Boletines
2026-09-15
New General Standard for the Processing of Biometric Data
The Superintendency for the Protection of Personal Data (SPDP) issued the General Standard for the Processing of Biometric Data, applicable to public and private entities that use biometrics to uniquely identify or verify natural persons. The regulation covers, among others, facial recognition, fingerprints, iris, and voice. This data is considered sensitive, and its processing therefore requires enhanced safeguards.
Main obligations for companies
- Conduct a risk analysis and a Data Protection Impact Assessment (EIPD) before implementing a biometric system; the EIPD must be updated every twelve months or if the risk level changes.
- Justify that biometrics is strictly necessary and that no less invasive alternative exists to achieve the purpose.
- When processing is based on consent, offer an alternative non-biometric mechanism, unless technical or factual impossibility is duly evidenced in the EIPD.
- Apply privacy by design, data minimization, strict access controls, and enhanced security measures. The use of biometric templates should be prioritized over the storage of raw biometric data.
Key restrictions
The standard prohibits reusing biometric data for a purpose other than the one that justified its collection. It also prohibits mass and indiscriminate identification of persons in public spaces, unless expressly authorized by law.
Companies may not base decisions that produce legal effects or affect fundamental rights exclusively on automated biometric systems. Likewise, the identifying use of biometrics with respect to girls, boys, and adolescents is restricted and subject to enhanced conditions.
Recommended actions
Companies that use biometrics for access control, attendance, authentication, fraud prevention, or video surveillance should:
- Identify their biometric systems and data flows.
- Verify the legal basis and necessity of the processing.
- Prepare or update the EIPD and the risk analysis.
- Implement non-biometric alternatives where applicable.
- Review technical measures, access controls, and privacy notices.
- Compliance and effective date
Organizations that already use biometric systems must bring their processes and systems into compliance within twelve months of the standard's publication in the Official Registry. The publication date is not stated in the document analyzed, so it should be confirmed in order to calculate the exact deadline.
If you require advice on biometric data, please contact our Personal Data Protection team
This document does not constitute legal opinion; it is for general informational purposes only.
If you require specific advice, please contact us at the following addresses:
Share
Related News
Related Practice Areas
RELATED PROFESSIONALS


