11.3 Privacy Issues Around Biometrics: Facial, Voice, Fingerprint, and DNA Data

Key Takeaways

  • A compromised biometric cannot be revoked or reissued, so systems should store protected templates rather than raw samples and avoid central databases where possible.

  • 1:1 verification compares a person to their own enrolled template; 1:N identification searches a whole gallery, and false matches grow quickly with gallery size.

  • Cancelable biometrics, biometric salting, and fuzzy extractors make templates revocable or derive keys from noisy readings without storing raw biometrics.

  • Illinois BIPA requires a public retention policy, written notice, and a written release before collection, bans profiting from biometrics, and provides statutory damages of $1,000 per negligent and $5,000 per intentional or reckless violation.

  • Under GDPR Article 9, biometric data used to uniquely identify a person is special-category data, and large-scale processing of it requires a DPIA under Article 35(3)(b).

Last updated: October 2026

11.3 Privacy Issues Around Biometrics: Facial, Voice, Fingerprint, and DNA Data

Quick Summary: Biometric data (faces, fingerprints, voices, irises, DNA) is permanent and directly tied to the body, so a compromised template cannot be reset like a password. The BoK asks technologists to understand privacy issues around facial recognition, speech recognition, fingerprint identification, and DNA. The key engineering choices are local 1:1 verification instead of central 1:N identification, template protection, strict consent and retention under laws such as Illinois BIPA and GDPR Article 9, and avoiding raw sample storage altogether.

Biometrics occupy a special place in privacy engineering because they connect digital records to a person's body. They are increasingly used for phone unlock, payments, building access, workforce time clocks, airport boarding, and identity verification, and also for surveillance.


Biometric Data Fundamentals and Irrevocability

Biometric data refers to personal data resulting from specific technical processing relating to the physical, physiological, or behavioral characteristics of a natural person, which allow or confirm the unique identification of that natural person.

  • Physiological Modalities: Fingerprints, facial geometry, iris patterns, retinal vasculature, palm veins, hand geometry, and DNA.
  • Behavioral Modalities: Voice acoustics, keystroke dynamics, signature dynamics, and gait patterns.

The Immutability Crisis

The fundamental challenge of biometric privacy is immutability:

TRADITIONAL CREDENTIALS (Revocable):           BIOMETRIC CREDENTIALS (Immutable):
+---------------------------------------+       +---------------------------------------+
| User Password / API Private Key       |       | User Fingerprint / Iris / Face Mesh   |
|               |                       |       |               |                       |
| [Security Breach / Database Leak]     |       | [Security Breach / Database Leak]     |
|               v                       |       |               v                       |
| Revoke Old Key -> Issue Fresh Key     |       | CREDENTIAL CANNOT BE REVOKED!         |
| System returns to secure baseline.    |       | Biological trait is permanently       |
|                                       |       | compromised across all global systems!|
+---------------------------------------+       +---------------------------------------+

If an attacker steals an alphanumeric password, the system generates a new password. If an attacker extracts an individual's unencrypted fingerprint minutiae map or high-resolution facial coordinate template, that credential cannot be revoked or replaced. The user cannot be issued a new face or different fingers. The compromise remains permanent for the remainder of the individual's life, creating permanent exposure to credential replay, impersonation, and cross-database correlation.

Raw Biometric Samples vs. Templates vs. Feature Vectors

Privacy engineering requires maintaining clear technical distinctions across stages of biometric processing:

  1. Raw Biometric Sample: The direct analog-to-digital capture from a physical sensor (e.g., an uncompressed 500 DPI fingerprint bitmap, a 4K facial photograph, a raw WAV audio recording). Raw samples contain extensive secondary data: facial photographs reveal race, approximate age, emotional expression, and physical health markers; retinal scans reveal diabetes and vascular disease. Storing raw biometric samples is an egregious violation of data minimization.
  2. Feature Extraction: Algorithmic processing that extracts distinctive geometric or mathematical landmarks from the raw sample. In fingerprints, algorithms isolate minutiae points (ridge endings and bifurcations). In facial recognition, deep convolutional neural networks (CNNs) map facial features into a dense, high-dimensional feature vector (e.g., a 128-dimensional or 512-dimensional floating-point embedding vector representing distances between facial landmarks, jawline curvature, and nasal bridge depth).
  3. Biometric Template: The mathematical representation of extracted features formatted for storage and comparison. If a template is stored in plaintext, adversaries can execute inversion attacks—reconstructing synthetic facial images or 3D-printed synthetic fingerprint molds directly from the mathematical template.

