Understand biometric and facial-recognition risks, LGPD requirements and legal, technical and operational practices for responsible implementation.

Check it out!

What Are Biometrics and Facial Recognition?

Biometrics is the technical analysis of a person’s physical or behavioral characteristics for identification, verification, or authentication purposes. Common examples include fingerprints, face, iris, voice, hand geometry, signature, gait, and behavioral patterns.

Facial recognition is a specific biometric application based on facial analysis. It generally involves capturing an image, detecting the face, extracting facial characteristics, generating a biometric template, and comparing that template with a reference or enrolled database.

It is important to distinguish four functions that are often treated as if they were the same:

  • Detection: locating a face in an image or video.
  • Verification: confirming that a person is who they claim to be, usually in a 1:1 relationship.
  • Identification: determining who the person is by comparing the face against a larger database, usually in a 1:N relationship.
  • Classification: inferring attributes or categories such as age range, apparent gender, emotion, or other signals derived from the image.

The distinction is decisive for risk assessment. A system used to grant an already enrolled person access to a restricted area tends to involve different risks from a system that identifies people in real time in public or semi-open spaces. The first case may involve controlled authentication; the second may involve systematic monitoring, large-scale processing, information asymmetry, and effects on individual freedoms.

Why Do Biometric Data Require Greater Care Under the LGPD?

The Brazilian General Data Protection Law defines sensitive personal data as personal data concerning racial or ethnic origin, religious conviction, political opinion, trade-union membership, health or sex life, genetic data, or biometric data when linked to a natural person. Therefore, when a fingerprint, facial image, or biometric template can be associated with a person, processing enters a higher-requirement category.

In practice, this means the organization must demonstrate not only that the technology works, but also that processing is legitimate, necessary, proportionate, secure, and transparent. LGPD principles should guide the entire data life cycle: collection, enrollment, storage, consultation, comparison, sharing, retention, deletion, and auditing.

Legal Bases: Saying It Is “For Security” Is Not Enough

For sensitive data, Article 11 of the LGPD provides specific processing hypotheses. Biometric projects commonly involve discussions about specific and highlighted consent, compliance with legal or regulatory obligations, execution of public policies, regular exercise of rights, protection of life, health protection, and fraud prevention and data-subject security in identification and authentication processes within electronic systems.

The legal basis must be selected case by case. “Security” should not be used as a generic justification for any biometric collection. The organization must explain which risk it intends to reduce, why biometrics are appropriate for that objective, whether a less intrusive alternative exists, and how data-subject rights will be preserved.

Consent Is Not Always the Best Answer

When applicable, consent must be freely given, informed, unambiguous, specific, and highlighted. In environments with power asymmetry — for example employment relationships, schools, essential-service provision, or access to buildings where no real alternative exists — consent may be questionable. If the person has no practical choice, the expression of will may not be considered genuinely free.

Therefore, before adopting biometrics as a mandatory standard, the organization should assess whether there is a non-biometric alternative, such as a card, credential, QR code, PIN, physical document, operator validation, or another method proportionate to the risk.

Main Risks of Facial Recognition

1. Undisclosed Collection and Low Transparency

One of the most common risks is collecting an image or template without clear notice to the data subject. This may occur in environments with visible cameras but without adequate notice that facial recognition or biometric analysis is in use. Transparency requires informing the purpose, controller, form of processing, legal basis, retention period, sharing arrangements, data-subject rights, and contact channel.

2. Secondary Use and Purpose Deviation

Data collected for one purpose should not be reused for another incompatible purpose. For example, a company collects facial biometrics for access control and later uses the same database for disciplinary control, marketing, behavioral monitoring, or sharing with third parties without a new compliance assessment. This type of expansion may violate the principles of purpose, adequacy, and necessity.

3. False Positives, False Negatives, and Identification Errors

Biometric systems are not infallible. Accuracy may vary according to lighting, face angle, camera resolution, occlusions, aging, enrollment quality, training-dataset diversity, and algorithm configuration. In sensitive contexts, a false positive may cause embarrassment, improper blocking, unjustified intervention, or material and reputational harm. A false negative may prevent legitimate access, delay service, or compromise operations.

