The moment you capture a visitor's face for a match, or a fingerprint for access, you've collected biometric data — and that raises the bar on how carefully you have to handle it. India's DPDP Act treats personal data seriously across the board, and biometric identifiers deserve particular caution because, unlike a password, you can't reset someone's face.
What counts as biometric data
Biometric data is information about a person's physical or behavioural characteristics used to identify them — a facial image used for matching, a fingerprint template, an iris scan. A face photo captured purely as a badge picture is different from a face template used to authenticate, but the safe assumption is that anything you use to identify someone biometrically deserves the strictest handling.
The duties that come with it
- Consent — capture it explicitly, with a clear notice, before collecting biometric data.
- Purpose limitation — use it only to confirm the visit, never for unrelated profiling.
- Minimisation — collect the least you need; prefer a match result over a stored template where possible.
- Retention — delete biometric data promptly when the visit is over and you no longer need it.
- Security — encrypt it, restrict access tightly, and keep an audit trail of who accessed it.
A note on 'sensitive' data
Global privacy regimes often classify biometric data as a special, higher-risk category. India's DPDP framework is still settling the detail through its rules, so rather than assume where the line falls, treat biometric data as high-risk by default and confirm your specific obligations with your compliance function or counsel. Over-protecting it is rarely the wrong call.
Using Live Face responsibly
Face matching at entry — see how Live Face works — can be done in a privacy-respecting way: match against the photo in a consented, verified record, keep the check purpose-limited to admitting the visitor, and don't quietly build a face database on the side. Pair that with never storing the full Aadhaar number (Aadhaar masking) and consent captured at the point of collection (getting consent right).
How Certopact approaches biometric data
In Certopact Entry, Live Face is consent-based and purpose-limited — used to confirm identity for the visit, not to accumulate biometric profiles — alongside Aadhaar visitor verification that never stores the Aadhaar number. This article is general information, not legal advice; confirm your biometric-data obligations with your own counsel.