Compare the available Commission, Council and Parliament texts and amendments affecting this recital.
Recital total: 1 part · 4 Council drafts · 14 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
The wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to this tracked part. A newly proposed provision may have no earlier text of its own.
Commission source wording and instructions
Recital 34
Commission proposal
Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Recital 34
May Presidency compromise
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric recognition includes two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing , including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
Recital 34
June Presidency compromise · 10 June
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. Processing of biometric data could be carried out for two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-toone’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For example, such safeguards could include technical and organisational measures ensuring that original biometric samples of the data subject cannot be reconstructed from the template stored on a device or a database. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing , including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
Recital 34
June Presidency compromise · 18 June
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. Processing of biometric data could be carried out for two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-toone’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For example, such safeguards could include technical and organisational measures ensuring that original biometric samples of the data subject cannot be reconstructed from the template stored on a device or a database. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing, including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
Recital 34
September Presidency compromise
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. Processing of biometric data could be carried out for two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-toone’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For example, such safeguards could include technical and organisational measures ensuring that original biometric samples of the data subject cannot be reconstructed from the template stored on a device or a database. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing, including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
Recital 34 4 Council drafts
Recital 34
21 May 2026 · May Presidency compromise
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric recognition includes two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing , including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
Recital 34
10 June 2026 · June Presidency compromise · 10 June
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. Processing of biometric data could be carried out for two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-toone’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For example, such safeguards could include technical and organisational measures ensuring that original biometric samples of the data subject cannot be reconstructed from the template stored on a device or a database. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing , including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
Recital 34
18 June 2026 · June Presidency compromise · 18 June
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. Processing of biometric data could be carried out for two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-toone’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For example, such safeguards could include technical and organisational measures ensuring that original biometric samples of the data subject cannot be reconstructed from the template stored on a device or a database. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing, including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
Recital 34
3 September 2026 · September Presidency compromise
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. Processing of biometric data could be carried out for two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-toone’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For example, such safeguards could include technical and organisational measures ensuring that original biometric samples of the data subject cannot be reconstructed from the template stored on a device or a database. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing, including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Political group at the amendment date where available; otherwise the current Parliament affiliation.
Alternative wordingAmendment 4 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
(34) BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric datarecognition includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or hertheir claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or hertheir identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation (EU) 2016/679 should also be allowed where the verification of the claimed identity of the data subject is necessary and proportionate for a legitimate purpose pursued by the controller, and subject to appropriate safeguards laid down under Union law. When such verification is necessary, the controller should choose the least intrusive of the equally effective means available. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and should be subject to appropriate safeguards. That derogation should only apply where suitable safeguards apply to enableensure that the biometric data subjectaretounderhavethe sole control of the data subject. Sole control means that the data subject can effectively decide when and how their biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, where the biometric data are securely stored solely aton the sidedevice of the data subject or are securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject,thatandprocessing is not likelysubject to createmeasuressignificantensuringrisksthetooverallhissecurityorofherprocessing,fundamentalincludingrightsduringandthefreedoms.enrolmentThe controller does not gain knowledgephase of the data subject’s biometric data or only for a very limited time during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
Remove proposed wordingAmendment 122 · Arash Saeidi JURI
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Alternative wordingAmendment 313 · Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec ITRE · LIBE
(34) BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric datarecognition includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or hertheir claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or hertheir identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary and proportionate for a legitimate purpose pursued by the controller, and subject to appropriate safeguards laid down under Union law. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. When such verification is necessary, the controller should choose from equally effective means the least intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should only apply where suitable safeguards apply to enableensure that the biometric data subjector the means needed for the verification, such as sensors, cameras, or software that extract features and perform pattern recognition to haveverify the individual, are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how their biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, where the biometric data are securely stored solely at the sidedevice of the data subject or are securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, thatandprocessing is not likelysubject to createmeasuressignificantensuringrisksthetooverallhissecurityorofherprocessing,fundamentalincludingrightsduringandthefreedoms.enrolmentThe controller does not gain knowledgephase of the data subject’s biometric data or only for a very limited time during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
Alternative wordingAmendment 314 · Angelika Winzig ITRE · LIBE
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, meansis personal data that result from processing of certain characteristics of a natural person through a specific technical means, and whichthatallowsallow or confirmsconfirm the unique identification of that person. The notion of biometric datarecognition includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or hertheir claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or hertheir identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation (EU) 2016/679 should also be allowed where the verification of the claimed identity of the data subject is necessary and proportionate for a legitimate purpose pursued by the controller, and suitable safeguards apply to enable the data subject to haveappropriate safeguards laid down under Union law. The required proportionality entails choosing the least intrusive of the equally effective means available. The appropriate safeguards shall ensure that the biometric data are under the sole control of the data subject so that the data subject can effectively decide when and how their biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. ForThis would for example, be the case where the biometric data are securely stored solely aton the sidedevice of the data subject or are securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject,thatandprocessing is not likelysubject to createmeasuressignificantensuringrisksthetooverallhissecurityorofherprocessing,fundamentalincludingrightsduringandthefreedoms.enrolmentThe controller does not gain knowledgephase of the data subject’s biometric data or only for a very limited time during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
Justification
Redrafted to align with the definition of biometric data in Article 4(14) GDPR.
