dpia-biometric-systems

Installation
SKILL.md

DPIA for Biometric Systems

Overview

Biometric data processing for uniquely identifying natural persons falls under GDPR Article 9(1) special category data and triggers a mandatory DPIA under Article 35(3)(b) — "processing on a large scale of special categories of data." The European Data Protection Board (EDPB) Guidelines on DPIA list biometric processing as an inherently high-risk activity requiring assessment regardless of scale. This skill provides a structured DPIA methodology specifically designed for biometric identification and authentication systems.

When a DPIA Is Mandatory for Biometric Systems

Under EDPB WP248rev.01, a DPIA is required when processing meets two or more criteria from the nine-factor list. Biometric systems commonly trigger:

EDPB Criterion Biometric Relevance
Special category data (Criterion 4) Biometric data under Art. 9(1) when used for unique identification
Systematic monitoring (Criterion 3) Facial recognition CCTV, continuous gait analysis
Large-scale processing (Criterion 5) Organisation-wide deployment of fingerprint scanners
Innovative technology (Criterion 8) Behavioural biometrics, emotion detection, multimodal biometrics
Vulnerable data subjects (Criterion 7) Employees (power imbalance), children, patients
Automated decision-making (Criterion 2) Biometric-based access decisions without human review
Installs
26
GitHub Stars
228
First Seen
Jun 9, 2026
dpia-biometric-systems — mukul975/privacy-data-protection-skills