Direct answer · GDPR
Biometric data and facial databases
As a rule, no. Facial features processed to uniquely identify a person are biometric data (Article 4(14)) and fall under the prohibition on processing special categories of personal data (Article 9(1)). That prohibition applies unless an exception in Article 9(2) applies, such as explicit consent; a legal basis under Article 6 is needed as well. The Dutch Data Protection Authority fined Clearview AI a total of EUR 30.5 million in 2024 for a database of facial images scraped from the internet. Separately, since 2 February 2025 the AI Act prohibits AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage (Article 5(1)(e) AI Act).
For you to establish
- On which exception of Article 9(2) does the organisation rely?
Articles
- Art. 4(14) GDPR Definition of biometric data.
- Art. 9(1) GDPR Prohibition on processing special categories of personal data, including biometric data for unique identification.
- Art. 9(2) GDPR The exceptions to the prohibition.
- Art. 5(1)(e) AI Act Prohibition on creating facial databases through untargeted scraping (since 2 February 2025).
Enforcement
- Clearview AI: 30.5 million euro fine and penalty orders for illegal facial database (Autoriteit Persoonsgegevens, Besluit tot opleggen boetes en lasten onder dwangsom Clearview AI Inc., AP, 16 mei 2024 (kenmerk niet gepubliceerd; bekendgemaakt 3 september 2024), 2024-05-16)Fines of EUR 20 million and EUR 10.5 million for a scraped facial database (Art. 6, 9(1), 12 and 14).
