New General Regulation on the Processing of Biometric Data
By Robalino

The Superintendence for the Protection of Personal Data (SPDP) issued the General Regulation on the Processing of Biometric Data, applicable to public and private entities that use biometric data to uniquely identify or verify natural persons. The regulation covers, among other areas, facial recognition, fingerprints, iris scans and voice recognition. These data are considered sensitive, and their processing therefore requires enhanced safeguards.
Key obligations for companies
Companies must:
- Conduct a risk analysis and a Data Protection Impact Assessment (DPIA) before implementing a biometric system. The DPIA must be updated every twelve months or whenever the level of risk changes.
- Demonstrate that the use of biometrics is strictly necessary and that there is no less intrusive alternative to achieve the intended purpose.
- When processing is based on consent, provide a non-biometric alternative, unless a duly documented technical or factual impossibility is established in the DPIA.
- Apply privacy by design, data minimization, strict access controls and enhanced security measures. The use of biometric templates should be prioritized over the storage of raw biometric data.
Key restrictions
The regulation prohibits the reuse of biometric data for a purpose different from the one that justified their collection. It also prohibits the mass and indiscriminate identification of individuals in public spaces, unless expressly authorized by law.
Companies may not rely exclusively on automated biometric systems to make decisions that produce legal effects or significantly affect fundamental rights. In addition, the use of biometric identification involving children and adolescents is restricted and subject to enhanced safeguards.
Recommended actions
Companies that use biometrics for access control, attendance monitoring, authentication, fraud prevention or video surveillance should:
- Identify their biometric systems and data flows.
- Verify the legal basis and necessity of the processing.
- Prepare or update the DPIA and risk analysis.
- Implement non-biometric alternatives where applicable.
- Review technical measures, access controls and privacy notices.
Compliance and effective date
Organizations that already use biometric systems will have twelve months from the publication of the regulation in the Official Gazette to bring their processes and systems into compliance. The publication date is not stated in the document analyzed and should therefore be confirmed in order to calculate the exact deadline.
If specific advice on biometric data is required, please contact our Personal Data Protection team:
Pedro Córdova Balda, Partner
María Paula Arellano, Associate
Gianpiero Stephano Bacigalupo Matamoros, Associate
This document does not constitute legal advice and is provided for general informational purposes only.
