Facial recognition and other biometrics carry heightened risks and must respect lawfulness, necessity, proportionality and minimisation; the controller should first weigh the effect on fundamental rights and look at less intrusive means. Article 9 applies when three criteria meet: physical, physiological or behavioural characteristics, a specific technical processing, and the purpose of uniquely identifying a person. Classifying people by age or gender without templates to identify them is outside Article 9, but storing templates to recognise someone again (re-entry, repeat targeting) is inside it from the start. Biometric recognition that private organisations install for their own ends will in most cases need explicit consent from everyone concerned.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.