Processing is prohibited by default and requires: Because this involves a special category of personal data,
Biometric data used to uniquely identify individuals is a special category, prohibited by default unless a specific exception such as explicit consent and safeguards apply.
The question
A company wants to add facial-recognition login that processes biometric data to uniquely identify employees. Because this involves a special category of personal data, what is the baseline lawful-processing expectation?
Preparing for AIGP? Take the free 5-min readiness quiz →
- The biometric data may be processed on legitimate interests alone, provided the company documents the purpose in its processing records.Plausible because legitimate interests supports ordinary data, but special-category processing needs a specific Article 9 condition, not legitimate interests.
- A standard privacy notice is sufficient here, because biometric identifiers are treated much like ordinary contact and account details under the rules.Plausible as transparency matters, but a notice does not supply the lawful condition special-category data demands.
- Encryption of the stored biometric templates removes them from special-category status and any additional processing conditions.Plausible since encryption reduces risk, but it does not change the data's special-category classification or lift the conditions.
- Processing is prohibited by default and requires a specific legal exception, such as explicit consent, together with heightened safeguards. ✓Correct: biometric data used to uniquely identify a person is a special category, presumptively prohibited absent a specific exception and safeguards.
The trap
Treating biometric identifiers as ordinary personal data that legitimate interests or a privacy notice alone can justify. How to remember it
Biometric data used to uniquely identify individuals is a special category, prohibited by default unless a specific exception such as explicit consent and safeguards apply.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- Carry out a data protection impact assessment: Considering the controller's obligations, which step is →
- Copyright may prohibit or limit using the material: From an intellectual-property standpoint, which →
- The tool may cause unlawful disparate impact: Under nondiscrimination law, what is the primary legal risk even →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.