Alternative wordingAmendment 315 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
(34) BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed only where the verification of the claimed identity of the data subject is strictly necessary and proportionate for a legitimate public interest or regulatory purpose pursuedpersued by the controller, and suitable safeguards apply to enableensure that both the biometric data and the operational means of processing remain under exclusive and continuous control of the data subject throughout enrolment, transmission, verification and erasure, enabling the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process. Biometric verification should not be deployed as a standard authentication mechanism where equally effective, less intrusive alternative verification methods are available. Controller should choose from equally effective means the least intrusive one. Storing encrypted templates on a controller's database does not satisfy the requirement of sole user control if decryption or comparison occurs within systems controlled technically or operationally by the controller.
Alternative wordingAmendment 316 · Nadine Morano ITRE · LIBE
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means andeitherwhich allows or confirmsallowing the unique identification of or confirming the identify of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The‘Biometric identification’processmeansisthebasedautomatedonrecognition of a ‘one-to-many’person’ssearchphysical, physiological, behavioural, or psychological features for the purpose of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claimingestablishing his or her identity by comparing biometric data of that individual to that of other individuals recorded in a database. ‘Biometric verification’ means the automated, one-to-one verification, including authentication, of the identity of a natural person by comparing his or her biometric data to previously provided biometric data. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessarycarried out for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process. However, where justified by the operational and security requirements of strategic public transport infrastructure, the biometric data may be retained under the controller’s responsibility, provided that the controller guarantees a high level of personal data protection. Such processing should only be authorised if it is strictly necessary, proportionate to the aim pursued and carried out with respect for the rights and freedoms of the data subjects.
Alternative wordingAmendment 317 · Diana Iovanovici Şoşoacă ITRE · LIBE
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes, while respecting and safeguarding fundamental human rights and freedoms and the individual’s consent. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a well-defined purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process, and the persons within its organisation who access the data must be clearly specified and easily identifiable. Provision must be made for sanctions in the event of malfunctions or data breaches, and fundamental human rights and freedoms and informed consent must be respected and safeguarded.
Alternative wordingAmendment 318 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purposeone-to-onepursued by the controllerverification, and suitable safeguards apply to enable the data subject to have sole control of the verification process. ForThoseexamplesafeguards should include, whereinter alia, that the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processingthe identity confirmation is notrequiredlikelyby Union or Member State law with suitable and specific measures to createsafeguardsignificant risks to his or herthe fundamental rights and freedomsthe interests of the data subject and there are no less intrusive alternative solutions that could achieve the same objective as effectively. The controller doesshould not gain knowledge of the biometric data or only for a very limited time during the verification process. The biometric data and personal data related to the verification process that is not necessary to retain should therefore be deleted after the verification process, in accordance with the principles established in Regulation (EU) 2016/679.
