Get in touch Privacy, data & technology
Biometrics & facial recognition
Specialist advice for technologies that identify, verify or categorise people through their physical or behavioural characteristics.
See how we can helpClear legal direction
Biometric information is closely connected to identity, difficult to replace and capable of affecting people at scale. O’Brien Legal helps organisations examine the case for using biometrics, test the proposal carefully and build the legal and governance safeguards the technology demands.
The full regime now applies
The transition deadline has passed.
The Biometric Processing Privacy Code 2025 came into force on 3 November 2025 for new biometric processing. Organisations already using biometric processing had until 3 August 2026 to align with the new rules. That transition deadline has now passed, so every organisation carrying out processing covered by the Code is now inside the full regime.
Amendment No 1 has been in force since 1 May 2026. The Code contains 13 rules that modify the Information Privacy Principles for biometric processing. They are built around necessity and proportionality, with specific notification and safeguard requirements.
Biometric processing includes automated identification, verification and categorisation using physical or behavioural features such as faces, fingerprints, voices and behavioural patterns. The Code does not set a minimum accuracy threshold, but accuracy, testing and the consequences of errors remain important parts of a sound assessment.
How we can help
Advice built around the real decision.
Advice on the Biometric Processing Privacy Code 2025 and Privacy Act 2020
Proportionality assessments and privacy impact assessments
Facial recognition, voice, fingerprint and behavioural biometrics
Notices, transparency, consent and individual rights
Vendor due diligence and biometric technology contracts
Governance, monitoring, testing and deployment reviews
When to get in touch
You may be dealing with this now.
You are considering biometric identity verification or authentication
Facial recognition is proposed for security, safety or loss prevention
A vendor product contains biometric capability that has not been assessed
You need to review an existing system against current requirements
The aim
A clear view, grounded in evidence, of whether and how the proposed use should proceed, with safeguards proportionate to the impact on people.