Biometric System Architectures: 1:1 Verification vs. 1:N Identification

A critical architectural distinction in privacy engineering is the operational difference between 1:1 Verification and 1:N Identification:

Dimension1:1 Verification (Authentication)1:N Identification (Surveillance / Recognition)
System Question"Are you who you claim to be?""Who are you? (Does this person match anyone in the database?)"
Identity ClaimProvided upfront by user (e.g., username, employee ID card).No claim provided; system searches an unconstrained probe against all records.
Database ArchitectureLocal, decentralized storage (e.g., on-device Secure Enclave).Centralized gallery database containing NN enrolled biometric templates.
Computational ScopeA single comparison: Tprobe≈TclaimedT_{\text{probe}} \approx T_{\text{claimed}}.NN pairwise comparisons: Tprobe≈TiT_{\text{probe}} \approx T_i for i=1…Ni = 1 \dots N.
Privacy Risk ProfileLow: User maintains physical custody of their reference template.Severe: Mass surveillance, function creep, compounding false-positive rates.
Typical Use CasesSmartphone unlock (Apple FaceID), physical door access tokens.Public CCTV facial recognition, police mugshot searches, border checkpoints.

The Compounding Error Rate in 1:N Systems

In a 1:1 verification system, the False Match Rate (FMR)—the probability that a probe matches an incorrect enrolled template—can be calibrated to a small value (e.g., α=0.001\alpha = 0.001, or 0.1%).

However, in a 1:N identification system searching an enrolled gallery of size NN, the probability of generating at least one false positive match across the gallery (Pfalse_matchP_{\text{false\_match}}) compounds exponentially:

Pfalse_match=1−(1−α)NP_{\text{false\_match}} = 1 - (1 - \alpha)^N

If a city deploys a public surveillance camera searching a gallery of N=100,000N = 100,000 individuals with a 1:1 FMR of α=0.0001\alpha = 0.0001 (0.01%):

Pfalse_match=1−(1−0.0001)100000=1−(0.9999)100000≈1−0.0000454≈99.995%P_{\text{false\_match}} = 1 - (1 - 0.0001)^{100000} = 1 - (0.9999)^{100000} \approx 1 - 0.0000454 \approx 99.995\%

Searching an unconstrained probe against a large gallery produces an almost guaranteed false positive, resulting in wrongful detentions, misidentifications, and severe chilling effects on civil liberties. Furthermore, deep learning facial models exhibit statistically documented demographic bias, exhibiting substantially higher False Match Rates and False Non-Match Rates (FNMR) against women and individuals with darker skin tones.


Template Protection Mechanisms

To prevent stolen templates from exposing raw biometrics or being linked across multiple systems, privacy engineers deploy biometric template protection:

1. Cancelable Biometrics

Cancelable biometrics applies a non-invertible, user-specific mathematical transformation to the feature vector prior to storage:

Tstored=f(Traw,K)T_{\text{stored}} = f(T_{\text{raw}}, K)

Where ff is a non-linear distortion function (e.g., non-invertible geometric morphing, bio-hashing, or random projection) and KK is a user-specific secret key. During verification, the fresh probe is transformed using the identical function and key before comparison.

  • Revocability: If a stored template TstoredT_{\text{stored}} is compromised, the organization revokes key KK and issues a new key K′K', generating a new, uncorrelated template Tstored′T'_{\text{stored}} from the same physical finger or face.
  • Unlinkability: Different services utilize different keys (K1,K2K_1, K_2), preventing databases from cross-matching templates to track individuals across platforms.

2. Biometric Salting

Biometric salting blends user-specific cryptographic salts into the feature vector coordinates before passing the data through a one-way transformation. While salting prevents dictionary and cross-matching attacks, it requires maintaining the confidentiality of the salt; if the salt is exposed, the underlying feature space may be vulnerable to brute-force inversion.

3. Fuzzy Extractors and Fuzzy Vaults

Biometric measurements are inherently noisy: two consecutive scans of the same finger never produce identical digital bits due to skin elasticity, sensor angle, and pressure. Traditional cryptographic hash functions (such as SHA-256) cannot be applied to biometrics because even a 1-bit difference in the input produces a completely different hash output (the avalanche effect).

