![]() |
This summer, César Augusto Fontanillo López, PopEye’s Data Manager, published the second installment of his two-part series ‘Against Biometric Identifiability‘ in the European Data Protection Law Review Journal. César is a doctoral researcher at the Centre for IT & IP Law (CiTiP) at KU Leuven and a Fullbright Schuman Fellow at the Information Society Project (ISP) at Yale Law School. His work examines privacy and data protection through a multidisciplinary lens. He is currently pursuing his PhD, which stress-tests the risk-based approach to data regulation through a three-part inquiry combining psychometric, normative, and regulatory research. In this interview, César discusses his most recent paper and provides some reflections on EU law and its relation to biometric data. You can read the full paper here: https://edpl.lexxion.eu/article/EDPL/2025/4/10
|
Biometric data follows a very particular regulatory logic in EU data protection law. It is the only sensitive data category governed through a dual—or bifurcated—regime. Whereas other data categories, like genetic data or data concerning health, attract the sensitive data processing regime as such, biometric data only benefits from this stronger form of protection when it uniquely identifies an individual. Where this threshold is not met, they remain ordinary personal data. This means that biometric data must satisfy two layers of identifiability before it attracts the heightened protection of the sensitive data processing regime: first, the general identifiability standard required for all personal data, and second, the stricter standard of unique identifiability required for sensitive biometric data. The central question that these papers set out to answer is whether EU data protection law is justified in regulating biometric data through this bifurcated approach.
The main takeaway is that the existing sensitive data processing regime for biometric data is unsound because the notion of “unique identification” that underpins it cannot act as an adequate regulatory criterion. This position marks an important departure from other doctrinal accounts which have sought to give substantive content to “unique identification”, including those that treat it as an “upper-limit” construct, confined to already “identified” individuals instead of those who are merely “identifiable” (Jasserand, 2016) and those that exclude biometric verification from this notion (Bygrave and Tosoni, 2020). Distancing itself from these positions, the paper argues that the current regulatory logic should be abolished altogether. It argues that the notion of biometric “unique identification” cannot supply a higher or independent standard of identification that would justify treating biometric data differently from other data categories, and that legislators and policymakers should exercise caution when importing concepts from technical disciplines, especially where those concepts sit uneasily within the internal logic of data protection law or risk fragmenting its coherence.
PopEye is an EU-funded project working on privacy-preserving biometric technologies for passenger identification and verification. Like many other EU-funded biometric projects, PopEye raises concrete questions about identification, authentication, verification, and GDPR compliance. My paper offers an alternative reading of how biometric data in such systems should be classified and regulated. It examines the underlying legal categories that those systems process and offers an alternative way to interpret them.
Part I, titled The Law of What is Reasonably Likely, established the conceptual foundation for the main claims developed in Part II. It examined identifiability in the law of personal data and argued that identifiability is built around three general criteria: (i) singling out, meaning the ability to isolate a record within a set of records in a way that identifies the individual; (ii) linkability, meaning the ability to match two or more records concerning an individual within one or more datasets; and (iii) inference, meaning the ability to deduce, with significant probability, the value of an attribute about identified or identifiable individuals. These criteria are brought together within a general framework that responds to questions of fact that are reasonably likely to arise in a given context.
The broader argument of Part I is that EU data protection law is moving away from the law of everything—a framework that allows almost anything to be treated as personal data—towards the law of what is reasonably likely. Under this latter conception, the legal qualification of personal data is a context—and agent—driven exercise, which turns on whether a standard of “reasonable likelihood” is met to the conviction of a court of law. This trajectory is driven, at least in part, by the increasing activism of the General Court of the Court of Justice of the European Union, whose recent judgments point towards a stricter interpretation of what counts as personal data. Part II uses that general framework to criticise the dual regime of biometric data and existing doctrinal accounts of biometric identifiability.
