Digital Omnibus tracker

Digital Omnibus proposal

Recital 34

Compare the available Commission, Council and Parliament texts and amendments affecting this recital.

Recital total: 1 part · 4 Council drafts · 14 Parliament amendments

Removed wording is struck through; added or replacement wording is highlighted.

Institutional text

European Commission proposal

The wording proposed by the Commission at the start of this legislative file.

Commission source wording and instructions

Recital 34

Commission proposal

Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.

Institutional text

Council Presidency texts

Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.

Recital 34

May Presidency compromise

Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric recognition includes two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing , including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.

Competing proposals

European Parliament amendments

These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.

More filters

Political group at the amendment date where available; otherwise the current Parliament affiliation.

Alternative wording Amendment 4 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
(34) BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric datarecognition includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or hertheir claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or hertheir identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation (EU) 2016/679 should also be allowed where the verification of the claimed identity of the data subject is necessary and proportionate for a legitimate purpose pursued by the controller, and subject to appropriate safeguards laid down under Union law. When such verification is necessary, the controller should choose the least intrusive of the equally effective means available. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and should be subject to appropriate safeguards. That derogation should only apply where suitable safeguards apply to enableensure that the biometric data subjectare tounder havethe sole control of the data subject. Sole control means that the data subject can effectively decide when and how their biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, where the biometric data are securely stored solely aton the sidedevice of the data subject or are securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, thatand processing is not likelysubject to createmeasures significantensuring risksthe tooverall hissecurity orof herprocessing, fundamentalincluding rightsduring andthe freedoms.enrolment The controller does not gain knowledgephase of the data subject’s biometric data or only for a very limited time during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
Remove proposed wording Amendment 122 · Arash Saeidi JURI
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Source identification

Header printed in the source: Recital 34

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 311 · Sibylle Berg, Martin Sonneborn ITRE · LIBE
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Source identification

Header printed in the source: Recital 34

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 312 · Pernando Barrena Arza ITRE · LIBE
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Source identification

Header printed in the source: Recital 34

Deletion marker printed in the source: deleted

Alternative wording Amendment 313 · Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec ITRE · LIBE
(34) BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric datarecognition includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or hertheir claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or hertheir identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary and proportionate for a legitimate purpose pursued by the controller, and subject to appropriate safeguards laid down under Union law. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. When such verification is necessary, the controller should choose from equally effective means the least intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should only apply where suitable safeguards apply to enableensure that the biometric data subjector the means needed for the verification, such as sensors, cameras, or software that extract features and perform pattern recognition to haveverify the individual, are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how their biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, where the biometric data are securely stored solely at the sidedevice of the data subject or are securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, thatand processing is not likelysubject to createmeasures significantensuring risksthe tooverall hissecurity orof herprocessing, fundamentalincluding rightsduring andthe freedoms.enrolment The controller does not gain knowledgephase of the data subject’s biometric data or only for a very limited time during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
Alternative wording Amendment 314 · Angelika Winzig ITRE · LIBE
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, meansis personal data that result from processing of certain characteristics of a natural person through a specific technical means, and whichthat allowsallow or confirmsconfirm the unique identification of that person. The notion of biometric datarecognition includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or hertheir claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or hertheir identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation (EU) 2016/679 should also be allowed where the verification of the claimed identity of the data subject is necessary and proportionate for a legitimate purpose pursued by the controller, and suitable safeguards apply to enable the data subject to haveappropriate safeguards laid down under Union law. The required proportionality entails choosing the least intrusive of the equally effective means available. The appropriate safeguards shall ensure that the biometric data are under the sole control of the data subject so that the data subject can effectively decide when and how their biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. ForThis would for example, be the case where the biometric data are securely stored solely aton the sidedevice of the data subject or are securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, thatand processing is not likelysubject to createmeasures significantensuring risksthe tooverall hissecurity orof herprocessing, fundamentalincluding rightsduring andthe freedoms.enrolment The controller does not gain knowledgephase of the data subject’s biometric data or only for a very limited time during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
Justification

Redrafted to align with the definition of biometric data in Article 4(14) GDPR.

