On 26 February 2026 the Italian Data Protection Authority (Garante) fined an employer that recorded attendance by means of its employees’ fingerprints, reiterating that “the legal framework in force does not permit the processing of employees’ biometric data for the purpose of recording attendance at work” (Garante). It is the same principle affirmed in February 2024 with a fine of EUR 70,000 imposed on a company that used facial recognition for the same purpose (Garante). Two years on, the answer is identical, and the reason the Authority holds to this line lies not only in the rules on consent or on the legal basis, but in the nature of the data.
What biometric data is, and what sets it apart
Regulation (EU) 2024/1689 defines biometric data as personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, such as facial images or dactyloscopic data. Alongside this definition, Article 3 draws a precise distinction between biometric identification, that is, the automated recognition that compares a person’s data with data stored in a database, and biometric verification, which is the one-to-one comparison carried out to confirm that a person is who they claim to be, and then goes on to define emotion recognition systems, biometric categorisation systems and remote identification systems, both real-time and post (European Commission). Regulation (EU) 2016/679, for its part, places biometric data processed for the purpose of uniquely identifying a person among the special categories of data, the processing of which is prohibited save for the exceptions set out in Article 9.
The distinction between identification and verification is not a formal matter: it is the line along which almost the entire body of rules runs. Confirming that the person unlocking a telephone is its owner does not raise the same problems as recognising a face in a crowd, and European law treats the two cases differently.
What all these operations have in common is a characteristic that no security measure removes: biometric data cannot be replaced. A compromised password can be changed, a key can be revoked, a card number can be reissued. A fingerprint, the structure of an iris, the geometry of a face remain the same for a lifetime. The legal consequence is that, in the event of a breach, there is no remedial measure that restores the data subject to the previous position. The only genuinely effective protection is the protection that operates beforehand.
The prohibitions in Article 5: four cases, in force since 2 February 2025
The AI Act prohibits four uses concerning biometrics, and it has prohibited them since 2 February 2025, the date of application of Chapters I and II, well before the general date of 2 August 2026 that is commonly cited.
Under point (e), the use of AI systems “that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage” is prohibited. Under point (f), the use of AI systems “to infer emotions of a natural person in the areas of workplace and education institutions” is prohibited, with the sole exception of medical or safety reasons. Under point (g), biometric categorisation that classifies persons “to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation” is prohibited. Under point (h), real-time remote biometric identification in publicly accessible spaces for the purposes of law enforcement is prohibited, save for three exhaustively listed cases and subject to the safeguards of paragraphs 2 and 3, among them the prior authorisation of a judicial authority or an independent administrative authority and the rule that “no decision that produces an adverse legal effect on a person may be taken based solely on the output of the system” (European Commission).
Two readings that recur frequently need to be corrected. Emotion recognition is not prohibited outright: it is prohibited in the workplace and in education institutions, whereas elsewhere it falls among the high-risk systems. And not every form of remote biometric identification is prohibited, but only real-time identification, in publicly accessible spaces, for the purposes of law enforcement. It should be added that the Digital Omnibus, Regulation (EU) 2026/1744, has not touched the biometric prohibitions: it added two new points concerning non-consensual synthetic sexual content and child sexual abuse material, applicable from 2 December 2026.
What remains high-risk: Annex III, point 1
What is not prohibited is not, for that reason alone, unrestricted. Annex III, at point 1, classifies as high-risk, in so far as their use is permitted under the law, remote biometric identification systems, biometric categorisation systems based on sensitive or protected attributes or characteristics, and emotion recognition systems. Expressly left outside is biometric verification “the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be”.
The architecture, therefore, has three tiers: prohibited in the exhaustively listed cases, high-risk for the rest, unrestricted only for one-to-one verification. The obligations of Chapter III for the systems in Annex III will, however, apply from 2 December 2027, according to the timetable redrawn by the Digital Omnibus, whereas the prohibitions, as noted, already operate.
The workplace: a consistent line from the Garante, and a law that is silent
In the workplace the Italian framework is clearer than is generally believed, and it does not depend on the AI Act. The Garante proceeds from its general prescriptive decision on biometrics of 12 November 2014, still cited in its decisions (Garante), and from Article 2-septies of the Personal Data Protection Code (Legislative Decree No 196 of 30 June 2003), to conclude that there is no provision permitting the use of biometric data for attendance monitoring. The worker’s consent does not fill the gap, owing to the well-known asymmetry of the relationship.
