Biometric Governance
Biometric Law-Enforcement Authorisation and Reporting
What this control does
Control authorised law-enforcement biometric use through approvals, scope limitations, documentation and reporting.
How to implement
Use a specialist legal and operational approval process for law-enforcement remote biometric identification. Keep real-time use under Article 5 separate from post-remote identification under Article 26(10); their authorization routes, conditions and deadlines differ. Document the permitted purpose, necessity, scope and required human decision safeguards. Track each use, any required impact assessment, registration and notification, and the applicable stop/deletion response to refusal. Prepare annual reports where Article 26(10) requires them, while protecting sensitive operational data. Do not treat one authorization as permission for unrestricted future use.
Suggested timing and triggers
Before and during each use; within the applicable authorization and notification deadlines; annually where the relevant reporting duty requires.
Evidence examples
Case-specific legal and necessity assessment Required authorization, impact assessment and registration Use logs and human-decision records Notifications, refusal responses and deletion evidence Applicable annual reports excluding protected operational data
How to check this control
Select a completed use and verify its legal route, scope and authorization timing. Trace any refusal or restriction into system use and data handling. Reconcile the relevant reporting records to the cases covered.
Related EU AI Act obligations
Article 5(1)(h), 5(2)-(7)
Do Not Use Real-Time Remote Biometric Identification in Public Spaces for Law Enforcement Except Where Specifically Permitted
Article 5(1)(h), 5(2)
Limit Permitted Real-Time Remote Biometric Identification to Specified Objectives and Targeted Identity Confirmation
Sub-obligation of Article 5(1)(h), 5(2)-(7): Do Not Use Real-Time Remote Biometric Identification in Public Spaces for Law Enforcement Except Where Specifically Permitted
Article 5(2)
Complete a Fundamental Rights Impact Assessment and Register the System Before Permitted Use
Sub-obligation of Article 5(1)(h), 5(2)-(7): Do Not Use Real-Time Remote Biometric Identification in Public Spaces for Law Enforcement Except Where Specifically Permitted
Article 5(3)
Obtain Required Prior Authorisation for Each Permitted Use
Sub-obligation of Article 5(1)(h), 5(2)-(7): Do Not Use Real-Time Remote Biometric Identification in Public Spaces for Law Enforcement Except Where Specifically Permitted
Article 5(4)
Notify Relevant Authorities of Each Permitted Use
Sub-obligation of Article 5(1)(h), 5(2)-(7): Do Not Use Real-Time Remote Biometric Identification in Public Spaces for Law Enforcement Except Where Specifically Permitted
Article 26(10)
Apply Required Safeguards When Using High-Risk AI for Post-Remote Biometric Identification in Law Enforcement
Article 26(10), first subparagraph
Obtain Required Authorisation for Post-Remote Biometric Identification Use
Sub-obligation of Article 26(10): Apply Required Safeguards When Using High-Risk AI for Post-Remote Biometric Identification in Law Enforcement
Article 26(10), first-third subparagraphs
Limit Post-Remote Biometric Identification to a Specific Investigation and Stop/Delete if Authorisation Is Rejected
Sub-obligation of Article 26(10): Apply Required Safeguards When Using High-Risk AI for Post-Remote Biometric Identification in Law Enforcement
Article 26(10), third subparagraph
Do Not Base Adverse Legal Decisions Solely on Post-Remote Biometric Identification Output
Sub-obligation of Article 26(10): Apply Required Safeguards When Using High-Risk AI for Post-Remote Biometric Identification in Law Enforcement
Article 26(10), fifth subparagraph
Document Each Post-Remote Biometric Identification Use and Make Records Available on Request
Sub-obligation of Article 26(10): Apply Required Safeguards When Using High-Risk AI for Post-Remote Biometric Identification in Law Enforcement
Article 26(10), sixth subparagraph
Submit Annual Reports on Post-Remote Biometric Identification Use
Sub-obligation of Article 26(10): Apply Required Safeguards When Using High-Risk AI for Post-Remote Biometric Identification in Law Enforcement