Topic · 12 stories
Biometrics: fingerprints, face data and news
In short
Biometrics are body-based identifiers such as fingerprints, faces, irises and voices, used to confirm or establish who someone is. In 2026 companies and governments collect them more widely: Anthropic added face verification for flagged Claude accounts, the FBI wants its biometric database exempted from parts of the Privacy Act, and the EU data protection supervisor warns that the Europol overhaul would put non-suspects' fingerprints in a police database. A password can be changed after a leak, a face cannot, which is why the disputes are about who holds the data and on what legal basis.
What is biometrics
Biometrics are measurable traits of a person’s body or behaviour, such as fingerprints, face shape, irises, voice or the way someone types, used to confirm or establish who that person is. A system converts the trait into a digital template, stores it, and compares it with a new measurement. It does this for one of two purposes: verification (“is this the person they claim to be?”) or identification (“who is this?”). Verification is usually about your own phone; identification is about databases held by companies and states.
Biometrics differ from passwords in one respect that explains most disputes: you cannot change them. A leaked password is reset, a leaked face or fingerprint is not. For that reason regulators treat biometric data as sensitive, and its collection draws more fights than collecting an email address. For the password side, see password security.
What are biometrics on a phone and how do I turn them off
Biometrics on a phone mean unlocking the device, approving payments and signing in to apps with a fingerprint or face scan instead of a passcode. Apple describes its version in its Face ID support page (checked 10 October 2026). The TrueDepth camera projects invisible dots and captures an infrared image, and the Secure Enclave compares the result with your enrolled face data. Face ID data stays on the device and is not backed up to iCloud.
To stop using it, open Settings, go to Face ID & Passcode and turn off iPhone Unlock. The Reset Face ID option deletes the stored face data from the device. The page does not describe Touch ID steps.
Is biometric data protected by law
Yes: in the EU it is a special category of data, and some US states have dedicated laws. GDPR Article 4(14) defines biometric data as personal data from specific technical processing of physical, physiological or behavioural traits that allows or confirms unique identification, such as facial images or fingerprint data. Article 9(1) prohibits processing it to uniquely identify a person, and paragraph 2 lists exceptions, including explicit consent (per the GDPR text on EUR-Lex, checked 10 October 2026).
Disputes test the edges. On July 15, 2026 the Norwegian Data Protection Authority ordered SATS to change the legal basis for gym check-in photos after 26 complaints, 19 of them forwarded by Finland. The contractual-necessity basis under Article 6(1)(b) was wrong, the authority said, and the correct one is legitimate interests under Article 6(1)(f), which gives members a right to object under Article 21. SATS had told them it did not apply. The authority noted that gym access works with a membership card scan. It issued a reprimand and four orders, no fine, with a deadline of September 11, 2026.
In the US, Illinois’ Biometric Information Privacy Act requires written notice of collection, the purpose and retention period, and a written release. Customers of Walmart filed a class action over voiceprints collected on customer service calls. The complaint says an AI system creates a voiceprint each time a customer calls, without telling them the specific purposes beyond an automatic message mentioning business purposes including fraud prevention. Walmart’s privacy policy, updated June 18, 2026, says it collects biometrics such as voiceprints. The plaintiffs seek 1,000 to 5,000 dollars per violation. A Walmart spokesperson did not respond to a request for comment.
Which companies collect biometric data
Many do, mostly to separate humans from bots or to check age and identity. Anthropic published a privacy policy on June 8, 2026 that, from July 8, lets it ask consumer users for age or identity verification. It applies to Claude Free, Pro and Max, not Team, Enterprise or Platform accounts. Data collected includes government ID images, face photos or video and facial geometry templates, and the check is run by Persona Identities. The policy also lists “vital interests” as a legal basis, normally reserved for life-or-death situations, without explanation.
A spokesperson, Thariq Shihipar, said the requirement applies only to a small group of flagged accounts that can appeal through verification instead of losing access. Digital IDs and photocopies are not accepted. Illinois’ law sets 1,000 to 5,000 dollars per violation. More in Claude and age verification.
World takes the opposite approach: prove you are human without saying who you are. It made World ID available to robots running peaqOS. A machine requests a proof, World App presents a zero-knowledge proof, and the machine learns it is dealing with a unique human but gets no name or face. Automated traffic reached 53% of web requests in 2025, 40% of it malicious. World reports nearly 18 million people verified at an Orb in 160 countries; peaq reports more than 3.3 million machines with verified identities. The project co-founded by OpenAI CEO Sam Altman then raised 52.5 million dollars in a token sale led by Pantera Capital. Its Orbs depend on Nvidia chips, which World’s business chief calls limited in supply, and adoption has lagged.
How governments collect biometric data
Governments collect them at arrests, borders, immigration checks and licensing, then pool them in large databases. The FBI has built Next Generation Identification (NGI) since 2008: faces, fingerprints, iris scans and tattoos of tens of millions of people, gathered not only at arrests but also for immigration, background checks and state licensing. In September it proposed exempting NGI from parts of the Privacy Act, which would deny people the right to know what the bureau holds and remove its duty to correct records. EFF and scores of civil liberties groups filed comments against it, and the Government Accountability Office criticized the FBI for hiding the scope of its face recognition program. See also facial recognition.
In Europe the fight is over Europol. The European Data Protection Supervisor said in Opinion 18/2026 that the Commission’s June 24 proposal fails to protect biometric data of people with no criminal connection. Europol could process photographs and fingerprints for an unspecified, potentially indefinite period without adequate oversight. The EDPS names three problems: no clear necessity criteria, no retention periods, and a self-authorization route around prior EDPS approval. The budget would double to 3 billion euros for 2028-2034 and staff would double.