Here a point must be flagged that we consider decisive for those working in compliance: Law No 132 of 23 September 2025 does not contain a single provision on biometrics. In its twenty-eight articles the words “biometric”, “facial”, “video surveillance” or “fingerprints” do not appear. Numerous commentaries circulated in 2026 attribute to it rules on real-time biometric identification and on judicial authorisation: those provisions belong to Legislative Decree No 160 of 9 September 2026, published in the Official Gazette (Gazzetta Ufficiale) of 15 September and in force from the 30th (Gazzetta Ufficiale), and they concern police activities, not employment. The decree builds the authorisation of real-time remote biometric identification on two tracks, the public prosecutor outside criminal proceedings, under Article 8, and the judge for preliminary investigations within them, under the new Article 359-ter of the Code of Criminal Procedure; it prohibits populating databases by means of “untargeted scraping”; it requires that the reference database be compiled for each use and deleted on expiry; and, in Article 10, paragraph 11, it rules out the use of post facial recognition “for the purposes of generalised or indiscriminate monitoring and biometric identification of persons”. On the employment relationship, by contrast, the law and the decree are both silent. The only occasion on which the law mentions dignity is Article 11, paragraph 2, precisely in relation to work, where it provides that the use of artificial intelligence “may not take place in a manner contrary to human dignity or in breach of the confidentiality of personal data”: on the overall design of that text we have written in our commentary on the Italian implementation of the AI Act.
Airports and Opinion 11/2024: the storage of the biometric template
The most instructive case of recent years concerns not employment but transport. In May 2024 the European Data Protection Board adopted an opinion on the use of facial recognition to streamline the flow of passengers, distinguishing four scenarios according to who stores the biometric data and where (EDPB). The conclusion is that only those solutions in which the biometric template, or the key needed to use it, remains under the exclusive control of the passenger can be regarded as compatible with the principle of data minimisation, whereas centralised storage under the control of the operator exposes the entire data set if the confidentiality of the repository is compromised, and significantly reduces the passenger’s control over their own data.
On that basis, in September 2025 the Italian Data Protection Authority (Garante) ordered the provisional limitation of a biometric boarding system in operation at a Milan airport, which by the end of July had already involved more than 24,000 data subjects (Garante). The defect challenged was not the purpose, which is legitimate, but the architecture: the centralised storage of the biometric template.
For law enforcement, the reference remains the Board’s Guidelines 05/2022, adopted in their final version on 26 April 2023, which state that the processing of biometric data “constitutes a serious interference in itself” and that “this does not depend on the outcome”, and that the strict necessity required by Article 10 of Directive 2016/680 excludes “any processing of a general or systematic nature” (EDPB).
Irreversibility put to the test: two documented breaches
That irreversibility is not a theoretical argument is shown by two incidents documented by public oversight bodies. In 2015 the breach of the systems of the United States Office of Personnel Management resulted in the theft of the fingerprints of approximately 5.6 million people, as part of an incident that affected the personal data of 22.1 million individuals (Government Accountability Office). In 2019 a subcontractor of the United States customs authority transferred to its own network, without authorisation, the biometric data collected in a facial recognition pilot project, and that network was breached: approximately 184,000 images of travellers were compromised. The Inspector General of the Department of Homeland Security observes in its report that the incident may damage the public’s trust in the government’s ability to safeguard biometric data (DHS Office of Inspector General).
To be kept distinct from these two incidents is the case of the mass collection of facial images from the web, which is not a breach but an upstream unlawful act, fined by the Italian Data Protection Authority (Garante) in February 2022 with EUR 20 million (Garante) and by the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) in September 2024 with EUR 30.5 million. It is precisely the practice that Article 5, point (e), of the AI Act subsequently prohibited.
Critical aspects: what is lost with the data
The rules we have examined protect biometric data as data, through the categories of lawfulness, minimisation and security. We consider that this framework captures only part of the problem, and that the part left uncovered is the one hardest to translate into an obligation.
When biometric data is stolen, the data subject does not lose a piece of information about themselves: they lose the possibility of separating themselves from it. Their physical characteristics remain usable by third parties, without their knowledge and without any time limit, and no revocation can restore the previous situation. It is in this sense that the subject touches on dignity, and not merely on privacy: it concerns the person’s capacity to remain in control of their own identifiability. If this reading is accepted, a practical consequence follows, which is the reason why architecture matters more than purpose. The choice between storing the template on the data subject’s device and storing it in a central repository is not a technical preference but the decision that determines whether a future incident will be remediable or definitive, and it is the same reason why Article 25 of Regulation (EU) 2016/679 places protection “by design” before every other measure.
It should be said, finally, that the regulatory trend does not all run in one direction. In February 2026 the European Data Protection Board and the European Data Protection Supervisor recalled, in a joint opinion on the simplification package, that biometric data enjoys particular protection on account of the heightened risks to the rights of data subjects, and that even technically less intrusive solutions may entail high risks when processing takes place on a large scale (EDPB). It is a reminder worth bearing in mind while simplification is under discussion.
Conclusions
European law treats biometrics on three levels, prohibition, high risk and one-to-one verification, and the Italian Data Protection Authority (Garante) maintains, in the field of employment, a line that depends not on the AI Act but on Article 9 of Regulation (EU) 2016/679 and Article 2-septies of the Code. Law 132/2025, contrary to what one reads, adds nothing on this ground, and Legislative Decree 160/2026, which exercised the delegated power conferred by it, regulates biometrics only in police activities. For those designing a system, the operational question is not whether the processing is permitted, but where the biometric template is stored and who controls it: it is the only choice that, in the event of a breach, distinguishes an incident from harm that cannot be repaired.
Author: Valentina Grazia Sapuppo








