ARLINGTON, Va. — The Department of the Army has published Army Regulation 25-99, “Biometric Program and DoD Biometric Data Management”, effective July 21, 2026, to establish modernized policies, requirements, and responsibilities for operation, use, and protection of biometric data applicable to the U.S. Army Biometric Program and Department of War (DoW) biometric data management.
Determining identity has never been more important to the security of our nation. Defense Forensics and Biometrics Agency (DFBA) maintains the DoW’s authoritative biometric database, used by all military services. It stores biometric data collected during military operations and shares this information with strategic partners. Biometrics—fingerprints, iris pattern, facial recognition, hand geometry, palm print, voice recognition, keystroke recognition, and gait—provide certainty of identification. Identification of persons of interest, adversaries, and military threat actors is possible by maintaining DoW’s database and making its content discoverable by the appropriate agencies.
The Army was lacking a comprehensive policy document governing coverage of the full range of biometric operations: collection, storing, sharing, and exploitation of biometrics data in support of military operations; as well as clear delineation of roles and responsibilities associated with the Army’s biometric program. The new Army regulation provides policy and guidance that enable Army personnel: to employ biometric capabilities across the operational continuum and warfighting functions, to ensure the storage and handling of identity information is in accordance with privacy law and policy, to reduce risk to Army personnel and missions, and to optimize the Army’s biometric enterprise capabilities. The capabilities in the U.S. Army Biometric Program are essential for the whole-of-government approach to combat near-peer threats and violent extremist organizations during all phases of Army and joint operations.
The regulation applies to all actions for those Army personnel involved in all of the data’s life cycle—collection, storage, and sharing of identity information. It covers all of the Army’s biometric enterprise capabilities: those who collect biometrics, the system that stores the data, offices that maintain system operations, agreements negotiated to share the data with partners, operators who review and conclude matches or nonmatches, and more. It also applies to the retention, storage, and security management of the data held in the Army’s biometric repository in accordance with privacy laws and regulations.
To support the joint force, biometrics play an important and critical role in identifying adversaries and denying them anonymity. The regulation dictates that identity information will be exchanged between Army forces and will be integrated and interoperable to the fullest extent possible to enable operations. The collecting, matching, storing, and sharing of biometrics are critical capabilities supporting tactical and operational decision making across full range of military operations for DoW warfighting, intelligence/counterintelligence, law enforcement, force protection, screening and vetting, security, homeland defense, counterterrorism, business, and information environment mission areas.
This Army regulation leads to an evolution in Army biometric and related activities while also ensuring compliance with law and policy; protecting privacy and civil liberties of those individuals whose data is collected. Army Regulation 25-99 “Biometric Program and DoD Biometric Data Management” can be accessed here on the Army Publishing Directorate’s website using a common access card.