UK GDPR Article 9, Special Categories of Personal Data Including Biometric Data
UK GDPR, Art. 9; Data Protection Act 2018, Sch. 1
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
A sensitive categories rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Obtain explicit consent, or establish another UK General Data Protection Regulation (GDPR) Article 9(2) or Data Protection Act 2018 Schedule 1 basis, before capturing or storing a faceprint, voiceprint, or other biometric identifier derived from a photo, video, or audio recording, whether or not the source recording itself was publicly available.
- Treat biometric data as covered from the moment you collect it once you have determined a purpose of unique identification, not only from the point you actually perform identification or verification, per the ICO's Biometric recognition guidance.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
UK GDPR Art. 83(5)(a) puts an infringement of Article 9 (special categories, including biometric data for unique identification) under the higher maximum amount: the higher of £17,500,000 or 4% of worldwide annual turnover (DPA 2018 s.157(5)).
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- GBP
- Fixed cap
- 17,500,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Information Commissioner's Office (ICO), the UK's single supervisory authority for data protection and PECR, exercising the Article 57 tasks and Article 58 powers conferred on the Commissioner by Data Protection Act 2018 s.115.
Enforcement record
Hand count from the ICO's own enforcement action register (Type facet Monetary penalties plus Enforcement notices), read across the register's first two pages (50 of 222 total listed actions of every type), which cover 7 August 2026 back to 24 April 2025, past the twelve-month cutoff. In the twelve months ending 7 August 2026 (the register's most recent entry), the ICO published 18 monetary penalty notices and 14 enforcement notices, for a combined actions_per_year of 32. Reprimands and prosecutions are excluded. Where the register lists a monetary penalty notice and an enforcement notice against the same underlying matter as two separate rows (for example Elderly Aids Limited, 6 August 2026), each row counts once as its own published enforcement instrument. fines_per_year is omitted: several monetary penalty rows in the register's list view state no penalty figure in the summary text shown there (only the full decision notice states it), so a sum from the visible list would understate the true total. This is the ICO's enforcement record for the data protection and PECR regime generally, not a record specific to this instrument's own provisions.
- As of
- 2 September 2026
- Source link
- https://ico.org.uk/action-weve-taken/enforcement/
- Actions per year
- 32
What it reaches
Excludes recording-derived identifiersNo
Obligation class
Consent, Biometric
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Biometric data used for identification, fingerprints, facial templates, voiceprints, is special category data under UK GDPR Article 9, the same definition as EU GDPR.
The DPA 2018's Schedule 1 supplies the UK's own list of Article 9(2)(g) substantial public interest conditions, 23 conditions in Part 2 of Schedule 1, in addition to explicit consent, employment and social-security processing authorised by law, vital interests, not-for-profit bodies, data manifestly made public, legal claims, health and social care, public health, and archiving and research.
The ICO's own "Biometric recognition" guidance, published in final form 5 March 2024, states that biometric data becomes special category personal data from the moment of collection once a purpose of unique identification has been determined for it.
The Data (Use and Access) Act 2025 inserted a new Article 11A UK GDPR giving the Secretary of State a ministerial power to expand, by regulation, what description of processing is subject to Article 9's prohibition or its exceptions; no such regulation had been made as of the date shown. The ICO fined Clearview AI Inc GBP 7,552,800 for, among other findings, failing to meet the higher data protection standard biometric data requires.
In October 2025, the Upper Tribunal held that the First-tier Tribunal had wrongly found Clearview's processing outside UK GDPR's material scope, restoring the ICO's jurisdiction to have issued the fine and enforcement notice and remitting the substantive appeal against them to the First-tier Tribunal for determination.
When LexLint raises it
processes_biometricsprocesses_voicehigh_risk_decisions
Read the law
legislation.gov.uk, official consolidated text
ICO Biometric recognition guidance (5 March 2024); ICO v Clearview AI Inc, Upper Tribunal (October 2025)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.