Alternative wording Amendment 315 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
(34) BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed only where the verification of the claimed identity of the data subject is strictly necessary and proportionate for a legitimate public interest or regulatory purpose pursuedpersued by the controller, and suitable safeguards apply to enableensure that both the biometric data and the operational means of processing remain under exclusive and continuous control of the data subject throughout enrolment, transmission, verification and erasure, enabling the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process. Biometric verification should not be deployed as a standard authentication mechanism where equally effective, less intrusive alternative verification methods are available. Controller should choose from equally effective means the least intrusive one. Storing encrypted templates on a controller's database does not satisfy the requirement of sole user control if decryption or comparison occurs within systems controlled technically or operationally by the controller.
Alternative wording Amendment 316 · Nadine Morano ITRE · LIBE
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means andeither which allows or confirmsallowing the unique identification of or confirming the identify of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The‘Biometric identification processmeans isthe basedautomated onrecognition of a ‘one-to-many’person’s searchphysical, physiological, behavioural, or psychological features for the purpose of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claimingestablishing his or her identity by comparing biometric data of that individual to that of other individuals recorded in a database. ‘Biometric verification’ means the automated, one-to-one verification, including authentication, of the identity of a natural person by comparing his or her biometric data to previously provided biometric data. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessarycarried out for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process. However, where justified by the operational and security requirements of strategic public transport infrastructure, the biometric data may be retained under the controller’s responsibility, provided that the controller guarantees a high level of personal data protection. Such processing should only be authorised if it is strictly necessary, proportionate to the aim pursued and carried out with respect for the rights and freedoms of the data subjects.
Alternative wording Amendment 317 · Diana Iovanovici Şoşoacă ITRE · LIBE
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes, while respecting and safeguarding fundamental human rights and freedoms and the individual’s consent. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a well-defined purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process, and the persons within its organisation who access the data must be clearly specified and easily identifiable. Provision must be made for sanctions in the event of malfunctions or data breaches, and fundamental human rights and freedoms and informed consent must be respected and safeguarded.
Alternative wording Amendment 318 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purposeone-to-one pursued by the controllerverification, and suitable safeguards apply to enable the data subject to have sole control of the verification process. ForThose examplesafeguards should include, whereinter alia, that the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processingthe identity confirmation is notrequired likelyby Union or Member State law with suitable and specific measures to createsafeguard significant risks to his or herthe fundamental rights and freedomsthe interests of the data subject and there are no less intrusive alternative solutions that could achieve the same objective as effectively. The controller doesshould not gain knowledge of the biometric data or only for a very limited time during the verification process. The biometric data and personal data related to the verification process that is not necessary to retain should therefore be deleted after the verification process, in accordance with the principles established in Regulation (EU) 2016/679.
Alternative wording Amendment 319 · Jan-Christoph Oetjen, Svenja Hahn, Andreas Glück ITRE · LIBE
(34) BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric datarecognition includes two distinct functions, namely the identification of a natural person or the verification of their claimed identity according to Article 3 (also35) calledand authentication(36) of hisRegulation or(EU) her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity2024/1689. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation (EU) 2016/679 should also be allowed where the verification ofand the claimed identityidentification of the data subject is necessary and proportionate for a purpose pursued by the controller,. andThe suitablederogation safeguardsshould only apply to enablewhere the data subject is offered a non-biometric alternative and appropriate safeguards laid down under Union law are implemented to haveensure solefundamental controlrights of the verificationdata processsubject are adequately protected. It should be ensured that no photo or video is captured, even if not recorded and not processed, from individuals who do not consent to the facial recognition through appropriate measures. For example, where the biometric data are securely stored solely aton the sidedevice of the data subject or are securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, thatand processing is not likelysubject to createmeasures significantensuring risksthe tooverall hissecurity orof herprocessing, fundamentalincluding rightsduring andthe freedoms.enrolment The controller does not gain knowledgephase of the data subject’s biometric data or only for a very limited time during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
Alternative wording Amendment 320 · Axel Voss ITRE · LIBE
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation (EU) 2016/679 should also be allowed where thedata verificationsubject ofis theoffered claimeda identitynon-biometric alternative and suitable safeguards are implemented to ensure fundamental rights of the data subject isare necessaryadequately forprotected a purpose pursued bythrough the controller, and suitable safeguards apply to enable the data subject to have sole controlimplementation of the verificationnecessary processsafeguards. For example, this is the case, where the biometric data areis securely stored solely atby the sidedevice of the data subject, or arethe biometric data is securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, thatand processing is not likelysubject to createmeasures significantensuring risksthe overall security of the processing, including during the enrolment phase of data subject and at the time when the data subject agrees to his or her fundamental rights and freedoms. The controller does not gain knowledge ofshare the biometric data or onlyencryption forkey. Other examples of appropriate safeguards are ensuring that end-to-end encryption, or similar state of the art technology, is used when data are transmitted over a verycommunication limitedchannel timeand duringproviding data subjects with the verificationpossibility processto securely erase their biometric data in accordance with Article 17 of Regulation (EU) 2016/679.
Justification

Biometric identification can enable trusted digital identity services, including the European Digital Identity Wallet, but requires clear safeguards. The amendment provides legal certainty for voluntary biometric use where a comparable non-biometric alternative is available and fundamental rights are protected. Secure local storage, encryption controlled by the data subject, secure enrolment and transmission, and erasure options ensure user control, privacy and security by design while supporting responsible European innovation.

Alternative wording Amendment 321 · Oliver Schenk, Axel Voss, Romana Tomc, Marion Walsmann, Lena Düpont, Marie- Sophie Lanig, Ana Miguel Pedro, Andrea Wechsler, Dimitris Tsiodras ITRE · LIBE
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verificationdata ofsubject theis claimedoffered identitya non-biometric alternative and suitable safeguards are implemented to ensure fundamental rights of the data subject isare necessaryadequately forprotected a purpose pursued bythrough the controller, and suitable safeguards apply to enable the data subject to have sole controlimplementation of the verificationnecessary processsafeguards. For example, where the biometric data are securely stored solely atby the device the side of the data subject, or the biometric data is are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, thatand processing is not likelysubject to createmeasures significantensuring risksthe overall security of the processing, including during the enrolment phase of data subject and at the time when the data subject agrees to his or her fundamental rights and freedoms. The controller does not gain knowledge ofshare the biometric data or onlyencryption forkey. Other examples of appropriate safeguards are ensuring that end-to-end encryption, or similar state of the art technology, is used when data are transmitted over a verycommunication limitedchannel timeand duringproviding data subjects with the verificationpossibility processto securely erase their biometric data in accordance with Article 17 of Regulation (EU) 2016/679.
Alternative wording Amendment 322 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
(34) BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of recognition through biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a legitimate purpose pursued by the controller, and suitableeffective safeguards apply to enable the data subject to have sole control of the verification process. ForIn example,order whereto protect the highly sensitive nature of biometric data, areprocessing securelythereof storedshould solelyonly atoccur outside the sidedevice of the data subject orin arehighly securelyexceptional storedcases atand theonly sidewhen any such processing involves state of the controllerart privacy technology, such as encryption, the key to which is in asole state-of-the-artpossession encrypted form and the encryption key or equivalent means is held solely byof the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedomszero knowledge proofs. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.