A city transport authority plans to deploy live facial recognition at a busy metro interchange. Cameras will capture the face of every passing commuter, convert each face into a biometric template, and match it in real time against a watchlist of persons sought by police, so that the overwhelming majority of those scanned are uninvolved members of the public. The authority concedes the templates are used to uniquely identify individuals. Applying the GDPR and the EDPB guidelines on video devices and on proportionality, which TWO steps must the authority take before it may lawfully launch this processing? (Select TWO.)
- ACarry out a data protection impact assessment and, where the assessment shows a residual high risk that cannot be mitigated, consult the competent supervisory authority before starting the processing. Correct
- BIdentify a condition under Article 9(2) GDPR, supported by Union or Member State law providing suitable safeguards, because the facial templates are special category biometric data. Correct
- CDocument a legitimate interests assessment under Article 6(1)(f) GDPR, which on its own authorises the biometric matching once the authority shows its security interest outweighs commuter privacy.
- DOffer every scanned commuter the right to data portability under Article 20 GDPR so they can receive and reuse the biometric template generated from their face.
- EAppoint a representative in the Union under Article 27 GDPR before the cameras begin capturing and matching the biometric data of commuters at the interchange.
Why A is correct: Systematic large-scale monitoring of a publicly accessible area triggers a mandatory Article 35 DPIA, and Article 36 requires prior consultation where residual high risk remains, so this step is genuinely required.
Why B is correct: Templates used to uniquely identify a person are biometric special category data, so an Article 6 basis alone is insufficient and an Article 9(2) exception backed by law is required before processing.
Why C is wrong: Legitimate interests is tempting because ordinary CCTV often relies on it, but a public authority cannot use it for its tasks and it never lifts the Article 9 prohibition on biometric data, so it is insufficient here.
Why D is wrong: Portability under Article 20 applies only to data the subject provided under consent or contract and is irrelevant to watchlist matching, so invoking it confuses an unrelated data subject right with the required safeguards.
Why E is wrong: Article 27 applies to controllers without an EU establishment caught by the targeting or monitoring criteria, not to a domestic public authority already established in the Union, so it is the wrong obligation.