DPO Privacy
DPO Privacy
PlatformSolutionsAI governancePlansContentAbout us
PTENES
Book a demo
Book a demo
PlatformSolutionsAI governancePlansContentAbout usBook a demo
HomePublicationsData Subject Rights
Data Subject Rights

Biometric data and facial recognition: when convenience does not dispense with necessity, proportionality and governance

Biometric data combine high impact and high risk. Learn why technological convenience does not replace the need for robust governance, especially in light of the ANPD's new agenda.

R
Rafael Oliveira
March 09, 202612 min read

Biometric data remain among the most sensitive and strategic topics on the privacy agenda. Not only because biometrics are directly linked to the identification of people, but because their use combines three high-impact factors: sensitive personal data, potentially high risk and real difficulty in reversing the effects of misuse, leaks or excessive processing. The ANPD (Brazilian Data Protection Authority) itself included biometric data in its 2025-2026 Regulatory Agenda and opened a specific call for input on the topic, precisely to assess the need for regulatory and guidance action.

In recent months, the subject has gained even more practical relevance in two highly visible contexts. On the one hand, in the use of facial recognition and biometrics of fans at sporting events, including impacts on children and adolescents. On the other, in discussions about age verification on the internet, where the debate on verification mechanisms has come to include biometric solutions and other means of age confirmation.

Biometrics are not just another piece of data (and convenience is no excuse)

In the architecture of the LGPD (Brazilian General Data Protection Law), biometric data, when linked to a natural person, are not treated as ordinary information. They belong to the category of sensitive personal data. And this classification completely changes the level of care required in governance.

The debate on biometrics and facial recognition is not only about technological usefulness. It structurally involves questions of legitimacy, necessity, adequacy, data collection minimization, information security, retention period, transparency and, fundamentally, the impact on data subjects' rights and freedoms.

The debate is no longer only about technological usefulness and now involves legitimacy, necessity, adequacy, minimization, security, retention, transparency and impact on fundamental rights.

This point is crucial because biometrics are usually presented to the market as synonymous with efficiency, innovation, speed and fraud reduction. But from a governance and regulatory standpoint, the most important question is not just whether the technology works or whether it is easier. The question is a different one: is it really necessary for that specific purpose, in proportion to the risk it creates?

Not every identification problem requires biometrics. Not every security objective justifies facial recognition. And not every gain in operational convenience outweighs the risks created by the massive collection and retention of irrefutable bodily characteristics.

The core of the analysis: necessity and proportionality

For those working in practical data governance, approving processes that involve biometrics and facial identification requires looking directly at two central principles: necessity and proportionality.

Necessity means verifying whether the use of that sensitive data is indispensable to achieve the intended purpose. It is not enough for the collection of a face or fingerprint to be merely convenient, modern or faster. It is necessary to assess whether there is a concrete justification for using that data in the name of that objective.

Proportionality, in turn, requires constantly weighing benefit against impact. And the practical rule is clear: the greater the potential for intrusion, surveillance, systemic error (false positives and false negatives), discrimination, exclusion from access or improper secondary use, the more rigorous the controller's proportionality analysis must be.

This rigor increases substantially in situations involving large-scale collection, recurring monitoring, use in public spaces, strong power imbalances (such as employment relationships) or combination with data on vulnerable groups (such as children and adolescents).

The reasoning for the governance team cannot be “the technology is available, so let's use it and document it later.” The reasoning must be: “what problem do we want to solve, why would biometrics be necessary to the point of ruling out less invasive alternatives, and what immediate risks do we create with this collection?”

The point many organizations overlook: there are always questions before deployment

What is most often seen in the market, in projects involving facial recognition, facial biometrics, fingerprints or voice, are processes that start at the wrong end: with the purchase of the solution. But regardless of the technology or supplier chosen, the structural governance questions must come before the tool is switched on. Because if the “requirements” do not hold up, and there is no legal basis for the scope or no adequacy to the purpose, the problem will be the controller's, not the tool vendor's.

Essential checks include:

  • What specific purpose will support this collection (authentication, identification, fraud prevention, security or another)?
  • What type of biometrics will actually be processed?
  • Could the purpose be effectively achieved by less privacy-invasive means?
  • Will the template or biometric reference be stored by the controller, or will it remain only on the user's device? And for how long?
  • How, and to whom, will access to this database be granted? Will there be sharing with third parties?
  • Has the data subject been, or can they be, adequately informed in a transparent manner, or will collection take place in an overt or covert context?
  • Is the legal basis that will support the collection (for example, consent, or fraud prevention and security where applicable) clearly designed and compatible with recent decisions and sector-specific regulations?
  • Are minors (children or adolescents) within the scope of this processing, requiring compliance with art. 14 of the LGPD and the best interests of the minor?
  • Who will prepare the Data Protection Impact Assessment (DPIA)?
  • Have these risks been assessed, mitigated and documented so they can be demonstrated, or merely passed on through a generic contract?

