Privacy and Civil Liberties

IBIA is committed to protecting individual privacy and civil liberties while enabling the responsible use of biometric technologies to enhance security and convenience.

Background

As biometric technologies become increasingly embedded in everyday life—from unlocking smartphones and authorizing financial transactions to securing borders and aiding criminal investigations—questions about the collection, use, storage, and sharing of biometric data have moved to the forefront of public policy debates.

Because biometric characteristics such as fingerprints, facial features, and iris patterns are immutable and uniquely tied to individuals, they represent a particularly sensitive category of personal data that demands strong protections. At the same time, biometric technologies serve as one of the most effective tools for protecting privacy, preventing identity theft, and ensuring that only authorized individuals can access sensitive information and systems.

Striking the right balance between leveraging the security and convenience benefits of biometrics and safeguarding individuals’ rights requires thoughtful, evidence-based policies rather than blanket restrictions that can undermine both privacy and public safety.

IBIA Position

IBIA Position

IBIA is a strong advocate for the protection of individual privacy in the development and use of biometric technologies. IBIA has published Privacy Policy Principles that provide general guidelines for the commercial use of biometric technologies and data, and encourages all implementers and operators to develop and publish privacy policies incorporating these principles.

 

IBIA’s key positions on this issue include:

Implementers and Operators Should Adopt Privacy Policy Principles for Biometric Data

IBIA recommends that implementers and operators of commercial biometric technology adopt privacy policies built on established information privacy principles, including:

  • Collection limitation (identifying the type of biometric data captured, its purpose, and the retention period)
  • Purpose specification (disclosing why information is being captured and whether it will be used for other purposes)
  • Data quality (maintaining accuracy and providing mechanisms for correcting errors)
  • User limitation (permitting only authorized individuals and applications to access biometric data)
  • Security safeguards (protecting data through encryption, anonymization, and robust cybersecurity practices)
  • Openness (providing individuals with the ability to request a record of their data)
  • Accountability (maintaining and independently reviewing audit logs)
  • Problem resolution and redress (establishing clear processes for individuals to raise concerns and seek remedies such as revocation, deletion, or change of biometrics used for identification)
Biometric Technology Users Should Provide Notice, Consent, and Transparency

Biometric technology users should communicate with individuals about what biometric information is being collected, what it will be used for, with whom it will be shared, and for how long it will be retained. Notice and consent should be provided for all but a narrowly defined set of national security and public safety situations, and all communications should be in plain, accessible language. Public-sector users should additionally notify the public of planned biometric technology procurements and deployments and provide opportunities for public comment.

Biometrics Should be Used as a Privacy-Enhancing Technology

Far from being inherently at odds with privacy, biometrics are among the most effective tools available for protecting personal information. By binding access to the individual rather than to transferable credentials like passwords or cards, biometric authentication helps prevent unauthorized access, identity theft, and fraud—safeguarding the very privacy interests that critics of the technology claim to defend.

Privacy Does Not Equal Anonymity

IBIA draws an important distinction between privacy and anonymity. It is possible to retain privacy without being anonymous, and it is possible to be anonymous while still having one's privacy invaded. There are numerous federal laws defining and protecting various aspects of privacy; however, criminals, terrorists, and adversarial intelligence agents thrive on anonymity. Policies should protect privacy without granting anonymity to those who would exploit it.

IBIA Supports Federal Legislation Over a Patchwork of State Laws

IBIA supports the development of uniform federal privacy legislation for biometric data that would preempt the growing and inconsistent patchwork of state laws. State-level approaches such as the Illinois Biometric Information Privacy Act (BIPA) have created compliance difficulties, particularly for the commercial sector, and in practice have done little to protect the public. A uniform federal framework would establish safe, reasonable, and consistent rules for the use of biometrics, including facial recognition, across all sectors and jurisdictions.

All Key Issues

The Matching Process:

This process answers the question, “Are you who you claim to be?” The user makes an identity claim (e.g., by providing a username), and the system performs a one-to-one comparison between their live biometric template and the single template stored for that specific identity. This is used for authentication, such as unlocking a device or accessing a secure account. 

This process answers the question, “Who are you?” The system performs a one-to-many comparison, searching an entire database of stored templates to find a match for the user’s live biometric template. This is used in applications like law enforcement to identify a suspect from a crime scene fingerprint, or in national ID programs to prevent duplicate registrations.