
Escrito por:
Executive Summary
Resolution No. SPDP-SPD-2026-0039-R issued by the Superintendency of Personal Data Protection (hereinafter, the “SPDP”), published in Official Gazette (Registro Oficial) No. 376 of September 24, 2026, issues the General Standard for the Processing of Biometric Data.
Purpose of the regulations
The regulations govern the conditions, safeguards, and limits applicable to the processing of biometric data in order to effectively protect data subjects’ rights, developing the principles of the Organic Law on Personal Data Protection (hereinafter, the “LOPDP”) while taking into account two characteristics of this data: 1) it enables a person to be uniquely identified; and 2) its processing entails risks to data subjects’ privacy. The LOPDP already defines biometric data as sensitive data, including, for example, facial images and fingerprint data.
Scope
- To whom it applies: controllers and processors, public and private, that process biometric data to identify individuals within the territorial scope of the LOPDP.
- Processing covered: automated and partially automated processing, as well as non-automated processing when the data form part of structured systems or databases.
- Nature: compliance is mandatory, without prejudice to other sector-specific regulations concerning biometric technologies.
- Differentiated regime: if the processing neither seeks nor produces the unique identification of individuals, the LOPDP, its General Regulations, and the general secondary regulations apply, together with the applicable security measures.
Key obligations
- Prior risk analysis and data protection impact assessment (DPIA): all biometric processing must be preceded by a risk analysis and a data protection impact assessment that justify the use of biometrics. A DPIA is mandatory before implementing any biometric system. It must be reviewed every 12 months and whenever the level of risk changes.
- Presumption of high risk: processing that uniquely identifies individuals is deemed high risk. Processing that systematically evaluates personal aspects to make automated decisions and processing that monitors public-access areas on a large scale are also deemed high risk.
- Lawful basis: processing is lawful only if a valid basis exists under the LOPDP’s sensitive-data regime.
- Enhanced consent and non-biometric alternative: if consent is the basis, it must be prior, freely given, specific, informed, unequivocal, and explicit. At least one equivalent alternative that does not use biometrics must also be offered. The data subject may withdraw consent at any time, and the withdrawal must take effect promptly.
- Significant power imbalance: an imbalance exists when there is legal subordination or direct economic dependence. It also exists when access to rights, essential services, or material benefits is conditioned on biometric processing, or when the data subject has no genuine alternatives. In such cases, as a general rule, a non-biometric alternative must be offered.
- Purpose limitation: biometric data may not be reused for a purpose different from the original purpose. A new purpose requires new consent or compliance with the LOPDP’s sensitive-data requirements.
- Necessity and proportionality: before implementing the system, it must be assessed whether less intrusive means are available. Biometrics are admissible only if strictly necessary.
- Privacy by design and enhanced security: systems must incorporate data minimization, strictly limited access, enhanced security, and architectures that reduce risks. Security measures must align with the SPDP’s Risk Management and Impact Assessment Guide. The use of biometric templates should be preferred, and the storage of raw data should be avoided except where strictly technically necessary.
- Transparency: the data subject must receive clear and accessible information, without technical barriers, communicated by a verifiable means.
- Automated decisions: decisions producing legal effects may not be based solely on automated biometric identification. A merely formal human intervention is not sufficient either. The data subject may request a reasoned explanation of the decision.
Specific limitations
- Facial recognition: compliance with Article 26 of the LOPDP (exceptions to the prohibition on processing sensitive data), preparation of a DPIA, and application of enhanced measures throughout the data life cycle are required. The analysis must be updated when the technology changes. The use of facial recognition does not, by itself, make the processing large-scale.
- Public spaces: mass and indiscriminate identification is prohibited unless a provision having the force of law expressly authorizes it. The definition of public space includes private places open to the public, such as shopping malls and stadiums.
- Children and adolescents: processing for identification purposes is prohibited unless no less intrusive means exist and a risk analysis and DPIA have been completed. The explicit consent of the legal representative is required, or the processing must serve to safeguard the data subject’s life. Adolescents aged 15 to 17 may consent on their own behalf if the information is adapted to their age. Their legal representative may request withdrawal for substantiated reasons.
Exceptions and special regimes
- Technical or factual impossibility: the non-biometric alternative may be dispensed with only if the impossibility is substantiated in the DPIA. For example, where no alternatives with equivalent security exist or where available alternatives are insufficient to address fraud and impersonation.
- Legal mandate: the alternative is also not required where an obligation arises from a provision having the force of law or from a competent authority.
- Fraud prevention and money laundering: using biometrics to authenticate transactions subject to enhanced due diligence is not considered a significant power imbalance.
- Non-identifying processing: if it is technically demonstrated that there is no unique identification or verification, the LOPDP’s general lawful bases may be used.
Time limits
- Effective date: the regulations take effect upon publication in the Official Gazette (Registro Oficial), that is, as of September 24, 2026.
- Existing systems: entities already using biometric systems have 12 months from publication to bring themselves into compliance, that is, until September 24, 2027.
- DPIA: it must be reviewed every 12 months and whenever the level of risk changes.
Practical implications for companies
- Inventory: identify all biometric systems in use, such as attendance monitoring, physical access, digital onboarding (KYC), or video surveillance, and determine whether they uniquely identify individuals.
- DPIA and risk analysis: prepare or update them for each processing activity and establish an annual review.
- Employment relationships: legal subordination is an express instance of a significant power imbalance. Accordingly, biometric time clocks should offer a reasonable non-biometric alternative.
- Financial sector: document the application of the enhanced due diligence exception and the potential technical impossibility in relation to fraud.
- Retail and shopping malls: review the use of facial recognition, given that these places are public spaces under the regulations.
- Documentation and policies: update consent forms, privacy notices, and withdrawal procedures.
- Technical architecture: migrate to biometric templates and restrict access.
- Providers: the regulations also apply to processors. Contracts with biometric technology providers should be reviewed.
Risks and sanctions
- Noncompliance is subject to the SPDP’s sanctioning powers under the LOPDP.
- Legal risks: 1) processing data without a valid basis, rendering the processing unlawful; 2) reusing data for a different, unjustified purpose; 3) operating without a DPIA; 4) making automated decisions without effective human review.
- Operational risks: 1) systems may need to be redesigned; 2) alternative channels may need to be created; and 3) provider relationships may need to be renegotiated within the transition period.
Legal Notice. This executive summary does not constitute legal advice, and each situation should be assessed case by case with a qualified professional. The points raised are general observations based on the text of the technical standard. They do not replace a full legal analysis of the LOPDP, its General Regulations, or other applicable provisions, to which the standard itself refers. In addition, the SPDP may revise and update the technical standard at any time. It is therefore advisable to confirm that the standard is in force and to check its current text before making any decisions.
© TobarZVS
This publication contains information of general interest and does not constitute legal opinion on specific issues. Any analysis will require legal advice from the Firm.