Biometric Data & Facial Recognition Compliance Check
Check whether your use of facial recognition, fingerprint scanning, or other biometric technology meets UK GDPR's special category data rules.
Why this matters
Biometric data used to uniquely identify a person — facial recognition templates, fingerprints, iris scans, voice patterns — is classed as special category data under Article 9 of UK GDPR, alongside health and ethnicity data. This means it can only be processed with explicit consent or another narrow legal condition, and businesses must be able to justify why less intrusive alternatives weren’t used instead. The Information Commissioner’s Office has published detailed guidance on biometric data and, separately, on live facial recognition technology aimed squarely at retailers and employers who have rapidly adopted these tools for staff attendance, building access, and loss prevention.
Enforcement is no longer theoretical. In February 2024 the ICO issued a formal reprimand to Serco Leisure over its use of facial recognition and fingerprint scanning to monitor staff attendance across leisure centres, finding the company had failed to properly assess whether a less intrusive method could achieve the same purpose. Retailers deploying facial recognition for shoplifting and loss prevention have also faced complaints and regulatory scrutiny over inadequate signage, consent, and data retention practices. Any UK business using biometric technology — however small the deployment — needs a documented lawful basis, a Data Protection Impact Assessment, and a genuine alternative for people who don’t want to take part.
What you'll need
- Details of any biometric technology used (facial recognition, fingerprint scanning, iris or voice recognition)
- The purpose it's used for (e.g. staff attendance, building access, loss prevention, age verification)
- Whether a Data Protection Impact Assessment (DPIA) has been carried out
- Your current privacy notice and any biometric-specific consent wording
What you'll get
A personalised compliance report covering: a score out of 100, an executive summary, a list of findings ranked by severity, and a prioritised action plan with timeframes.
This check reviews your use of facial recognition, fingerprint scanning, or other biometric technology against UK GDPR’s special category data rules — covering consent, DPIAs, proportionality, and retention.
General guidance only — not legal advice. Consult a qualified UK solicitor for specific issues.