Commissioned by Nok Nok Labs, the White Paper evaluates key privacy implications of processing biometric data; comparing the benefits and risks of on-device and on-server matching for biometric authenticationLondon, UK – May 12, 2016 – Nok Nok Labs, an innovator in modern authentication and a founding member of the FIDO (Fast IDentity Online) Alliance, today published a White Paper from PwC Legal comparing key privacy implications of on-device and on-server matching of biometric data.
Phillip Dunkelberger, President & CEO of Nok Nok Labs
For organisations considering biometrics as they move away from reliance on usernames and passwords, the report highlights why device-side matching of biometric data is a compelling approach to satisfy key privacy requirements on cross-border personal data transfers, as well as providing the benefits of individual choice and control around such personal data.
Biometric data is considered to be sensitive personal data and some jurisdictions have already specifically referenced it in privacy guidance and legislation.
This paper emphasises key privacy considerations, sets out the implications of processing biometric data in the EU, Switzerland, Canada, USA and the Asia-Pacific region, and touches on best practice recommendations in these jurisdictions.
“Biometric authentication and verification can be one of the most secure ways to control access to restricted systems and information,” said Stewart Room, partner at PwC Legal. “Unlike authentication based on traditional passwords, authentication through biometric data is easier to use in practice, and can be far more secure.
“However, this is a double-edged sword, because biometric data is extremely sensitive due to its uniqueness and how intrinsic it is to a specific individual.
Additional efforts must be made to keep this data secure including choosing a proper compliance system and infrastructure, training staff how to handle it and protecting it from unauthorised access or disclosure.”
Other key findings in the White Paper include:
Freely given, informed user consent is required before processing biometric data in almost every jurisdiction covered in the White Paper
With centralised storage of biometric data, the potential for large-scale loss of data is significantly increased
On-device authentication will generally avoid international cross-border biometric data transfer implications.
Conversely, on-server authentication for a global network of biometric users results in international transfers of data; transfer of personal data, including biometric data, out of a jurisdiction is generally restricted
“Biometrics are a compelling way to improve mobile application usability and avoid the security pitfalls of username/passwords, but significant privacy concerns come into play,” said Phillip Dunkelberger, President & CEO of Nok Nok Labs. “With biometrics, it is crucial to understand the difference between on-device and on-server matching, as the difference between the two approaches significantly affects the risk and exposure of data in a breach.
The on-device approach, as used by Nok Nok Labs technology, ensures optimal privacy for biometric information.”
The full report can be found here: https://go.noknok.com/PwCLegal-Biometric-WP.html.
# # #
About PwC LegalAt PwC Legal we combine legal advice with the expertise of professionals in Tax, Accounting and HRS to provide our clients with commercial solutions to the most complex business issues. We’re a network of 2,500 legal experts in over 85 countries committed to delivering an exceptional service to clients and experience for our people.
The white paper has been prepared by PwC Legal LLP upon request by Nok Nok Labs, Inc, and does not constitute legal advice.
About Nok Nok LabsNok Nok Labs provides organisations with the ability to bring a unified approach to deploy easy to use and secure authentication infrastructure to their mobile and web applications, using standards-based solutions that include support for FIDO and other specifications.
The Nok Nok S3 Authentication Suite enables organisations to accelerate revenues, reduce fraud, and strengthen security and privacy. Nok Nok Labs is a founding member of the FIDO Alliance with industry leading customers and partners that include NTT DOCOMO, PayPal, Alipay, Samsung and Lenovo.
For more information, visit www.noknok.com.
Nok Nok Labs, Nok Nok and NNL are all trademarks of Nok Nok Labs, Inc.
FIDO is a trademark of the Fast IDentity (FIDO) Online Alliance.
Media contacts for Nok Nok LabsLindsey Challis or Gemma WhiteNok Nok Labs team at Finn Partners+44 020 3217 7060NNL@finnpartners.com
Tom RiceNok Nok Labs team at Merritt Group+1 703-856-2218NNLPR@merrittgrp.com