Identity and Privacy Law
55.0 What this chapter gives you#
- You will be able to say exactly what makes a piece of information personal data under Article 4(1) of the General Data Protection Regulation, apply the identifiability test from the Breyer judgment of 2016, and explain what the Court of Justice changed about that test in September 2025.
- You will be able to choose a lawful basis for an identity system from the six in Article 6(1), write the justification down, and explain why consent is the wrong answer far more often than product teams assume.
- You will be able to decide whether a particular use of a face, a fingerprint or an iris falls inside Article 9, using the phrase “for the purpose of uniquely identifying a natural person” as the hinge it actually is.
- You will be able to turn data minimization, purpose limitation and storage limitation into a retention schedule with real field lists and real dates, rather than a paragraph of policy language.
- You will be able to apply Article 22 to a system that refuses people, name the two judgments that decided what counts as an automated decision and what an explanation must contain, and design the human review that Article 22(3) requires.
- You will be able to state the substantive differences between the GDPR and India’s Digital Personal Data Protection Act 2023, including what a consent manager is, what a notice must contain, and which European rights have no Indian equivalent.
- You will be able to price the risk of a biometric deployment in Illinois under 740 ILCS 14, including what the August 2024 amendment did to the arithmetic and what it left untouched.
- You will be able to pick a transfer mechanism for identity data leaving the European Economic Area, name the current instruments with their dates, and say which of them is under appeal as of August 2026.
- You will be able to write a data protection impact assessment for an identity system that a regulator would accept, section by section, and know when Article 36 forces you to consult a regulator before you launch.
- You will be able to list the design decisions that data protection law simply removes from you, which is the whole point of this chapter.
There is a habit of mind, common in engineering teams and almost universal in start-ups, which treats law as something that happens after the software. You build the thing, it works, and then somebody in a different building writes a privacy notice describing what you built. The notice is the compliance. The system is the system.
For identity data that habit is wrong in a way that costs money and occasionally kills products. Identity data is the most heavily regulated category of data there is, governed by general data protection statutes, specific biometric statutes, sectoral rules for banking and health and telecommunications, consumer protection law, employment law, and increasingly artificial intelligence law. Those rules do not merely tell you how to describe your architecture. They tell you that certain architectures may not be built at all, that certain data may not be kept past a certain date, that certain decisions may not be made by a machine alone, and that certain databases may not physically exist in certain countries. A retention rule is not a documentation task. It is a constraint on your storage layer that changes what queries are possible two years from now.
This chapter is about those constraints, and it is deliberately concrete. We will follow one company through one project, in three jurisdictions, and do the arithmetic. The company is a self-storage business called Harrow Lane Storage, headquartered in Dublin, with thirty-one sites across Ireland and the United Kingdom, one site in Chicago and a shared services office in Bengaluru. It has 46,000 active customers. Somebody has proposed replacing the keypad codes at the gates with face recognition, because customers keep forgetting the codes and the call centre spends eleven minutes on every reset. The proposal is sensible, cheap and popular. It is also, in three legal systems, three different problems.
Two chapters neighbour this one and we will not trespass on them. Chapter 54 covers age assurance, and chapter 56 covers the right not to be identified, live facial recognition in public space and the prohibitions in the European Union’s artificial intelligence law. Where either subject arises here it gets one line and a pointer. This chapter is about the data protection rules that apply to ordinary, consensual, commercially motivated identity systems built by people with no bad intentions at all.
The plain version#
The village tool library and its ledger#
Imagine a village with a tool library in the church hall. Anyone can borrow a drill, a ladder or a wallpaper steamer. Because tools go missing, the volunteer on the desk writes things in a ledger: who borrowed what, on what day, and when they brought it back. To be sure the name is real, the volunteer glances at a driving licence and copies the number in too.
For the first year the ledger is a nuisance. By year five it is something else. It is a complete record of which households own no ladder, who was doing building work in the month their neighbour’s shed burned down, who borrowed a carpet cleaner three days after a family argument, and who has never borrowed anything at all. Nobody set out to build that record. It assembled itself, one honest line at a time, out of a reasonable desire to get the drills back.
Now the village writes rules about the ledger. Not rules about drills. Rules about the ledger. There are five of them, and they are the whole of data protection law in miniature.
The first rule is about what counts. The ledger obviously counts, because it has names in it. But the volunteers also keep a second book, in which each borrower is a number rather than a name, and there is a card index in a drawer that turns numbers back into names. The village decides that the numbered book counts too, because the drawer exists. Anything you can turn back into a person is treated as being about that person.
The second rule is about permission. You may not write in the ledger just because you feel like it. You need a reason the village recognizes as a good one. “The borrower said it was fine” is one such reason, and the village notices very quickly that it is a weak one, because a person standing at the desk who wants the drill will say yes to anything.
The third rule is about restraint. You write down what you need and no more. To get the drill back you need a name and a way to reach the person. You do not need their date of birth, their employer, or a photocopy of their licence. If you take more than you need, you have taken it whether or not you ever look at it.
The fourth rule is about time and about drift. You keep the entry while it is doing its job and then you destroy it, and you may not quietly start using the ledger for a different job. The ledger exists to get tools back. It does not exist so that the parish council can work out who is renovating and might afford a bigger donation.
The fifth rule is about travel. If the ledger is photocopied and posted to a records company in the next county, the village’s rules go with it, or the copy does not go.
Every idea in this chapter is one of those five rules, written in exact language, backed by fines, and applied to the most sensitive kind of ledger entry there is: the entry that says who somebody is.
What “your data” actually means, and why it is wider than your name#
Most people, asked what their personal data is, name three or four things: their name, their address, their date of birth, perhaps their bank details. The legal answer is much wider, and the width is the part that catches engineers out.
Personal data is any information about a person you can pick out. Two words in that sentence are doing heavy work.
About is generous. A photograph is about you. A shoe size recorded next to your customer number is about you. So is an opinion somebody typed into a comment box concerning you, and so is a decision somebody made about you. It does not have to be true, private, or interesting.
Pick out is the word that surprises people. You do not need a name. If a database has one row per person, and that row can be matched to a real human being by anybody holding the right extra piece of information, the row is about that human being. A customer number is personal data because the customer file exists. A device identifier is personal data because the account it logged into exists. A hashed email address is personal data because whoever made the hash can make it again and compare.
This is why “we removed the names” is almost never the end of a conversation about privacy. Removing the name replaces one label with another label. If some route back exists, and somebody could reasonably take that route, the data is still about the person.
There is a second surprise. Some kinds of information about you are treated as much more dangerous than the rest, and the law puts a second lock on them: health, religion, politics, trade union membership, sex life, ethnic origin, genetic data. And one more that matters enormously to us, which is a measurement of your body used to work out which person you are. A photograph is ordinary data. The same photograph turned into a numerical description of your face, in order to tell you apart from everybody else, is not ordinary at all.
Five questions the law asks before you may keep anything#
Strip away the vocabulary and a data protection regulator is asking five questions, in this order, about every field in your database.
Is this about a person? If not, most of the rules stop. What entitles you to have it? Not what excuses it, what entitles you: there is a short, closed list of entitlements and you must pick one before you collect, not afterwards. Is this one of the dangerous kinds? If so, the short list becomes much shorter, and most of what remains is unavailable to an ordinary business. Do you need all of it, and for how long? Every field must justify itself and every field must have a date on which it dies. And where does it go? Out of the building is a question, out of the country is a bigger question, and into a machine that decides something about the person is the biggest question of all.
If you can answer those five for every field, you have done most of the work. If you cannot answer them for a field, you have found either a design flaw or a field that should not exist.
The gate at Harrow Lane: a worked example#
Harrow Lane Storage has 46,000 active customers and thirty-one sites. Each site has a gate with a keypad. Customers forget their codes at a rate of about 900 resets a month, each reset costing eleven minutes of call centre time. At a fully loaded cost of 34 euro an hour, that is 900 times eleven minutes, which is 165 hours a month, which is 5,610 euro a month, or 67,320 euro a year. The face recognition system quoted at 41,000 euro to install and 19,000 euro a year to run. On the spreadsheet, it pays for itself in under a year.
Here is what the system would do. A camera at the gate takes a picture. Software converts the picture into a list of numbers describing the geometry of the face. That list is called a template. The template is compared with those already stored for that site’s customers, and if one matches closely enough the gate opens.
Now run the five questions. Is it about a person? Yes, unambiguously; the whole point is to tell one person from another. What entitles the company to have it? The obvious answer, and the wrong one, is “the customer agreed when they signed up”, and we will spend some time on why that is weak. Is it one of the dangerous kinds? Yes: a face template made in order to work out which customer this is, is exactly the case the second lock was written for. Do they need all of it, and for how long? They need it while the person is a customer, not after they close their unit, and they do not need the original photographs once the templates exist. Where does it go? The matching software runs on a cloud service whose servers are in Virginia, and that single sentence turns a local project into an international transfer question.