Alternative wordingAmendment 319 · Jan-Christoph Oetjen, Svenja Hahn, Andreas Glück ITRE · LIBE
(34) BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric datarecognition includes two distinct functions, namely the identification of a natural person or the verification of their claimed identity according to Article 3 (also35)calledandauthentication(36) of hisRegulationor(EU)her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity2024/1689. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation (EU) 2016/679 should also be allowed where the verification ofandthe claimed identityidentification of the data subject is necessary and proportionate for a purpose pursued by the controller,.andThesuitablederogationsafeguardsshould only apply to enablewhere the data subject is offered a non-biometric alternative and appropriate safeguards laid down under Union law are implemented to haveensuresolefundamentalcontrolrights of the verificationdataprocesssubject are adequately protected. It should be ensured that no photo or video is captured, even if not recorded and not processed, from individuals who do not consent to the facial recognition through appropriate measures. For example, where the biometric data are securely stored solely aton the sidedevice of the data subject or are securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject,thatandprocessing is not likelysubject to createmeasuressignificantensuringrisksthetooverallhissecurityorofherprocessing,fundamentalincludingrightsduringandthefreedoms.enrolmentThe controller does not gain knowledgephase of the data subject’s biometric data or only for a very limited time during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
Alternative wordingAmendment 320 · Axel Voss ITRE · LIBE
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation (EU) 2016/679 should also be allowed where thedataverificationsubjectofistheofferedclaimedaidentitynon-biometric alternative and suitable safeguards are implemented to ensure fundamental rights of the data subject isarenecessaryadequatelyforprotecteda purpose pursued bythrough the controller, and suitable safeguards apply to enable the data subject to have sole controlimplementation of the verificationnecessaryprocesssafeguards. For example, this is the case, where the biometric data areis securely stored solely atby the sidedevice of the data subject, or arethe biometric data is securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, thatandprocessing is not likelysubject to createmeasuressignificantensuringrisksthe overall security of the processing, including during the enrolment phase of data subject and at the time when the data subject agrees to his or her fundamental rights and freedoms. The controller does not gain knowledge ofshare the biometric data or onlyencryptionforkey. Other examples of appropriate safeguards are ensuring that end-to-end encryption, or similar state of the art technology, is used when data are transmitted over a verycommunicationlimitedchanneltimeandduringproviding data subjects with the verificationpossibilityprocessto securely erase their biometric data in accordance with Article 17 of Regulation (EU) 2016/679.
Justification
Biometric identification can enable trusted digital identity services, including the European Digital Identity Wallet, but requires clear safeguards. The amendment provides legal certainty for voluntary biometric use where a comparable non-biometric alternative is available and fundamental rights are protected. Secure local storage, encryption controlled by the data subject, secure enrolment and transmission, and erasure options ensure user control, privacy and security by design while supporting responsible European innovation.
Alternative wordingAmendment 321 · Oliver Schenk, Axel Voss, Romana Tomc, Marion Walsmann, Lena Düpont, Marie- Sophie Lanig, Ana Miguel Pedro, Andrea Wechsler, Dimitris Tsiodras ITRE · LIBE
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verificationdataofsubjecttheisclaimedofferedidentitya non-biometric alternative and suitable safeguards are implemented to ensure fundamental rights of the data subject isarenecessaryadequatelyforprotecteda purpose pursued bythrough the controller, and suitable safeguards apply to enable the data subject to have sole controlimplementation of the verificationnecessaryprocesssafeguards. For example, where the biometric data are securely stored solely atby the device the side of the data subject, or the biometric data is are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, thatandprocessing is not likelysubject to createmeasuressignificantensuringrisksthe overall security of the processing, including during the enrolment phase of data subject and at the time when the data subject agrees to his or her fundamental rights and freedoms. The controller does not gain knowledge ofshare the biometric data or onlyencryptionforkey. Other examples of appropriate safeguards are ensuring that end-to-end encryption, or similar state of the art technology, is used when data are transmitted over a verycommunicationlimitedchanneltimeandduringproviding data subjects with the verificationpossibilityprocessto securely erase their biometric data in accordance with Article 17 of Regulation (EU) 2016/679.
