About this service
A facial image, a fingerprint, a voice characteristic, an iris pattern — biometric data is the strongest means of identifying a person and at the same time one of the most sensitive categories of data. A leak of biometrics cannot be fixed by changing a password: biometrics accompanies a person for life. That is precisely why the Georgian law on personal data protection places biometric data in the special-category regime and subjects its processing to special conditions. This service helps organisations that use — or plan to use — biometrics, from access control to customer verification.
What biometric data is
Article 3 of the law gives a precise definition: biometric data is data processed by technical means, connected to the data subject's physical, physiological or behavioural characteristics, which gives the possibility of the subject's unique identification or confirmation of identity. Two elements are decisive here: technical processing and the possibility of unique identification. A photograph merely stored in an archive is not ordinarily biometric data; the same photograph used by an algorithm to recognise a person already falls under the biometric regime. Biometric data enters the list of special categories where the purpose is unique identification — a classification with immediate practical consequences.
When biometric processing is permitted
Article 9 of the law establishes the rule of permission. Biometric data may be processed only in defined cases: where it is necessary for the purposes of conducting activities, security, the protection of property and the prevention of disclosure of secret information, and where achieving these purposes by other means is impossible or requires disproportionately great effort — biometrics must thus be the last resort, not the first choice. Beyond that, processing is permitted for the purposes of issuing identity documents in the manner established by law, identifying a person crossing the state border, combating unlawful migration, preventing and investigating crime, operational-search activity and other defined purposes. The list is closed: using biometrics „because it is convenient“ is not a lawful basis.
Written determination before processing
The specificity of biometric data also lies in the law's demand for advance documentation: the controller is obliged, before processing, in conformity with the principles of processing, to determine in writing the purpose and scope of biometric processing, the retention period of such data, the procedure and conditions of their storage and destruction, and the mechanisms for protecting the data subject's rights. This requirement returns biometric projects to the level of planning: no camera or scanner can be lawfully switched on before this document exists. Moreover, because of the special-category regime, where consent serves as the basis it must be in written form — as Article 6 of the law defines.
Impact assessment
Biometric projects often mean large-scale monitoring — and this activates the impact assessment established by Article 31 of the law: it is mandatory where, taking into account new technologies, there is a high probability of a risk of violating rights, and in addition in cases of systematic and large-scale monitoring of subjects' behaviour. The assessment is fixed in a written document kept for the entire period of processing, and on cessation — for at least 1 year. Face-recognition systems almost always meet these criteria — which is why the assessment is an integral part of the project.
Real cases
Examples show the boundaries. An office door opened by fingerprint: the purpose is protection of activity and property, and lawfulness requires establishing that entry by card or code does not provide the same protection. Video verification of a client in a banking application: where the face is used to confirm identity, this is the biometric regime — with a written determination and an assessment. Shop cameras comparing passers-by against photos on identity documents: this is face recognition and demands strict assessment. In each case the explanation is the same: what is the purpose, what is the alternative, and where the boundary of biometrics begins.
How we can help
Our specialists determine whether your planned system falls under the biometric regime; assess which basis of permission fits it and whether a less intrusive alternative exists; prepare the written determination — purpose, scope, retention period, destruction procedure, mechanisms for the subject's rights; and where necessary conduct the impact assessment. The result is a project that works technically and stands legally. Contact us for a concrete assessment of your system.
Let us note one frequent error too: organisations believe that if biometrics is collected „only for time attendance“, the special regime does not apply. It does: the moment a fingerprint or a face is used for the unique identification of a specific person, the whole construction engages — the closed basis, the written determination, the assessment, the security measures. A system's designation does not release it from the regime; only refusing unique identification does. And a note on the horizon: recognition technologies develop fast, while data once collected stays in systems for long. A properly designed solution includes the exit — the retention period, the destruction procedure and the path of migration to other means.
