Biometric Data

Biometric Data

Biometric data are measured values of physical or behavioral characteristics that can be used to identify a specific person — such as fingerprint, face, iris, or voice. Because, unlike a password, they cannot be changed, they are legally considered especially worthy of protection.

Biometric data are measured values of bodily characteristics that differ from person to person. Typical examples are the fingerprint, the shape of the face, the pattern of the iris in the eye, or the sound of the voice. Behavior can also be included, such as the way someone walks or types on a keyboard. Such characteristics can be used to recognize a person without them having to say or show anything. This is exactly what makes it practical — and at the same time sensitive. Because a password can be changed if it is stolen. A face cannot.

Why a stolen fingerprint is lost forever

The great advantage of biometric methods is convenience. The phone unlocks in a tenth of a second with a glance, no one has to remember a sequence of characters. At airports, too, electronic checks with facial matching are increasingly replacing checks by staff. For companies, this means shorter waiting times and lower personnel costs.

The disadvantage is finality. If a database of fingerprints is hacked, the damage is permanent. Those affected cannot exchange their fingers. In 2015, an attack on a US authority copied the fingerprints of several million government employees — this data remains compromised for the rest of their lives.

That is why the European General Data Protection Regulation treats biometric data as a special category. Anyone processing it for unique identification generally needs explicit consent or a clear legal basis. The EU’s AI Act goes even further and bans certain applications entirely, such as the untargeted scraping of facial images from the internet.

From image to numerical pattern

A system normally does not store a photo of the finger or face. Instead, a program calculates from it a long series of numbers, the so-called template. These numbers describe characteristic points: the distance between the eyes, the branching of the fingerprint lines, the curve of the nose. The original image can hardly be reconstructed from the template, which is meant to limit the damage in the event of theft.

With every subsequent check, a new template is calculated and compared with the stored one. Two measurements are never exactly identical — light, angle, and skin moisture are constantly changing. The system therefore only checks whether the similarity is above a threshold value. If this value is set too high, authorized persons are rejected. If it is set too low, strangers get through.

It is important to distinguish between two tasks. In verification, someone claims to be a specific person, and the system only checks this one comparison. In identification, the system searches for a face in a database with millions of entries. The second task is significantly more error-prone, because with so many comparisons, random matches become more likely.

From the phone to video surveillance

Biometrics is most commonly encountered on one’s own smartphone. Face ID and fingerprint sensors store the template in a sealed-off chip area on the device. It does not leave the phone and does not travel to the manufacturer either. This local storage is an important difference from systems that store everything on central servers.

In the news, the term usually comes up in connection with surveillance. There is particular controversy over facial recognition in public places and over companies that have collected billions of portrait photos from social networks and sold them to police authorities. Studies have also shown that some systems are significantly more likely to make mistakes with women and people with darker skin, because the training data was unbalanced.

A new topic is forgeries created by AI. If a voice can be reconstructed from just a few seconds of audio, it is barely usable anymore as sole proof at a bank counter. Providers are therefore relying on liveness detection, which checks whether a real human is actually in front of the camera. Incidentally, a common misconception is that biometrics is forgery-proof. It is only a probability judgment, not proof.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.