Consent for Processing Biometric Personal Data by Generative AI: Practical Implementation Problems
https://doi.org/10.17803/2542-2472.2026.38.2.014-025
Abstract
The paper examines the compliance of biometric personal data processing in generative AI systems with the legislation of the Russian Federation and provides a comparative analysis of the legal regulation of relations under examination in Russia and the European Union. The study identifies systemic gaps in ensuring the lawful processing of biometric personal data by generative artificial intelligence systems. The study has established that prohibitions on the use of biometric personal data in user prompts are largely declaratory in nature, as evidenced by an analysis of the privacy policies of GigaChat and DeepSeek, which place responsibility for the unlawful use of personal data on the user. The opaque mechanism for obtaining a data subject’s consent to the processing of biometric personal data, as well as conditioning access to the service on the mandatory processing of such data for neural network training purposes, appear to constitute the principal challenges to ensuring lawful data processing by generative artificial intelligence systems. Based on a comparative analysis of Russian and European legislation, the author proposes the following: (1) to establish a mandatory prohibition on the processing of biometric personal data by generative AI systems, coupled with the imposition of legal liability, or alternatively to require operators of generative artificial intelligence systems to implement mechanisms for verifying the existence of the data subject’s written consent to processing; and (2) to require that the processing of biometric personal data exclusively for neural network training purposes be carried out only on the basis of separate informed consent of the data subject, while access to the service should remain possible even in the absence of such consent. The proposed measures are aimed at eliminating existing contradictions, ensuring genuine control by data subjects over their biometric personal data, and strengthening their legal protection.
About the Author
D. V. PecheninRussian Federation
Daniil V. Pechenin, Master’s Student, IT-Law Master’s Course
References
1. Bolotaeva OS. Biometric personal data as a means of individualization of an individual. Law and State: Theory and Practice. 2024;8(236). (In Russ.).
2. Dobrobaba MB. The concept of personal data: the problem of legal certainty. Courier of Kutafin Moscow State Law University (MSAL). 2023;2:42-52. (In Russ.). DOI: 10.17803/2311-5998.2023.102.2.042-052.
3. Kovalev IP. Legal regulation of the protection of personal human rights when using artificial intelligence technologies. Bulletin of the Moscow University named after S.Yu. Witte. Series 2, Legal Sciences. 2024;1(41).
4. Kuteinikov DL, Izhaev OA, Alekseevich LV, Zenin SS. Privacy in the realm of Artificial Intelligence Systems Application for Remote Biometric Identification. Lex russica. 2022;75(2):121-131. (In Russ.).
5. Litvin II. Features of the collection, processing and protection of personal data by artificial intelligence. Bulletin of the Ural law institute of the Ministry of the interior of Russia. 2021;4. (In Russ.).
6. Mosechkin IN. Deepfake technologies and biometric data: areas of criminal law regulation. Vestnik of Saint Petersburg University. Law. 2025;1:95-110. (In Russ.).
7. Novokshonova NA. Digital identification of a citizen: modern challenges. Bulletin Chelyabinsk State Univesity. Law. 2025;2. (In Russ.).
8. Platonova NI. Modern approach to understanding personal data. Law and Modern States. 2017;5. (In Russ.).
9. Selyuk AS. Protection of personal data in the framework of the use of artificial intelligence technologies. Agrarian and Land Law. 2025;4. (In Russ.).
10. Zharova AK. Deepfake technologies: social and legal risks of violation of a person’s privacy and legal decisions. Law and Order: History, Theory, Practice. 2025;2(45).
11. Zheludkov MA, Alekseeva AP. Ensuring the protection of biometric personal data from criminal use. Vestnik of the St. Petersburg University of the Ministry of Internal Affairs of Russia. 2025;2(106):159-169. (In Russ.).
12. Zhuzhgina AA, Solovyova DD. Legal regulation of the synthesis of human voice using artificial intelligence technologies. Vestnik of Lobachevsky University of Nizhni Novgorod. 2024;5. (In Russ.).
Review
For citations:
Pechenin D.V. Consent for Processing Biometric Personal Data by Generative AI: Practical Implementation Problems. Russian Law Online. 2026;(2):14-25. (In Russ.) https://doi.org/10.17803/2542-2472.2026.38.2.014-025
JATS XML