France - Biometric Recognition Bill (n°505)
Proposal / parliamentary bill on biometric recognition in public space
Proposition de loi relative à la reconnaissance biométrique dans l'espace public
France
RAI-FR-NA-PDLRLXX-2023A Senate proposal (text n°505, report deposited 31 May 2023) that establishes clear legal 'red lines' against mass, untargeted biometric identification in public spaces while creating a tightly governed experimental regime for narrowly defined exceptional uses (authentication at secured access for major events, targeted judicial and serious-crime investigations, and limited intelligence uses). The bill mandates oversight, reporting to Parliament, human review, security measures and an evaluation committee with a three-year experimental window.
Summary
Background and purpose: This parliamentary proposition (proposition de loi n°505, deposited at the Senate in April 2023 with a report registered 31 May 2023) was drafted to translate the conclusions of the Senate commission's May 2022 information report, which formulated 30 propositions to avoid the emergence of a "surveillance society". The bill responds to the lack of a specific legal framework for biometric recognition deployed in public or publicly accessible spaces and aims to enshrine in statute both firm prohibitions and exceptional experimental pathways under strict control and review.
Core principles: The bill sets fundamental legal 'red lines' that prohibit (i) remote biometric identification of persons in public spaces without consent (including live, real-time identification and mass or continuous scanning), and (ii) categorization, scoring or social ranking on the basis of biometric data. These prohibitions aim to protect privacy, personal dignity and other fundamental rights while permitting the legislature to consider narrow, exceptional uses under an experimental and closely supervised regime.
Experimental and exceptional use cases: The text defines a limited set of potential exceptions that may be authorised only under strict conditions and often on an experimental basis (usually for three years): (a) biometric authentication for controlled access to highly secured zones (notably for major public events) where non-biometric alternatives must remain available; (b) targeted a posteriori exploitation of images for investigations into the most serious crimes (limited spatio-temporal scope, under judicial control); (c) narrowly defined intelligence use by first-circle intelligence services, subject to prime-ministerial authorisation after CNCTR advice and strict purpose limitations (national defence, terrorism, threats to public order); (d) in exceptional, tightly constrained situations, limited real-time identification for investigations into grave threats to physical integrity.
Governance, oversight and safeguards: The bill constructs a multi-layered governance architecture: decisions authorising biometric identification are time-limited, reasoned, and subject to judicial or prosecutorial authorisation depending on the procedural context; any signals produced by automated systems must be subject to mandatory human verification by qualified and habilitated agents; a strengthened reporting regime requires immediate notice to Parliament and annual public reports; a scientific and ethical committee is mandated to monitor experiments and publish reports; the CNIL (French data protection authority) involvement and technical-security requirements are embedded throughout the text. The bill further requires data minimisation, purpose limitation, logs and audit trails, security and integrity safeguards, training for authorised personnel, and redress routes for individuals.
Accountability and evaluation: Experiments are time-limited (three years in the Senate's amendments), and a final governmental evaluation must decide on possible pérennisation (making permanent) or modification in light of domestic experience and developments at EU level. The bill foresees parliamentary access to information and the possibility of requiring supplementary information from the Government. Penalties for unlawful deployments are foreseen through administrative and criminal enforcement channels and the CNIL's regulatory powers.
Relationship with existing law: The proposition supplements the 1978 Data Protection Act, integrates with the GDPR (particularly the special category nature of biometric data) and the frameworks governing criminal investigation and intelligence (including CNCTR oversight), while aiming to remain coherent with EU-level work on AI and biometric identification. The text emphasises subsidiarity, narrow scope, and robust safeguards to enable specific state functions without enabling mass surveillance.
Implications: If adopted, the bill would create an explicit statutory baseline for acceptable and unacceptable uses of biometric recognition in public spaces, establish an experimental and evaluative approach to limited deployments, and elevate parliamentary and independent oversight over uses by law enforcement and intelligence. The text is a prominent example of a legislative attempt to reconcile public security, technological innovation and strong fundamental-rights safeguards.