There is a sixth thing, which is a consequence rather than a question. A face template for this system is a list of 512 numbers, each stored in four bytes, so 2,048 bytes per person. Multiply by 46,000 customers and the entire biometric database of Harrow Lane Storage is 94,208,000 bytes, which is about 94 megabytes. It fits on a phone. It fits in an email attachment if you compress it. The most dangerous asset the company will ever own is smaller than a film trailer, and that is exactly why the law treats it the way it does.
Why “the customer agreed” is a weaker answer than it sounds#
Here is the single most useful idea in this chapter for anybody building an identity product, and it is entirely explicable without jargon.
Consent, in law, means a real choice freely made. Three things wreck it.
The first is that a choice is not free if refusing costs you the service. If the only way to get into your own storage unit is to let a camera measure your face, you have not chosen. You have complied.
The second is that a choice is not free between unequal parties. An employee asked by an employer to scan their fingerprint to clock in is not in a position to say no. Neither is a benefits claimant asked by the state, or a patient asked by a hospital.
The third, and the one that catches builders out, is that consent can be taken back. If you rest your whole system on consent, then on the day a customer withdraws it you must stop, and you must delete. That is fine for a marketing list. It is impossible for an anti-money-laundering record you are legally required to retain for five years, and it is a nightmare for a security log.
So a mature identity system almost never rests on consent. It rests on something sturdier: a legal requirement, a contract that genuinely cannot be performed without the data, or a carefully argued and written-down business need that has been weighed against the harm to the person. Consent gets used where it belongs, which is for the genuinely optional extras.
There is one hard exception, and it is the one that bites Harrow Lane. For the dangerous categories, including biometrics used to identify, the ordinary sturdy options mostly disappear, and explicit consent is one of the very few doors left open. So the company is pushed towards the weakest basis precisely where the data is most sensitive. The way out is not a better consent form. The way out is to offer a genuine alternative, so that saying no costs the customer nothing. Keep the keypad. Offer the face as a convenience. Then the consent is real, and the whole structure stands up.
What the rules take away from you#
If you read the rules as a documentation exercise, you will conclude that Harrow Lane can build whatever it likes as long as the privacy notice is honest. That conclusion is false. Applied properly, the rules delete options from the design space before a line of code is written. They say the company may not keep the photographs, only the templates. They say it may not have one big national template database if a per-site database would do. They say a customer refused by the gate at half past eleven at night must be able to reach a human being, not a form. They say the Chicago site may not switch on at all without a written policy published in advance and a signature obtained in advance, on pain of a thousand dollars per person. They say the templates may not sit on the Virginia servers without a specific legal instrument in place first.
None of those are documentation. Every one of them is an architecture decision. That is what it means to say the rules change what you may build.
Where the plain version stops being true#
“Identifiable” is not a property of the data#
The plain version said that if some route back to the person exists, the data is personal. That is the right starting point and it is not quite the law, and the gap became much more important in the last year.
Identifiability is not a fixed property of a dataset. It is a relationship between a dataset and whoever is holding it. The same file can be personal data in your hands and not personal data in mine, if you hold the key and I do not, and if I have no realistic way of getting it.
The honest version: personal data is a relative concept. The test is whether identification is reasonably likely for the party in question, taking into account the time, cost and technology it would take, and any legal or contractual barriers standing in the way. A rigorous, key-separated pseudonymization can put a recipient outside the scope of the rules even though the sender remains firmly inside them.
This matters to identity engineering in a very direct way. It is the legal foundation of every design in which one party knows who you are and another party knows what you did. It also has a trap in it: the assessment is about realistic re-identification, not theoretical impossibility, and the bar is high. Regulators have generally read it narrowly. We will do the case law properly in the technical half.
Consent is not a shield, it is a liability#
The plain version said consent is weak. The stronger and less comfortable statement is that consent, wrongly used, actively increases your exposure.
If you rely on consent and it turns out not to have been freely given, you did not have a lawful basis at all. Every record you collected is unlawful from the first day, not from the day the regulator noticed. There is no partial credit. A company that had quietly relied on a legitimate business interest, and documented the balancing, would have been on firmer ground than a company that collected a tick-box which a regulator later reads as coerced.
There is also a timing trap. Consent must be obtained before processing. If your system captures the image and then shows the consent screen while the template is being computed, you have processed without a basis, and the fact that the user then agreed does not cure it.
The honest version: consent is the right basis for a narrow set of genuinely optional things, offered by a party with no power over you, which can be switched off cleanly and completely on request. Very little of an identity system fits that description.
“We only keep a mathematical code, not a photo”#
Vendors say this constantly, to imply that templates are somehow less regulated than images. The opposite is closer to the truth.
A photograph of a face is ordinary personal data. It becomes specially protected when it is put through technical processing to produce something that allows or confirms unique identification. The act of converting the photograph to a template is precisely the act that engages the stricter regime. Turning the picture into numbers does not launder it. It upgrades it.
There is a second claim in the same family: that templates are irreversible, so nothing can leak. Treat that as a claim to be tested rather than a fact. Research on template inversion has repeatedly shown that face images recognizable to humans, and images good enough to fool other matchers, can be reconstructed from embeddings under various assumptions about attacker knowledge. Whether a particular vendor’s template can be inverted is an empirical question about that vendor’s model, not a property of templates in general.
The honest version: a template is not a hash. A password hash is designed so that similar inputs give completely different outputs. A biometric template is designed so that similar inputs give similar outputs, because that is what makes matching work. That requirement is exactly what makes the strong irreversibility guarantees of password hashing unavailable. Your protection comes from encryption, access control and template protection schemes, not from the format. And you can change a password. You cannot change your face.
The rules are not one rulebook, and they do not agree#
The plain version implied a single set of five questions. In reality Harrow Lane stands in the overlap of at least four regimes that answer the same question differently.
European law asks whether biometric identification has a lawful basis and an Article 9 exception. Illinois law does not care about your lawful basis at all; it asks whether you published a retention policy and obtained a written release before you collected, and it lets every individual sue you personally. India’s law has no special category for biometrics, and constrains you instead through a notice-and-consent architecture with an unfamiliar intermediary in the middle. The United Kingdom’s regime is textually close to the European one and diverging slowly, and what matters in practice is the regulator’s enforcement priorities rather than the words.
You cannot satisfy all of them with one design decision, but you can usually satisfy all of them with one design discipline: collect the least, keep it the shortest time, keep it in the fewest places, and always leave a non-biometric route to the same outcome.
A DPIA is not paperwork you write afterwards#
Almost every impact assessment written in industry is written after the architecture is fixed, by somebody who was not in the design meetings, in order to be filed. Those documents are worthless and occasionally worse than worthless, because they are evidence that you considered the risk and proceeded anyway.
The honest version: an assessment is a decision record, not a description, and its value is measured by how many design decisions it changed. Its most important section is the one listing the options you rejected and why, because that is the section a regulator reads to find out whether you understood the risk or merely wrote it down.
Compliance does not make a system safe#
Everything in this chapter can be satisfied while building a system that hurts people. You can have a lawful basis, a signed assessment, a lawful transfer mechanism, a published retention schedule, and a gate that refuses a legitimate customer at eleven at night in the rain because her face changed after chemotherapy. Nothing in data protection law required anybody to measure that failure rate across skin tones or ages before deployment, and nothing in it obliges you to publish the number.
This book returns to that asymmetry deliberately. A system that wrongly lets somebody in produces an incident report and a number. A system that wrongly refuses somebody produces silence, and a person standing outside. Only one of the two is counted. Data protection law is the floor. It is not the ceiling, and was not designed to be.
The technical version#
Article 4(1), Recital 26, and the Breyer test#
Regulation (EU) 2016/679, the General Data Protection Regulation, entered into force on 24 May 2016 and has applied since 25 May 2018. Article 4(1) defines personal data as any information relating to an identified or identifiable natural person, and defines an identifiable natural person as one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.
Four elements have to be present: information, relating to, an identified or identifiable person, who is a natural person. Each has been litigated. For identity systems the fight is almost always over “identifiable”.
Recital 26 supplies the test. To determine whether a person is identifiable, account should be taken of all the means reasonably likely to be used, either by the controller or by another person, to identify the person directly or indirectly, and to ascertain whether means are reasonably likely to be used, account should be taken of all objective factors including the costs of and the amount of time required for identification, the available technology at the time of the processing, and technological developments. Recital 26 also states that the principles of data protection do not apply to anonymous information, which is the source of every argument about whether a dataset has been anonymized properly.