4. Algorithmic Bias and Discrimination

Facial-recognition models may perform unevenly across population groups. If the training data are unbalanced or the system is not tested under actual operating conditions, discriminatory effects related to race, ethnicity, gender, age, physical characteristics, or social context may arise. The LGPD prohibits processing for unlawful or abusive discriminatory purposes, and organizations should test and monitor this risk.

5. Improper Inferences

Facial images may reveal more than identity. Depending on the technology, they may enable inferences about health, emotions, apparent age, behavior, presence in certain locations, habits, and relationships. When such uses are unnecessary for the original purpose, they increase the risk of excessive processing and violation of legitimate privacy expectations.

6. Leakage of Biometric Templates

A password leak is serious, but the password can be changed. Biometrics generally stay with a person for life. Exposure of a biometric-template database may create persistent risks of fraud, identity theft, social engineering, and reputational harm. Biometric databases should therefore receive enhanced protection, including encryption, environment segregation, access control, logging, limited retention, and incident response.

7. Normalization of Surveillance

Indiscriminate use of smart cameras and facial recognition may alter privacy expectations in everyday environments. Even when the stated objective is legitimate, implementation without governance may create a sense of permanent monitoring and reduce data-subject trust.

Legal Best Practices Before Implementing Biometrics

Assess Necessity and Proportionality

The central question should be: are biometrics really necessary to achieve the intended purpose? If a less intrusive mechanism solves the problem with an adequate security level, it should be considered. Technology should not be adopted solely for operational convenience or commercial appeal.

Define a Specific and Documented Purpose

Avoid broad purposes such as “site security.” Prefer specific descriptions, such as “authenticate authorized employees for access to the telecommunications room” or “validate the identity of an enrolled user in an electronic-authentication process.” The more precise the purpose, the easier it is to demonstrate necessity, adequacy, and limitation of processing.

Map Processing Agents and Data Flows

Every project should identify the controller, processor, vendors, subprocessors, storage locations, integrations, video systems, servers, cloud services, enrollment databases, logs, reports, and any sharing. Without this mapping, there is no effective governance.

Prepare a DPIA/RIPD When Risk Is High

A Personal Data Protection Impact Report is especially advisable when sensitive data processing, systematic monitoring, large-scale processing, artificial intelligence, children and adolescents, public security, critical access control, or sharing with multiple parties are involved. The RIPD should describe the processing, assess risks, and record safeguards.

Update Privacy Notices and Physical Signage

Environments using biometrics or facial recognition should provide clear communication. Physical and digital notices should explain the purpose of processing and direct the data subject to a complete privacy policy. Transparency should not depend on difficult legal language or hidden information.

Provide a Non-Biometric Alternative When Possible

A non-biometric alternative may reduce regulatory risk and increase trust. This is especially relevant for visitors, service providers, condominiums, occasional users, or data subjects in vulnerable positions.

Technical and Operational Best Practices

Data Minimization

Collect only what is necessary. If the objective is authentication, assess whether storing the raw image is necessary or whether a protected template is sufficient. Avoid enrolling attributes that are not essential.

Privacy by Design and by Default

Privacy should be built into the system from the design phase. This includes architecture, vendor selection, camera configuration, retention policy, database segregation, access permissions, logging, disposal, and team training. The default should be the minimum necessary processing, not the maximum possible collection.

Encryption, Pseudonymization, and Segregation

Biometric templates and associated databases should be protected with encryption at rest and in transit. Whenever possible, use pseudonymization, separation between identifiers and templates, tightly controlled key management, and segregated production, testing, and backup environments.

Access Control and Multifactor Authentication

Administrative access to biometric systems should follow the principle of least privilege. Profiles should be periodically reviewed, generic accounts should be avoided, and critical access should use multifactor authentication.