Alternative wordingAmendment 322 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
(34) BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of recognition through biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a legitimate purpose pursued by the controller, and suitableeffective safeguards apply to enable the data subject to have sole control of the verification process. ForInexample,orderwhereto protect the highly sensitive nature of biometric data,areprocessingsecurelythereofstoredshouldsolelyonlyatoccur outside the sidedevice of the data subject orinarehighlysecurelyexceptionalstoredcasesatandtheonlysidewhen any such processing involves state of the controllerart privacy technology, such as encryption, the key to which is in asolestate-of-the-artpossessionencrypted form and the encryption key or equivalent means is held solely byof the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedomszero knowledge proofs. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Recital 34
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric datarecognition includes two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation (EU) 2016/679 should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to enableensure that the biometric data subjectortothehavemeans needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the sidedevice of the data subject or are securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, thatand subject to measures ensuring the overall security of processing is,notincludinglikelyduringtothecreateenrolmentsignificant risks to his or her fundamental rights and freedoms. The controller does not gain knowledgephase of thedata subject’s biometric data or only for a very limited timeand during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
RemovedAdded
Both texts in full
European Commission proposal
Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Council Presidency text · ST 9547/26
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric recognition includes two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing , including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
Recital 34
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notionProcessing of biometric recognitiondataincludescould be carried out for two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-oneone-toone’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For example, such safeguards could include technical and organisational measures ensuring that original biometric samples of the data subject cannot be reconstructed from the template stored on a device or a database. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing , including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric recognition includes two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing , including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
Council Presidency text · ST 10426/26
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. Processing of biometric data could be carried out for two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-toone’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For example, such safeguards could include technical and organisational measures ensuring that original biometric samples of the data subject cannot be reconstructed from the template stored on a device or a database. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing , including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
Recital 34
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. Processing of biometric data could be carried out for two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-toone’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For example, such safeguards could include technical and organisational measures ensuring that original biometric samples of the data subject cannot be reconstructed from the template stored on a device or a database. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing, including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. Processing of biometric data could be carried out for two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-toone’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For example, such safeguards could include technical and organisational measures ensuring that original biometric samples of the data subject cannot be reconstructed from the template stored on a device or a database. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing , including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
Council Presidency text · ST 10677/26
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. Processing of biometric data could be carried out for two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-toone’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For example, such safeguards could include technical and organisational measures ensuring that original biometric samples of the data subject cannot be reconstructed from the template stored on a device or a database. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing, including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
Recital 34
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. Processing of biometric data could be carried out for two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-toone’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For example, such safeguards could include technical and organisational measures ensuring that original biometric samples of the data subject cannot be reconstructed from the template stored on a device or a database. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing, including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. Processing of biometric data could be carried out for two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-toone’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For example, such safeguards could include technical and organisational measures ensuring that original biometric samples of the data subject cannot be reconstructed from the template stored on a device or a database. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing, including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
Council Presidency text · ST 12535/26
Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. Processing of biometric data could be carried out for two distinct functions, namely the identification of a natural person or the verification (also called 'authentication') of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-toone’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller and, where applicable, subject to appropriate safeguards laid down under Union law or Member States law in accordance with Article 9(4) of Regulation (EU) 2016/679. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. The controller should choose from equally effective means the less intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For example, such safeguards could include technical and organisational measures ensuring that original biometric samples of the data subject cannot be reconstructed from the template stored on a device or a database. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how his or her biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, this is the case where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing, including during the enrolment phase of data subject’s biometric data and during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data at any time.
Recital 34
Wording reproduced in the amendment → Amendment 311 · ITRE–LIBE amendments 251–400 to the draft report: removal
Changes in context
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Amendment 311 · ITRE–LIBE amendments 251–400 to the draft report: removal
Wording reproduced in the amendment → Amendment 312 · ITRE–LIBE amendments 251–400 to the draft report: removal
Changes in context
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Amendment 312 · ITRE–LIBE amendments 251–400 to the draft report: removal
Wording reproduced in the amendment → Amendment 313 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(34) BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric datarecognition includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or hertheir claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or hertheir identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary and proportionate for a legitimate purpose pursued by the controller, and subject to appropriate safeguards laid down under Union law. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. When such verification is necessary, the controller should choose from equally effective means the least intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should only apply where suitable safeguards apply to enableensure that the biometric data subjector the means needed for the verification, such as sensors, cameras, or software that extract features and perform pattern recognition to haveverify the individual, are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how their biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, where the biometric data are securely stored solely at the sidedevice of the data subject or are securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, thatandprocessing is not likelysubject to createmeasuressignificantensuringrisksthetooverallhissecurityorofherprocessing,fundamentalincludingrightsduringandthefreedoms.enrolmentThe controller does not gain knowledgephase of the data subject’s biometric data or only for a very limited time during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Amendment 313 · ITRE–LIBE amendments 251–400 to the draft report
