TechnicalArticle 3(34)GDPR Article 9
Biometric Data
Personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data — a special category under GDPR Article 9.
Related terms
- Training DataData used for training an AI system through fitting its learnable parameters, including the weights of a neural network, to ensure the system can produce…
- Validation DataData used for evaluating the trained AI model and for tuning its non-learnable parameters and its learning process, in order, among other things, to…
- Testing DataData used for providing an independent evaluation of the AI system in order to confirm the expected performance of that system before its placing on the…
- Input DataData provided to or directly acquired by an AI system on the basis of which the system produces an output.
- Deep FakeAI-generated or manipulated image, audio, or video content that resembles existing persons, objects, places, entities, or events and that falsely appears…
- AI SystemA machine-based system designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or…
Related compliance controls
- RM-001Establish Risk Management SystemArticle 9(1) requires providers to establish, implement, document, and maintain a risk management system as a continuous iterative process throughout the entire lifecycle of the high-risk AI system.
- RM-002Identify Known and Foreseeable RisksProviders must identify and analyse known and foreseeable risks that the high-risk AI system may pose to health, safety, or fundamental rights when used as intended and under reasonably foreseeable misuse conditions.
- RM-003Risk Estimation and Probability AssessmentProviders must estimate and evaluate the likelihood and severity of potential harm, taking into account the intended purpose, foreseeable misuse, and the vulnerability of affected natural persons.
- RM-004Risk Evaluation Against Acceptance CriteriaProviders must evaluate identified risks against pre-defined risk acceptance criteria and document the rationale for accepting residual risks that cannot be fully mitigated.
Upgrade when it needs to be
The free questionnaire returns preliminary signals. The Full Assessment turns real system material into a governed decision record - extraction, component separation, evidence, national overlays, and a review-ready dossier.
Start free risk preview