The leading authority on applying that test is Case C-582/14, Patrick Breyer v Bundesrepublik Deutschland, decided by the Court of Justice on 19 October 2016 under the predecessor Directive but consistently applied under the Regulation. Mr Breyer objected to German federal websites logging his dynamic Internet Protocol address. A dynamic address is reassigned by the internet provider from a pool, so on its own it does not name anybody, and the website operator holds no subscriber records.
The Court held that the dynamic address was nevertheless personal data in the hands of the website operator, because German law gave the operator legal channels through which it could obtain the additional information held by the internet provider, in particular in the event of a cyber attack. Two things follow. First, the extra information does not have to be in your hands for the data to be personal. Second, the route to it has to be a real one; the Court’s reasoning turned on the existence of legal means, and it said the position would differ if identification were prohibited by law or practically impossible because it would require a disproportionate effort in time, cost and manpower.
Breyer is the reason your access logs are personal data, and the reason a device fingerprint, an advertising identifier, a hashed email and a customer reference number are personal data in almost every real deployment. Two later judgments extended it. In Case C-604/22, IAB Europe, decided on 7 March 2024, a string encoding a user’s advertising preferences was personal data for the organization that defined the string, because that organization had the means, through its members, to combine it with an identifier. In Case C-319/22, Gesamtverband Autoteile-Handel, decided on 9 November 2023, vehicle identification numbers, impersonal in themselves, became personal data when a manufacturer made them available to independent repairers who had means reasonably likely to link them to owners.
What the Court changed in 2025, and why identity engineers should care#
On 4 September 2025 the Court of Justice decided Case C-413/23 P, European Data Protection Supervisor v Single Resolution Board, ECLI:EU:C:2025:645. The dispute arose from the resolution of Banco Popular. The Single Resolution Board had collected written comments from shareholders and creditors, stripped the names, replaced them with randomly generated codes, and sent the comments to Deloitte as an independent valuer. Deloitte never had the key. The European Data Protection Supervisor found the Board had failed to tell people that Deloitte would receive their data.
The case was decided under Regulation (EU) 2018/1725, which governs the European Union’s own institutions, but its definitions are deliberately identical to the GDPR’s and the Court said so.
The Court held that pseudonymized data must not be regarded as constituting, in all cases and for every person, personal data. Pseudonymization is not part of the definition of personal data; it is a set of technical and organizational measures that reduces the risk of a dataset being correlated with identities. Whether data are personal must be assessed by reference to the means reasonably likely to be used by the party actually holding them. If a recipient has no key, no contractual right to one and no realistic means of cross-referencing, the data may not be personal data in that recipient’s hands even though they plainly remain personal data for the sender.
Three qualifications keep this from being the blank cheque some coverage suggested. First, the Court kept the Breyer and Gesamtverband line intact: data impersonal in themselves become personal when the controller puts them where somebody has means reasonably likely to identify, and are then personal for that person and indirectly for the controller too. Second, on the actual outcome, the Board lost, because the duty to inform under Article 15(1)(d) of Regulation 2018/1725, which corresponds to Article 13(1)(e) of the GDPR, attaches at collection and cannot be dissolved by the later possibility that a recipient will identify nobody. You must name the recipient in your notice regardless. Third, the European Data Protection Board has taken the opposite position in its Guidelines 01/2025 on pseudonymization, which went to public consultation in 2025 and treats pseudonymized data as personal. Where a court and a regulator disagree, the court wins in the long run and the regulator wins in your inbox next month. As of August 2026 the practical advice is to treat pseudonymized identity data as personal unless you hold a written, evidenced assessment saying otherwise for a specific recipient.
There is a legislative sequel. On 19 November 2025 the European Commission published its Digital Omnibus package, one part of which proposes to amend the GDPR’s definition of personal data to codify the relative approach, and to add a new Article 41a empowering the Commission to set technical criteria for when pseudonymized data may be treated as no longer personal for particular entities. The artificial intelligence part of the package became law: the European Parliament endorsed it on 16 June 2026, the Council on 29 June 2026, and it was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744, in force from 27 July 2026. The data part, containing the GDPR amendments, did not. As of August 2026 those changes remain proposals under negotiation.
| Data item | Personal data? | Why |
|---|---|---|
| Customer number | Yes | Customer file exists |
| Dynamic IP in web log | Yes | Breyer; legal route to ISP |
| Face template, site DB | Yes | One row per named customer |
| SHA-256 of an email | Yes | Hash recomputable from input |
| Aggregate gate count | No | No single person distinguished |
Article 9: biometrics for the purpose of unique identification#
Article 4(14) defines biometric data as personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data.
Article 9(1) prohibits the processing of a listed set of categories: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a natural person’s sex life or sexual orientation.
Read those two provisions together and the hinge becomes visible. Biometric data is defined by what the processing can do; special category status attaches only when the processing is done for the purpose of uniquely identifying. Recital 51 confirms it: the processing of photographs is not systematically covered, and photographs fall within the definition of biometric data only when processed through specific technical means allowing the unique identification or authentication of a person. The moment you run a photograph through an embedding model in order to tell one person from another, you have crossed into Article 9.
The European Data Protection Board’s Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement, version 2.0 published on 17 May 2023, set out the analysis in the policing context, and the reasoning about when a facial image becomes biometric data is the same commercially. The earlier Guidelines 3/2019 on processing of personal data through video devices, version 2.0 adopted on 29 January 2020, are more directly useful for a company with cameras: video surveillance that creates biometric templates in order to identify people falls within Article 9, and simply recording video does not.
Article 9(2) lists ten exceptions, and for a commercial identity system almost all are unavailable. Article 9(2)(b) covers employment and social security law obligations. Article 9(2)(f) covers legal claims. Article 9(2)(g) covers substantial public interest, but requires a basis in Union or Member State law that is proportionate and provides safeguards, which a private company does not have. That leaves Article 9(2)(a), explicit consent, as the workable door for Harrow Lane. Article 9(4) permits Member States to keep or introduce further conditions, including limitations, on genetic, biometric and health data, which is why national rules diverge inside the European Union.
Article 9 is a second lock, not an alternative one. You need a lawful basis under Article 6 and an exception under Article 9. Explicit consent under 9(2)(a) does not supply the Article 6 basis; you still need Article 6(1)(a) consent alongside it, and both must be valid.
The distinction between one-to-one and one-to-many is technically important and legally less decisive than vendors claim. Verification compares a live sample against the single template belonging to a claimed identity. Identification searches a live sample against a gallery. Both are processing for the purpose of uniquely identifying and both are inside Article 9. One-to-one is less risky in practice, because the gallery is a single record that can live on a device the person controls, but it is not outside the regime.
On necessity, Case C-205/21, Ministerstvo na vatreshnite raboti, decided on 26 January 2023, concerned Bulgarian police collecting biometric and genetic data from everybody charged with an intentional offence. The Court, applying the Law Enforcement Directive 2016/680 rather than the GDPR, held that such processing is permitted only where strictly necessary, that this is a heightened standard, and that national law providing for systematic collection without an assessment of strict necessity in the individual case is contrary to the Directive.
The clearest commercial illustration is the Information Commissioner’s Office action against Serco Leisure. On 23 February 2024 the ICO issued nine enforcement notices to Serco Leisure, Serco Jersey and seven associated community leisure trusts, ordering them to stop using facial recognition and fingerprint scanning to monitor the attendance of more than 2,000 employees at 38 leisure facilities, and to destroy the biometric data they were not legally obliged to retain, within three months. The reasoning is this chapter in miniature. Biometrics were not shown to be necessary or proportionate when identity cards or fobs would do, no alternative was offered, and the imbalance of power between employer and employee meant consent could not be freely given.
Two Clearview AI matters calibrate the risk for anyone building a gallery from images they did not collect. In September 2024 the Dutch data protection authority fined Clearview 30.5 million euro for building a database of over 30 billion scraped photographs converted into biometric codes and for failing to answer access requests, with further penalty payments of up to 5.1 million euro for continued non-compliance. In the United Kingdom the ICO fined Clearview 7.5 million pounds in May 2022; the First-tier Tribunal set that aside in 2023 on jurisdictional grounds; and on 8 October 2025 the Upper Tribunal allowed the ICO’s appeal on three of four grounds, holding the activity within the territorial scope of United Kingdom data protection law. As of August 2026 the merits are back before the First-tier Tribunal and Clearview has permission to appeal further.
