The classic trap
Recital 39 reminds us of a frequently forgotten point: as soon as an AI system involves biometrics (facial recognition, voice print, behavioural analysis) outside the strict law enforcement context, GDPR Article 9 applies with its prohibition-by-default logic. Luxembourg's CNPD, like its European counterparts, has already issued prohibition decisions against facial recognition systems deployed by private actors (access control, marketing, retail analytics). The recurring mistake is to believe that the AI Act 'authorises' biometrics as long as it is not high-risk, whereas it actually defers to the stricter GDPR baseline.
The reading key: dual AI Act + GDPR Article 9 compliance
Recital 39 establishes a three-tier articulation that every organisation must master before any biometric deployment:
- Real-time law enforcement use in public spaces: governed by the AI Act (Article 5) with strict prohibitions and narrow exceptions reserved for authorities.
- Any other biometric use (employee access control, customer authentication, in-store video analytics, banking KYC): remains fully subject to GDPR Article 9(1) and its prohibition by default, except explicit consent or limited exception.
- Non-real-time law enforcement use: police-justice Directive 2016/680 Article 10, transposed in Luxembourg.
Concretely, a Luxembourg employer deploying a biometric clock-in system must demonstrate not only AI Act compliance (transparency, human oversight if high-risk) but above all justify a GDPR Article 9 legal basis, which almost systematically excludes employee consent (power imbalance) and requires a strict necessity analysis. The CNPD has already sanctioned several such systems.
How Luxgap automates this risk
Our Luxgap Biometric Gatekeeper makes silent deployment of non-compliant biometric processing impossible in your IS. The tool continuously scans your Microsoft Entra ID, Azure AI Services, AWS Rekognition, Kaba/Zucchetti time clocks, marketing CRMs (Salesforce Einstein, HubSpot) and video surveillance platforms (Milestone, Genetec) to detect any active biometric function, even dormant in a cloud licence.
- Automatically detects every biometric API called (Face API, Voice ID, fingerprint matching) and identifies the business owner who activated it.
- Classifies the use according to the AI Act + GDPR Article 9 grid: law enforcement, access control, marketing, authentication, and determines the applicable legal regime.
- Automatically generates the pre-filled biometric DPIA with necessity-proportionality test and documented non-biometric alternatives.
- Verifies the existence of a valid Article 9 legal basis and alerts if employee consent is invoked in a subordination context.
- Produces a time-stamped compliance file, enforceable before the CNPD, demonstrating dual AI Act and GDPR compliance for each active biometric processing.
- Alerts in real time (Teams, Slack) as soon as a new biometric system is activated in your cloud tenant without prior DPO validation.
Available as a complement to a Luxgap DPO mandate or as a dedicated SaaS module depending on your scope. Request your demonstration and our teams will run a free scan within 48h to map the biometric processing active in your IS, before any engagement.