AI Governance with context-aware operations.