To solve this, cryptographers developed Fuzzy Extractors:

ENROLLMENT:                                            VERIFICATION:
+-------------------------------------------+          +-------------------------------------------+
| Raw Biometric Input W                     |          | Fresh Biometric Probe W' (noisy)          |
|        |                                  |          |        |                                  |
|        v                                  |          |        v                                  |
| [Fuzzy Extractor Generation: Gen(W)]      |          | [Fuzzy Extractor Reproduction: Rep(W', P)]|
|        |                                  |          |        |                                  |
|        +------------+                     |          |        | (Evaluates Error-Correcting Code)|
|        |            |                     |          |        v                                  |
|        v            v                     |          | Reconstructed Cryptographic Key R         |
| Secret Key R    Helper Data P             |          | (Exact match to R if dist(W, W') <= t)    |
| (High-entropy   (Publicly stored,         |          +-------------------------------------------+
|  uniform key)    leaks zero info about W) |                          ^
+-------------------------------------------+                          |
                      |                                                |
                      +----------> Public Helper Data P ---------------+
  • Generation Phase (Gen)(\text{Gen}): Takes a noisy biometric reading WW and produces a uniform cryptographic key RR and a public string of helper data PP: Gen(W)→(R,P)\text{Gen}(W) \to (R, P)
  • Reproduction Phase (Rep)(\text{Rep}): Given a fresh, noisy biometric probe W′W' and the helper data PP, the reproduction algorithm reconstructs the exact original cryptographic key RR, provided the distance metric between WW and W′W' falls within an error tolerance threshold tt (d(W,W′)≤td(W, W') \le t): Rep(W′,P)→R\text{Rep}(W', P) \to R

The helper data PP uses error-correcting codes (such as Reed-Solomon or BCH codes) to absorb measurement noise. The security guarantee is that RR stays close to uniformly random even to someone who sees PP; PP itself does leak some information about WW, so the design must limit that entropy loss, and templates should still be stored with access controls.

Loading diagram...
Biometric Template Protection vs. 1:1 Verification and 1:N Identification

Statutory and Regulatory Boundaries

Because biometric data is immutable, regulatory authorities impose severe statutory penalties for unauthorized collection, storage, or commercialization.

1. Illinois Biometric Information Privacy Act (BIPA - 740 ILCS 14/)

Enacted in 2008, the Illinois Biometric Information Privacy Act (BIPA) is the most litigated and stringent biometric privacy statute in the United States. BIPA establishes strict operational mandates for private entities:

  • Section 15(a) Retention and Destruction Schedule: Entities must develop and publish a publicly available written policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information when the initial purpose for collection has been satisfied, or within 3 years of the individual's last interaction with the entity, whichever occurs first.
  • Section 15(b) Written Informed Consent: No private entity may collect, capture, purchase, or otherwise obtain a person's biometric identifier without first: (1) informing the subject in writing that biometric data is being collected; (2) stating the specific purpose and duration for which the data will be used; and (3) receiving a signed, written release from the subject.
  • Section 15(c) Total Ban on Profiting: Private entities are strictly prohibited from selling, leasing, trading, or otherwise profiting from an individual's biometric data under any circumstances.
  • Section 15(d) Disclosure Restrictions: Biometrics cannot be disclosed or redisclosed without valid consent, unless required by valid warrant or subpoena.
  • Section 20 Private Right of Action: Unlike almost all other US privacy laws, BIPA provides an explicit private right of action for aggrieved individuals without requiring proof of actual financial injury (Rosenbach v. Six Flags Entertainment Corp., 2019). Statutory liquidated damages are set at:
    • $1,000 for each negligent violation.
    • $5,000 for each intentional or reckless violation.

Statutory Update (2024 Reform): Following the Illinois Supreme Court ruling in Cothron v. White Castle System, Inc. (holding that damages accrue on a "per-scan" basis rather than per individual), the Illinois legislature enacted amendments capping statutory damages to one recovery per person for the same repeating technological violation, preserving substantial class-action liability while preventing catastrophic theoretical liabilities.