(34) Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric recognition includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of their claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming their identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should be allowed where the verification of the claimed identity of the data subject is necessary and proportionate for a legitimate purpose pursued by the controller, and subject to appropriate safeguards laid down under Union law. Where biometric data are processed for the purpose of confirming the identity of a data subject, controllers should, where possible, prioritise authentication methods that do not involve the processing of biometric data. When such verification is necessary, the controller should choose from equally effective means the least intrusive one. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and subject to appropriate safeguards. For the purposes of this Regulation, biometric identification should be understood as the processing of biometric data through comparison against a database intended to determine the identity of a natural person, whereas biometric verification refers to a one-to-one comparison used solely to confirm a claimed identity. This derogation should only apply where suitable safeguards apply to ensure that the biometric data or the means needed for the verification, such as sensors, cameras, or software that extract features and perform pattern recognition to verify the individual, are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how their biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, where the biometric data are securely stored solely at the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, and subject to measures ensuring the overall security of processing, including during the enrolment phase of the data subject’s biometric data during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
Wording reproduced in the amendment → Amendment 314 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, meansis personal data that result from processing of certain characteristics of a natural person through a specific technical means, and whichthatallowsallow or confirmsconfirm the unique identification of that person. The notion of biometric datarecognition includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or hertheir claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or hertheir identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation (EU) 2016/679 should also be allowed where the verification of the claimed identity of the data subject is necessary and proportionate for a legitimate purpose pursued by the controller, and suitable safeguards apply to enable the data subject to haveappropriate safeguards laid down under Union law. The required proportionality entails choosing the least intrusive of the equally effective means available. The appropriate safeguards shall ensure that the biometric data are under the sole control of the data subject so that the data subject can effectively decide when and how their biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. ForThis would for example, be the case where the biometric data are securely stored solely aton the sidedevice of the data subject or are securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject,thatandprocessing is not likelysubject to createmeasuressignificantensuringrisksthetooverallhissecurityorofherprocessing,fundamentalincludingrightsduringandthefreedoms.enrolmentThe controller does not gain knowledgephase of the data subject’s biometric data or only for a very limited time during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Amendment 314 · ITRE–LIBE amendments 251–400 to the draft report
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, is personal data that result from processing certain characteristics of a natural person through a specific technical means, and that allow or confirm the unique identification of that person. The notion of biometric recognition includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of their claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming their identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary and proportionate for a legitimate purpose pursued by the controller, and subject to appropriate safeguards laid down under Union law. The required proportionality entails choosing the least intrusive of the equally effective means available. The appropriate safeguards shall ensure that the biometric data are under the sole control of the data subject so that the data subject can effectively decide when and how their biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. This would for example be the case where the biometric data are securely stored solely on the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject and subject to measures ensuring the overall security of processing, including during the enrolment phase of the data subject’s biometric data during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
Wording reproduced in the amendment → Amendment 315 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(34) BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed only where the verification of the claimed identity of the data subject is strictly necessary and proportionate for a legitimate public interest or regulatory purpose pursuedpersued by the controller, and suitable safeguards apply to enableensure that both the biometric data and the operational means of processing remain under exclusive and continuous control of the data subject throughout enrolment, transmission, verification and erasure, enabling the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process. Biometric verification should not be deployed as a standard authentication mechanism where equally effective, less intrusive alternative verification methods are available. Controller should choose from equally effective means the least intrusive one. Storing encrypted templates on a controller's database does not satisfy the requirement of sole user control if decryption or comparison occurs within systems controlled technically or operationally by the controller.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Amendment 315 · ITRE–LIBE amendments 251–400 to the draft report
(34) Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should be allowed only where the verification of the claimed identity of the data subject is strictly necessary and proportionate for a legitimate public interest or regulatory purpose persued by the controller, and suitable safeguards apply to ensure that both the biometric data and the operational means of processing remain under exclusive and continuous control of the data subject throughout enrolment, transmission, verification and erasure, enabling the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process. Biometric verification should not be deployed as a standard authentication mechanism where equally effective, less intrusive alternative verification methods are available. Controller should choose from equally effective means the least intrusive one. Storing encrypted templates on a controller's database does not satisfy the requirement of sole user control if decryption or comparison occurs within systems controlled technically or operationally by the controller.
Wording reproduced in the amendment → Amendment 316 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means andeitherwhich allows or confirmsallowing the unique identification of or confirming the identify of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The‘Biometric identification’processmeansisthebasedautomatedonrecognition of a ‘one-to-many’person’ssearchphysical, physiological, behavioural, or psychological features for the purpose of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claimingestablishing his or her identity by comparing biometric data of that individual to that of other individuals recorded in a database. ‘Biometric verification’ means the automated, one-to-one verification, including authentication, of the identity of a natural person by comparing his or her biometric data to previously provided biometric data. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessarycarried out for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process. However, where justified by the operational and security requirements of strategic public transport infrastructure, the biometric data may be retained under the controller’s responsibility, provided that the controller guarantees a high level of personal data protection. Such processing should only be authorised if it is strictly necessary, proportionate to the aim pursued and carried out with respect for the rights and freedoms of the data subjects.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Amendment 316 · ITRE–LIBE amendments 251–400 to the draft report
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means either allowing the unique identification of or confirming the identify of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification of his or her claimed identity, which rely on different technical processes. ‘Biometric identification’ means the automated recognition of a person’s physical, physiological, behavioural, or psychological features for the purpose of establishing his or her identity by comparing biometric data of that individual to that of other individuals recorded in a database. ‘Biometric verification’ means the automated, one-to-one verification, including authentication, of the identity of a natural person by comparing his or her biometric data to previously provided biometric data. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is carried out for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process. However, where justified by the operational and security requirements of strategic public transport infrastructure, the biometric data may be retained under the controller’s responsibility, provided that the controller guarantees a high level of personal data protection. Such processing should only be authorised if it is strictly necessary, proportionate to the aim pursued and carried out with respect for the rights and freedoms of the data subjects.
