Verihubs Logo
Home Blog What Is Biometric Data? Privacy Rules for Business
11 min read • Face Recognition • Published on October 8, 2026

What Is Biometric Data? Privacy Rules for Business

What Is Biometric Data? Privacy Rules for Business

Biometric data is personal data produced by technically processing a person’s physical or behavioural traits, such as the face or fingerprints, so that they can be uniquely identified. Most privacy laws, including GDPR and the laws of Malaysia, Vietnam and Thailand, treat it as sensitive data. That means stricter consent, retention and security rules for any business that collects it.

What Counts as Biometric Data: A Photo vs a Face Template

Ordinary photo vs biometric sample vs biometric template - which ones count as biometric data under GDPR

The legal definition is narrower than most people assume. Under GDPR Article 4(14), biometric data is personal data resulting from “specific technical processing” of physical, physiological or behavioural characteristics that allows or confirms a person’s unique identification. Facial images and fingerprint data are the examples the law gives.

The key words are technical processing. GDPR Recital 51 makes the point directly: a photograph is not automatically biometric data. It becomes biometric data when a system processes it to identify or authenticate someone, for example by turning it into a face template.

Ordinary photoBiometric sampleBiometric template
What it isAn image of a personThe image a system captures for identificationA numeric representation derived from the sample
ExampleA profile pictureA KYC selfie sent for matchingThe vector a face matcher compares
Usually biometric data under GDPR?NoYes, once processed for identificationYes
Resettable after a leak?NoNoPartly, if the system can re-enrol with a new template

This distinction matters in practice. A company that only shows a user’s photo in a profile has a lighter burden than one that runs face matching on it. However, once a KYC selfie goes through a matcher, it is biometric data, and the stricter rules apply.

Types of Biometric Data and Common Examples

Biometric data falls into two broad groups. Physical, or physiological, biometrics describe the body. Behavioural biometrics describe patterns in how a person acts.

  • Physical: face geometry, fingerprints, palm prints and palm veins, iris and retina patterns, voice characteristics and DNA in some laws.
  • Behavioural: typing rhythm, mouse and touch-screen patterns, gait, and the way someone holds a phone.

For digital onboarding and payments, the face dominates, because a phone camera can capture it and a business can match it against an ID photo. Our comparison of fingerprint and facial recognition covers why. Behavioural data is growing too, but it usually produces a risk score rather than a hard identity match.

How Biometric Data Moves Through a Verification System

How biometric data moves - capture, processing into a template, matching against a reference and storage

Understanding the data flow is the first step to a defensible privacy design. A typical face verification follows four stages, and each one creates a different kind of record.

  1. Capture. The app records a selfie or short video. This raw sample is the most sensitive item, because anyone can view it.
  2. Processing. Next, the system checks liveness and converts the face into a template, a set of numbers.
  3. Matching. Then it compares the template with a reference, such as the ID portrait or the template stored at onboarding.
  4. Storage. Finally, the business keeps some records: often the template, the result and an audit trail, and sometimes the raw image.

Each stage is a design choice. For example, a system can discard the raw selfie after matching, or keep it for dispute handling. That choice drives most of the privacy risk, so make it deliberately. For the matching step itself, see our explainer on face verification.

Why Face Data Is Sensitive Data Under GDPR and APAC Privacy Laws

Lawmakers treat biometric data as high risk for one simple reason: you cannot change your face. A leaked password is an inconvenience, but a leaked face template can follow a person for life. Biometric data can also enable tracking across services, which raises surveillance concerns.

Because of these risks, most regimes put biometric data in a protected class. GDPR Article 9 calls it a special category and generally prohibits processing it to identify someone unless an exception applies, such as explicit consent. Several Asian laws have now followed a similar path, although the details differ.

The table below compares how five regimes treat biometric data in identity verification, as of October 2026. Laws change, so confirm current texts with counsel before you rely on any row.

JurisdictionIs biometric data sensitive?Typical basis for face checksRetentionCross-border transfer
European Union (GDPR)Yes, a special category under Article 9Explicit consent, or another Article 9 exception set by lawOnly as long as necessary for the purposeAdequacy decision or safeguards such as standard contractual clauses
Singapore (PDPA 2012)Not a separate category in the Act, but regulators expect extra careConsent, or a recognised exception such as legitimate interestsStop retaining once the purpose endsRecipient must give a comparable standard of protection
Malaysia (PDPA, amended 2024)Yes, listed as sensitive personal data since 1 April 2025Explicit consent, unless a statutory exception appliesNo longer than the purpose requiresAllowed where the destination offers substantially similar protection or another condition is met
Vietnam (Law No. 91/2025/QH15)Yes, listed as sensitive personal dataConsent, with additional duties for sensitive dataDelete when the purpose ends, unless law requires longerRequires a transfer impact assessment
Thailand (PDPA 2019)Yes, under Section 26Explicit consent, unless an exception appliesErase when no longer neededDestination must have adequate standards, unless an exception applies

Key Dates and Breach Notification Deadlines

A few dates help with planning. Thailand’s PDPA has been fully in force since 1 June 2022. Malaysia’s amendments arrived in phases during 2025, including mandatory data protection officers and breach notification. Vietnam’s new Law on Personal Data Protection took effect on 1 January 2026 and replaced Decree 13 of 2023.

