The classic trap
Recital 14 locks in semantic coherence between the AI Act and the GDPR: the notion of biometric data must be interpreted identically across both texts. In practice, many organisations deploying facial recognition, biometric access control or emotion detection assume they are outside the AI Act scope because they already completed a GDPR DPIA. That is wrong: a single processing operation now triggers dual compliance (CNPD for the personal data dimension, AI Office and the future AI market surveillance authority for the AI system dimension), with obligations that stack rather than substitute.
The three biometric purposes recital 14 forces you to distinguish
The legislator explicitly names three uses, which do not carry the same risks or prohibitions under the AI Act:
- Authentication (1:1 verification, e.g. fingerprint unlock): generally acceptable, but still sensitive data under Article 9 GDPR.
- Identification (1:N, e.g. facial recognition in a crowd): largely prohibited in real time in public spaces under Article 5 AI Act, with narrow exceptions.
- Categorisation and emotion recognition: prohibited in the workplace and in education (Article 5 AI Act), even with consent.
The classic trap: labelling a system as simple authentication when it actually performs categorisation (gender, estimated age, emotional state), which pushes it into prohibited territory. Qualification must be documented purpose by purpose, not globally.
How Luxgap automates this risk
Our Luxgap Biometric Use Classifier eliminates qualification ambiguity by technically analysing your biometric systems to produce, for each use case, a qualification opposable to the CNPD and the AI Office. The tool connects to your reference systems (Active Directory for access controls, Microsoft Defender for Windows Hello endpoints, Intune or Jamf MDM for mobile devices, IP camera APIs, Teams or Zoom platforms with emotion detection enabled) and reconstructs the real biometric flow, rather than relying on vendor declarations.
- Automatically detects every active biometric processing in your IT estate by cross-referencing application inventory, authentication logs and MDM configurations.
- Classifies each use case against the three-purpose grid from recital 14 (authentication, identification, categorisation or emotions) and maps it to the relevant AI Act article.
- Alerts in real time when a system shifts from authentication to categorisation following a vendor update (e.g. discreet activation of age detection in an access control camera).
- Generates the Article 35 GDPR DPIA and the Article 27 AI Act impact assessment in a single coherent document, citing the shared definitions from GDPR Article 4(14) and AI Act recital 14.
- Produces a time-stamped biometric register, opposable during a CNPD inspection or a request from the AI market surveillance authority.
Available as part of a Luxgap DPO or CISO mandate or as a standalone SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual biometric systems, with a free 48-hour blank audit to map your processing operations and identify AI Act prohibition zones before any engagement.