Full article
Read full text ↗Overview
The proposition de loi relative to biometric recognition in public spaces (Senate text n°505, report registered 31 May 2023) establishes statutory "red lines" that prohibit mass or untargeted biometric identification in public and publicly accessible spaces while authorising a narrow, experimental set of uses subject to strict controls, oversight and evaluation. The text responds directly to the Senate commission's 2022 information report, "La reconnaissance biométrique dans l'espace public : 30 propositions pour écarter le risque d'une société de surveillance", and is intended to reconcile the legitimate public-security or operational benefits of biometric tools with protection of privacy and fundamental rights. The bill frames exceptions as experiments with limited duration, subject to judicial or executive authorisations and continuous oversight; see the primary bill text and report at Senate report (May 31, 2023) and the deposited proposition PDF at Senate proposition PDF.
Definitions
The proposition distinguishes key concepts to reduce ambiguity: "biometric data" (data resulting from specific technical processing relating to physical, physiological or behavioral characteristics enabling unique identification), "authentication" (1:1 comparison verifying that a person is who they claim to be), "identification" (1:N comparison to find a person among a database), "real-time identification" (live processing enabling immediate action), and "a posteriori exploitation" (processing of recorded images after the fact). The bill also defines "spaces accessible to the public" and sets boundaries between police administrative functions and police judiciaire (judicial police) uses. These definitions are designed to shape the permitted, prohibited and experimental regimes in subsequent articles.
Governance and Institutional Framework
The governance architecture established by the proposition is multi-layered and centred on judicial, parliamentary and independent oversight. Authorisations for a posteriori identification in judicial investigations must originate from the magistrate in charge or the relevant prosecutor and are strictly time-limited; intelligence uses by first-circle services require prime-ministerial authorization after advice from the CNCTR (Commission nationale de contrôle des techniques de renseignement). The proposal mandates a scientific and ethical committee to evaluate experiments and publish reports, and strengthens reporting to Parliament: immediate information to both Assemblée nationale and Sénat for administrative measures, and an annual public report summarizing authorisations, deployments, incidents and outcomes. The CNIL (Commission nationale de l'informatique et des libertés) retains a central regulatory and supervisory role regarding data-protection compliance and technical safeguards; see the CNIL's role referenced in the report at Senate report. The bill seeks to balance executive functionality with independent and parliamentary scrutiny.
Key Focus Areas
The bill concentrates on several interlocking focus areas: (1) Rights and prohibitions – a clear ban on remote, untargeted biometric identification in public spaces and on the scoring/categorization of individuals on biometric grounds; (2) Narrow experiments – tightly defined contexts where biometric tools can be trialled (authentication at secured access points for major events, a posteriori criminal investigations limited to the most serious offences, narrowly circumscribed intelligence applications); (3) Authorization and human oversight – all automated signals must be reviewed by trained human operators and authorisations are time-bound, reasoned, and revocable; (4) Technical and organisational safeguards – data minimisation, encryption, secure storage, access controls, and mandatory audit logs; (5) Transparency and evaluation – obligation to publish evaluation reports, public summaries, and to permit parliamentary inquiry; (6) Redress and remedies – mechanisms for individuals to contest wrongful identification or seek remedies; and (7) Compatibility with EU law and GDPR – particular attention to special-category nature of biometric data and the need for explicit legal bases and safeguards. By foregrounding these areas the bill attempts to enable limited beneficial uses without normalising pervasive biometric surveillance.
Implementation Framework
Implementation is framed through an experimental regime: authorisations are granted under precise legal conditions for a limited period (the Senate's amendments envisage a three-year experimental window). For judicial investigations, magistrates or prosecutors authorise short-duration a posteriori searches limited to defined spatial and temporal perimeters. For intelligence services, prime-ministerial authorisation after CNCTR advice is required, with strict lists of eligible objectives (national defence, prevention of terrorism, threats to republican institutions, major public order risks). Real-time deployments are permitted only in exceptional, narrowly targeted circumstances and subject to enhanced safeguards: separate dedicated cameras (distinct from general-purpose videoprotection), restricted numbers of cameras, limited geographic scope, and specialized training for operators. The bill mandates privacy and data-protection impact assessments (DPIAs), technical conformity checks, and the involvement of CNIL when applicable. A scientific and ethical committee advises on methodology, metrics and public reporting to inform the final governmental evaluation.
