AMLEGALS — Strategic Lawyering
Biometric & Surveillance Data

Biometric data privacy in India: what the DPDPA requires

Fingerprints at office doors, facial recognition at airports, CCTV in retail stores, Aadhaar-linked authentication for banking—biometric data now underpins everyday transactions across India. The Digital Personal Data Protection Act, 2023, does not carve out a separate “sensitive data” category the way the 2011 SPDI Rules did, but biometric identifiers still attract the Act’s full obligations: lawful basis, purpose limitation, data minimisation, reasonable security safeguards and the right of erasure.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 5 min read

Abstract fingerprint ridges merging with data circuit lines on navy and gold background
Short answer

The DPDPA treats biometric data as personal data. Every entity collecting fingerprints, facial scans, iris patterns or other biometric identifiers must obtain consent under Section 6 (or rely on a Section 7 legitimate use), issue a notice under Section 5, apply Section 8(5) security safeguards, and honour erasure requests under Section 12. There is no separate “sensitive data” tier in the DPDPA—heightened duties arise instead from the Significant Data Fiduciary designation (Section 10) and the children’s data provisions (Section 9).

  • Biometric Data
  • DPDPA
  • Facial Recognition
  • CCTV Privacy
  • Aadhaar
  • Data Protection
Governing law
DPDPA 2023 + DPDP Rules 2025
Lawful basis
Consent (S.6) or legitimate use (S.7)
Security standard
Reasonable safeguards (S.8(5))
Max penalty
Up to ₹250 crore (S.8(5) breach)

What qualifies as biometric personal data under the DPDPA

Section 2(t) defines “personal data” as any data about an individual who is identifiable by or in relation to such data. Biometric identifiers—fingerprints, palm prints, iris scans, retina patterns, facial geometry, voiceprints and gait signatures—fall squarely within this definition whenever they can identify a living individual.

Unlike the 2011 SPDI Rules under the IT Act 2000 (which listed biometrics under “sensitive personal data or information” with a higher consent bar), the DPDPA applies a single consent standard to all personal data. The heightened-obligation mechanism in the DPDPA is the Significant Data Fiduciary (SDF) designation under Section 10, not a data-category tier.

  • Fingerprint and palm-print templates stored by attendance systems
  • Facial geometry captured by CCTV analytics or airport e-gates
  • Iris and retina scans used in Aadhaar-based authentication
  • Voiceprints collected by call-centre identity-verification systems
  • Gait or behavioural biometrics used by security platforms

CCTV and facial recognition: applying the DPDPA to surveillance

CCTV systems that record identifiable footage are processing personal data. When those systems run facial-recognition analytics—matching faces against a watchlist, for instance—they are processing biometric personal data. The DPDPA applies in full.

A retail chain using CCTV for theft prevention may argue Section 7(a) (“voluntarily provided” for a specified purpose) if the footage is captured with adequate notice. But once the same footage feeds a facial-recognition engine that profiles shoppers by demographics, the original purpose has changed and fresh consent is needed.

Employers using CCTV in workplaces may rely on Section 7(i) (employment purposes) for safety-related surveillance, but this does not cover behavioural monitoring unrelated to the employment contract.

Aadhaar and the DPDPA: dual-law compliance

Aadhaar-based authentication—using fingerprints or iris scans against the CIDR—engages both the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, and the DPDPA. Section 16(2) of the DPDPA preserves stricter obligations in other laws: the Aadhaar Act’s consent and purpose-limitation requirements continue to apply alongside the DPDPA’s consent and security obligations.

Entities that use Aadhaar authentication as Data Fiduciaries must comply with UIDAI regulations on storage (no entity other than UIDAI may store Aadhaar biometric data) as well as Section 8(5) and Section 8(7) of the DPDPA (reasonable safeguards and erasure upon purpose completion).

Security safeguards for biometric data

Section 8(5) requires every Data Fiduciary to protect personal data by taking reasonable security safeguards to prevent a personal data breach. For biometric data, industry standards point to encryption of templates at rest, salted hashing for match-on-server architectures, access-control logs for biometric databases and periodic vulnerability assessments.

