PONOPT FIELD NOTES · Privacy и governance

Biometric vs Non-Biometric Analytics: Key Differences Before Procurement

Biometric vs non-biometric analytics before procurement: GDPR and AI Act obligations, accuracy, bias and proportionality trade-offs, plus a pre-purchase audit checklist.

The decision turns on whether you need to identify individuals or only measure patterns. Biometric analytics that link a face, fingerprint or gait to a specific person triggers the strictest regime — special-category data under Article 9 GDPR, a mandatory DPIA and a genuine necessity test. Non-biometric analytics built on genuinely anonymous aggregates usually sits outside data protection law, but only if anonymity is provable. Match the technology to the operational decision you actually need to make.

Key takeaways

  • The decisive criterion is identification: data becomes biometric in the special-category sense only when processed to uniquely identify a person; anonymous aggregates do not.
  • Genuinely anonymous, aggregated analytics generally falls outside data protection law, but anonymity must be provable and robust against re-identification.
  • Under the GDPR and UK GDPR, biometric identification needs an Article 9(2) exception plus a lawful basis, and biometric use in the workplace almost always demands a DPIA before deployment.
  • The EU AI Act classifies remote biometric identification and biometric categorisation on protected attributes as high risk; simple verification is excluded.
  • In California the CCPA treats biometric data as sensitive personal information and requires a privacy risk assessment before processing begins.
  • Regulators favour less intrusive means: if a badge or fob would suffice, biometrics is usually disproportionate and may be unlawful.
  • Biometric errors cannot be reset like a password, so accuracy thresholds, bias testing and small reference databases are procurement requirements, not options.

Define the real question: who, or how many?

The single most consequential procurement decision is whether your operational question requires knowing who an individual is or only measuring what happens at scale. Face, fingerprint, iris, voice and gait systems that tie a measurement back to a specific person enter an entirely different regulatory regime than analytics that count people, measure dwell time, queue length or occupancy without ever assigning an identity. That distinction, not the marketing label on the product, should drive the choice.

Under the GDPR and UK GDPR, data only qualifies as special-category biometric data when it is processed to uniquely identify a person. Systems producing only anonymous, aggregated metrics typically process no personal data at all, provided the aggregation is genuine and re-identification is not realistically possible. This creates a three-tier landscape: full identification (heaviest obligations), verification or authentication of an already known person (lighter under the AI Act but still biometric processing), and anonymous behavioural measurement (lowest exposure). Treat any vendor description that blurs these tiers as a warning.

How regulation weighs the two classes differently

In the EU and UK, biometric data processed for unique identification is a special category under Article 9 GDPR and UK GDPR: processing is prohibited by default and allowed only where one of the narrow Article 9(2) exceptions applies in addition to a separate lawful basis. European regulators, including France's CNIL, frame the test around necessity — its model regulation for workplace access asks directly whether a badge system would be enough, whether the need is only convenience, and whether the protected areas are genuinely sensitive; a no on any point means biometrics should not be deployed.

Biometric use is also routinely treated as high risk for people's rights, which makes a data protection impact assessment (DPIA) mandatory before deployment and expected to be revisited, typically every three years. Non-biometric anonymous analytics rarely triggers a DPIA. Where a system still processes personal data but does not identify people, the obligations are lighter, though identifiability and re-identification risk must still be assessed rather than assumed away.

Additional obligations differ by region, and several of them now apply directly at the procurement stage.

  • EU AI Act: remote biometric identification and biometric categorisation based on sensitive or protected attributes are high risk; simple verification (e.g. facial authentication) is excluded.
  • California CCPA: biometric data counts as sensitive personal information, triggering a privacy risk assessment before processing; automated decision-making on significant decisions requires notice and opt-out from January 2027.
  • Workplace context: the ICO's Serco case shows employers cannot rely on employee consent where there is a power imbalance and less intrusive options exist.