Logs, Auditing, and Traceability

It is necessary to record who accessed the database, when, for what purpose, which operation was performed, which data were exported, and whether enrollment records were changed. Logs should be protected against improper alteration and periodically reviewed.

Retention and Secure Disposal

Biometric data should not be retained indefinitely. The organization should define a retention period compatible with the purpose and delete data when the relationship ends or the purpose no longer exists, except where an applicable legal obligation requires otherwise.

Accuracy Testing and Human Review

Before implementation, the system should be tested under actual lighting, flow, angle, distance, user-diversity, and operating conditions. For decisions with significant impact, human review and a contestation procedure are recommended.

Vendor Management

Contracts with access-control, VMS, camera, analytics, cloud, or support vendors should address LGPD roles, confidentiality, security measures, subcontracting, data location, audit rights, retention period, deletion at termination, incident notification, and support for exercising data-subject rights.

Incident Response Plan

The organization should be prepared to detect, contain, investigate, document, and communicate incidents. The official ANPD page on Security Incident Notification states that confirmed incidents involving personal data subject to the LGPD and capable of causing relevant risk or harm must be communicated to the ANPD and the affected data subjects. Resolution CD/ANPD No. 15/2024 established a three-business-day notification period for such cases, except where specific sector legislation establishes another period.

Practical Checklist for Assessing a Biometric Project

QuestionWhy it matters
Is the purpose clear and documented?Prevents purpose deviation and facilitates accountability.
Is there an appropriate legal basis for sensitive data?Reduces legal risk and guides controller obligations.
Is there a less intrusive alternative?Supports necessity and proportionality.
Was the data subject clearly informed?Supports transparency and free access.
Does the system store raw images or templates?Defines the risk level and required controls.
Are encryption and access control in place?Protects sensitive data against unauthorized access.
Does the vendor contract include LGPD and security clauses?Defines responsibilities and reduces third-party risk.
Is there a retention period?Prevents excessive retention and reduces exposure.
Are logging and auditing available?Enables traceability and incident investigation.
Is there an incident response plan?Reduces impact and supports compliance with Article 48 of the LGPD.

Common Mistakes When Using Facial Recognition

  1. Implementing technology before defining purpose, scope, and legal basis.
  2. Treating consent as a universal solution.
  3. Collecting raw images when a protected template would be sufficient.
  4. Using the same database for new purposes without reassessment.
  5. Failing to test accuracy under actual operating conditions.
  6. Ignoring false positives, false negatives, and algorithmic bias.
  7. Failing to offer an alternative or a contestation channel.
  8. Failing to inform data subjects clearly and accessibly.
  9. Failing to audit vendors, integrations, and subprocessors.
  10. Having no incident response plan for biometric data.

Relationship with Electronic Security, Access Control, and Computer Vision

Biometric projects rarely exist in isolation. They are generally connected to access-control systems, CCTV, VMS, IP networks, servers, cloud services, enrollment stations, turnstiles, electromagnetic locks, and integrations with corporate databases. Compliance therefore depends on both legal analysis and technical design.

In corporate, industrial, and institutional environments, biometrics should be treated as part of a broader electronic-security architecture. To deepen the technical foundation, also see A3A articles on electronic-security design, biometric access, access-control types, and computer vision.

Conclusion

Biometrics and facial recognition can support security, efficiency, and convenience, but they should not be treated as simple software or camera features. They are technologies that handle permanent characteristics of people and therefore require robust governance.

Responsible use begins before purchasing the solution: it requires defining the purpose, assessing necessity, selecting the legal basis, conducting impact assessment, designing a secure architecture, managing vendors, ensuring transparency for data subjects, and continuously monitoring the system. When these elements are neglected, technology intended to reduce risk can create new legal, technical, and reputational liabilities.

Need to assess a biometric, facial-recognition, access-control, or video-surveillance project under the LGPD? A3A Engenharia can support technical analysis, system specification, electronic-security governance, and good practices for responsible implementation.

Sources and References Consulted

This content is technical and informational and does not replace legal advice specific to a particular case.