The classic trap
Recital 38 locks down a frequently misunderstood point: real-time remote biometric identification in publicly accessible spaces for law enforcement purposes falls exclusively under the AI Act, which applies as lex specialis over Article 10 of Directive 2016/680. In practice, a competent authority deploying such a system outside the framework of AI Act Article 5 cannot fall back on the Law Enforcement Directive to justify it. Conversely, the same systems used for non-law-enforcement purposes (private security, marketing, access control) escape the specific AI Act authorisation regime but remain fully subject to GDPR and CNPD supervision.
The dual classification you must master before any biometric deployment
Before considering a remote biometric identification system, the purpose must be qualified with absolute rigour, because the applicable regime changes radically:
- Law enforcement purpose (prevention, detection, investigation of criminal offences by a competent authority): in-principle prohibition under AI Act Article 5, save for exhaustively listed exceptions (search for victims, imminent terrorist threat, suspect of serious offence) with prior judicial or independent administrative authorisation.
- Non-law-enforcement purpose (site security, access control, commercial fraud prevention, even by a competent authority acting outside its law enforcement mission): no AI Act authorisation regime, but Article 6 + Annex III high-risk regime, plus GDPR Article 9 (biometric data = special category) under CNPD supervision.
- Classic trap: a municipal police force or customs service using facial recognition for access control to its own premises is not acting for law enforcement purposes; AI Act Article 5 does not apply, but GDPR does.
- Reverse trap: a private operator (security, transport) running a system whose outputs are routed to a law enforcement authority falls de facto into the Article 5 regime, even if the formal deployer is private.
- Recital 38 clarifies that the AI Act does not create a legal basis within the meaning of Article 8 of Directive 2016/680: the national legal basis remains indispensable, the AI Act only frames it.
How Luxgap automates this risk
Our Luxgap Biometric Use Classifier eliminates the qualification ambiguity that brings down most early biometric projects: it analyses your real use case (documented purpose, deployer identity, recipients of outputs, public or private space context) and produces in under 5 minutes a clear verdict between AI Act Article 5 law enforcement regime, Annex III high-risk regime, or out-of-AI-Act-scope but under GDPR Article 9. The tool relies on a specialised LLM agent trained on the AI Act, Directive 2016/680, EDPB facial recognition guidelines and CNPD doctrine.
- Automatically classifies each biometric use case along a 4-dimension matrix (purpose, deployer, space, real-time or deferred) and returns the applicable legal regime with citation of AI Act and GDPR articles.
- Detects hidden re-qualifications where a private use shifts to law enforcement as soon as a transmission protocol to police forces exists, by analysing your contracts and partnership agreements loaded in Odoo, M365 or SharePoint.
- Generates the prior authorisation file required by AI Act Article 5(3), pre-filled with proportionality analysis, discarded less intrusive alternatives and technical safeguards.
- Produces in parallel the GDPR Article 35 DPIA and the AI Act Article 27 fundamental rights impact assessment, avoiding duplicate work.
- Sends real-time alerts via Teams or email as soon as a regulatory development (EU AI Office text, CNPD decision, CJEU case law on Schrems or biometrics) impacts the qualification of your active systems.
- Produces a timestamped, cryptographically sealed PDF report, enforceable before the CNPD or AI supervisory authority during an inspection.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a demonstration on your real use case, with a free 48-hour white audit to legally qualify your biometric project before any budget commitment.