The cost of errors you cannot undo

The defining property of biometrics is that a breach cannot be undone: as the ICO put it in the Serco case, you cannot reset someone's face or fingerprint the way you reset a password. Recognition systems compare samples probabilistically, so false accepts and false rejects can never be fully eliminated. The choice of threshold — how sensitive the system is — determines who gets wrongly blocked or wrongly admitted, and the ICO expects controllers to set and justify thresholds for their own context rather than accept defaults.

Accuracy must be paired with bias testing. The ICO notes that fingerprint recognition is measurably less accurate for adults over seventy and children under twelve, and that a system offering no alternative to a person with a disability can be discriminatory and therefore unlawful. Larger reference databases increase the chance of false matches, which is why regulators advise keeping them as small as possible — also a data-minimisation requirement. Anonymous analytics carries far lower re-identification exposure, but claims of anonymisation must be evidenced, and sensor placement or calibration errors can still distort flow metrics.

Proportionality and total cost of ownership

Procurement should begin with necessity and proportionality. CNIL's logic is blunt: if a badge is sufficient the answer is no; if the goal is only convenience the answer is no; if the protected premises are not especially sensitive the answer is no. The ICO reached the same conclusion for Serco's attendance monitoring, where 2,000-plus employees had their faces and fingerprints scanned to clock in and out even though ID cards or fobs would have been far less intrusive and clearly fit for purpose.

Consent is a fragile foundation in the workplace because of the power imbalance: if declining means not getting paid or not being hired, consent is unlikely to be voluntary. The ICO consequently requires a real, proactive alternative. The true cost of biometrics includes the DPIA, threshold tuning, ongoing bias monitoring, encryption of templates, deletion of raw samples as soon as a template is created, retention limits, and periodic audits. Non-biometric analytics carries far lower compliance overhead, but it cannot answer identity-dependent questions such as controlling access to a secure zone or attributing an action to a named employee. The task should define the class of data, not the reverse.

Turning the comparison into procurement gates

The comparison collapses into a set of verifiable questions you can embed in a request for proposal and in vendor scoring. For every candidate, obtain a written statement of the data class produced, a documented necessity and proportionality case, the existence and date of a DPIA, documented accuracy figures with their source, evidence of bias testing, a minimisation and retention scheme, and a contractual exit path that deletes models and templates.

Any vendor that cannot show what it genuinely collects and stores fails due diligence. If the task can be solved with anonymous aggregates, start from non-biometric analytics and move to biometrics only when identification is genuinely unavoidable. This ordering lowers legal risk and total cost of ownership before signature rather than after the first regulatory enforcement notice.

Pre-procurement audit checklist for analytics vendors

Run this checklist before you commit. Each item maps to a regulatory or operational risk discussed above; a single 'no' or 'cannot demonstrate' is a red flag that should either change the requirement or push you toward the other class of analytics.

  1. Define the decision: must the system identify specific individuals, or can the question be answered with anonymous, aggregated counts? If identity is not required, start from non-biometric.
  2. Confirm the data class: request a written statement of whether the system produces biometric data for unique identification under GDPR Article 9/UK GDPR or only anonymised metrics, and whether raw images are retained.
  3. Demand the necessity and proportionality case: why is biometric processing needed when a badge, fob or non-biometric alternative exists (CNIL's test says if a badge is enough, the answer is no).
  4. Check for a completed DPIA and ask for its date, owner and renewal plan; biometric use is high risk and must be reassessed, typically every three years.
  5. Ask how freely given, explicit consent or another Article 9(2) ground is obtained, and how a worker can opt out without penalty — the ICO's Serco case shows employer consent is hard to defend.
  6. Request documented accuracy metrics (false accept/reject rates), their source (lab versus your environment) and whether the threshold can be tuned locally.
  7. Ask for bias testing across demographics and a mitigation plan, including known failure modes such as lower fingerprint accuracy for older adults and young children.
  8. Verify storage minimisation: raw biometric samples deleted once a template is created, templates encrypted, and all data removed when a person leaves.
  9. Confirm breach and retention behaviour: maximum retention period, who holds templates, and whether biometric data can ever be restored or reset after a leak — unlike passwords, it cannot.
  10. For US deployment, confirm whether a CCPA privacy risk assessment applies and who certifies it, and whether Illinois-style state biometric statutes create a private right of action.
  11. Request an exit path: an API to export or delete data, and what happens to models and templates if you terminate the contract.
  12. Test the vendor's anonymity claims: how re-identification is prevented and who has independently verified it.