Lawful bases, and why consent is usually the wrong one#
Article 6(1) lists six bases, and processing is lawful only if at least one applies.
| Article 6(1) basis | Fits identity work? | Typical use |
|---|---|---|
| (a) consent | Rarely | Optional convenience |
| (b) contract | Sometimes | Account creation |
| (c) legal obligation | Often | KYC, AML, right to work |
| (d) vital interests | Almost never | Medical emergency |
| (e) public task | Public bodies only | Statutory registers |
| (f) legitimate interests | Usually | Fraud control, security |
Article 4(11) defines consent as any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they signify agreement by a statement or a clear affirmative action. Article 7 adds conditions. Article 7(1) puts the burden of demonstrating consent on the controller. Article 7(3) gives the right to withdraw at any time, and requires that withdrawal be as easy as giving. Article 7(4) says that in assessing whether consent is freely given, utmost account shall be taken of whether the performance of a contract is made conditional on consent to processing that is not necessary for that contract. Recital 43 says consent should not provide a valid legal ground where there is a clear imbalance between the data subject and the controller, in particular where the controller is a public authority.
Five reasons consent fails for identity systems, in the order they usually bite. It fails on conditionality, because if the identity check is a precondition of the service there is no real alternative and the consent is not freely given; this is why the answer to Harrow Lane’s problem is to keep the keypad working. It fails on imbalance: employer to employee, state to citizen, platform to dependent user, hospital to patient, of which the Serco notices are the case in point. It fails on withdrawal, because you cannot honour a withdrawal against a five-year anti-money-laundering record that a different statute compels you to retain. It fails on granularity, because a single tick covering identity verification, fraud analytics, marketing personalization and model training is not four consents but usually zero valid ones. And it fails on evidence, because Article 7(1) means producing, for a specific individual on a specific date, what they were shown and what they did, which most systems cannot. A defensible consent record looks like this.
{
"subject_ref": "HL-46113",
"basis": "art6(1)(a) + art9(2)(a)",
"purpose": "gate_entry_face_match",
"notice_version": "hl-bio-notice-3.2",
"notice_hash": "b1946ac9-2a3f-4e17-9b0d-7c11f6a8",
"captured_at": "2026-03-14T09:41:07Z",
"method": "on_screen_double_opt_in",
"alternative_offered": "keypad_pin",
"withdrawn_at": null
}
The three fields that carry the legal weight are notice_version, which lets you reconstruct what was actually shown, alternative_offered, which is the evidence that refusal was free, and withdrawn_at, which must be honoured within the systems, not just the record.
Where consent fails, legitimate interests under Article 6(1)(f) is usually the correct basis, and it is not a soft option. It requires a documented three-part assessment: identify the interest and check it is lawful and real; show the processing is necessary, in the sense that no less intrusive route achieves the outcome; and balance it against the interests, rights and freedoms of the data subject, taking account of their reasonable expectations. Recital 47 says a controller’s interests may provide a legal basis provided the interests or fundamental rights of the data subject do not override them, and expressly names fraud prevention. Article 21(1) then gives a right to object which you must answer with compelling legitimate grounds.
Note the asymmetry that catches out biometric projects. Legitimate interests is a perfectly good Article 6 basis for a face-matching gate. It does nothing for Article 9, where no such exception exists at all.
Article 5 applied: minimization, purpose limitation, storage limitation#
Article 5(1) sets six principles and Article 5(2) makes the controller responsible for, and able to demonstrate, compliance with them. That last clause is the accountability principle, and it is the reason documentation is not optional even though documentation alone is not compliance.
Article 5(1)(b) requires that data be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes. Article 5(1)(c) requires that data be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed; the Regulation prints the parenthetical name as “data minimisation”. Article 5(1)(e) requires that data be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are processed.
Article 6(4) supplies the compatibility test for a new purpose: consider any link between the original and new purposes, the context in which the data were collected and in particular the relationship between subject and controller, the nature of the data and especially whether Article 9 categories are involved, the possible consequences for the subject, and the existence of appropriate safeguards including encryption or pseudonymization.
Applied to identity work, four rules of thumb follow, and each is a design instruction rather than a policy sentence. Do not keep the evidence once you have the conclusion: having checked a passport to establish who somebody is, what you need afterwards is the conclusion and an audit trail proving a check occurred, not a full-colour scan; chapter 54 handles the age case properly. Do not keep the raw biometric once you have the template, because the image was an input and keeping it doubles your exposure while adding nothing. Do not centralize what can be partitioned, because thirty-one site galleries of a few hundred templates are a materially smaller target than one national gallery of 46,000, and faster to search. And do not store an identifier where a derived, non-reversible fact would serve: a national identification number stored in full is a permanent liability, while a salted keyed hash used only for duplicate detection is not, provided the key sits in a hardware security module and is rotated.
Here is what a real retention schedule looks like for the Harrow Lane project. Not a policy paragraph, a table with fields, triggers and dates.
| Field | Trigger | Retention |
|---|---|---|
| Enrolment photograph | Template created | Delete at once |
| Face template | Contract ends | 30 days |
| Gate event, matched | Event | 90 days |
| Gate event, refused | Event | 12 months |
| Consent record | Withdrawal or exit | 6 years |
| ID document scan | Verification done | Not retained |
Three of those rows will start an argument in a real company, and the arguments are worth having. The refused-entry events are kept longer than the successful ones because they are the evidence you need when somebody complains that the system failed them, and because a run of refusals is a security signal. The consent record outlives the biometric data because Article 7(1) requires you to be able to demonstrate consent after the fact, and the limitation period for a civil claim in Ireland is six years. And the document scan row says “not retained”, which will be resisted, because somebody always wants to keep it just in case. “Just in case” is not a purpose.
That schedule has to be enforced by the system rather than by memory, which means a purge job with a fixed time and a signed manifest written to write-once storage as evidence. And it has to survive the backup problem. Deleting rows from a live database does not delete them from backups, and restoring a backup from before the deletion resurrects the data. The practical answer used by serious systems is to encrypt each site’s templates under a distinct key and destroy the key rather than chase the ciphertext, because destroying a key is an operation you can actually complete and evidence. That is an implementation detail rather than a legal requirement, but it is the difference between a deletion promise you can keep and one you cannot.
Article 22: automated decisions and identity-based exclusion#
Article 22(1) gives the data subject the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. Article 22(2) allows such decisions where necessary for entering into or performing a contract, authorized by Union or Member State law with suitable safeguards, or based on explicit consent. Article 22(3) requires, in the contract and consent cases, at least the right to obtain human intervention, to express a point of view, and to contest the decision. Article 22(4) provides that such decisions shall not be based on Article 9 special category data unless 9(2)(a) or 9(2)(g) applies and suitable measures to safeguard rights and legitimate interests are in place.
Two judgments define the current shape of Article 22.
Case C-634/21, OQ v Land Hessen, decided on 7 December 2023 and universally known as the SCHUFA case, concerned a German credit scoring agency which argued that it merely produced a score and the bank made the decision. The Court held that the automated establishment of a probability value concerning a person’s ability to meet payment commitments constitutes an automated individual decision within Article 22(1) where a third party to whom the value is transmitted draws strongly on it to decide whether to establish, implement or end a contractual relationship. That collapses the defence scoring vendors habitually rely on. If your identity assurance score is what determines whether the relying party opens the account, you are making the decision, whoever presses the button.
Case C-203/22, CK v Magistrat der Stadt Wien, decided on 27 February 2025, concerned a mobile phone contract refused on the basis of an automated creditworthiness assessment by Dun and Bradstreet Austria. The Court addressed what Article 15(1)(h) means by meaningful information about the logic involved. It is not the algorithm and not the source code. It is an explanation of the procedure and principles actually applied, in a concise, transparent, intelligible and easily accessible form, sufficient for the person to understand which of their personal data were used and in what way, so that they can exercise the rights in Article 22(3). Trade secrets do not permit a blanket refusal; where asserted, the disputed information goes to the supervisory authority or the court, which balances.
Now apply it to the gate. Ayesha Nolan arrives at the Dublin site at 23:10 on 4 April 2026. The matcher returns a similarity score of 0.58 against her enrolled template, and the site threshold is 0.62. The gate does not open. There is no member of staff on site after 20:00.
Is that an Article 22 decision? It is based solely on automated processing, because nobody reviewed it. Does it produce legal effects or similarly significantly affect her? Denial of access to property she is paying to store, at night, with no alternative route in, is a strong candidate. It is also based on Article 9 data, which brings Article 22(4) into play, so it needs explicit consent and suitable safeguards on top of everything else.
