GDPR Article 9, Special Categories of Personal Data Including Biometric Data
Regulation (EU) 2016/679, Art. 9
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
A sensitive categories rule binding public and private bodies.
As of 23 August 2026.
What it requires
- Obtain explicit consent, or establish another Article 9(2) basis, before capturing or storing a faceprint, voiceprint, or other biometric identifier derived from a photo, video, or audio recording, whether or not the source recording itself was publicly available.
- Treat any biometric identifier your system derives through its own technical processing as special category data, even where the underlying image or audio was lawfully public.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
Article 83(5)(a) names Article 9 directly among the basic-principles-for-processing provisions carrying the higher administrative-fine tier, up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- EUR
- Fixed cap
- 20,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
The data protection supervisory authority designated by each EU Member State under Article 51, coordinated on cross-border cases through the one stop shop mechanism and the European Data Protection Board (Articles 68-76).
Enforcement record
CMS GDPR Enforcement Tracker Report, 7th edition (cut-off 1 March 2026, published 21 May 2026): 2,685 fines with complete amount, date and controller information recorded across the EU/EEA since the GDPR became applicable on 25 May 2018 (3,062 including cases with incomplete information), totalling approximately EUR 6.11 billion, the first time the tracker's cumulative total crossed EUR 6 billion. actions_per_year (440) and fines_per_year (approximately EUR 487.6 million) are the report's own comparison against its prior, 2025 edition (roughly a one-year interval between editions), not a fixed calendar year; trend is recorded as rising on that reported increase. Counts DPA-imposed administrative fines only; the report does not separately track private civil claims under Article 82. This is the Regulation's enforcement record as a whole, not specific to Article 9.
- As of
- 2 September 2026
- Trend
- Rising
- Currency
- EUR
- Source link
- https://cms.law/en/int/publication/GDPR-Enforcement-Tracker-Report/numbers-and-figures
- Total fines
- 6,110,000,000
- Fines per year
- 487,600,000
- Actions per year
- 440
What it reaches
Excludes recording-derived identifiersNo
Obligation class
Consent, Biometric
Also on the record
EEA status
- Annex
- XI
- Status
- Incorporated
- Force date
- 20 July 2018
- Joint committee decision number
- 154/2018
- Source link
- https://www.efta.int/eea-lex/32016r0679
- Decision date
- 6 July 2018
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 9(1) prohibits processing special categories of personal data, including biometric data processed for the purpose of uniquely identifying a person, unless a listed Article 9(2) exception applies, most commonly explicit consent.
Article 4(14) defines biometric data as data from specific technical processing of physical, physiological or behavioural characteristics, with the statute's own examples (facial images, fingerprint data) stated as non-exhaustive, so the same definition reaches a voiceprint once a system derives an identification capable template from audio, even though the text never uses the word voice.
Recital 51 confirms an ordinary photograph is not itself biometric data and only becomes covered when processed through a specific technical means allowing unique identification, so a faceprint a controller derives from one, even from a publicly available photograph, is newly covered special category data; the General Data Protection Regulation (GDPR) text does not separately discuss audio recordings.
The Dutch data protection authority fined Clearview AI EUR 30.5 million (decision dated 16 May 2024, publicly announced 3 September 2024) for building a facial recognition database from photographs scraped off the public internet without an Article 9 basis.
The Dutch decision itself catalogs parallel GDPR enforcement against Clearview by other Member State authorities on the same underlying conduct, including the Italian Garante (decision dated 10 February 2022) and the French CNIL (decision dated 17 October 2022). The Hellenic Data Protection Authority separately fined Clearview EUR 20,000,000 for the same conduct on 13 July 2022.
When LexLint raises it
processes_biometricsprocesses_voicehigh_risk_decisions
Read the law
Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.