Wording reproduced in the amendment → Amendment 317 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes, while respecting and safeguarding fundamental human rights and freedoms and the individual’s consent. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a well-defined purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process, and the persons within its organisation who access the data must be clearly specified and easily identifiable. Provision must be made for sanctions in the event of malfunctions or data breaches, and fundamental human rights and freedoms and informed consent must be respected and safeguarded.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Amendment 317 · ITRE–LIBE amendments 251–400 to the draft report
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes, while respecting and safeguarding fundamental human rights and freedoms and the individual’s consent. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a well-defined purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process, and the persons within its organisation who access the data must be clearly specified and easily identifiable. Provision must be made for sanctions in the event of malfunctions or data breaches, and fundamental human rights and freedoms and informed consent must be respected and safeguarded.
Wording reproduced in the amendment → Amendment 318 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purposeone-to-onepursued by the controllerverification, and suitable safeguards apply to enable the data subject to have sole control of the verification process. ForThoseexamplesafeguards should include, whereinter alia, that the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processingthe identity confirmation is notrequiredlikelyby Union or Member State law with suitable and specific measures to createsafeguardsignificant risks to his or herthe fundamental rights and freedomsthe interests of the data subject and there are no less intrusive alternative solutions that could achieve the same objective as effectively. The controller doesshould not gain knowledge of the biometric data or only for a very limited time during the verification process. The biometric data and personal data related to the verification process that is not necessary to retain should therefore be deleted after the verification process, in accordance with the principles established in Regulation (EU) 2016/679.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Amendment 318 · ITRE–LIBE amendments 251–400 to the draft report
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should be allowed where the verification of the claimed identity of the data subject is necessary for a one-to-one verification, and suitable safeguards apply to enable the data subject to have sole control of the verification process. Those safeguards should include, inter alia, that the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that the identity confirmation is required by Union or Member State law with suitable and specific measures to safeguard the fundamental rights and the interests of the data subject and there are no less intrusive alternative solutions that could achieve the same objective as effectively. The controller should not gain knowledge of the biometric data or only for a very limited time during the verification process. The biometric data and personal data related to the verification process that is not necessary to retain should therefore be deleted after the verification process, in accordance with the principles established in Regulation (EU) 2016/679.
Wording reproduced in the amendment → Amendment 319 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(34) BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric datarecognition includes two distinct functions, namely the identification of a natural person or the verification of their claimed identity according to Article 3 (also35)calledandauthentication(36) of hisRegulationor(EU)her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity2024/1689. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation (EU) 2016/679 should also be allowed where the verification ofandthe claimed identityidentification of the data subject is necessary and proportionate for a purpose pursued by the controller,.andThesuitablederogationsafeguardsshould only apply to enablewhere the data subject is offered a non-biometric alternative and appropriate safeguards laid down under Union law are implemented to haveensuresolefundamentalcontrolrights of the verificationdataprocesssubject are adequately protected. It should be ensured that no photo or video is captured, even if not recorded and not processed, from individuals who do not consent to the facial recognition through appropriate measures. For example, where the biometric data are securely stored solely aton the sidedevice of the data subject or are securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject,thatandprocessing is not likelysubject to createmeasuressignificantensuringrisksthetooverallhissecurityorofherprocessing,fundamentalincludingrightsduringandthefreedoms.enrolmentThe controller does not gain knowledgephase of the data subject’s biometric data or only for a very limited time during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Amendment 319 · ITRE–LIBE amendments 251–400 to the draft report