What the law therefore obliges the company to build is not a paragraph in a notice. It is:
Gate refusal path
capture -> match -> below threshold
|
v
[1] retry once, new frame
|
still below
|
v
[2] fallback: keypad PIN
|
refused
|
v
[3] intercom to 24h operator
|
v
[4] operator override, logged:
who, when, reason, score
|
v
[5] event written to refusal log
retained 12 months, reviewed
monthly for pattern by site
Steps 2 and 3 are the Article 22(3) human intervention, made real. Step 4 is the audit trail that lets you answer a subject access request under Article 15(1)(h) with an actual account of what happened, which is what CK v Magistrat der Stadt Wien requires. Step 5 is how you find out that your system fails one demographic group more often than another, which no article of the Regulation obliges you to discover and which you should discover anyway. False accepts are counted because they generate incidents; false rejects are not counted because the person goes away. If you write nothing else into your design from this chapter, write the refusal log.
The European Union’s artificial intelligence law, Regulation (EU) 2024/1689, classifies remote biometric identification and biometric categorization as high-risk in Annex III point 1. Those obligations were originally due from 2 August 2026; Regulation (EU) 2026/1744, in force since 27 July 2026, moved them to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for systems embedded in products regulated under Annex I. The Article 5 prohibitions, applicable since 2 February 2025, are chapter 56’s territory.
India’s DPDP Act 2023 and the 2025 Rules#
The Digital Personal Data Protection Act 2023 received the President’s assent on 11 August 2023. It has 44 sections and one schedule. It applies to digital personal data processed within India, and to processing outside India where it relates to offering goods or services to data principals in India. Its vocabulary is different: the individual is a data principal, the organization deciding purposes and means is a data fiduciary, and a data processor processes on a fiduciary’s behalf.
For two years the Act was law without machinery. The Digital Personal Data Protection Rules 2025 were notified on 13 November 2025, and they commence in phases. Rules 1 and 2, and rules 17 to 21 establishing the Data Protection Board of India, took effect on notification. Rule 4, on the registration and obligations of consent managers, takes effect one year after publication, which is 13 November 2026. Rules 3, 5 to 16, 22 and 23, which carry the substantive compliance obligations, take effect eighteen months after publication, which is 13 May 2027. As of August 2026, an Indian data fiduciary is inside the Act and mostly outside the operative Rules, which is an uncomfortable place to be building.
The structural differences from the GDPR are not cosmetic.
There are two grounds for processing, not six. Section 4 permits processing only for a lawful purpose for which the data principal has given consent, or for certain legitimate uses. Section 6 sets the consent standard: free, specific, informed, unconditional and unambiguous, with a clear affirmative action, limited to the personal data necessary for the specified purpose, and withdrawable with comparable ease. Section 7 lists the legitimate uses, which include voluntary provision of data by the principal for the specified purpose, provision by the State of subsidies, benefits, services, certificates, licences or permits, compliance with a legal obligation, medical emergency, public health, disaster, and employment purposes. There is no general legitimate-interests balancing test of the European kind. If your processing is not consented and does not fit an enumerated legitimate use, there is no third door.
There is no special category. The Act does not single out biometric, health, genetic, religious or caste data for stricter treatment; a face template and a postal address sit under the same rules. This is the sharpest divergence from Europe. It does not mean biometrics are unregulated in India. It means the constraint arrives through notice, consent, purpose limitation, security safeguards under Rule 6, and the general obligation in Section 8 to erase when the purpose is no longer served.
The notice is prescriptive. Section 5 requires notice given with or before a consent request, and Rule 3 requires it to be presented independently of any other information, in clear and plain language, with an itemized description of the personal data and the specified purpose described together with the goods, services or uses the processing enables, plus the means of withdrawing consent, exercising rights and complaining to the Board. Section 5(3) requires that the principal be able to access the notice in English or any language in the Eighth Schedule to the Constitution, of which there are twenty-two.
The consent manager has no European equivalent. It is a person registered with the Board who enables a data principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. Rule 4 and the First Schedule set the conditions: a company incorporated in India, a minimum net worth of INR 2 crore, demonstrated technical, operational and financial capacity, and consent records kept for at least seven years. Registration opens on 13 November 2026. Whether it works is an empirical question about coverage.
Children are defined as under eighteen, without gradation. Section 9 requires verifiable consent from a parent or lawful guardian and prohibits tracking, behavioural monitoring and advertising targeted at children. Rule 10 sets out how verifiable consent works, including reliance on identity details already held or on a virtual token mapped to a verified identity, and the Fourth Schedule exempts certain classes of fiduciary and certain purposes.
Rights are narrower. Sections 11 to 14 give access to information about processing, correction and erasure, grievance redressal, and the right to nominate another person to exercise rights on death or incapacity, which has no GDPR counterpart and is a genuinely good idea. There is no portability right, no general right to object, and no equivalent of Article 22. If an Indian identity system refuses somebody by machine, the Act gives no right to human review.
Section 10 empowers the government to designate significant data fiduciaries by reference to volume and sensitivity of data, risk to the rights of principals, sovereignty and integrity of India, risk to electoral democracy, security of the State and public order. A designated fiduciary must appoint a Data Protection Officer based in India who is responsible to the board of directors, appoint an independent data auditor, and undertake periodic impact assessments and audits.
Breach handling is fast and unqualified: Rule 7 requires the fiduciary to inform each affected data principal without delay and the Board within seventy-two hours, with no risk threshold of the kind in GDPR Article 33(1). Retention is prescribed for large platforms: Rule 8 and the Third Schedule require e-commerce entities and social media intermediaries with not less than two crore registered users in India, and online gaming intermediaries with not less than fifty lakh, to erase after three years from the date the principal last approached them for the specified purpose or exercised rights, or from commencement of the Rules, whichever is latest. Two crore is twenty million; fifty lakh is five million.
Cross-border transfer is permissive by default. Section 16 empowers the Central Government to restrict transfer to notified countries. Rule 15 states that personal data may be transferred outside India subject to the restriction that the fiduciary meets such requirements as the Central Government may by general or special order specify in respect of making the data available to any foreign State, or to any person or entity under the control of or any agency of such a State. There is no adequacy list, no standard contractual clauses and no transfer impact assessment. There is instead an executive power exercisable at any time. Sectoral localization rules survive independently, the strictest being the Reserve Bank of India’s April 2018 directive requiring payment system data to be stored only in India.
Penalties are in the Schedule to the Act and are levied by the Data Protection Board. The largest is up to INR 250 crore for failure to take reasonable security safeguards under Section 8(5). Failure to notify a breach carries up to INR 200 crore, as do breaches of the children’s obligations in Section 9. Breach of the additional obligations of a significant data fiduciary carries up to INR 150 crore, a residual head covers other breaches at up to INR 50 crore, and a data principal who breaches their own duties under Section 15 can be penalized up to INR 10,000.
| Question | GDPR | DPDP Act 2023 |
|---|---|---|
| Lawful bases | Six in Art 6(1) | Consent or listed uses |
| Special categories | Yes, Article 9 | None |
| Automated decisions | Art 22 rights | No equivalent |
| Portability | Article 20 | Not provided |
| Transfers | Chapter V toolkit | Executive order model |
| Max penalty head | 20m EUR or 4% | INR 250 crore |
Illinois BIPA and the American state biometric statutes#
The Illinois Biometric Information Privacy Act, 740 ILCS 14, was enacted as Public Act 95-994 and took effect on 3 October 2008. Its legislative findings record that major national corporations had selected Chicago and other Illinois locations as pilot sites for biometric payment at grocery stores, petrol stations and school cafeterias, and that biometrics are unlike other identifiers because a compromised social security number can be changed and a compromised fingerprint cannot. The statute predates the iPhone’s fingerprint sensor by five years and was written by people worrying about exactly the right thing.
Section 10 defines a biometric identifier as a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry, and excludes writing samples, written signatures, photographs, demographic data, tattoo descriptions and physical descriptions. Biometric information means any information based on an individual’s biometric identifier used to identify an individual, regardless of how it is captured, converted, stored or shared. The photograph exclusion has been persistently litigated, because a face template derived from a photograph is generally held to be biometric information even though the photograph itself is excluded.
Section 15 imposes five duties. Section 15(a) requires a written, publicly available policy establishing a retention schedule and destruction guidelines, with destruction at the earlier of satisfaction of the initial purpose or three years after the individual’s last interaction. Section 15(b) prohibits collection unless the entity first informs the subject in writing that biometric data is being collected or stored, informs them in writing of the specific purpose and length of term, and receives a written release. Section 15(c) prohibits profiting from biometric data. Section 15(d) restricts disclosure. Section 15(e) requires storage using the reasonable standard of care in the industry, and in a manner at least as protective as the entity uses for other confidential and sensitive information.
Section 20 is what makes BIPA different from every European instrument. It gives a private right of action to any person aggrieved by a violation, with liquidated damages of 1,000 dollars or actual damages, whichever is greater, for a negligent violation; 5,000 dollars or actual damages for an intentional or reckless violation; plus reasonable attorneys’ fees, expert witness fees and other litigation expenses, and injunctive relief. There is no regulator to negotiate with and no discretion to reduce a fine for cooperation. There is a plaintiffs’ bar.
