Biometrics

Scanning the law

by Mark Rowe

The European Regulation on the Protection of Individuals with regard to the Processing of Personal Data, adopted in 2016, is due to be enforceable in May 2018.

As an integral component of EU privacy and human rights law, a biometric firm says, it regulates the processing and distribution of personal data. In essence it will become illegal, or certainly contrary to the regulation, to link the stored data to the individual. The regulation states that personal data should not be processed unless the individual is informed and at least one of a set of strict criteria are met.

While the EU regulations are designed to protect individual’s rights to privacy, they will have implications for the security industry which now must adapt to comply, says ievo Ltd, the Newcastle-based manufacturer of biometric recognition products.

Shaun Oakes, Managing Director of ievo Ltd, says: “The regulation is designed to prevent stored data being linked to individuals and used for purposes other than ensuring the security of whatever system it was designed for and transferring this data to third parties. Biometric data – fingerprint scans in our case – comes under the heading of a ‘special privacy element’ which are forbidden to use and process, unless, and this is very important, one of a number of criteria apply, the most pertinent of which is the data subject has given permission.

“As all scans are taken either voluntarily (after the individual has given his or her permission) or legitimately to ensure the safety and security of others, the ievo range of biometric systems fully comply with this legislation as they utilise feature-based matching – they do not store the raw biometric data or image; but rather extract a salient set of features known as minutiae from which an individual template is generated.

“In essence, we use a system of ‘pseudonymisation’ where the data is processed in a manner where it can no longer be attributed to an individual without the use of additional information which is stored separately and subject to strict technical and organisational control.

“Following a High-Resolution scan of the finger our algorithms separate the foreground from the background of the image; it then enhances the image, detects minutiae points and creates a pattern. It is this pattern that is stored on our controller (which are installed separately from the sensor) which, when combined with encryption using AES (Advanced Encryption Standard) ciphers and further confidential safeguards serve to eliminate tampering. It is important to note that the original scanned image of a fingerprint is never stored.

“As such, ievo biometric readers fully comply with the new legislation, but many older systems which store biometric and/or personal data of card holders, or those with knowledge of key pad combinations, may well have to review their compliance.”

Related News

  • Biometrics

    Product videos

    by Mark Rowe

    ievo Ltd, the Newcastle-based manufacturer of biometric recognition products, have launched a new set of product videos aimed primarily at installation partners…

  • Biometrics

    Voice biometrics view

    by Mark Rowe

    A perspective on security and customer service through voice biometrics is offered by Claire Richardson, pictured, VP – Workforce Optimisation Solutions, EMEA,…

  • Biometrics

    A chain of trust

    by Mark Rowe

    Biometric fingerprint authentication is still in its infancy and often seen as a ‘gimmick’/nice to have. However, businesses and consumers should not…

Newsletter

Subscribe to our weekly newsletter to stay on top of security news and events.

© 2024 Professional Security Magazine. All rights reserved.

Website by MSEC Marketing