Breach notification is also tight almost everywhere. GDPR sets a 72-hour window to notify the regulator. Singapore requires notice within three calendar days for notifiable breaches, and several other regimes in the region now use similar short deadlines. In practice, any team that holds face templates should assume a breach clock of about three days.

Regulated sectors add their own rules on top. For instance, banking regulators increasingly require biometrics for high-risk transactions, as Vietnam’s Decision 2345 shows. Those rules sit alongside privacy law, so a bank must satisfy both.

What a Verification Vendor Should Store, and for How Long

Most businesses do not run face matching themselves. They use a vendor, which makes the vendor’s data practices part of your compliance. A sound setup follows the principle of keeping the least sensitive data for the shortest time.

  • Convert early. Turn the raw sample into a template as soon as possible, which is also what Singapore’s PDPC recommends in its 2022 guide on biometric data.
  • Store templates, not images, by default. Keep raw selfies only where a clear purpose, such as dispute handling or a legal duty, requires them.
  • Set a retention clock. Link retention to the customer relationship or a legal record-keeping period, then delete automatically.
  • Separate identifiers. Store templates apart from names and ID numbers, so a single breach exposes less.
  • Encrypt and log. Encrypt data at rest and in transit, and log every access to biometric records.
  • No secondary use. Do not train models or run analytics on customer biometrics without a lawful basis and clear notice.

Ask vendors to put each of these in the contract, not just in a pitch. Also check where processing happens, because a vendor using servers abroad triggers the transfer rules in the table above.

Questions for Your DPO Before Going Live With Face Verification

Before launch, walk through these questions with your data protection officer or counsel. Each one maps to an obligation in most of the regimes above.

  1. What is our legal basis for processing biometric data, and do we need explicit consent?
  2. Does our consent screen explain the purpose, retention and the right to withdraw in plain language?
  3. Have we completed a data protection impact assessment for biometric processing?
  4. Which records do we keep: raw images, templates, results, or all three, and why?
  5. Where does the vendor process and store data, and which transfer rules apply?
  6. Can we meet the breach notification deadline in every market we serve?
  7. What is the fallback for users who refuse or cannot complete a biometric check?
  8. How do we delete a customer’s biometric data when they close their account?

How Individuals Can Protect Their Own Biometric Data

Customers have a part to play too, and businesses that explain it earn more trust. A few habits go a long way:

  • Read the notice before the selfie. Check why the app wants your face, how long it keeps it, and who it shares it with.
  • Prefer on-device unlock for convenience. Phone face unlock and fingerprint unlock usually keep the template on the device, while a bank’s server-side check is for proving identity.
  • Be wary of unknown apps that ask for face scans. Fake loan and investment apps sometimes collect selfies and ID photos to reuse in fraud.
  • Use your rights. In most of the markets above, you can ask a company what biometric data it holds and request deletion when the purpose has ended.

How Verihubs Approaches Biometric Data in Face Verification

On the matching side, Verihubs face recognition compares the selfie with the reference template. NIST has tested the matcher in its FRTE 1:1 and 1:N evaluations, according to the product page, and the company is ISO 27001 certified for information security. Pair it with liveness detection so the face you store belongs to a real, present customer.

Frequently Asked Questions About Biometric Data

What is biometric data?

Biometric data is personal data created by technically processing a person’s physical or behavioural traits, such as the face, fingerprints or voice, so that they can be uniquely identified. Most privacy laws treat it as sensitive data.

Is a photo biometric data?

Not automatically. Under GDPR, a photo becomes biometric data when a system processes it with technical means to identify or authenticate a person, such as converting it into a face template for matching.

Is biometric data sensitive personal data?

In most major regimes, yes. GDPR treats it as a special category, and Malaysia, Vietnam and Thailand list it as sensitive personal data. Singapore’s PDPA does not create a separate category, but regulators still expect extra protection.

Usually, yes. GDPR, Malaysia and Thailand generally require explicit consent for sensitive data unless a legal exception applies. Check the specific basis available in each market before collecting face data.

How long can a company keep biometric data?

Only as long as the stated purpose requires, plus any period the law demands for record-keeping. Good practice is to keep templates rather than raw images and to delete them automatically at the end of the retention period.

What happens if someone steals biometric data?

The person cannot change their face or fingerprints, so the risk lasts. That is why laws require strong security and quick breach notification, and why systems should store templates separately from other identifiers.

What Is Biometric Data Worth Protecting? Everything You Cannot Reset

The simplest way to think about biometric data is by what happens when it leaks. You can change a password and cancel a card, but faces and fingerprints stay the same for life. That single fact explains why lawmakers from Brussels to Bangkok treat this data as sensitive.

For businesses, the practical response is design, not paperwork. Collect only what the check needs, convert samples to templates early, keep data for a defined period, and choose vendors who can prove all of it. Teams that build this way find compliance easier, and customers find it easier to trust the selfie step.

Planning face verification across several Asian markets? Talk to Verihubs about data handling, retention and matching for each market.

Client Verihubs
Find out how accurate Verihubs Face Recognition
Get FREE Trial
View Blog