In Rosenbach v Six Flags Entertainment Corp, 2019 IL 123186, decided on 25 January 2019, the Illinois Supreme Court held that a person is aggrieved within the meaning of Section 20 when a private entity fails to comply with a Section 15 requirement, and need not plead or prove any actual injury beyond the statutory violation. Stacy Rosenbach’s fourteen-year-old son had his thumbprint taken for a season pass. That was enough. Rosenbach is the most consequential biometric privacy decision in the United States, because it converted a technical compliance failure into a certifiable class action.
In Cothron v White Castle System Inc, 2023 IL 128004, decided on 17 February 2023, the same court held that a separate claim accrues under Sections 15(b) and 15(d) each time a private entity scans or transmits biometric data, not merely on the first occasion. White Castle’s own filings put its potential exposure in the billions.
The legislature responded. Senate Bill 2979 was signed on 2 August 2024 as Public Act 103-769, effective immediately, adding subsections (b) and (c) to Section 20. A private entity that more than once collects the same biometric identifier from the same person using the same method of collection commits a single violation of Section 15(b), for which the person is entitled to at most one recovery, and the equivalent applies to repeated disclosure to the same recipient under Section 15(d). The same Act amended the Section 10 definitions so that “written release” expressly includes an electronic signature. On 1 April 2026 the Seventh Circuit held, in litigation arising from Union Pacific, that the damages amendment applies retroactively to cases pending when it took effect.
The arithmetic on the Chicago site shows what a statutory amendment is worth. That site has 1,900 customers. Assume each enters twice a week for two years, which is 208 scans per person.
| Scenario | Calculation | Exposure |
|---|---|---|
| Cothron, negligent | 1,900 x 208 x 1,000 | 395,200,000 USD |
| Cothron, reckless | 1,900 x 208 x 5,000 | 1,976,000,000 USD |
| Post-2024, negligent | 1,900 x 1,000 | 1,900,000 USD |
| Post-2024, reckless | 1,900 x 5,000 | 9,500,000 USD |
The amendment cut the theoretical exposure by a factor of 208. It did not cut it to zero, and the surviving number, 1.9 million dollars for a single site of a mid-sized company, is still larger than the entire European fine exposure calculated below. That is the correct lesson. In the United States the risk is civil litigation, and it does not scale with your turnover; it scales with your headcount of data subjects.
Real settlement figures, for calibration.
| Case | Statute | Amount |
|---|---|---|
| Facebook, Illinois class | BIPA | 650m USD |
| Clearview AI, approved 2025 | BIPA | 51.75m USD |
| Texas v Meta, July 2024 | CUBI | 1.4bn USD |
| Texas v Google, 2025 | CUBI and DTPA | 1.375bn USD |
| 40 states v Google, 2022 | State consumer law | 390m USD |
The Facebook settlement, arising from the Tag Suggestions face-tagging feature, was approved in 2021. The Clearview AI settlement was approved on 20 March 2025 and was unusual in structure, giving the class a share of the company’s value rather than cash the company did not have. Google’s Photos face grouping produced a separate Illinois settlement, and TikTok settled a multidistrict action including BIPA claims. [UNVERIFIED: the exact amounts and approval dates of the Illinois Google Photos settlement and the TikTok multidistrict settlement]
Texas is the other jurisdiction that matters and it works differently. The Capture or Use of Biometric Identifier Act, Texas Business and Commerce Code section 503.001, has no private right of action; it is enforced by the Attorney General, and the numbers are larger. The 1.4 billion dollar Meta settlement announced in July 2024 was the first ever obtained under CUBI and, at the time, the largest privacy settlement obtained by any single state. The 1.375 billion dollar Google settlement, announced in May 2025 and finalized subsequently, combined CUBI and Deceptive Trade Practices Act claims. Washington’s House Bill 1493 of 2017, codified at RCW 19.375, likewise has no private right of action. The map changes every legislative session, and the number to check before any deployment is not how many states have a biometric law but how many of them let individuals sue.
Cross-border transfer of identity data#
Chapter V of the GDPR, Articles 44 to 50, governs transfers to third countries. Article 44 sets the general principle: any transfer may take place only if the conditions of Chapter V are complied with, including for onward transfers, and all provisions must be applied so that the level of protection guaranteed by the Regulation is not undermined.
| Mechanism | Article | Current instrument |
|---|---|---|
| Adequacy decision | 45 | Per-country decisions |
| Standard clauses | 46(2)(c) | Decision 2021/914 |
| Binding corporate rules | 47 | Authority-approved |
| Certification | 46(2)(f) | Rare in practice |
| Derogations | 49 | Occasional only |
Adequacy under Article 45 means the Commission has decided that a third country ensures an adequate level of protection, after which transfers need no further authorization. The standard contractual clauses were adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, replacing the older sets, and are structured in four modules covering controller to controller, controller to processor, processor to processor and processor to controller. Binding corporate rules under Article 47 are approved by a lead supervisory authority and suit large groups moving data internally. Article 49 derogations, including explicit consent to the specific transfer, are for occasional, non-repetitive transfers of a limited number of subjects, and are not a basis for a production data flow.
The case that reorganized the field is Case C-311/18, Data Protection Commissioner v Facebook Ireland and Maximillian Schrems, decided on 16 July 2020 and known as Schrems II. The Court invalidated the EU-US Privacy Shield adequacy decision because United States surveillance law did not provide protection essentially equivalent to that required by European Union law and did not offer data subjects actionable rights before an independent body. Crucially, it upheld the standard contractual clauses but held that an exporter using them must verify, case by case, whether the law of the destination country allows compliance, and must adopt supplementary measures where it does not. That verification exercise is the transfer impact assessment, and there is no template that discharges it.
The consequence arrived on 22 May 2023, when the Irish Data Protection Commission fined Meta Platforms Ireland 1.2 billion euro and ordered it to suspend future transfers of Facebook user data to the United States within five months, on the basis that its use of the 2021 clauses with supplementary measures did not address the risks the Court had identified.
The Commission adopted a new adequacy decision for the United States on 10 July 2023, establishing the EU-US Data Privacy Framework, backed by Executive Order 14086 and the Data Protection Review Court. In Case T-553/23, Latombe v Commission, the General Court delivered judgment on 3 September 2025, ECLI:EU:T:2025:831, dismissing the challenge and leaving the Framework in force. It has been appealed to the Court of Justice as Case C-703/25 P. As of August 2026 the Framework is valid and the appeal is pending, which is precisely the condition in which a prudent controller keeps a second mechanism ready.
The United Kingdom position is settled for the moment. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. The Commission’s 2021 UK adequacy decisions were given a six-month technical extension to 27 December 2025 to allow the impact of that Act to be assessed, and on 19 December 2025 the Commission renewed both the GDPR and Law Enforcement Directive decisions for a further six years, to 27 December 2031. In the other direction the United Kingdom operates its own adequacy regulations, the International Data Transfer Agreement, and the Addendum that bolts UK terms onto the European standard clauses.
Three points about identity data specifically are easy to miss. First, a biometric template does not stop being personal data by being sent abroad; the relative approach from the Single Resolution Board judgment may help you argue that a processor holding only unlabelled templates and no key is not holding personal data, but it does not help the exporter and does not remove the transfer from Chapter V. Second, identity data attracts the surveillance analysis more strongly than most categories, because the reason Schrems II turned on section 702 of the United States Foreign Intelligence Surveillance Act and Executive Order 12333 is that those authorities concern identifiable persons, and a dataset that is by construction a register of who people are is the hardest possible case. Third, onward transfer is where real deployments fail: your processor’s sub-processor’s disaster recovery region is a transfer, Article 44 applies the rules to onward transfers, and the standard clauses require the importer to bind sub-processors to equivalent terms. Map the chain to its end, or you do not know where your templates are.
Harrow Lane’s answer is the one most European companies reach. Keep the templates in the European Economic Area, use a region in Ireland or Germany rather than Virginia, accept the modest extra cost, and reduce a hard legal problem to a procurement decision. That is not a dodge. It is the rules changing what you build.
The data protection impact assessment, in full#
Article 35(1) requires an assessment where a type of processing, in particular using new technologies, and taking into account its nature, scope, context and purposes, is likely to result in a high risk to the rights and freedoms of natural persons. Article 35(3) makes it mandatory in three cases: systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions are based that produce legal effects or similarly significantly affect the person; processing on a large scale of Article 9 special categories or Article 10 criminal data; and systematic monitoring of a publicly accessible area on a large scale. Article 35(4) obliges supervisory authorities to publish lists of operations requiring an assessment, and every European authority’s list includes biometric identification. The Harrow Lane gate hits at least two of the three limbs on its own, so there is no judgement call to make.
