Is face recognition legal for event photography under GDPR?

Facial recognition creates biometric data, which Article 9 of the GDPR treats as a special category and prohibits processing by default. For event photography the workable basis is usually explicit consent under Article 9(2)(a). Ordinary photographs are not biometric data; it is the recognition step that changes the legal position.

This is a summary for photographers, not legal advice. Take advice for your own jurisdiction and use case.

The distinction that matters

A photograph of a person is personal data, processed under one of the Article 6 bases. Running facial recognition over it produces biometric data for the purpose of uniquely identifying a natural person, which falls under Article 9 and is prohibited unless a specific exception applies. Recital 51 states plainly that photographs only become biometric data when processed through specific technical means allowing identification.

What that means in practice

  • Explicit consent from the people being identified is the usual route, and it must be freely given, specific and revocable.
  • Minors need particular care. Consent for a child is given by whoever holds parental responsibility, and youth sport is exactly where this bites.
  • Recognition must be switchable. If someone withdraws consent you have to be able to stop processing them and remove what you derived.

In SnapFlow

Recognition is opt-in per account and gated per plan, consent state is recorded, and withdrawing it stops further processing for that person. See our privacy policy for how the data is stored and for how long.

Sources

Related