Questions people ask

When does analytics data legally become biometric data?

Under the GDPR and UK GDPR, data is biometric in the special-category sense only when it is processed to uniquely identify a person — for example comparing a face against a database to establish who someone is. If a system produces only anonymous, aggregated metrics such as visitor counts, flow and occupancy, and never links them to an individual, it generally falls outside biometric treatment and often outside data protection law entirely, provided anonymity is genuine and re-identification is not realistically possible.

Can an employer rely on employee consent for biometric timekeeping?

Usually not safely. In the Serco case the ICO ordered the employer to stop facial recognition and fingerprint scanning for attendance of over 2,000 staff because employees were not offered a real alternative and consent was not voluntary given the power imbalance and the threat of not being paid. The ICO's guidance is that less intrusive means such as ID cards or fobs should be used where they suffice, and any biometric consent must be freely given with a genuine opt-out. Consent is the weakest lawful basis in an employment relationship.

Is non-biometric, aggregated analytics always outside data protection law?

No. Only genuinely anonymous, aggregated data falls out of scope, when re-identification is not realistically possible with the means available. If aggregates can be cross-referenced with cameras, geolocation or external records to reconstruct an identity, the personal-data regime returns. A vendor must demonstrate how re-identification is prevented, ideally with independent verification; otherwise the compliance risk rests with the buyer, not the vendor.

Does the EU AI Act apply to every biometric system?

No. Under Annex III, remote biometric identification (in real time or post-recorded) and biometric categorisation based on sensitive or protected attributes, as well as emotion recognition, are high risk. Simple biometric verification — such as unlocking a device by matching a face to a single enrolled template — is excluded from that high-risk category. Regardless, any processing of biometric data, including verification, remains processing of a special category under the GDPR and needs its own lawful basis and risk assessment.

Why does biometric analytics need a DPIA when anonymous analytics usually does not?

Biometric processing for identification almost always presents a high risk to people's rights because the data cannot be reset after a breach, algorithmic errors have real consequences, and consent in a workplace is often not freely given. Regulators therefore require a data protection impact assessment before deployment and expect it to be revisited, typically every three years. Anonymous aggregate analytics normally processes no personal data and so does not trigger a mandatory DPIA, unless the specific context still creates high risk.

What is the difference between identification and verification when choosing a system?

Identification answers 'who is this person?' by comparing a sample against a large reference database, which raises the risk of false matches and attracts the heaviest obligations. Verification answers 'are you who you claim to be?' by comparing a sample against one enrolled template; under the EU AI Act simple verification is excluded from the high-risk category. Both operations, however, process biometric data and remain sensitive under the GDPR. Choose identification only where the task genuinely requires establishing identity among many people.

Sources and further reading

Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.

  1. ICO orders Serco Leisure to stop using facial recognition technology to monitor attendance of leisure centre employeesInformation Commissioner's Office (ICO)
  2. How do we process biometric data fairly?Information Commissioner's Office (ICO)
  3. Employment informationInformation Commissioner's Office (ICO)
  4. Le contrôle d'accès biométrique sur les lieux de travailCNIL (Commission nationale de l'informatique et des libertés)
  5. California Finalizes Pivotal CCPA Regulations on AI, Cyber Audits, and Risk GovernanceWiley (law firm alert)
  6. AI System — High Risk: definition (AI Act)Dastra
  7. Russia Introduced New Rules on Data Processing ConsentGorodissky & Partners