Skip to main content
Praxikon

Direct answer · GDPR

May an organisation process biometric data or a database of facial features?

Short answer

As a rule, no. Facial features processed to uniquely identify a person are biometric data (Article 4(14)) and fall under the prohibition on processing special categories of personal data (Article 9(1)). Processing requires an exception in Article 9(2), such as explicit consent, and a legal basis under Article 6. Clearview AI was fined EUR 30.5 million in total for a scraped facial database.

Direct answer · GDPR

Biometric data and facial databases

As a rule, no. Facial features processed to uniquely identify a person are biometric data (Article 4(14)) and fall under the prohibition on processing special categories of personal data (Article 9(1)). That prohibition applies unless an exception in Article 9(2) applies, such as explicit consent; a legal basis under Article 6 is needed as well. The Dutch Data Protection Authority fined Clearview AI a total of EUR 30.5 million in 2024 for a database of facial images scraped from the internet. Separately, since 2 February 2025 the AI Act prohibits AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage (Article 5(1)(e) AI Act).

For you to establish

  • On which exception of Article 9(2) does the organisation rely?

Articles

  • Art. 4(14) GDPR Definition of biometric data.
  • Art. 9(1) GDPR Prohibition on processing special categories of personal data, including biometric data for unique identification.
  • Art. 9(2) GDPR The exceptions to the prohibition.
  • Art. 5(1)(e) AI Act Prohibition on creating facial databases through untargeted scraping (since 2 February 2025).

Enforcement

Read the article Check your own case General interpretation, not legal advice. The official source remains authoritative.

Check your own situation

Describe your system or project in the free case check and get a reasoned first assessment of, among other things, the DPIA obligation, Article 22 GDPR and the AI Act, with the source for every conclusion.

Go to the free case check
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist