Findings
8 Biometric data
Illinois asks for written notice, the purpose and term in writing and a written release before the first collection; Texas for notice and consent and destruction within a year of the purpose ending; the EU and UK for an Art. 9 condition as well as a basis; the Netherlands allows biometric identification only for a weighty access need, not time registration.
For the DPO and counsel: Which written notice, release, consent or Art. 9 condition covers each person whose fingerprint, face or hand is taken, and what is the destruction date?
Where it comes from, location by location
- Biometric datastatutory requirementBefore the first collection: written notice that a biometric identifier is collected, the specific purpose and term in writing, and a written release; a public retention schedule with destruction when the purpose is met or within three years of the last interaction; no disclosure without consent. BIPA s 15(a)BIPA s 15(b)(1)BIPA s 15(b)(2)BIPA s 15(b)(3)BIPA s 15(d)
- Biometric datastatutory requirementInform and obtain consent before capture; destroy within a reasonable time and at the latest one year after the purpose ends, which for an employer's security identifiers is the end of employment. Texas CUBI 503.001(b)(1)Texas CUBI 503.001(b)(2)Texas CUBI 503.001(c)(3)Texas CUBI 503.001(c-2)
- Biometric datastatutory requirementBiometric data used to identify a person needs an Art. 9 condition as well as an Art. 6 basis; a non-biometric alternative without restriction. GDPR Art. 9EDPB video guidelines para 5.1(a)
- Biometric datastatutory requirementBiometric data for physical and logical access only within the safeguard measures of the Code. Italian Privacy Code Art. 2-septies(7)
- Biometric datastatutory requirementA lawful basis and an Art. 9 condition, a documented reason why biometrics are necessary, an assessment before processing, and a non-biometric alternative without disadvantage. UK GDPR Art. 9ICO monitoring guidance para 4.1ICO monitoring guidance para 4.2ICO monitoring guidance para 4.3
- Biometric datastatutory requirementBiometric data is sensitive personal information; staff can limit its use. (when you say the business meets the CCPA thresholds) CCPA 1798.121