Biometric data is personal data resulting from specific technical processing relating to physical, physiological or behavioural characteristics. The EU AI Act and GDPR define it differently, and the difference matters.
What it is
GDPR Article 4(14) requires that the processing allow or confirm the unique identification of a person. AI Act Article 3(34) drops that requirement.
The consequence is that data can be biometric for AI Act purposes while not being biometric data under GDPR — so a GDPR analysis does not carry across.
Why it matters
The AI Act's prohibition on emotion inference in workplace and education contexts hangs entirely on this definition. Whether a signal counts as biometric decides whether the prohibition applies at all.
A common confusion
Behavioural telemetry — tab-switching, window focus, dwell time — is not biometric data. It records actions taken in software, not physiological or behavioural characteristics of the person in the biometric sense.
Related
See also emotion inference, dpia (data protection impact assessment) and client-side inference. See the full glossary for the rest, or the EU AI Act guide for the wider context.
See where your content loses people
Book a walkthrough and we will show you the engagement data on your own content.