FB pixel

Italian data protection authority introduces new privacy rules on biometric data

 

Italian data protection authority, the Garante, recently issued a new set of privacy rules designed for facilitating the processing of biometric data, according to a report by Gaming Tech Law.

With the Internet of Things technologies and specifically biometric wearables significantly relying on the processing of biometric data, the Garante has introduced the new rules to aid companies in developing these technologies.

First, the provision to the data subject of a privacy information notice must now list key information, including all the information prescribed by Italian law, whether there are alternative technologies available to collecting biometric data, and specific instructions on how to use the device, along with any signs or warnings where biometric data is being collected to access specific areas.

The data protection authority (DPA) must be notified prior to the data processing with the exception of cases where the processing is being performed by medical practitioners.

There must be strict security measures in place for deleting the raw data collected during the biometric capture, using encryption technologies for their storage and transfer and using mobile device auditing technologies.

Data can be stored for no longer than the required term which varies based on the type of processed biometric data.

In the event of a data breach, the DPA must be notified via email within 24 hours of its occurrence.

The DPA must approve in advance the detailed application measures to be implemented in the data processing.

Prior consent from the individuals must also be given, except in specific scenarios where the Italian DPA has identified the processing of biometric data to face a lower risk and therefore does not require prior consent.

These cases include the biometric fingerprint or issue voice of a person to access databases and information systems, accessing sensitive areas or using dangerous machines where the data processing can also likely occur without the individual’s consent, confirming the content of electronic documents through advanced electronic signature, and scanning fingerprints and the topography of the palm of the hand to gain access to either public or private areas.

Article Topics

 |   |   | 

Latest Biometrics News

 

Yoti challenges academic research, invites independent audit of age assurance platform

Yoti has publicly challenged research presented by academics from the Georgia Institute of Technology and the University of California, Irvine,…

 

US probe puts prediction market identity controls under the spotlight

The U.S. House Committee on Oversight and Government Reform has opened an inquiry into Polymarket and Kalshi, pressing the two…

 

Age assurance landscape diverging between US, everywhere else

In the EU and UK, the debate over age assurance for social media has reached the highest levels of government,…

 

2026 World Cup to test online betting age verification at scale

Jumio research suggests the 2026 World Cup could drive a surge in online sports betting while increasing concerns about minors…

 

ID4Africa’s Joseph Atick on why Africa is setting the pace for digital identity

At the ID4Africa 2026 AGM in Abidjan, digital identity leaders focused on a common theme: building sustainable digital identity ecosystems…

 

UK selects Cognitec for facial age estimation in asylum assessments

The UK government has selected a vendor for facial age estimation. The £322,000 ($433,745) contract begins on June 1, 2026…

Comments

27 Replies to “Italian data protection authority introduces new privacy rules on biometric data”

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events