Skip to content

Case Notes

Case Notes

This case related to Biometrics data

Case No.:2026E01

A bank introduces mandatory facial recognition login for its mobile application

The Enquiry

Whether the bank can require customers to provide facial recognition data for mandatory mobile application logins.

Our Response

Data Protection Principle (DPP) 1 of Schedule 1 to the Ordinance provides that personal data shall only be collected for a lawful purpose directly related to a function or activity of the data user. The data collected should be necessary and adequate but not excessive for such purpose. The means of collection should be lawful and fair. In addition, when collecting personal data from a data subject directly, the data user shall inform the data subject whether it is obligatory to provide the data, the purpose of collection, the classes of transferees of the data, and the right and means to request access to and correction of their data.

Given the sensitive nature of biometric data, data users should first consider whether such collection is necessary for the purposes of their activities. Data users must have sufficient justification if they collect biometric data without adopting less intrusive measures, or if they collect such data in addition to employing those measures. Even if the biometric data collected is considered “adequate but not excessive”, the means of collection must be fair in the circumstances, so data users have the obligations to ensure that data subjects are given a free and informed choice to choose whether to have their biometric data collected.

The PCPD has issued “Guidance on Collection and Use of Biometric Data”, assisting data users to comply with the requirements under the Ordinance when collecting biometric data. Data users should read this guidance before deciding whether to collect biometric data.

(Uploaded in August 2026)


Category : Provisions/DPPs/COPs/Guidelines : Topic/Subject Matter :