Facial recognition in stadiums and events: the debate has moved to the center of the agenda

As mentioned, the subject has also ceased to be theoretical because of real and recent developments in highly visible contexts, such as stadiums. By publishing a note and a technical document on biometric access to sporting events in order to comply with obligations set out in the General Sports Law (Lei Geral do Esporte), the ANPD reinforced in practice how critical this topic is for the country.

This is important because it materially confirms one of the central logics of governance: the mere fact that processing finds theoretical justification in a legal text (such as the need to identify those gaining access) does not suspend or override all the other requirements of the LGPD itself.

It remains fully necessary to observe principle-based limits such as risk mitigation, documentation and the determination of a fair retention period for stored data (so as not to create perpetual databases with no remaining legitimate purpose), and to apply reinforced safeguards to properly process and protect data of children and adolescents collected through the same biometric process.

Age verification: a new regulatory front for biometrics

A similar, and equally challenging, situation arises in the sensitive field of age verification on the internet (age assurance) and minors' access to online platforms and digital content. Recently, studies under way at the Ministry of Justice in the federal government have sought models more robust than the ineffective or weak barriers of the “tick here and declare that you are over 18” type, and the debate, both globally and in Brazil, now openly discusses systemic alternatives to identify or block profiles.

The tension this places on governance is clear: to effectively protect children and prevent exposure, platforms must find technological solutions, often based on facial scanning, authentication biometrics linked to government databases and massive cross-referencing of identifying traces, which by their very nature tend to be highly, or even exceptionally, intrusive.

The governance frontier in this field is to keep only projects in which the platform and the controller can permanently demonstrate their technical capacity, a robust legal footing aligned with sector-specific rules, and control through the DPIA and Privacy by Design showing that biometrics are in fact a safe and proportionate mechanism.

The problem is not only collecting. It is governing the entire lifecycle

A sound guideline for operations in this area, and one that must be maintained: with biometrics as one of the ANPD's chosen topics, the controller's or processor's control and risk never begin, nor end, at the moment a person's face is captured or a finger touches a sensor.

The level of governance maturity can only be considered real when risks and controls actively cover the complete lifecycle.

  • Regulatory risk arises already in the project documentation, in the product design and in the choice of what it will be based on (legal basis, purpose, context).
  • That same risk is greatly amplified or minimized depending on the proper design of the data's security flows.
  • Risk can reach a critical stage of contractual sanctions when the design exists only on paper or when there is thoughtless, excessive or weak sharing with direct suppliers or hidden sub-processors.
  • Risk can also gain, or lose, a prolonged legal afterlife depending on storage retention policies and on real, secure capabilities and routines for permanent and irreversible disposal.

The real focus of any governance analysis of biometrics therefore rests on a familiar term: evidence, and a technical and regulatory trail.

Where privacy governance comes in, in practice, and why it cannot be solved “on paper” alone

Mature companies and teams have clearly begun to understand the real routines and metrics involved. Organizations and managers with good control in this demanding and closely monitored area (biometrics) should always have the following records on this particular processing available for prompt demonstration:

  • Detailed and unified mapping of the processing: Ensuring clear, up-to-date mapping and description at every point, channel and core process in which the organization collects or cross-references templates;
  • Lawfulness with clean bases and grounds: Clarifying where the legal basis is strictly grounded and documenting it;
  • Active assignment of limited needs, with documented alternatives and project rejections;
  • Real assessments of risks to users and of systematic or occasional discrimination by automated systems;
  • Non-negotiable retention criteria and controlled lifecycles (enforced through deletion or blocking);
  • Active transparency towards ordinary citizens; and
  • The great central link: documentation of where, how and by whom the review took place.

RoPA, DPIA and privacy by design: why have they never been mere formalities here?

It is important to highlight how well-known LGPD instruments (RoPA, DPIA and PbD) become immediately practical when biometrics are involved.

The Record of Processing Activities (RoPA, or Personal Data Inventory) is much more than a simple entry in a database; it requires and enables a reading of the processing, and only on the basis of solid, documented and constantly updated mapping within the program can organizations effectively build or guarantee controls, or know exactly which process to block in the chain if necessary or affected.

In Brazil and abroad, including in European guidance and that of other authorities, there is a market consensus that this processing is, by definition, very likely to entail high and continuous risk, and therefore always calls for, and in many cases requires, an effective assessment document: the Data Protection Impact Assessment (DPIA). No initiative in this ecosystem can today proceed with real governance and accountability in a biometrics or facial recognition program or project of any scale without a documented process in a sound and robust Impact Assessment from the very start of the live process and its purpose, analyzed by people responsible for assessing and monitoring the data and for identifying in depth whether, and how, the mitigating measures actually work, so as to maintain the safeguarding and clear minimization that the ANPD requires.

This means incorporating these steps from the outset, in the design and technical premises, with a focused and central view towards acting with Privacy by Design. And not only for privacy's sake, but as a real practice that questions beforehand, instead of documenting flaws afterwards.

