Biometric data remain among the most sensitive and strategic topics on the privacy agenda. Not only because biometrics are directly linked to the identification of people, but because their use combines three high-impact factors: sensitive personal data, potentially high risk and real difficulty in reversing the effects of misuse, leaks or excessive processing. The ANPD (Brazilian Data Protection Authority) itself included biometric data in its 2025-2026 Regulatory Agenda and opened a specific call for input on the topic, precisely to assess the need for regulatory and guidance action.
In recent months, the subject has gained even more practical relevance in two highly visible contexts. On the one hand, in the use of facial recognition and biometrics of fans at sporting events, including impacts on children and adolescents. On the other, in discussions about age verification on the internet, where the debate on verification mechanisms has come to include biometric solutions and other means of age confirmation.
Biometrics are not just another piece of data (and convenience is no excuse)
In the architecture of the LGPD (Brazilian General Data Protection Law), biometric data, when linked to a natural person, are not treated as ordinary information. They belong to the category of sensitive personal data. And this classification completely changes the level of care required in governance.
The debate on biometrics and facial recognition is not only about technological usefulness. It structurally involves questions of legitimacy, necessity, adequacy, data collection minimization, information security, retention period, transparency and, fundamentally, the impact on data subjects' rights and freedoms.
This point is crucial because biometrics are usually presented to the market as synonymous with efficiency, innovation, speed and fraud reduction. But from a governance and regulatory standpoint, the most important question is not just whether the technology works or whether it is easier. The question is a different one: is it really necessary for that specific purpose, in proportion to the risk it creates?
Not every identification problem requires biometrics. Not every security objective justifies facial recognition. And not every gain in operational convenience outweighs the risks created by the massive collection and retention of irrefutable bodily characteristics.
The core of the analysis: necessity and proportionality
For those working in practical data governance, approving processes that involve biometrics and facial identification requires looking directly at two central principles: necessity and proportionality.
Necessity means verifying whether the use of that sensitive data is indispensable to achieve the intended purpose. It is not enough for the collection of a face or fingerprint to be merely convenient, modern or faster. It is necessary to assess whether there is a concrete justification for using that data in the name of that objective.
Proportionality, in turn, requires constantly weighing benefit against impact. And the practical rule is clear: the greater the potential for intrusion, surveillance, systemic error (false positives and false negatives), discrimination, exclusion from access or improper secondary use, the more rigorous the controller's proportionality analysis must be.
This rigor increases substantially in situations involving large-scale collection, recurring monitoring, use in public spaces, strong power imbalances (such as employment relationships) or combination with data on vulnerable groups (such as children and adolescents).
The point many organizations overlook: there are always questions before deployment
What is most often seen in the market, in projects involving facial recognition, facial biometrics, fingerprints or voice, are processes that start at the wrong end: with the purchase of the solution. But regardless of the technology or supplier chosen, the structural governance questions must come before the tool is switched on. Because if the “requirements” do not hold up, and there is no legal basis for the scope or no adequacy to the purpose, the problem will be the controller's, not the tool vendor's.
Essential checks include:
- What specific purpose will support this collection (authentication, identification, fraud prevention, security or another)?
- What type of biometrics will actually be processed?
- Could the purpose be effectively achieved by less privacy-invasive means?
- Will the template or biometric reference be stored by the controller, or will it remain only on the user's device? And for how long?
- How, and to whom, will access to this database be granted? Will there be sharing with third parties?
- Has the data subject been, or can they be, adequately informed in a transparent manner, or will collection take place in an overt or covert context?
- Is the legal basis that will support the collection (for example, consent, or fraud prevention and security where applicable) clearly designed and compatible with recent decisions and sector-specific regulations?
- Are minors (children or adolescents) within the scope of this processing, requiring compliance with art. 14 of the LGPD and the best interests of the minor?
- Who will prepare the Data Protection Impact Assessment (DPIA)?
- Have these risks been assessed, mitigated and documented so they can be demonstrated, or merely passed on through a generic contract?
Facial recognition in stadiums and events: the debate has moved to the center of the agenda
As mentioned, the subject has also ceased to be theoretical because of real and recent developments in highly visible contexts, such as stadiums. By publishing a note and a technical document on biometric access to sporting events in order to comply with obligations set out in the General Sports Law (Lei Geral do Esporte), the ANPD reinforced in practice how critical this topic is for the country.
This is important because it materially confirms one of the central logics of governance: the mere fact that processing finds theoretical justification in a legal text (such as the need to identify those gaining access) does not suspend or override all the other requirements of the LGPD itself.
It remains fully necessary to observe principle-based limits such as risk mitigation, documentation and the determination of a fair retention period for stored data (so as not to create perpetual databases with no remaining legitimate purpose), and to apply reinforced safeguards to properly process and protect data of children and adolescents collected through the same biometric process.
Age verification: a new regulatory front for biometrics
A similar, and equally challenging, situation arises in the sensitive field of age verification on the internet (age assurance) and minors' access to online platforms and digital content. Recently, studies under way at the Ministry of Justice in the federal government have sought models more robust than the ineffective or weak barriers of the “tick here and declare that you are over 18” type, and the debate, both globally and in Brazil, now openly discusses systemic alternatives to identify or block profiles.