The distinction is problematic because the current regime adds unnecessary complexity to the regulation of biometric data in ways that generate legal uncertainty and under-protect individuals. Because biometric data is tied to a “unique identification” standard and specific modalities, legal debates often become trapped in questions such as:
Is a facial image or biometric sample sensitive biometric data?
What is the legal status of stored biometric templates which are not yet being used to uniquely identify individuals?
Is “identification” different from “authentication” or “verification”?
If so, does biometric data used for these purposes fall outside the sensitive data regime?
Does the term “unique identification” mean discovering someone’s civil identity, or merely singling them out?
If a biometric recognition system always works with a margin of error, can it ever “uniquely” identify someone?
What happens with new biometric data uses, like categorisation or emotion recognition?
These questions are the product of the current dual regime, and as the literature shows, legal scholars often disagree on how they should be answered, which has generated sustained criticism of the existing framework. The result is a regime that is difficult to apply consistently, and that may leave individuals under-protected when biometric data is used for purposes other than identification.
A single framework would begin with the ordinary question: Does the data relate to an identified or identifiable natural person? That question should be assessed through the general criteria of singling out, linkage, and inference. The same test should apply to all data categories—including biometric data. What would change is that biometric data would no longer require a second biometric identifiability inquiry, which appears largely tautological once the general test of identifiability is taken seriously. If that is the case, the second identifiability layer collapses, and what is left in the definition of biometric data is just the general identifiability test. In the absence of any further ground for sensitivity capable of justifying a different treatment of biometric data, the law should recognise biometric data as sensitive data, provided it qualifies as personal data. This would simplify the legal regime, increase its consistency, reduce uncertainty, and strengthen the protection of individuals.
The dual regime is specifically rooted in EU data protection law—including in the GDPR, the EUDPR, and the Law Enforcement Directive—but the broader problem is not only European. Many legal systems and policy debates struggle with the same assumptions about biometric data, identifiability, and biometric recognition modalities. Some jurisdictions understand biometric identification and the types of data that qualify as biometric data differently from the EU; others do not formally recognise biometric data as a sensitive data category in legislation, but nevertheless extend its protection beyond the European approach through authoritative guidance; and still, others provide a more protective statutory regime than the EU framework.
For instance, the UK Information Commissioner’s Office understands that “unique identification” is slightly different to “identification”, as it refers to someone being singled out with accuracy and based on the biometric data itself, without additional information. Australia follows a similar logic, yet its Data Availability and Transparency Act specifies that data that is not personal cannot be biometric data (e.g., eye colour) by itself, is not biometric data. Canada does not recognise the concept of sensitive data at the federal level, but the Office of the Privacy Commissioner notes that biometric data also comprises other combinable information used to identify individuals, and that it can be used for recognition and classification purposes. Mexico does not recognise either the category of biometric data in its laws, but the now defunct INAI issued a technical note in which it extended the protection of biometric data when it refers to the most intimate sphere of the data subject; its improper use results in discrimination, or its illegitimate use entails a serious risk. Finally, Brazil openly differs from the European approach to biometric data, as it treats this data category as sensitive data as such in the LGPD. Perhaps this last regulatory avenue is the one most closely aligned with the arguments advanced in this two-part paper.
I am still working on the concept of identifiability more generally. I am currently developing a paper that attempts to formalise a general theory of identifiability in logical terms. My ambition is to shed further light on this concept and make it more expressive and analytically precise to enhance legal certainty and increase the likelihood that similar cases are assessed similarly. I presented this paper at TILTing Perspectives in July this year, and I will also pitch it at the Privacy Law Scholars Conference in November. Identifiability is also a central concept in the book The Past, Present, and Future of European Data Regulation, which I have co-authored with Professor Bart van der Sloot, and which is expected to be published by Hart at the end of this year. The book aims to offer an in-depth account of the European data regulatory landscape, from its historical roots to the challenges posed by new technological developments. Through detailed legal and technical analysis, it explores key data categories—including anonymised data, pseudonymised data, aggregated data, sensitive data, and metadata—and highlights their fluid and changing nature, as well as the growing possibilities for movement between these categories.