Monitoring and Evaluation
Monitoring is continuous and multi-stakeholder. The law requires immediate notification to both houses of Parliament of administrative measures, regular interim reports from the executive, and public annual reports detailing authorisations, deployments, error rates, incidents, security breaches and outcomes. The mandated scientific and ethics committee must produce public evaluation reports during the experimental period and the Government must deliver a final evaluation at the end of the experimentation that considers operational results, rights impacts and EU legal developments. Audit logs, independent audits and CNIL inspections are foreseen; the parliamentary right to request supplementary information enhances democratic oversight. These layers aim to ensure transparency, enable course-corrections and inform the decision on whether to pérenniser or terminate the experiments.
Penalties, Liability, and Appeals
While the proposition principally designs preventive and governance measures, it also contemplates enforcement mechanisms. Unlawful deployments or violations of safeguards can trigger administrative sanctions (including CNIL fines and injunctions), orders to suspend or cease processing, destruction of unlawfully-processed data, and potential criminal liability where illegal acts (unauthorised capture, illicit processing, or abuse of office) are established under existing penal provisions. The bill maintains individuals' rights of judicial appeal and CNIL complaint routes and envisages compensation avenues for unlawful identifications or rights infringements. The restitution and redress mechanisms are anchored in existing civil and administrative remedies and the supervisory remit of the CNIL.
Relationship to Other Instruments
The proposition is expressly designed to complement and supplement existing French and EU instruments. It amends parts of the French Data Protection Act (law n°78-17 of 6 January 1978) and interacts with the GDPR regime for special categories (biometric data). It also integrates with procedural law governing police judiciaire and administrative policing and with the CNCTR framework for intelligence techniques. The bill references the legal bases created for the 2024 Olympic Games (law n° 2023-380, May 19, 2023) to avoid regulatory fragmentation and proposes an experimental approach that keeps the text aligned with pending or evolving EU AI and biometric identification initiatives. The aim is not to supersede existing protections but to create a specific legal instrument calibrated to biometric risks in public spaces.
International Alignment
The bill situates France's approach within broader international and European discussions on biometric identification and AI governance. It echoes debates at EU level concerning remote biometric identification and the regulation of high-risk AI systems and seeks to preserve consistency with GDPR and with anticipated EU rules (such as the AI Act discussions extant at the time of drafting). The experimental and evaluative design is intended to permit France to adapt to EU developments while preserving national oversight for security-sensitive functions. The law also references best-practice principles from international human-rights and data-protection instruments, aiming for interoperability with cross-border judicial cooperation and data-exchange limitations.
Implementation Timeline
| Milestone | Date / Duration |
|---|---|
| Proposition deposited at Senate | 2023-04-05 (Senate deposit of text n°505) |
| Report registered at Senate | 2023-05-31 (report by Philippe Bas) |
| Senate adoption (1st reading) | 2023-06-12 (adopted by the Sénat and transmitted to Assemblée nationale) |
| Experimental authorisation window (if adopted as proposed) | 3 years from promulgation (Senate amendment) |
| Interim reporting | Annual public reports during experimentation |
| Final government evaluation | At conclusion of 3-year experimental period |
Sources and References
Requirements for a company
What an organisation has to do under France - Biometric Recognition Bill (n°505), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.
Must do
13- Do not use remote, untargeted biometric identification in public spaces.All entities operating biometric systems in public spaces.
- Refrain from scoring or categorizing individuals based on biometric data.All entities processing biometric data.
- Obtain time-limited authorization from a magistrate or prosecutor for a posteriori identification in judicial investigations.Judicial authorities conducting a posteriori biometric identification.
- Secure prime-ministerial authorization after CNCTR advice for intelligence uses of biometric recognition.First-circle intelligence services using biometric recognition.
- Ensure all automated biometric signals are reviewed by trained human operators.Entities deploying biometric recognition systems.
