The facial data is a special category: Under GDPR, why does this processing face a stricter standard than
Biometrics used to uniquely identify a person are special-category data, so processing is barred unless an Article 9 condition applies.
The question
A workplace wants to deploy an AI system that identifies employees from facial images to control building access. Under GDPR, why does this processing face a stricter standard than ordinary personal data processing?
Preparing for AIGP? Take the free 5-min readiness quiz →
- The facial data is pseudonymized, so an added layer of technical safeguards is recommended before usePlausible-sounding but wrong: identifying someone from a face is not pseudonymization, and that is not the trigger.
- The facial data is publicly available, so the balancing test under legitimate business interests must be documentedIncorrect framing: employee facial images are not public, and legitimate interests does not lift the Article 9 bar.
- The facial data is a special category, so processing is prohibited unless a specific Article 9 condition applies ✓Correct: biometrics used to uniquely identify a person are special-category data needing an Article 9 condition.
- The facial data is used for security, so a mandatory retention schedule of the images must be publishedA security purpose does not change the classification; retention rules are separate from the special-category standard.
The trap
Assuming a legitimate security or access-control purpose lowers the special-category (Article 9) protection for biometrics. How to remember it
Biometrics used to uniquely identify a person are special-category data, so processing is barred unless an Article 9 condition applies.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- Carrying out a data protection impact assessment before: Before deployment, which GDPR controller obligation →
- Whether the copyright holders retain rights that can limit: Which intellectual property consideration most →
- Disparate impact: Under nondiscrimination law, which theory of liability is most directly implicated? →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.