Home > Ask the Security Experts > Questions & Answers > Do privacy regulations protect biometrics information?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Do privacy regulations protect biometrics information?

Joel Dubin, past SearchSecurity.com expert EXPERT RESPONSE FROM: Joel Dubin, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 09 December 2006
As an HR professional, I've noticed that many infosec experts recommend biometrics -- particularly fingerprint recognition -- as a way to secure computer access and data. It would seem that employees' fingerprints or fingerprint templates should be subject to the same privacy rules as other sensitive personal data, but I do not see this issue being addressed from either the human resources or IT/IS arenas. What is your advice regarding the handling of biometric data as personal HR data?


BROWSE BY TAG
Enterprise Identity and Access Management,   User Authentication Services,   Biometric Technology,   Security Audit, Compliance and Standards,   Data Privacy and Protection,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Biometric Technology
Biometrics project studies ways to combat bank fraud
Apple iPhone app could boost two-factor
Vein-reading biometrics popping up in health care, financials
Exploring authentication methods: How to develop secure systems
Pre-boot biometric user authentication tools and strategies
To what exactly would a request for biometric data from an insurance provider pertain?
Keystroke recognition aids online authentication at credit union
What are the possible benefits of microchip implants and RFID tags for employees?
Biometrics vs. biostatistics
How are biometric signatures more than a fingerprint scanner?
Biometric Technology Research

Data Privacy and Protection
How to write a risk methodology that blends business, security needs
PCI compliance requirement 3: Protect data
Mass. Senate seeks to amend, weaken data breach notification law
Bruce Schneier and Marcus Ranum Face-Off: Should We Have an Expectation of Online Privacy?
Kodak CISO on virtualization, compliance
Federal efforts to secure cyberinfrastrucure
Attackers cash in on fundamental data handling mistakes, Verizon finds
RSA panel to discuss surveillance, privacy concerns
Mass. officials explain new data protection regulations
HIPAA changes force healthcare to improve data flow
Data Privacy and Protection Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
biometric payment  (SearchSecurity.com)
electro-optical fingerprint recognition  (SearchSecurity.com)
false acceptance  (SearchSecurity.com)
finger vein ID  (SearchSecurity.com)
fingernail storage  (SearchSecurity.com)
keystroke dynamics  (SearchSecurity.com)
live capture  (SearchSecurity.com)
multifactor authentication (MFA)  (SearchSecurity.com)
password hardening  (SearchSecurity.com)
ridge  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Your first hunch is absolutely correct. Biometric data is still personal information and, as a result, should be treated with the utmost privacy and protected just like any employee data should be. Biometric data is unique and, in some circumstances, its unauthorized release can harm your employees.

But your HR and IT departments may have overlooked that fact since biometrics data doesn't look, act or feel like other personal information. Before allowing user access to a system, the various elements captured by a biometrics system -- fingerprints, voice prints, iris patterns or facial features -- all have to be converted to digital data that can be read by authentication hardware and software. Such digital data is often stored in directories like Active Directory, holding authentication profiles of users that are invisible and inaccessible to HR and IT staff.

Biometrics aren't foolproof though. If the digital data representing a biometric profile is stolen, or sniffed off an insecure network, it can sometimes be copied and reused, similar to how a stolen user ID and password is used. Malicious hackers can then gain access to the system.

On the other hand, biometric data is considered an authentication credential, like a user ID and password, and may not legally be considered personal information equivalent to a Social Security number or account number. You may want to consult your legal or compliance departments to get a precise read on pertinent legislation, like the Sarbanes-Oxley Act (SOX) or the Gramm-Leach-Bliley Act (GLBA), that affects employee records.

More information:

  • Get a glimpse of where biometric authentication is headed.
  • Learn which policies and standards can protect personal data.




  • Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts