Emotion Recognition AI under the GDPR and AI Act

Emotion Recognition Systems (“ERS”) are AI systems designed to identify or infer a person’s emotions or intentions from biometric signals. Depending on the system, those signals may include facial movements, or physiological indicators such as heart rate. The systems have been marketed for uses ranging from healthcare to recruitment, employee monitoring and education.

However, these uses have prompted significant scientific, legal and ethical concerns. The main issue is that an observable expression does not necessarily reveal a person’s internal emotional state. When uncertain inferences are used to assess a person, the consequences may extend beyond inaccuracy to discrimination, intrusive monitoring and interference with individual autonomy.

In Europe, ERS are governed by the General Data Protection Regulation (GDPR) which regulates the processing of personal data used and generated by these systems. Also, the EU Artificial Intelligence Act (AI Act) which introduces more targeted rules, prohibitions, transparency duties and requirements for high-risk systems. Together, the regimes impose significant constraints, but important questions remain about their scope and practical application.

In July 2025, the Dutch Data Protection Authority described AI-based emotion recognition as “questionable and risky”. It highlighted the absence of scientific consensus, the possibility of inaccurate or discriminatory conclusions and the intrusive nature of monitoring faces. The regulator was particularly concerned about uses that could affect decisions in employment or education. Its intervention reflects a broader shift from treating emotion recognition as an experimental analytics tool towards viewing it as a technology capable of materially affecting privacy, equality and individual autonomy.

The GDPR

The GDPR does not expressly refer to emotion data, but its definition of personal data is sufficiently broad to capture many ERS inputs and outputs. Article 4(1) covers any information relating to an identified or identifiable person. In Nowak v Data Protection Commissioner, the Court of Justice of the European Union confirmed that subjective information, including assessments and, may constitute personal data where it relates to an individual by reason of its content, purpose or effect.

The treatment of biometric and health-related inputs requires greater care. A facial image or physiological measurement is not automatically special-category data. Under Article 9 GDPR, biometric data receives special protection where it is processed for the purpose of uniquely identifying a person. Physiological information

may constitute health data where it reveals information about an individual’s physical or mental health.

Controllers must identify an Article 6 lawful basis and, where special-category data is involved, a separate Article 9 condition. Consent may be difficult to rely upon in employment or educational settings because of the imbalance of power between the parties. Legitimate interests may also be difficult to establish where monitoring is intrusive, unexpected or capable of influencing significant decisions.

A data protection impact assessment is also likely to be required where ERS involve innovative technology, systematic monitoring or processing that presents a high risk to individuals. The assessment should address not only data security but also the system’s scientific validity, the possibility of discriminatory outcomes, the consequences of incorrect inferences and whether less intrusive alternatives are available.

Article 13 applies where personal data is collected directly from the individual, while Article 14 may apply to derived information that was not obtained directly from them. A controller may therefore need to explain both the collection of the underlying signals and the generation and use of emotional inferences.

Although the GDPR requires information about the purposes, data categories and, in appropriate cases, the logic and consequences of automated decision-making, it does not necessarily give an individual access to a detailed technical explanation of every inference. This creates a practical transparency gap. As a person may be told that their behavioural and biometric data is processed without understand which emotions were attributed and whether the output asserted was accurate.

The AI Act

Article 3(39) of the AI Act defines an emotion recognition system as an AI system intended to identify or infer the emotions or intentions of natural persons based on their biometric data. The definition therefore contains three central elements: there must be an AI system; it must identify or infer emotions or intentions; and it must do so using biometric data.

Article 5(1)(f) prohibits the use of such systems to infer emotions in workplaces and educational institutions, except where the use is intended for medical or safety reasons. It reflects both the disputed reliability of the technology and the unequal power relationships present in those environments. A breach may attract an administrative fine of up to EUR 35 million or 7% of worldwide annual turnover, subject to the Act’s proportionality rules.

Outside prohibited workplace and educational uses, emotion recognition systems are generally listed as high-risk under Annex III. This classification brings requirements relating to risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, and cybersecurity.

Following the EU’s 2026 AI Omnibus reforms, the high-risk requirements for stand-alone Annex III systems are scheduled to apply from 2 December 2027. This does not, remove the need to prepare gathering performance evidence, redesigning governance processes and negotiating appropriate contractual protections may require substantial lead time.

Article 50(3) requires deployers of emotion recognition systems to inform individuals who are exposed to them. That transparency obligation applies from 2 August 2026 and is not confined to systems classified as high-risk. It should be addressed alongside, rather than treated as a substitute for, the more extensive transparency requirements under the GDPR.

What Businesses Should Do Now

Organisations considering ERS should begin with a detailed assessment of the actual use case rather than the vendor’s label. They should determine whether the system infers an emotion or intention, whether it does so use biometric data, where it will be deployed and whether its output will influence a decision about an individual. In workplace and educational contexts, the starting point should be that emotion inference is prohibited unless a narrowly construed medical or safety exception can be demonstrated.

Due diligence should extend beyond ordinary technical and contractual review. Providers should be required to produce evidence of the system’s scientific basis, testing methodology, demographic performance and known limitations. A data-mapping exercise should identify the signals collected, the inferences generated, the lawful bases relied upon, any Article 9 data and the parties that receive or use the output. Organisations should also establish proportionate retention periods, restrict access and ensure that individuals receive meaningful information about the system’s operation and consequences.

Human oversight must be substantive; reviewers should have the authority and contextual information required to question an output. Emotional inferences should not determine high-impact decisions, including recruitment, disciplinary action or access to services. Without independent supporting evidence and a meaningful opportunity for the affected person to challenge the conclusion.

Contracts should allocate responsibility for regulatory classification, technical documentation, audit rights, performance monitoring, incident management and material changes to the system. Organisations should also establish a process for reviewing the use case as regulatory guidance, scientific evidence and the technology itself evolve.

Conclusion

Emotion recognition occupies an unusually difficult position at the intersection of data protection, AI governance and contested science. The GDPR provides a broad framework for regulating the personal data on which ERS rely, but its conventional concepts of lawful basis, transparency and automated decision-making do not resolve every difficulty created by uncertain emotional inferences. The AI Act responds more directly by prohibiting certain uses, classifying other systems as high-risk and requiring individuals to be informed when they are exposed to the technology.

The Dutch DPA’s intervention is a clear indication that regulators will not treat emotion recognition as an ordinary analytics feature. For businesses, compliance should therefore begin before procurement and should extend beyond documentation. The central question is whether its use is defensible, necessary and proportionate to the risks it creates. Where an organisation cannot prove the legitimate purpose of the system, it becomes a decision whether to deploy the system at all.

Andrea Motha, July 2026