Article 35(7) prescribes the minimum contents: a systematic description of the envisaged processing operations and the purposes, including where applicable the legitimate interest pursued; an assessment of the necessity and proportionality of the processing in relation to the purposes; an assessment of the risks to the rights and freedoms of data subjects; and the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance. Article 35(2) requires the advice of the Data Protection Officer where one is designated, and Article 35(9) says that where appropriate the controller shall seek the views of data subjects or their representatives.
Article 36(1) requires prior consultation with the supervisory authority where the assessment indicates that the processing would result in a high risk in the absence of measures taken to mitigate it. The trigger is high residual risk, after your mitigations. Article 36(2) gives the authority up to eight weeks to respond, extendable by six.
The recognized methodology is the Article 29 Working Party’s Guidelines on Data Protection Impact Assessment, WP248 rev.01, adopted on 4 April 2017 and last revised on 4 October 2017, endorsed by the European Data Protection Board on 25 May 2018. It sets out nine criteria, of which two or more usually indicate high risk: evaluation or scoring; automated decision-making with legal or similar significant effect; systematic monitoring; sensitive data or data of a highly personal nature; data processed on a large scale; matching or combining datasets; data concerning vulnerable data subjects; innovative use of new technological or organizational solutions; and processing that prevents data subjects from exercising a right or using a service or contract. The gate scores five of the nine: automated decision-making with significant effect, systematic monitoring, sensitive data, innovative use, and prevention of access to a contracted service.
Here is the skeleton of a real one. This is the shape a supervisory authority expects, and the section that decides whether it is a genuine assessment is section 6.
DPIA: face recognition gate entry, all sites
Version 1.4 Owner: Head of Estates DPO: reviewed
Status: sections 1-9 complete, 10 open
1 Scope and screening
Art 35(3)(a) and (b) both engaged. Mandatory.
2 Description of processing
Data flow diagram, field list, retention table,
processors and sub-processors, locations.
3 Purpose and necessity
Stated purpose. Evidence of the problem: 900
PIN resets/month, 11 min each, 67,320 EUR/yr.
4 Lawful basis and Art 9 condition
Art 6(1)(a) + Art 9(2)(a). Freely given because
keypad retained. Withdrawal path specified.
5 Proportionality
Less intrusive options and why rejected or kept.
6 Alternatives considered and rejected
Fobs; app-based unlock; PIN + SMS; on-device
template with no central gallery. Reasons.
7 Consultation
Art 35(9): customer panel, 22 participants.
Art 35(2): DPO advice, dated, recorded.
8 Risk register
Each risk: likelihood, severity, inherent score,
mitigations, residual score, owner, review date.
9 Measures
Site-scoped galleries; per-site keys; template
encryption at rest; 30-day post-exit deletion;
refusal log; demographic error monitoring.
10 Residual high risk and Art 36
If any residual risk remains high, consult the
supervisory authority before go-live.
11 Sign-off and review
Signed by controller. Review at 12 months or on
any material change, whichever is sooner.
The risk register in section 8 is where most assessments become dishonest, because it is easier to write “low” than to argue for it. A defensible entry for this project reads as prose rather than a colour code: the risk is that a legitimate customer is refused entry at night with no staff on site; the likelihood is moderate because the vendor’s documentation gives a false rejection rate of about one in a hundred at the configured threshold and the site sees roughly 340 entries a week, which predicts around three refusals a week; the severity is high for the individual because the alternative is a wasted journey; the mitigation is the fallback chain, the twenty-four-hour intercom and the refusal log; the residual likelihood of an unresolved refusal is low because every step of the fallback is monitored; and the review trigger is any month in which refusals exceed twenty at a single site or the log shows a pattern by time of day. That entry contains four numbers, an owner and a trigger. A register full of amber cells with no numbers contains none of those, and a regulator can tell the difference immediately.
Three failure modes account for most rejected assessments. The first is describing the system rather than assessing it, so that section 2 is twelve pages and section 6 is empty. The second is treating vendor claims as evidence: a stated false match rate is a marketing figure until you have measured it on your own population, in your own lighting, at your own threshold. The third is signing it after the contract is signed, at which point the exercise cannot change anything and its only function is to document that you knew.
India has an analogue with a narrower trigger. Section 10(2)(c)(i) of the DPDP Act requires a significant data fiduciary to undertake a periodic data protection impact assessment, defined in place as a process comprising a description of the rights of data principals and the purpose of processing of their personal data, assessment and management of the risk to those rights, and such other matters as may be prescribed. The duty attaches to designation, not to the riskiness of a particular operation, which is a materially different design: a small Indian company running face recognition has no statutory assessment duty at all.
The bill, and what the rules actually removed#
Pull the whole worked example together. Harrow Lane wanted a face gate. Here is what the legal analysis did to it.
The company’s group turnover is 88 million euro. Article 83(5) sets the top tier of administrative fines at up to 20 million euro or 4 per cent of total worldwide annual turnover of the preceding financial year, whichever is higher. Four per cent of 88 million is 3.52 million, so the 20 million figure governs. Article 83(4) sets the lower tier at 10 million euro or 2 per cent. For a company this size the flat euro figures are the ceiling that matters, not the percentages, which is the reverse of the intuition most executives bring to the conversation.
Set that against 1.9 million dollars of BIPA exposure on a single American site with 1,900 customers, and INR 250 crore as the top Indian head. Three regimes, three completely different shapes of risk: a regulator with discretion, a plaintiff class with none, and a board with a schedule.
Now the design, before and after.
| Design choice | Before analysis | After analysis |
|---|---|---|
| Gallery scope | One national DB | Per-site galleries |
| Enrolment images | Kept indefinitely | Deleted on template |
| Hosting region | Virginia | Ireland |
| Keypad | Removed | Retained as fallback |
| Chicago site | Same rollout | Deferred; 15(a)+(b) |
| Night refusals | Try again tomorrow | Intercom to operator |
| Refusal data | Not logged | 12 months, reviewed |
Seven rows. Every one of them is an engineering decision, a cost line and a schedule change. Not one of them is a sentence in a privacy notice. The privacy notice describes the result; it does not produce it.
That is the thesis, demonstrated rather than asserted. Identity data is the most regulated data there is, and the rules change what you may build.
There is a last observation, and it is the one to take into chapter 56. Everything above is compatible with a system that quietly fails a particular group of people more often than the rest, and the only line in the whole analysis that would surface it is the refusal log, which no article of any of these statutes required. The law made the company build a fallback. It did not make the company count who needed it. That gap is where the next chapter starts.
55.98 Common wrong ideas#
Wrong: If we remove names and use random identifiers, the data is no longer personal data. Right: Identifiability is assessed by reference to all the means reasonably likely to be used by the controller or another person, including legal routes to additional information, so a keyed pseudonym is still personal data for anyone holding or able to obtain the key; since Case C-413/23 P of 4 September 2025 the same dataset may be non-personal in a recipient’s hands, but only where that recipient has no key, no contractual right to one and no realistic means of cross-referencing, and it stays personal for the sender.
Wrong: We have consent, so we are covered. Right: Consent must be freely given, specific, informed, unambiguous, evidenced under Article 7(1) and withdrawable as easily as it was given under Article 7(3); it is not freely given where the service is conditional on it or where there is an imbalance of power, and if it fails then every record collected under it was unlawful from the first day rather than from the day the regulator noticed.
Wrong: We only store a mathematical template, not a photograph, so the strict biometric rules do not apply. Right: Article 9(1) is engaged by processing biometric data for the purpose of uniquely identifying a natural person, and Recital 51 makes clear that a photograph becomes biometric data precisely when it is put through specific technical means allowing unique identification, so converting the image to a template is the step that engages the stricter regime rather than the step that escapes it.
Wrong: Legitimate interests can cover a face recognition system if the balancing test comes out in our favour. Right: Legitimate interests under Article 6(1)(f) can supply the lawful basis, but Article 9 contains no legitimate-interests exception at all, so a commercial biometric identification system still needs explicit consent under Article 9(2)(a) or another listed condition, and both locks must be satisfied at once.
Wrong: Article 22 does not apply because a person is nominally in the loop. Right: Article 22(1) catches decisions based solely on automated processing, and Case C-634/21 of 7 December 2023 held that producing a score is itself the decision where a third party draws strongly on it, so a human who rubber-stamps an output without the authority or information to change it does not take the processing outside Article 22; Article 22(3) requires real intervention, the ability to express a point of view and the ability to contest.