The tension this places on governance is clear: to effectively protect children and prevent exposure, platforms must find technological solutions, often based on facial scanning, authentication biometrics linked to government databases and massive cross-referencing of identifying traces, which by their very nature tend to be highly, or even exceptionally, intrusive.
The problem is not only collecting. It is governing the entire lifecycle
A sound guideline for operations in this area, and one that must be maintained: with biometrics as one of the ANPD's chosen topics, the controller's or processor's control and risk never begin, nor end, at the moment a person's face is captured or a finger touches a sensor.
The level of governance maturity can only be considered real when risks and controls actively cover the complete lifecycle.
- Regulatory risk arises already in the project documentation, in the product design and in the choice of what it will be based on (legal basis, purpose, context).
- That same risk is greatly amplified or minimized depending on the proper design of the data's security flows.
- Risk can reach a critical stage of contractual sanctions when the design exists only on paper or when there is thoughtless, excessive or weak sharing with direct suppliers or hidden sub-processors.
- Risk can also gain, or lose, a prolonged legal afterlife depending on storage retention policies and on real, secure capabilities and routines for permanent and irreversible disposal.
The real focus of any governance analysis of biometrics therefore rests on a familiar term: evidence, and a technical and regulatory trail.
Where privacy governance comes in, in practice, and why it cannot be solved “on paper” alone
Mature companies and teams have clearly begun to understand the real routines and metrics involved. Organizations and managers with good control in this demanding and closely monitored area (biometrics) should always have the following records on this particular processing available for prompt demonstration:
- Detailed and unified mapping of the processing: Ensuring clear, up-to-date mapping and description at every point, channel and core process in which the organization collects or cross-references templates;
- Lawfulness with clean bases and grounds: Clarifying where the legal basis is strictly grounded and documenting it;
- Active assignment of limited needs, with documented alternatives and project rejections;
- Real assessments of risks to users and of systematic or occasional discrimination by automated systems;
- Non-negotiable retention criteria and controlled lifecycles (enforced through deletion or blocking);
- Active transparency towards ordinary citizens; and
- The great central link: documentation of where, how and by whom the review took place.
RoPA, DPIA and privacy by design: why have they never been mere formalities here?
It is important to highlight how well-known LGPD instruments (RoPA, DPIA and PbD) become immediately practical when biometrics are involved.
The Record of Processing Activities (RoPA, or Personal Data Inventory) is much more than a simple entry in a database; it requires and enables a reading of the processing, and only on the basis of solid, documented and constantly updated mapping within the program can organizations effectively build or guarantee controls, or know exactly which process to block in the chain if necessary or affected.
In Brazil and abroad, including in European guidance and that of other authorities, there is a market consensus that this processing is, by definition, very likely to entail high and continuous risk, and therefore always calls for, and in many cases requires, an effective assessment document: the Data Protection Impact Assessment (DPIA). No initiative in this ecosystem can today proceed with real governance and accountability in a biometrics or facial recognition program or project of any scale without a documented process in a sound and robust Impact Assessment from the very start of the live process and its purpose, analyzed by people responsible for assessing and monitoring the data and for identifying in depth whether, and how, the mitigating measures actually work, so as to maintain the safeguarding and clear minimization that the ANPD requires.
This means incorporating these steps from the outset, in the design and technical premises, with a focused and central view towards acting with Privacy by Design. And not only for privacy's sake, but as a real practice that questions beforehand, instead of documenting flaws afterwards.
The role of software, the hidden protagonist: turning a sensitive topic into a continuous control process
Entering this area of the LGPD requires infrastructure and tools, not just committees. At the same time, the challenge cannot be left to teams caught up in a purely bureaucratic effort, with slow updates to a complex, fragmented base scattered across spreadsheets or unreviewable folders that never contain all the links and relationships needed to document, in a traceable way, the institution's regulatory maturity under continuous regulatory scrutiny of active processes.
Software solutions focused strictly on governance management, such as DPO Privacy, are designed precisely for this:
- Providing the team with broad, centralized management in an Inventory or RoPA module, in which every detail of photo collection, verification logs, purpose or linkage is fully integrated and not forgotten;
- Linking supporting legal bases or complementary laws to the real purposes without gaps;
- Making flows transparent; and
- Actively enabling, supporting and guiding robust and efficient reviews through workflows that trigger the complete stages, so that DPOs and specialist professionals can analyze real risks with internal frameworks suited to their own DPIAs, without losing the software's traceable history, with joint approvals and control deadlines to act within the timeframes of the LGPD and the ANPD.
Conclusion
Biometric data and facial recognition are, and will certainly remain, intertwined with the most significant corporate development strategies. But the context is evolving very quickly towards a different reality, one of very real regulatory maturity. For any Brazilian organization, the message is that biometric solutions now carry the undeniable premise of moving beyond the “mere adoption of a modern tool”: under the ANPD's scrutiny, mature and compliant corporate and public organizations can no longer treat biometrics and facial recognition as a simple legal or technological advance, approved in isolation and blindly, or kept in “files stored without review” in an improvised way. Biometrics are not a shortcut or a mere convenience, and those who adopt them must be able to answer, in a legally sound manner: is it necessary? And do their governance and records demonstrate, to themselves and to the authorities, the protection of data, so as neither to fail nor to exclude anyone, which is what the Authority and the LGPD always seek: ethical and innovative progress, but demonstrable progress.


