Danish DPA Authorizes Biometric Facial Recognition at Football Matches Under Strict GDPR Conditions
AC Horsens football club sought and received conditional authorization from Denmark's Datatilsynet to deploy facial recognition technology for biometric data processing at live events — one of the most privacy-sensitive use cases under GDPR. This case highlights that biometric data processing requires explicit regulatory approval, rigorous Data Protection Impact Assessments (DPIAs), and clearly defined data retention limits. The interaction between national CCTV surveillance law and GDPR creates compliance complexity that organizations must navigate carefully. Failure to obtain proper authorization or adhere to imposed conditions could result in significant fines and reputational damage. This case serves as a landmark reminder that technology adoption must be legally grounded before deployment, not after.
Tactical Insight
Before Deployment
- Conduct a full Data Protection Impact Assessment (DPIA) before implementing any biometric or facial recognition system.
- Obtain explicit regulatory authorization from the relevant Data Protection Authority (DPA) when processing special category data under GDPR Article 9.
- Map all applicable national laws (e.g., CCTV Acts) alongside GDPR to identify conflicting or complementary obligations.
Operational Controls
- Define and enforce strict data retention schedules specific to each processing purpose (e.g., dispute resolution vs. security monitoring).
- Implement technical access controls ensuring biometric data is accessible only to authorized personnel with a documented need.
- Log all access to and processing of biometric data to support audit trails and accountability.
Long-term Governance
- Establish a recurring review process to reassess DPIA findings as technology, usage, or legal frameworks evolve.
- Appoint or consult a Data Protection Officer (DPO) for ongoing oversight of high-risk processing activities.
- Train staff handling biometric systems on GDPR obligations, data minimization principles, and breach response procedures.