AR 25-99 governs the U.S. Army Biometric Program and DoD Biometric Data Management, including biometric data throughout its lifecycle.
View AR 25-99 on armypubs.army.mil
AR 25-99 addresses biometric activities and operations, biometric data management, and coordination across Army, DoD, and partner organizations. It requires secure access to personally identifiable information and establishes planning and approval requirements for biometric capabilities.
Applies to: This regulation establishes policies, duties, responsibilities, and relationships applicable to the U.S. Army Biometric Program and Department of Defense (DoD) Biometric Data Management.
Most biometric data is considered personally identifiable information (PII). PII collected and used in the execution of this regulation will be maintained under secure access to prevent any unauthorized use, disclosure, or loss. (paragraph 3-1)
The CONOPS will define the objectives of the capability and, at a minimum, will detail the information being collected, the population focus of the collection, the purpose and use for collecting the information, the organizations and personnel performing the collection, and the length or time frame of collection activities. (paragraph 3-1)
The CONOPS will be approved by the first general officer or member of the Senior Executive Service in the chain of command following review by the servicing staff judge advocate. (paragraph 3-1)
The Army will use biometric, biographic, behavioral, and contextual data to identify physiological and/or behavioral characteristics and differentiate one individual from another in support of national and military objectives consistent with United States Army, DoD Capstone Concept of Operations for Employing Biometrics in Military Operations, dated 10 June 2012. (paragraph 3-2)
The DFBA Director oversees common storage, matching, and sharing activities of biometric data collected as a part of military operations to support DoD Components and/or Joint Force Commanders.