The EU is also finalizing the EBSP agreement with the Trump administration, under which US border control could screen EU travellers against biometric databases. The US said in 2022 that access to such databases would be required for visa-free travel. Talks began in 2022, the Council gave a mandate in December 2025, and a revised draft leaked in May 2026. EDRi argues the text departs from member states’ mandate and likely violates EU data protection law.
Biometric databases are also targets. Kaspersky’s GReAT team disclosed on July 16 that the GoSerpent backdoor had looted police and biometric data across Southeast Asia for five years. Kaspersky assesses a probable but unconfirmed link to TetrisPhantom and has not attributed the campaign to any state.
Can AI read images from brain scans
Yes, in a lab and with errors. Weizmann Institute researchers led by Michal Irani built an AI tool that predicts what a person is looking at from brain scans and recreates the image with a diffusion model. They trained it on public scans of eight subjects and used a reverse encoder to generate synthetic training data. It sometimes fails: a dog in a bathtub came back as a goat. The technique needs large, expensive fMRI machines, but Marcello Ienca of the Technical University of Munich said a wearable EEG version would be a game changer that could let a company pull brain information without consent.
What it means for you
- Before handing over a face image, fingerprint or voice, find out who stores it, for how long, and whether you can object. In the EU you have GDPR rights to ask.
- Phone unlock keeps the template on the device (for Face ID, per Apple); uploading a scan to a service gives it to someone else.
- If a service asks for an ID and a selfie, check whether it runs the check itself or through a third party, and what its policy says about deletion.
- Keep a password or hardware key on important accounts, because you cannot reset a biometric after a leak.
Still open: whether the FBI gets its NGI exemption, what the Europol overhaul looks like after the EDPS criticism, whether the EBSP agreement is signed as drafted, and how the Chicago court treats the Walmart claims.
Key facts
- Weizmann Institute researchers built an AI tool that reconstructs what a person is looking at from brain scans. It was trained on scans of eight people and still needs large, expensive fMRI machines. (source)
- The FBI proposed exempting its NGI biometric database (faces, fingerprints, irises, tattoos of tens of millions of people) from parts of the Privacy Act, incl. the right to see and fix records. (source)
- Norway's data authority ordered gym chain SATS to change the legal basis for check-in photos and honor members' right to object. Reprimand and four orders, no fine; deadline 11 September 2026. (source)
- The EDPS said in Opinion 18/2026 that the Commission's Europol proposal fails to protect biometric data of people with no criminal link. Europol's budget would double to 3 billion euros by 2034. (source)
- Walmart customers filed a class action in Chicago under Illinois BIPA, alleging an AI system creates a voiceprint on every customer service call. They seek 1,000 to 5,000 dollars per violation. (source)
- World, the iris-scanning ID project co-founded by Sam Altman, raised 52.5 million dollars in a Worldcoin token sale led by Pantera Capital. Adoption has lagged; staff were cut in June. (source)
- The Commission is finalizing the EBSP agreement with the Trump administration that would let US border control screen EU travellers against biometric databases. EDRi says it likely violates EU law. (source)
- Anthropic's privacy policy, effective 8 July, lets it ask consumer Claude users for a government ID and a selfie. Persona runs the check, and facial geometry templates may count as biometric data. (source)
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Timeline
- AI reconstructs images people see from brain scans, raising consent worries Privacy
- FBI moves to exempt biometric mega-database from Privacy Act rules Privacy
- World ID comes to robots, letting delivery machines verify humans without identity data Privacy
- Norway orders SATS to change check-in photo legal basis and honor objections Privacy
- EDPS warns Europol overhaul would put non-suspect biometric data in cross-border database Privacy
- Walmart faces class action over voiceprint collection under Illinois biometric law Privacy
- Sam Altman’s Eye-Scanning ID Startup World Raises $52.5 Million Privacy
- EU Near Deal to Share Biometric Data with US for Visa-Free Travel Privacy
- GoSerpent Backdoor Looted Police and Biometric Data Across Southeast Asia for Five Years Security
- Anthropic Privacy Policy Now Collects Biometric Data From Flagged Claude Users Privacy
FAQ
What is biometrics?
Biometrics are measurable body or behaviour traits, such as fingerprints, face shape, irises, voice or typing pattern, used to confirm or establish who someone is. A system turns the trait into a digital template and compares it with a stored one, either to verify a claimed identity or to identify an unknown person.
How do I turn off biometrics on an iPhone?
Open Settings, go to Face ID & Passcode and turn off iPhone Unlock. Reset Face ID deletes your Face ID data from the device. This is Apple's own description (checked 10 October 2026); the page does not cover Touch ID.
Is biometric data protected by law?
Yes. Under GDPR Article 9, processing biometric data to uniquely identify a person is prohibited unless an exception applies, such as explicit consent. Illinois' BIPA requires written notice and consent, with damages of 1,000 to 5,000 dollars per violation, the amount sought in the Walmart suit.
Which companies collect biometric data?
Many do, mostly to tell humans from bots or to check age and identity. Anthropic can ask flagged Claude Free, Pro and Max users for an ID image and face photo or video, checked by Persona Identities, and World verifies people at its Orb and issues World ID, which it now offers to robots on peaqOS.
Can governments collect my biometrics?
Yes, at arrests, borders, immigration checks and licensing. The FBI's Next Generation Identification database holds faces, fingerprints, iris scans and tattoos of tens of millions of people, and in September 2026 the FBI proposed exempting it from parts of the Privacy Act.
Does Anthropic collect biometric data from Claude users?
Yes, from some users. Since 8 July 2026 Anthropic can ask Claude Free, Pro and Max users for a government ID and a selfie or video, processed by Persona. A spokesperson said it applies to a small group of accounts flagged for policy violations, who can appeal through identity verification.