Wrong: India’s DPDP Act is a lighter GDPR, so a GDPR programme covers it. Right: The DPDP Act 2023 has two grounds for processing rather than six, no special category for biometric or health data, no general legitimate-interests basis, no portability right and no automated-decision right, requires notice in any of the twenty-two Eighth Schedule languages on request, introduces registered consent managers with no European equivalent, and imposes an unconditional seventy-two hour breach notification to the Board, so the two map onto each other only partially and in both directions.
Wrong: The 2024 amendment to BIPA solved the Illinois damages problem. Right: Public Act 103-769, effective 2 August 2024, limits repeated collections of the same identifier from the same person by the same method to a single recovery, and the Seventh Circuit held on 1 April 2026 that this applies retroactively to pending cases, but it left intact the private right of action, the 1,000 and 5,000 dollar liquidated damages, the attorneys’ fees provision and the holding in Rosenbach that no actual injury need be shown, so a 1,900-customer site still carries a 1.9 million dollar floor if notice and written release were not obtained first.
Wrong: We use the standard contractual clauses, so our transfers are lawful. Right: Schrems II held on 16 July 2020 that a controller using the clauses must verify case by case whether the destination country’s law permits compliance and adopt supplementary measures where it does not, which is why the Irish Data Protection Commission fined Meta 1.2 billion euro on 22 May 2023 despite its use of the 2021 clauses with supplementary measures already in place.
Wrong: A data protection impact assessment is a document you produce for the file once the design is agreed. Right: Article 35(7) requires an assessment of necessity and proportionality and of the measures envisaged to address risks, which is only meaningful while the design can still change, and Article 36(1) obliges you to consult the supervisory authority before processing where high risk remains after mitigation, so an assessment written after go-live discharges neither duty and instead evidences that you understood the risk and proceeded.
Wrong: Complying with data protection law means the identity system is safe and fair. Right: Every rule in this chapter can be satisfied by a system that refuses a legitimate person at night with no staff on site and no record of how often that happens to whom, because nothing in the GDPR, the DPDP Act or BIPA requires demographic error rates to be measured or published, so compliance is the floor and counting your own false rejections is the part you have to choose to do.
55.99 Chapter summary in 20 lines#
- Identity data is the most heavily regulated category of data there is, and its rules constrain architecture rather than documentation.
- Article 4(1) of Regulation (EU) 2016/679 defines personal data as any information relating to an identified or identifiable natural person, and Recital 26 supplies the reasonably-likely-means test.
- Case C-582/14 Breyer, decided on 19 October 2016, held a dynamic IP address to be personal data for a website operator with legal means to obtain the subscriber information held by the internet provider.
- Case C-413/23 P, EDPS v Single Resolution Board, decided on 4 September 2025, held that pseudonymized data are not personal data in all cases and for every person, and that identifiability is assessed from the position of the party holding the data.
- That judgment nevertheless upheld the finding against the Board, because the duty to name recipients in a notice attaches at collection and does not depend on what a recipient can later do.
- The Digital Omnibus package of 19 November 2025 proposes to codify the relative approach, and as of August 2026 only its artificial intelligence part is law, as Regulation (EU) 2026/1744.
- Article 6(1) offers six lawful bases, and consent is the weakest for identity work because it fails on conditionality, imbalance of power, withdrawal, granularity and evidence.
- Article 9(1) prohibits processing biometric data for the purpose of uniquely identifying a natural person, so converting a photograph into a template is the step that engages the stricter regime.
- Article 9 is a second lock rather than an alternative one, and contains no legitimate-interests exception, which pushes commercial biometric systems towards explicit consent under Article 9(2)(a).
- The ICO’s nine enforcement notices of 23 February 2024 stopped Serco Leisure and associated trusts from monitoring the attendance of over 2,000 employees at 38 sites by face and fingerprint.
- Article 5(1)(b), (c) and (e) require purpose limitation, data minimization and storage limitation, and translate into a retention schedule with named fields, triggers and periods.
- Deleting rows does not delete backups, so serious systems encrypt per partition and destroy the key, which is what makes a deletion promise keepable.
- Article 22 gives the right not to be subject to a decision based solely on automated processing with legal or similarly significant effect, and Case C-634/21 of 7 December 2023 held that producing a score can itself be that decision.
- Case C-203/22 of 27 February 2025 held that meaningful information about the logic involved means the procedure and principles actually applied, not source code, and that trade secrets permit no blanket refusal.
- India’s Digital Personal Data Protection Act 2023 was assented on 11 August 2023, and the Rules notified on 13 November 2025 commence in phases running to 13 May 2027.
- That Act has two grounds for processing rather than six, no special category for biometrics, no automated-decision right, consent managers requiring INR 2 crore net worth, and a top penalty of INR 250 crore.
- Illinois BIPA, in force since 3 October 2008, gives a private right of action with liquidated damages of 1,000 dollars for negligence and 5,000 for recklessness, and Rosenbach v Six Flags, 2019 IL 123186, held that no actual injury need be shown.
- Public Act 103-769 of 2 August 2024 limited repeat collections to a single recovery, cutting a 395 million dollar exposure on a 1,900-customer site to 1.9 million, and the Seventh Circuit held on 1 April 2026 that it applies retroactively.
- Chapter V transfers rest on adequacy, the 2021 standard contractual clauses and binding corporate rules, with Schrems II requiring case-by-case verification, and the EU-US Data Privacy Framework survived Case T-553/23 and is on appeal as C-703/25 P.
- Article 35(7) fixes what an impact assessment must contain and Article 36(1) forces prior consultation where high risk remains after mitigation, and the only test of a real assessment is how many design decisions it changed.
Chapter sources: Regulation (EU) 2016/679, in particular Articles 4(1), 4(11), 4(14), 5, 6, 7, 9, 13, 15, 21, 22, 33, 35, 36, 44 to 49 and 83, and Recitals 26, 32, 43, 47 and 51; Regulation (EU) 2018/1725 Articles 3(1), 3(6) and 15(1)(d); Case C-582/14 Breyer, 19 October 2016, ECLI:EU:C:2016:779; Case C-311/18 Schrems II, 16 July 2020; Case C-205/21 Ministerstvo na vatreshnite raboti, 26 January 2023; Case C-319/22 Gesamtverband Autoteile-Handel, 9 November 2023; Case C-634/21 OQ v Land Hessen (SCHUFA), 7 December 2023; Case C-604/22 IAB Europe, 7 March 2024; Case C-203/22 CK v Magistrat der Stadt Wien, 27 February 2025; Case C-413/23 P EDPS v Single Resolution Board, 4 September 2025, ECLI:EU:C:2025:645; Case T-553/23 Latombe v Commission, 3 September 2025, ECLI:EU:T:2025:831, on appeal as C-703/25 P; EDPB Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement, version 2.0 of 17 May 2023; EDPB Guidelines 3/2019 on processing of personal data through video devices, version 2.0 adopted 29 January 2020; EDPB Guidelines 01/2025 on pseudonymisation, consultation version; Article 29 Working Party WP248 rev.01 on Data Protection Impact Assessment, adopted 4 April 2017 and revised 4 October 2017, endorsed by the EDPB on 25 May 2018; Commission Implementing Decision (EU) 2021/914 of 4 June 2021; the EU-US Data Privacy Framework adequacy decision of 10 July 2023; the United Kingdom adequacy renewals of 19 December 2025 running to 27 December 2031; Regulation (EU) 2024/1689 Annex III point 1 as amended by Regulation (EU) 2026/1744, in the Official Journal of 24 July 2026 and in force from 27 July 2026; the Digital Omnibus proposals of 19 November 2025; the Digital Personal Data Protection Act 2023 (India), assented 11 August 2023, Sections 2 to 17 and the Schedule; the Digital Personal Data Protection Rules 2025, notified 13 November 2025, Rules 3, 4, 6, 7, 8, 10, 13 and 15 and the First, Third and Fourth Schedules; the Reserve Bank of India directive on storage of payment system data, April 2018; the Illinois Biometric Information Privacy Act, 740 ILCS 14, Public Act 95-994 effective 3 October 2008, as amended by Public Act 103-769 effective 2 August 2024; Rosenbach v Six Flags Entertainment Corp, 2019 IL 123186; Cothron v White Castle System Inc, 2023 IL 128004; Texas Business and Commerce Code section 503.001 with the Texas Attorney General settlements with Meta of July 2024 and Google of 2025; Washington RCW 19.375; ICO enforcement notices against Serco Leisure and associated trusts, 23 February 2024; the ICO statement on the Upper Tribunal judgment concerning Clearview AI Inc of 8 October 2025; the Autoriteit Persoonsgegevens decision fining Clearview AI 30.5 million euro, September 2024; the Irish Data Protection Commission decision of 22 May 2023 fining Meta Platforms Ireland 1.2 billion euro; the Data (Use and Access) Act 2025, Royal Assent 19 June 2025.