2. Other State Frameworks (Texas CUBI and Washington State)

  • Texas Capture or Use of Biometric Identifier Act (CUBI): Mandates informed consent and imposes statutory penalties of up to $25,000 per violation, enforced exclusively by the Texas Attorney General (no private right of action).
  • Washington State (RCW 19.375): Regulates the commercial use of biometric identifiers, prohibiting enrollment into commercial databases without notice and consent.

3. GDPR Article 9: Special Category Biometric Data

Under GDPR Article 9(1), the processing of "biometric data for the purpose of uniquely identifying a natural person" is categorized as special category personal data and is prohibited by default. Processing is lawful only if the organization satisfies one of the specific exceptions in Article 9(2):

  • Explicit consent (Article 9(2)(a)).
  • Necessary for carrying out obligations in employment or social security law (Article 9(2)(b)).
  • Necessary for reasons of substantial public interest (Article 9(2)(g)).

Under GDPR Article 35(3)(b), large-scale processing of special category data, including biometric identification, requires a Data Protection Impact Assessment (DPIA). If the DPIA shows a high residual risk that the controller cannot mitigate, Article 36 requires prior consultation with the supervisory authority.


Modality-Specific Issues the BoK Mentions

ModalityPrivacy IssuesEngineering Responses
Facial recognitionCan work at a distance without the person's knowledge; enables tracking across cameras; documented demographic error differencesAvoid 1:N searches; on-device matching; opt-in enrollment; demographic accuracy testing
Speech and voice recognitionRecordings reveal health, emotion, and bystanders' speech; voices can be clonedProcess commands on device; delete raw audio; voice biometrics only with liveness checks
Fingerprint identificationLatent prints can be lifted; central databases are high-value targetsOn-device templates in secure hardware; no raw image storage
DNAReveals relatives' information, ancestry, and health predispositions; cannot be changedSeparate consent for research and law-enforcement matching; strong access controls; minimal retention

DNA shows how biometric data affects people who never enrolled. Investigators have used genealogy databases to identify suspects through distant relatives, and the 2023 breach of a consumer genetics company exposed ancestry details of millions of customers through a "relatives" feature, even though most were not directly compromised.

Newer Rules to Watch

  • Colorado amended its privacy act in 2024 (HB 24-1130, effective July 1, 2025) to add biometric-specific duties, including a written retention and deletion policy and limits on requiring employees' biometric data.
  • The EU AI Act prohibits untargeted scraping of facial images to build recognition databases and, with narrow exceptions, real-time remote biometric identification in public spaces for law enforcement; it also prohibits emotion recognition in workplaces and schools.
  • The FTC's 2023 action against Rite Aid banned the retailer from using facial recognition for surveillance for five years after its system produced false matches that disproportionately affected women and people of color.
Test Your Knowledge

Why does the fundamental nature of biometric credentials create far greater long-term privacy and security exposure than traditional alphanumeric passwords or cryptographic private keys when a data breach occurs?

A

A compromised biometric cannot be revoked or reissued, so exposure is permanent.

B

Biometric scanners require continuous internet connectivity to function and cannot operate in offline environments.

C

Biometric templates occupy substantially more storage bytes in relational databases than SHA-256 password hashes.

D

Biometric credentials cannot be encrypted at rest or in transit because of hardware processor limitations in sensors.

Test Your Knowledge

An enterprise deploys automated facial recognition cameras at employee entrance turnstiles in Chicago, Illinois. Under the Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14/), which compliance mandate is strictly required before capturing any employee facial geometry templates?

A

The employer must conduct an annual public referendum with municipal voters approving the use of facial recognition technology.

B

The employer must publish a written policy establishing a retention schedule and destruction guidelines, inform subjects in writing of the specific purpose and duration, and obtain an executed written release.

C

The employer must notify the local municipal police department within 48 hours of installing the surveillance hardware.

D

The employer must ensure all biometric feature vectors are mirrored across at least three cloud availability zones within 10 days of capture for resilience.

Test Your Knowledge

A gym chain wants members to check in with their fingerprints. Which architecture best limits the privacy risk?

A

Email fingerprint images to the branch manager for manual comparison at each visit.

B

Use 1:1 matching against a protected template held on the member's card, device, or a local module.

C

Collect fingerprints without notice, because members already provide their names and addresses.

D

Store high-resolution fingerprint images in a central cloud database so that any branch can identify members by searching all records.

Sections you finish are checked off in the contents.