AI Act: Italy's Privacy Guarantor seeks stronger safeguards for biometric data
Translated from Italian, summarized and contextualized by DistantNews.
At a glance
- Italy's Privacy Guarantor has approved the legislative decree adapting national law to the EU's AI Act.
- The decree regulates the use of AI systems by police forces, setting limits for processing biometric data and remote biometric identification technologies.
- The Guarantor requested stronger safeguards for biometric data, clearer human supervision roles in AI systems, and precise responsibilities in research projects.
Rome, Italy โ Italy's Data Protection Authority (Garante Privacy) has given its approval to a legislative decree that aligns national legislation with the European Union's Artificial Intelligence Act (AI Act). The decree specifically addresses the deployment of AI systems by law enforcement agencies, establishing crucial boundaries, prerequisites, and safeguards for the processing of biometric data and the utilization of remote biometric identification technologies.
While finding the decree generally consistent with the AI Act and the relevant delegation law, the Privacy Guarantor has identified several areas requiring enhancement. Key recommendations include clarifying the role of human oversight within AI systems, defining responsibilities more precisely in research and experimentation initiatives, and ensuring the Guarantor's involvement in regulatory sandbox environments that involve personal data processing. Furthermore, the authority called for strengthened guarantees concerning the quality of biometric databases used for identification purposes.
The Guarantor expressed concerns that the automated and widespread processing of biometric data for individuals accessing public places or events is not fully aligned with the AI Act. The EU regulation permits post-event facial recognition only for targeted investigations. The authority emphasized that biometric data processing should be confined to already acquired recordings and only when a specific operational need exists, thereby avoiding mass, preemptive data collection. Finally, the Guarantor urged that provisions related to biometric identification under the new Article 359-ter of the Code of Criminal Procedure explicitly prohibit the use of databases obtained through indiscriminate scraping techniques or in violation of personal data protection laws.
Originally published by ANSA in Italian. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.