...If the hash is all that is transmitted, then it would not be personal information...

The GDPR defines personal data as data which can uniquely identify a person, either on its own or with other information which the holder of the data could reasonbly expect to have available to him.

Biometric data such as this hash is also considered 'sensitive' personal data under the GDPR, and is subject to a number of required additional protections....

