UAVG Article 29, Biometric-Data Exception for Authentication or Security
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
A biometric privacy rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Rely only on an authentication-or-security purpose, or another General Data Protection Regulation (GDPR) Article 9(2) basis, before processing biometric data of a person in the Netherlands for unique identification; UAVG Article 29's exception reaches no broader purpose on its face.
What it reaches
Excludes recording-derived identifiersNo
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
UAVG Article 29 is a genuine Dutch national addition beyond the General Data Protection Regulation (GDPR) Article 9 baseline, confirmed verbatim: it exercises the GDPR Article 9(2)(g) substantial public-interest derogation to permit processing biometric data for unique identification specifically where necessary for authentication or security purposes.
The provision does not itself enumerate safeguards, a retention limit, or qualifying use cases beyond authentication or security, and no further AP guidance elaborating its boundaries was found. The exception applies equally to a voiceprint and a faceprint; UAVG Article 29's own text does not distinguish by modality, and no AP guidance specifically addressing voiceprint biometrics as distinct from facial biometrics was found.
When LexLint raises it
processes_biometricsprocesses_voicehigh_risk_decisions
Read the law
wetten.overheid.nl, UAVG Art. 29 (verbatim, confirmed twice)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.