- Apply data minimisation, encryption, secure storage, access controls, and mandatory audit logs.Entities processing biometric data.
- +7 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under France - Biometric Recognition Bill (n°505), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | All entities operating biometric systems in public spaces. | Do not use remote, untargeted biometric identification in public spaces. “a clear ban on remote, untargeted biometric identification in public spaces” | Always | — | Critical |
| 2 | All entities processing biometric data. | Refrain from scoring or categorizing individuals based on biometric data. “ban on the scoring/categorization of individuals on biometric grounds” | Always | — | Critical |
| 3 | Judicial authorities conducting a posteriori biometric identification. | Obtain time-limited authorization from a magistrate or prosecutor for a posteriori identification in judicial investigations. “Authorisations for a posteriori identification in judicial investigations must originate from the magistrate in charge or the relevant prosecutor and are strictly time-limited” | Before deployment | — | Critical |
| 4 | First-circle intelligence services using biometric recognition. | Secure prime-ministerial authorization after CNCTR advice for intelligence uses of biometric recognition. “intelligence uses by first-circle services require prime-ministerial authorization after advice from the CNCTR” | Before deployment | — | Critical |
| 5 | Entities deploying biometric recognition systems. | Ensure all automated biometric signals are reviewed by trained human operators. “all automated signals must be reviewed by trained human operators” | During operation | — | Critical |
| 6 | Entities processing biometric data. | Apply data minimisation, encryption, secure storage, access controls, and mandatory audit logs. “data minimisation, encryption, secure storage, access controls, and mandatory audit logs” | During operation | — | Critical |
| 7 | Entities conducting real-time biometric deployments. | Use separate, dedicated cameras for real-time deployments, distinct from general-purpose videoprotection. “separate dedicated cameras (distinct from general-purpose videoprotection)” | Before deployment | — | Critical |
| 8 | Entities deploying biometric recognition systems. | Conduct privacy and data-protection impact assessments and technical conformity checks. “The bill mandates privacy and data-protection impact assessments (DPIAs), technical conformity checks, and the involvement of CNIL when applicable.” | Before deployment | — | Important |
| 9 | Entities deploying biometric recognition systems. | Notify or consult the CNIL where applicable and maintain audit trails for inspections. “The CNIL (...) retains a central regulatory and supervisory role regarding data-protection compliance and technical safeguards.” | During operation | — | Important |
| 10 | Executive bodies implementing administrative measures. | Immediately inform both houses of Parliament of administrative measures related to biometric recognition. “immediate information to both Assemblée nationale and Sénat for administrative measures” | Immediately | — | Important |
| 11 | Executive bodies overseeing biometric recognition experiments. | Publish annual public reports detailing authorisations, deployments, incidents, and outcomes. “an annual public report summarizing authorisations, deployments, incidents and outcomes.” | Annually | — | Important |
| 12 | Entities conducting biometric recognition experiments. | Cooperate with the scientific and ethical committee to evaluate experiments and publish reports. “The proposal mandates a scientific and ethical committee to evaluate experiments and publish reports” | During experimentation | — | Important |
| 13 | Entities deploying biometric recognition systems. | Establish mechanisms for individuals to contest wrongful identification or seek remedies. “Redress and remedies – mechanisms for individuals to contest wrongful identification or seek remedies” | Before deployment | — | Important |
Related Regulations
France AI Regulation Overview
France86% similar
Decree No. 2019-452 of 13 May 2019 - Authorising creation of the Alicem mobile certified online authentication system (Décret autorisant la création d'un moyen d'identification électronique ALICEM)
France86% similar
European Commission Guidelines regarding prohibited AI practices (guidance on Article 5 prohibitions)
European Union86% similar
Loi n° 2024-449 du 21 mai 2024 visant à sécuriser et à réguler l'espace numérique ("SREN")
France86% similar
Iniciativa que adiciona disposiciones para el uso de Inteligencia Artificial por unidades de seguridad pública (Bill authorizing/setting rules for AI use in public security investigations)
Mexico85% similar
© Regulations.AI · updated on 13-Jun-2026