Legislation in motion
Proposal: exception for biometric verification under the data subject's sole control (Article 9(2)(l) GDPR)
- Date
- Status
- proposal
- Body
- Europese Commissie
- Reference
- COM(2025) 837 final, artikel 3, punt 3, onder a (nieuw artikel 9, lid 2, onder l AVG), overweging 34; 2025/0360(COD); ST 15698/25
What it is about
The proposal adds an exception to the ban on processing biometric data. Processing is allowed where it is necessary to confirm a data subject's identity (verification, a one-to-one comparison) and the biometric data or the means needed for verification are under the sole control of the data subject. According to recital 34 this is the case, for example, where the data are stored only on the data subject's side, or stored by the controller in state-of-the-art encrypted form with the key held solely by the data subject. Identification (a one-to-many search in a database) is not covered. In Joint Opinion 2/2026 the EDPB and EDPS welcome the exception, but ask to add necessity and proportionality to the recital, to delete the statement that such processing is not likely to create significant risks, and to include examples of appropriate safeguards.
What this means in practice
If adopted, you could offer biometric verification (such as fingerprint or face login) without relying on explicit consent as the Article 9 exception, provided the data subject has sole control: storage on the person's own device, badge or smart card, or encrypted storage where only the data subject holds the key. Storing biometric data centrally in the clear or with a key you control would not be covered. You would still need a legal basis under Article 6, must check whether a less intrusive method suffices, and must carry out a risk assessment.
The GDPR articles concerned
Source: Raad van de EU, register (COM(2025) 837 final als ST 15698/25); EDPB-EDPS Joint Opinion 2/2026checked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Part of the file
Themes where this returns
The counterpart in the other law
- Article 2 AI Act: Scope
via Using special categories of personal data to detect bias
- Article 3 AI Act: Definitions
- Article 5 AI Act: Prohibited AI practices
- Article 6 AI Act: Classification rules for high-risk AI systems
- Article 10 AI Act: Data and data governance
- Article 50 AI Act: Transparency obligations for providers and deployers of certain AI systems
Case law8 of 10
- EU Court of Justice in KNLTB: a purely commercial interest can be a legitimate interest
2024-10-04 · final, Hof van Justitie van de Europese Unie
- Noord-Nederland District Court upholds DPA fine for village livestream, reduces it to 375 euros
2025-01-09 · status not established, Rechtbank Noord-Nederland
- Schrems v Meta: no unlimited retention and aggregation of data for targeted advertising
2024-10-04 · final, Hof van Justitie van de EU (Vierde kamer), Maximilian Schrems tegen Meta Platforms Ireland Limited
- Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
2026-07-29 · final, Raad van State, Afdeling bestuursrechtspraak
- Mousse: asking for Mr or Ms when selling a train ticket is not necessary
2025-01-09 · final, Hof van Justitie van de EU (Eerste kamer), Mousse tegen Commission nationale de l'informatique et des libertés (CNIL) en SNCF Connect
- Overijssel District Court revokes DPA fine for wifi tracking in Enschede
2024-02-02 · final, Rechtbank Overijssel
- Meta v Bundeskartellamt: competition authority may find a GDPR breach, strict conditions for legal bases behind personalised advertising
2023-07-04 · final, Hof van Justitie van de EU (Grote kamer), Meta Platforms Inc., Meta Platforms Ireland Ltd en Facebook Deutschland GmbH tegen Bundeskartellamt
- Interim relief judge: DPA must redact fine amount when giving an enforcement decision to complainants
2024-05-31 · status not established, Rechtbank Den Haag, voorzieningenrechter (kort geding, team handel)
Guidelines8 of 10
- Guidelines 03/2026 on web scraping in the context of generative AI
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Guidelines 05/2020 on consent under Regulation 2016/679
2020-05-04 · final, European Data Protection Board (EDPB)
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
2024-12-17 · final, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR (legitimate interest)
2024-10-08 · adopted, European Data Protection Board (EDPB)
- Guidelines 1/2026 on processing of personal data for scientific research purposes
2026-04-15 · adopted, European Data Protection Board (EDPB)
- Guidelines 01/2025 on Pseudonymisation
2025-01-16 · adopted, European Data Protection Board (EDPB)
- EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
2026-02-10 · final, European Data Protection Board en European Data Protection Supervisor
Enforcement and fines8 of 9
- Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
2026-02-03 · final, Autoriteit Persoonsgegevens
- Dutch DPA and tennis federation KNLTB end litigation: fine cut from 525,000 to at most 250,000 euros
2025-10-18 · status not established, Autoriteit Persoonsgegevens
- 600,000 euro fine for AS Watson (Kruidvat) over tracking cookies without consent
2024-05-02 · annulled, Autoriteit Persoonsgegevens
- 500 euro fine and penalty order for Stichting Oud Lemmer over webcam livestream
2021-07-09 · status not established, Autoriteit Persoonsgegevens
- DPA cuts Kruidvat fine to 50,000 euros on objection
2025-05-27 · status not established, Autoriteit Persoonsgegevens
- Experian Netherlands fined 2.7 million euros for credit scoring without legal basis or information
2025-10-16 · final, Autoriteit Persoonsgegevens
- Coolblue fined 40,000 euros on objection for cookies without consent
2024-12-23 · status not established, Autoriteit Persoonsgegevens
- Formal warning to the Dutch Minister of Education, Culture and Science not to put the CABR war archive online and searchable
2024-11-26 · final, Autoriteit Persoonsgegevens
Legislation in motion6 of 17
- Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
2026-09-11 · under negotiation, Raad van de Europese Unie, Iers voorzitterschap
- Proposal: exception for incidental special category data in AI development (Article 9(2)(k) and 9(5) GDPR)
2025-11-19 · proposal, Europese Commissie
- Proposal: legitimate interest for development and operation of AI (new Article 88c GDPR)
2025-11-19 · proposal, Europese Commissie
- Proposal: cookie rules move from ePrivacy to the GDPR, with new exceptions and a six-month rule (new Article 88a GDPR and Article 5(3) ePrivacy)
2025-11-19 · under negotiation, Europese Commissie
- Proposal: definition of scientific research, purpose limitation and information duty for research (Article 4(38), 5(1)(b) and 13(5) GDPR)
2025-11-19 · under negotiation, Europese Commissie
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper