dpia-biometric-systems
Installation
SKILL.md
DPIA for Biometric Systems
Overview
Biometric data processing for uniquely identifying natural persons falls under GDPR Article 9(1) special category data and triggers a mandatory DPIA under Article 35(3)(b) — "processing on a large scale of special categories of data." The European Data Protection Board (EDPB) Guidelines on DPIA list biometric processing as an inherently high-risk activity requiring assessment regardless of scale. This skill provides a structured DPIA methodology specifically designed for biometric identification and authentication systems.
When a DPIA Is Mandatory for Biometric Systems
Under EDPB WP248rev.01, a DPIA is required when processing meets two or more criteria from the nine-factor list. Biometric systems commonly trigger:
| EDPB Criterion | Biometric Relevance |
|---|---|
| Special category data (Criterion 4) | Biometric data under Art. 9(1) when used for unique identification |
| Systematic monitoring (Criterion 3) | Facial recognition CCTV, continuous gait analysis |
| Large-scale processing (Criterion 5) | Organisation-wide deployment of fingerprint scanners |
| Innovative technology (Criterion 8) | Behavioural biometrics, emotion detection, multimodal biometrics |
| Vulnerable data subjects (Criterion 7) | Employees (power imbalance), children, patients |
| Automated decision-making (Criterion 2) | Biometric-based access decisions without human review |