What counts as personal data in a photo or video — and why faces get treated differently from almost everything else in the frame.
Personal data is any information that relates to an identified or identifiable person. In a photo or video, that's a longer list than most people expect. It includes the obvious — a recognizable face — but also a voice on the audio track, a license plate, a visible name badge or ID card, a distinctive tattoo or scar, a house number or street sign in the background, and even a combination of ordinary details (a school uniform, a specific storefront, a timestamp) that together narrow down who someone is and where they were. Metadata matters too: many phones and cameras embed GPS coordinates and exact timestamps invisibly inside the image file itself, which can identify a location — or a person's home — even if nothing incriminating is visible in the frame.
Biometric data is a specific, more sensitive category: physiological, biological, or behavioral characteristics used to identify a specific individual. Think facial geometry, iris and retina patterns, fingerprints, voiceprints, and even distinctive gait. This is an important nuance that trips people up: a photo containing a visible face is personal data, but it doesn't automatically become biometric data. It crosses that line when it is processed to extract a unique identifying template — for example, running facial recognition software against the image to match it to an identity. A vacation photo with your friend's face in it is personal data. That same face run through a face-matching database is biometric data, and most privacy laws hold it to a higher standard.
Where This Shows Up in Everyday Footage
Event photography and crowd shots — conferences, weddings, concerts, sports games
Security cameras, doorbell cameras, and CCTV archives
Dashcam and drone footage, which often captures bystanders and private property incidentally
Social and user-generated content — vlogs, street interviews, "day in the life" footage
Workplace training videos and internal communications featuring employees
Documentary and street photography
Livestreams, webinars, and recorded meetings that show attendee video feeds
Why It Matters Before You Publish
A password can be reset. A credit card can be reissued. A face or a voiceprint cannot — once biometric data is exposed or misused, the person behind it can't simply get a new one. That permanence is why regulators treat this category so seriously, and it's why creators should think about it before publishing rather than after a takedown request arrives. The people most at risk are often the ones who never agreed to appear at all: bystanders in a public shot, protesters, patients near a medical setting, minors, or anyone whose safety depends on not being publicly identifiable. Combine that with how easily footage can be re-identified today — reverse image search, social media tagging, and increasingly capable AI — and "it's just a background face" stops being a safe assumption.
The hardest part of handling personal and biometric data isn't knowing the rules — it's finding every instance across hours of footage or hundreds of photos. BlurMe's dual-engine AI scans every frame and flags faces (and license plates) automatically, including in difficult conditions like low light or a crowded, moving scene, so nothing slips through because a reviewer missed one frame in three thousand.
See it applied to the two most common biometric identifiers: Blur Face in Photo and Blur Face in Video use AI to automatically detect and blur faces without any manual masking.
If your visitors still have questions, provide contact information or another resource for more help.