What qualifies as biometric personal data under the DPDPA
Section 2(t) defines “personal data” as any data about an individual who is identifiable by or in relation to such data. Biometric identifiers—fingerprints, palm prints, iris scans, retina patterns, facial geometry, voiceprints and gait signatures—fall squarely within this definition whenever they can identify a living individual.
Unlike the 2011 SPDI Rules under the IT Act 2000 (which listed biometrics under “sensitive personal data or information” with a higher consent bar), the DPDPA applies a single consent standard to all personal data. The heightened-obligation mechanism in the DPDPA is the Significant Data Fiduciary (SDF) designation under Section 10, not a data-category tier.
- Fingerprint and palm-print templates stored by attendance systems
- Facial geometry captured by CCTV analytics or airport e-gates
- Iris and retina scans used in Aadhaar-based authentication
- Voiceprints collected by call-centre identity-verification systems
- Gait or behavioural biometrics used by security platforms
Consent and notice obligations for biometric collection
Before collecting biometric data, a Data Fiduciary must issue a clear notice under Section 5 that states the specific personal data being collected (e.g. “facial geometry for access control”), the purpose of processing, and how the Data Principal can exercise rights under Sections 11–14. Consent under Section 6 must be free, specific, informed, unconditional and unambiguous.
Withdrawal of consent must be as easy as giving it (Section 6(4)). For biometric systems embedded in physical infrastructure—turnstiles, CCTV, ATMs—this means the organisation must provide a practical opt-out mechanism, not merely a clause buried in terms of service.
- Section 5 notice must name the specific biometric identifier being collected
- Section 6 consent must be purpose-specific—consent for attendance tracking does not extend to performance profiling
- Section 7 legitimate uses (employment, state function) can substitute consent but still require a Section 5 notice
- Section 6(4) requires that withdrawing consent be as easy as giving it
CCTV and facial recognition: applying the DPDPA to surveillance
CCTV systems that record identifiable footage are processing personal data. When those systems run facial-recognition analytics—matching faces against a watchlist, for instance—they are processing biometric personal data. The DPDPA applies in full.
A retail chain using CCTV for theft prevention may argue Section 7(a) (“voluntarily provided” for a specified purpose) if the footage is captured with adequate notice. But once the same footage feeds a facial-recognition engine that profiles shoppers by demographics, the original purpose has changed and fresh consent is needed.
Employers using CCTV in workplaces may rely on Section 7(i) (employment purposes) for safety-related surveillance, but this does not cover behavioural monitoring unrelated to the employment contract.
Aadhaar and the DPDPA: dual-law compliance
Aadhaar-based authentication—using fingerprints or iris scans against the CIDR—engages both the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, and the DPDPA. Section 16(2) of the DPDPA preserves stricter obligations in other laws: the Aadhaar Act’s consent and purpose-limitation requirements continue to apply alongside the DPDPA’s consent and security obligations.
Entities that use Aadhaar authentication as Data Fiduciaries must comply with UIDAI regulations on storage (no entity other than UIDAI may store Aadhaar biometric data) as well as Section 8(5) and Section 8(7) of the DPDPA (reasonable safeguards and erasure upon purpose completion).
Security safeguards for biometric data
Section 8(5) requires every Data Fiduciary to protect personal data by taking reasonable security safeguards to prevent a personal data breach. For biometric data, industry standards point to encryption of templates at rest, salted hashing for match-on-server architectures, access-control logs for biometric databases and periodic vulnerability assessments.
Rule 6 of the DPDP Rules 2025 requires technical and organisational measures “appropriate to the nature and volume of personal data processed.” Biometric databases—where a breach is irreversible (a person cannot change their fingerprints)—demand a higher baseline.
| Safeguard | DPDPA provision | Application to biometrics |
|---|---|---|
| Encryption at rest | S.8(5), Rule 6 | AES-256 or equivalent for stored templates |
| Access-control logging | S.8(5), Rule 6 | Audit trail for every biometric-database query |
| Breach notification | S.8(6), Rule 7 | Intimation without delay + detailed report within 72 hours |
| Erasure on purpose completion | S.8(7) | Delete templates when employment or contract ends |
| DPIA (if SDF) | S.10(2)(c), Rule 13 | Mandatory data protection impact assessment |
Penalties for biometric data mishandling
The DPDPA Schedule sets monetary penalty ceilings. Failing to implement reasonable security safeguards under Section 8(5) carries a ceiling of up to ₹250 crore, as determined by the Data Protection Board after inquiry. Failing to notify a breach under Section 8(6) carries a ceiling of up to ₹200 crore. These are not fixed charges; Section 33(2) lists the factors the Board considers—nature, gravity, duration of the breach, actions taken to mitigate, and any gain made from the contravention.
No penalty orders have been issued by the Board as of October 2026. The Board’s procedure is governed by Rules 17–21, with appeal to the Appellate Tribunal under Rule 22.
How AMLEGALS assists with biometric data compliance
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm advises organisations on lawful-basis mapping for biometric processing, drafting biometric-specific privacy notices, designing practical consent-withdrawal mechanisms for physical-infrastructure systems, and structuring security-safeguard frameworks that reflect the irreversible nature of biometric identifiers.