(34) Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric recognition includes two distinct functions, namely the identification of a natural person or the verification of their claimed identity according to Article 3 (35) and (36) of Regulation (EU) 2024/1689. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification and identification of the data subject is necessary and proportionate for a purpose pursued by the controller. The derogation should only apply where the data subject is offered a non-biometric alternative and appropriate safeguards laid down under Union law are implemented to ensure fundamental rights of the data subject are adequately protected. It should be ensured that no photo or video is captured, even if not recorded and not processed, from individuals who do not consent to the facial recognition through appropriate measures. For example, where the biometric data are securely stored solely on the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject and subject to measures ensuring the overall security of processing, including during the enrolment phase of the data subject’s biometric data during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
Wording reproduced in the amendment → Amendment 320 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation (EU) 2016/679 should also be allowed where thedataverificationsubjectofistheofferedclaimedaidentitynon-biometric alternative and suitable safeguards are implemented to ensure fundamental rights of the data subject isarenecessaryadequatelyforprotecteda purpose pursued bythrough the controller, and suitable safeguards apply to enable the data subject to have sole controlimplementation of the verificationnecessaryprocesssafeguards. For example, this is the case, where the biometric data areis securely stored solely atby the sidedevice of the data subject, or arethe biometric data is securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject, thatandprocessing is not likelysubject to createmeasuressignificantensuringrisksthe overall security of the processing, including during the enrolment phase of data subject and at the time when the data subject agrees to his or her fundamental rights and freedoms. The controller does not gain knowledge ofshare the biometric data or onlyencryptionforkey. Other examples of appropriate safeguards are ensuring that end-to-end encryption, or similar state of the art technology, is used when data are transmitted over a verycommunicationlimitedchanneltimeandduringproviding data subjects with the verificationpossibilityprocessto securely erase their biometric data in accordance with Article 17 of Regulation (EU) 2016/679.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Amendment 320 · ITRE–LIBE amendments 251–400 to the draft report
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where data subject is offered a non-biometric alternative and suitable safeguards are implemented to ensure fundamental rights of the data subject are adequately protected through the implementation of the necessary safeguards. For example, this is the case, where the biometric data is securely stored by the device of the data subject, or the biometric data is securely stored by the controller in a encrypted form and the encryption key or equivalent means is securely held the data subject, and subject to measures ensuring the overall security of the processing, including during the enrolment phase of data subject and at the time when the data subject agrees to share the biometric data or encryption key. Other examples of appropriate safeguards are ensuring that end-to-end encryption, or similar state of the art technology, is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data in accordance with Article 17 of Regulation (EU) 2016/679.
Wording reproduced in the amendment → Amendment 321 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verificationdataofsubjecttheisclaimedofferedidentitya non-biometric alternative and suitable safeguards are implemented to ensure fundamental rights of the data subject isarenecessaryadequatelyforprotecteda purpose pursued bythrough the controller, and suitable safeguards apply to enable the data subject to have sole controlimplementation of the verificationnecessaryprocesssafeguards. For example, where the biometric data are securely stored solely atby the device the side of the data subject, or the biometric data is are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, thatandprocessing is not likelysubject to createmeasuressignificantensuringrisksthe overall security of the processing, including during the enrolment phase of data subject and at the time when the data subject agrees to his or her fundamental rights and freedoms. The controller does not gain knowledge ofshare the biometric data or onlyencryptionforkey. Other examples of appropriate safeguards are ensuring that end-to-end encryption, or similar state of the art technology, is used when data are transmitted over a verycommunicationlimitedchanneltimeandduringproviding data subjects with the verificationpossibilityprocessto securely erase their biometric data in accordance with Article 17 of Regulation (EU) 2016/679.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Amendment 321 · ITRE–LIBE amendments 251–400 to the draft report
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should be allowed where the data subject is offered a non-biometric alternative and suitable safeguards are implemented to ensure fundamental rights of the data subject are adequately protected through the implementation of the necessary safeguards. For example, where the biometric data are securely stored solely by the device the side of the data subject, or the biometric data is are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, and subject to measures ensuring the overall security of the processing, including during the enrolment phase of data subject and at the time when the data subject agrees to share the biometric data or encryption key. Other examples of appropriate safeguards are ensuring that end-to-end encryption, or similar state of the art technology, is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely erase their biometric data in accordance with Article 17 of Regulation (EU) 2016/679.