The role of software, the hidden protagonist: turning a sensitive topic into a continuous control process

Entering this area of the LGPD requires infrastructure and tools, not just committees. At the same time, the challenge cannot be left to teams caught up in a purely bureaucratic effort, with slow updates to a complex, fragmented base scattered across spreadsheets or unreviewable folders that never contain all the links and relationships needed to document, in a traceable way, the institution's regulatory maturity under continuous regulatory scrutiny of active processes.

Software solutions focused strictly on governance management, such as DPO Privacy, are designed precisely for this:

  • Providing the team with broad, centralized management in an Inventory or RoPA module, in which every detail of photo collection, verification logs, purpose or linkage is fully integrated and not forgotten;
  • Linking supporting legal bases or complementary laws to the real purposes without gaps;
  • Making flows transparent; and
  • Actively enabling, supporting and guiding robust and efficient reviews through workflows that trigger the complete stages, so that DPOs and specialist professionals can analyze real risks with internal frameworks suited to their own DPIAs, without losing the software's traceable history, with joint approvals and control deadlines to act within the timeframes of the LGPD and the ANPD.

Conclusion

Biometric data and facial recognition are, and will certainly remain, intertwined with the most significant corporate development strategies. But the context is evolving very quickly towards a different reality, one of very real regulatory maturity. For any Brazilian organization, the message is that biometric solutions now carry the undeniable premise of moving beyond the “mere adoption of a modern tool”: under the ANPD's scrutiny, mature and compliant corporate and public organizations can no longer treat biometrics and facial recognition as a simple legal or technological advance, approved in isolation and blindly, or kept in “files stored without review” in an improvised way. Biometrics are not a shortcut or a mere convenience, and those who adopt them must be able to answer, in a legally sound manner: is it necessary? And do their governance and records demonstrate, to themselves and to the authorities, the protection of data, so as neither to fail nor to exclude anyone, which is what the Authority and the LGPD always seek: ethical and innovative progress, but demonstrable progress.

Whenever biometrics or related systems are being introduced or considered for use in a project, whether internally with employees or externally, active governance in management or the DPO will always also have the task of being proactive with the tool's owners, requiring them to evidence, on paper and in the system, the premises the LGPD demands, and of asking the team, at the right time and in a systematic way, with demonstrable records in a central pillar, the basic, first and everyday question: is this truly, and fully in legal and regulatory terms, necessary for this purpose, is the processing proportionate, and, in the end, is it part of an active, structured flow or plan that we can document as a compliance mitigation model?

Structure your governance with DPO Privacy

Centralize process mapping, risk calculation, RoPA, DPIA, the Data Subject Portal and AI governance in a single platform.

Schedule a demonstration
BiometricsFacial RecognitionANPDLGPDSensitive DataGovernance
Share
R
Rafael Oliveira
DPO & Compliance Specialist
  1. Biometrics are not just another piece of data (and convenience is no excuse)
  2. The core of the analysis: necessity and proportionality
  3. The point many organizations overlook: there are always questions before deployment
  4. Facial recognition in stadiums and events: the debate has moved to the center of the agenda
  5. Age verification: a new regulatory front for biometrics
  6. The problem is not only collecting. It is governing the entire lifecycle
  7. Where privacy governance comes in, in practice, and why it cannot be solved “on paper” alone
  8. RoPA, DPIA and privacy by design: why have they never been mere formalities here?
  9. The role of software, the hidden protagonist: turning a sensitive topic into a continuous control process
  10. Conclusion

Discover the platform

Centralize all data and privacy governance in one place.

Schedule a demo

Related articles

Data Subject Rights
March 09, 202615 min

Data subject rights and practical governance: why handling a request well takes much more than a service channel

Data subject rights are no longer just a legal topic of the LGPD (Brazilian General Data Protection Law); they have become one of the most sensitive points of data protection governance. Learn why structure and process are essential for a consistent response.

M
Maria Fernanda Costa
Head of Governance and Privacy
Data Subject Rights
February 05, 20269 min

Data Subject Portal: How to Fulfill Data Subject Rights under the LGPD

The LGPD grants data subjects a series of rights over their personal data. Learn how to implement an efficient service portal that complies with the legislation.

R
Rafael Oliveira
DPO & Compliance Specialist

Structure your governance with DPO Privacy

Centralize process mapping, risk calculation, RoPA, DPIA, the Data Subject Portal and AI governance in a single platform.

Schedule a demonstrationExplore features
Back to publications
DPO Privacy

Privacy and personal data protection governance platform for managing compliance with the LGPD (Brazilian General Data Protection Law) and the GDPR.

Platform

  • Modules
  • AI governance
  • Data and Technology
  • Enterprise
  • Plans
  • Security

Company

  • About us
  • Contact

Resources

  • Content
  • Help Center
  • Frequently asked questions

Legal

  • Terms of Use
  • Privacy Policy
  • Cookie Policy

© 2026 DPO Privacy · All rights reserved · Made in Brazil

Developed bysyntez