Rule 6 of the DPDP Rules 2025 requires technical and organisational measures “appropriate to the nature and volume of personal data processed.” Biometric databases—where a breach is irreversible (a person cannot change their fingerprints)—demand a higher baseline.

Biometric security safeguard mapping to DPDPA provisions
SafeguardDPDPA provisionApplication to biometrics
Encryption at restS.8(5), Rule 6AES-256 or equivalent for stored templates
Access-control loggingS.8(5), Rule 6Audit trail for every biometric-database query
Breach notificationS.8(6), Rule 7Intimation without delay + detailed report within 72 hours
Erasure on purpose completionS.8(7)Delete templates when employment or contract ends
DPIA (if SDF)S.10(2)(c), Rule 13Mandatory data protection impact assessment

Penalties for biometric data mishandling

The DPDPA Schedule sets monetary penalty ceilings. Failing to implement reasonable security safeguards under Section 8(5) carries a ceiling of up to ₹250 crore, as determined by the Data Protection Board after inquiry. Failing to notify a breach under Section 8(6) carries a ceiling of up to ₹200 crore. These are not fixed charges; Section 33(2) lists the factors the Board considers—nature, gravity, duration of the breach, actions taken to mitigate, and any gain made from the contravention.

No penalty orders have been issued by the Board as of October 2026. The Board’s procedure is governed by Rules 17–21, with appeal to the Appellate Tribunal under Rule 22.

How AMLEGALS assists with biometric data compliance

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm advises organisations on lawful-basis mapping for biometric processing, drafting biometric-specific privacy notices, designing practical consent-withdrawal mechanisms for physical-infrastructure systems, and structuring security-safeguard frameworks that reflect the irreversible nature of biometric identifiers.

Bottom line

Every biometric identifier that can identify a living person is personal data under the DPDPA. There is no separate sensitive-data tier—obligations scale through the SDF designation and the security-safeguard standard, not through a data-category label.

Key terms
Biometric personal data
Personal data consisting of fingerprints, facial geometry, iris patterns, voiceprints or other biological measurements that can identify a living individual.
Significant Data Fiduciary (SDF)
A Data Fiduciary notified under Section 10 of the DPDPA based on volume, sensitivity or risk of processing—subject to DPIA, DPO appointment and audit obligations.
CIDR
Central Identities Data Repository—the central database of Aadhaar numbers, biometric and demographic data maintained by UIDAI under the Aadhaar Act 2016.
Questions and answers

Biometric Data Privacy: common questions

Is biometric data treated as sensitive personal data under the DPDPA?

No. The DPDPA does not create a separate sensitive-data category. Biometric data is personal data and attracts the full set of obligations—consent, notice, security safeguards, erasure—but heightened duties come through the Significant Data Fiduciary designation (Section 10), not a data-type tier.

Can an employer collect fingerprints for attendance without consent?

An employer may rely on Section 7(i) (employment purposes) instead of consent, but must still issue a Section 5 notice explaining what biometric data is collected, why, and how the employee can exercise rights under Sections 11–14.

What happens if biometric data is breached?

The Data Fiduciary must intimate the Data Protection Board without delay and submit a detailed report within 72 hours (Section 8(6), Rule 7). The affected Data Principals must also be informed. Non-notification carries a penalty ceiling of up to ₹200 crore, as determined by the Board after inquiry.

Does CCTV footage count as biometric data?

Recorded CCTV footage of identifiable individuals is personal data. If the system runs facial-recognition analytics—matching faces against a database—it processes biometric personal data and the DPDPA applies in full.

Contact

Need guidance on biometric data compliance?

Submit a question about DPDPA obligations for biometric processing, CCTV, or Aadhaar-linked systems.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

Biometric Data Privacy: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Biometric Data Privacy?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Biometric Data Privacy under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Biometric Data Privacy under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Biometric Data Privacy?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Biometric Data Privacy rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Biometric Data Privacy?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Biometric Data Privacy · DPDPA Exposure Assessment