Wording reproduced in the amendment → Amendment 322 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(34) BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of recognition through biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a legitimate purpose pursued by the controller, and suitableeffective safeguards apply to enable the data subject to have sole control of the verification process. ForInexample,orderwhereto protect the highly sensitive nature of biometric data,areprocessingsecurelythereofstoredshouldsolelyonlyatoccur outside the sidedevice of the data subject orinarehighlysecurelyexceptionalstoredcasesatandtheonlysidewhen any such processing involves state of the controllerart privacy technology, such as encryption, the key to which is in asolestate-of-the-artpossessionencrypted form and the encryption key or equivalent means is held solely byof the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedomszero knowledge proofs. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Amendment 322 · ITRE–LIBE amendments 251–400 to the draft report
(34) Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of recognition through biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a legitimate purpose pursued by the controller, and effective safeguards apply to enable the data subject to have sole control of the verification process. In order to protect the highly sensitive nature of biometric data, processing thereof should only occur outside the device of the data subject in highly exceptional cases and only when any such processing involves state of the art privacy technology, such as encryption, the key to which is in sole possession of the data subject, and zero knowledge proofs. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Wording reproduced in the amendment → Amendment 4 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Changes in context
(34) BiometricProcessing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric datarecognition includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or hertheir claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or hertheir identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation (EU) 2016/679 should also be allowed where the verification of the claimed identity of the data subject is necessary and proportionate for a legitimate purpose pursued by the controller, and subject to appropriate safeguards laid down under Union law. When such verification is necessary, the controller should choose the least intrusive of the equally effective means available. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and should be subject to appropriate safeguards. That derogation should only apply where suitable safeguards apply to enableensure that the biometric data subjectaretounderhavethe sole control of the data subject. Sole control means that the data subject can effectively decide when and how their biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, where the biometric data are securely stored solely aton the sidedevice of the data subject or are securely stored at the side ofby the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject,thatandprocessing is not likelysubject to createmeasuressignificantensuringrisksthetooverallhissecurityorofherprocessing,fundamentalincludingrightsduringandthefreedoms.enrolmentThe controller does not gain knowledgephase of the data subject’s biometric data or only for a very limited time during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
(34) Processing of biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric recognition includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of their claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming their identity. Derogating from the prohibition to process biometric data under Article 9(1) of Regulation (EU) 2016/679 should be allowed where the verification of the claimed identity of the data subject is necessary and proportionate for a legitimate purpose pursued by the controller, and subject to appropriate safeguards laid down under Union law. When such verification is necessary, the controller should choose the least intrusive of the equally effective means available. The processing of biometric data for identity verification should therefore only be used where necessary and proportionate and should be subject to appropriate safeguards. That derogation should only apply where suitable safeguards apply to ensure that the biometric data are under the sole control of the data subject. Sole control means that the data subject can effectively decide when and how their biometric data are used for verification, without the controller having the technical capacity to access such biometric data in decrypted form or process them outside the strictly limited comparison process necessary for verification. For example, where the biometric data are securely stored solely on the device of the data subject or are securely stored by the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is securely held solely by the data subject and subject to measures ensuring the overall security of processing, including during the enrolment phase of the data subject’s biometric data during the verification process. Such verification may in particular be required in the context of electronic identification systems and trust services under Union law. Other examples of appropriate safeguards are ensuring that end-to-end encryption is used when data are transmitted over a communication channel and providing data subjects with the possibility to securely rectify or delete their biometric data at any time.
Wording reproduced in the amendment → Amendment 122 · JURI amendments 69–296 to the draft opinion: removal
Changes in context
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(34) Biometric data, as defined in Article 4(14) of Regulation (EU) 2016/679, means processing of certain characteristics of a natural person through a specific technical means and which allows or confirms the unique identification of that person. The notion of biometric data includes two distinct functions, namely the identification of a natural person or the verification (also called authentication) of his or her claimed identity, both of which rely on different technical processes. The identification process is based on a ‘one-to-many’ search of the data subject’s biometric data in a database, while the verification process is based on a ‘one-to-one’ comparison of biometric data provided by the data subject, who is thereby claiming his or her identity. Derogating from the prohibition to process biometric data under Article 9(1) of the Regulation should also be allowed where the verification of the claimed identity of the data subject is necessary for a purpose pursued by the controller, and suitable safeguards apply to enable the data subject to have sole control of the verification process. For example, where the biometric data are securely stored solely at the side of the data subject or are securely stored at the side of the controller in a state-of-the-art encrypted form and the encryption key or equivalent means is held solely by the data subject, that processing is not likely to create significant risks to his or her fundamental rights and freedoms. The controller does not gain knowledge of the biometric data or only for a very limited time during the verification process.
Amendment 122 · JURI amendments 69–296 to the draft opinion: removal