Facial recognition is an example of personal data processing and is covered by the GDPR. The General Data Protection Regulations (GDPR) stands as a robust framework protecting personal data both in the UK and across Europe.
One of the ideas behind the GDPR was to make it forward looking. Who knows where technology will go in the coming decades? For example, AI was not in anyone’s mind when the GDPR came into force in 2018. Since then facial recognition technology has also emerged, increasingly being deployed across various sectors from security to retail. Understanding how the GDPR applies in the context of of facial recognition technology is crucial to navigating the complexities of privacy and compliance.
What is Facial Recognition Technology?
Technology for recognising faces is a type of artificial intelligence (AI) that can identify or verify a person by analysing their face. Here’s a breakdown of the concept with some examples:
How it Works
Facial recognition systems work by capturing a digital image or video of a person’s face. The system then analyses the image, focusing on key features like the distance between the eyes, the shape of the jawline, and the proportions of the nose and mouth. This information is compared to a database of facial images to identify or verify the person.
Examples of Applications
-
Unlocking smartphones: Many smartphones now recognise faces to unlock the device instead of a passcode.
-
Security applications: Facial recognition can be used in border or security control at airports, railways, or secure buildings.
-
Law enforcement: Law enforcement agencies can use facial recognition to identify suspects or match faces captured on surveillance cameras with known criminals.
-
Social media: Some social media platforms use facial recognition to help users tag friends in photos or suggest connections based on facial similarities.
-
Photo organisation: Facial recognition technology can be used to automatically categorise photos by the people who appear in them.
It’s important to note that this technology is still under development and can be unreliable in certain situations. For example, it may struggle to recognise faces with poor lighting, obscured by sunglasses, or with significant changes in appearance like aging or weight gain (as your author can attest). Additionally, there are privacy concerns surrounding the use of facial recognition technology. It raises questions about data collection and potential misuse..
The GDPR: an Overview
The GDPR was introduced by the European Union as a common and comprehensive data protection framework. Although the UK has left the EU, it has retained the GDPR in UK law primarily through the Data Protection Act 2018.
The GDPR is designed to safeguard personal data, establishing stringent guidelines for its processing. It emphasises principles such as lawfulness, fairness, transparency, data minimisation, accuracy, and integrity. In the context of facial recognition, GDPR’s focus on protecting sensitive data becomes particularly pertinent.
Key takeaways from the GDPR include:
-
understanding all your personal data processing needs
-
knowing the lawful basis for this data processing and
-
comply with people rights to know and control how their data are used.
Facial Recognition and Special Category Data under UK GDPR
The GDPR classifies facial recognition data as special category data. This means it receives a higher level of protection compared to other personal data due to its sensitive nature.
Here’s a breakdown of why facial recognition data falls under special category data:
-
UK GDPR Definition: Article 9(1) of the UK GDPR defines special category data as including “genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, data concerning sex life or sexual orientation, and data concerning religious belief or philosophical belief.”
-
Biometric Data for Identification: Facial recognition technology uses facial features to uniquely identify individuals. This falls squarely within the definition of biometric data for identification purposes under the UK GDPR
Additional Considerations:
-
Transparency and Fairness: Organisations must be transparent about how they use facial recognition technology and the data collected through it. Individuals should be informed of their rights concerning their facial recognition data at the point at which their data is collected.
-
Data Minimisation: As with all personal data processing the collection and storage of facial recognition data should be limited to what’s strictly necessary for the identified purpose.
-
Data Security Measures: Robust security measures must be implemented to protect facial recognition data from unauthorised access, disclosure, or loss.
Facial recognition technology offers potential benefits, but its use under UK GDPR requires careful consideration and compliance. Organisations must ensure they have a lawful basis for processing it, prioritise transparency and fairness, and implement strong data protection measures.
The Legal Basis for Using Facial Recognition Technology
To lawfully process facial recognition data, organisations must identify a valid lawful basis. Explicit consent, is one of these lawful bases. This means individuals must provide clear and affirmative agreement to their data being used.
If you re relying on consent for processing biometric data then:
-
you must get explicit consent separately from other consent; and
-
give people a way of withdrawing their consent.
Regardless of the lawful basis you use the use of biometric data must be necessary and the processing of it must be proportional.
Sign Up Here:
The GDPR gives people various rights concerning their personal data. These include the right to access, rectify, and erase their data, as well as the right to restrict processing and object to it. Data subjects also have the right to data portability, allowing them to transfer their data across different services seamlessly. Ensuring these rights are respected is a key part of processing biometric data via facial recognition technology lawfully. Securing biometric data necessitates robust technical and organisational measures. Encryption and pseudonymisation may play important roles in protecting data against unauthorised access and breaches. Organisations must implement stringent security protocols to safeguard facial recognition data, ensuring compliance with GDPR’s requirements. Conducting Data Protection Impact Assessments (DPIAs) is required when you are thinking about processing biometric data. DPIAs help identify and mitigate potential privacy risks associated with facial recognition technology. You should be able to take steps to mitigate the risk associated with facial recognition technology before you start using it. Regular compliance audits will also help to ensure that data processing activities remain aligned with GDPR standards, addressing any vulnerabilities promptly. Face recognising technology has been deployed with varying degrees of success in a number of settings. Alongside the examples above it has been used in ways like: shops are increasingly deploying facial recognition technology to prevent shoplifting. the police have started to use it for public safety reasons. in some countries schools have used it to monitor student attendance. Each of these examples offer useful lessons in the importance of meaningful consent and ensuring the people whose data are being processed are fully informed. Balancing the benefits of facial recognition technology with the stringent requirements of GDPR is a complex but essential task. Ensuring compliance not only protects individuals’ privacy but also fosters trust and accountability. As technology continues to evolve, maintaining a commitment to responsible data practices will be paramount in navigating the future of facial recognition within the framework of GDPR. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
Data Subject Rights
Data Security
Impact Assessments and Compliance Checks

Case Studies and Examples
Conclusion
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: