News

Biometric Data Retention Is a Liability: The 2026 Case for Minimisation

Moca Network
August 25, 2026

Biometric data retention is the practice of storing facial templates, fingerprints or other physical identifiers after the verification that produced them has completed. Through 2026 the legal cost of that practice became considerably easier to quantify, and considerably harder to justify.

In late August, a federal judge certified a class of approximately 22,402 drivers in a biometric privacy action against a major transport operator. In a separate matter, a wrongfully arrested driver sought disclosure of 168 other individuals flagged by a venue's facial recognition system. In a third, an appellate court declined to certify a class over facial-analysis cameras, a reminder that outcomes vary while exposure does not.

The pattern across all three is the same. The liability attaches to holding the data, and it survives the business purpose that justified collecting it.

Key takeaways

  • Statutory biometric privacy regimes assess damages per person, per violation, which makes class size the dominant variable.
  • A certified class of 22,402 turns a compliance question into an existential one.
  • Deployments produce disclosable operational records: a system that flagged 168 people created 168 discoverable events.
  • Retention liability persists after the operational purpose ends and is not reduced by good security.
  • The only control that reliably reduces exposure is not holding the data.

Why per-person statutory damages change the arithmetic

Most data protection regimes assess penalties against an organisation's turnover or the severity of a breach. Statutory biometric privacy regimes work differently: they assign a fixed sum per affected individual per violation, and in several cases they do not require proof of concrete harm.

The consequences are structural.

FactorEffect on exposure
Number of individuals enrolledDirectly multiplies liability
Number of separate violations per personMultiplies again
Whether a breach occurredFrequently irrelevant
Quality of the organisation's securityFrequently irrelevant

That last row is the one most often misunderstood. An organisation that collected biometrics without the required notice and consent is exposed whether or not the data was ever at risk. Excellent encryption does not cure a consent defect. The violation is in the collection and retention, not in the outcome.

Class certification is therefore the decisive event. Before it, an organisation faces individual claims. After it, it faces the entire enrolled population as a single number.

The discovery surface nobody budgets for

The facial recognition disclosure dispute illustrates a second category of exposure that rarely appears in a deployment business case.

A recognition system generates records: every match, every alert, every action taken on the basis of one. When a single decision is challenged, those records become discoverable. A claimant seeking disclosure of the other individuals a system flagged is asking the operator to produce the full operational history of its deployment.

That history was never designed to be read by an adversarial party. It contains the false positive rate in practice rather than in the vendor datasheet, the pattern of who the system flagged, and the actions taken without independent verification.

Deploying biometric matching therefore creates two liabilities: the data, and the record of what was done with it.

Why "secure it better" is the wrong response

The instinctive response to biometric risk is stronger protection: encryption at rest, template hashing, access controls, shorter retention windows. All are worth doing. None addresses the underlying property.

A biometric cannot be reissued. When a password database is compromised, users rotate credentials and the exposure ends. When a biometric template database is compromised, the affected individuals carry that exposure permanently. There is no rotation.

This asymmetry means the risk-reduction curve for biometric retention flattens quickly. You can reduce breach probability substantially. You cannot reduce breach consequence at all, because the consequence is permanent by construction.

Which leaves one control with a genuinely different shape: hold less.

What minimisation looks like architecturally

Minimisation is often read as shorter retention. That helps, but it does not change the model. The structural version separates two things organisations habitually conflate.

Where verification happens. A qualified issuer performs the biometric verification once, under controlled conditions, with liveness and attack detection applied properly, and under an audit regime appropriate to holding that data.

What relying parties receive. Every subsequent party receives a cryptographic assertion about the verification, not the biometric. A zero-knowledge proof confirms the specific fact required, that a unique person is behind the account, that they are over a threshold age, that they passed verification at a stated assurance level, without transmitting the underlying data.

The exposure profile changes completely:

Retention modelCredential model
Parties holding biometricsEvery relying partyOne qualified issuer
Class size if compromisedFull enrolled population, per partyLimited to the issuer
Statutory exposure for relying partiesPer person, per violationMinimal, no biometric held
Discovery surfaceFull operational history at each partyVerification records at the issuer

A relying party cannot be sued for retaining data it never retained, and cannot leak what it never held.

AIR Identity is built on this separation. Verification is performed once by a qualified partner; relying partners confirm assertions through zero-knowledge proofs and never receive raw biometric or personal data. For organisations in fintech, travel and loyalty and gaming, where verified identity is operationally necessary but biometric custody is pure downside, that separation removes a liability without removing the capability.

Frequently asked questions

What is biometric data retention?

Biometric data retention is the storage of facial templates, fingerprints, iris scans, voiceprints or similar identifiers after the process that collected them has completed. Retention is the point at which most statutory biometric privacy obligations attach, covering notice, consent, disclosure limits and defined destruction schedules.

Why are biometric privacy class actions so expensive?

Because damages are assessed per person per violation and frequently do not require proof of harm. Once a class is certified, exposure scales directly with the number of people enrolled, so an organisation with tens of thousands of enrolled individuals faces a figure driven by class size rather than by any actual loss.

Does encrypting biometric data reduce legal liability?

It reduces breach probability, not statutory liability. Most biometric privacy claims turn on whether required notice and consent were obtained and whether retention and destruction rules were followed. An organisation that failed those requirements is exposed regardless of how well the data was protected.

How can a business verify identity without storing biometrics?

By separating verification from reliance. A qualified issuer performs the biometric verification once and issues a credential. Relying parties then confirm the assertion cryptographically, using a zero-knowledge proof, without receiving the biometric. The relying party gets the assurance and holds no biometric data.

What is a zero-knowledge proof in identity verification?

A zero-knowledge proof is a cryptographic method that lets one party prove a statement is true without revealing the information that makes it true. In identity, it allows a service to confirm that a user is over eighteen, is a unique person, or passed verification at a given assurance level, while learning nothing else about them.

Related reading

More from AIR: AIR Identity, travel and loyalty, or browse the full AIR blog.

Holding biometric data you do not need to hold? See how AIR Identity delivers verified assurance without transferring raw personal data, or read the developer documentation.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
News
Proof of Human: Why Bot Detection Moved to the Login Layer in 2026
Governments are now procuring technology to block automated agentic AI at sign-in. Proof of human has become an authentication requirement, not a research topic.
News
Age Assurance Accuracy Standards: The 2026 Benchmarks Explained
Age assurance now has measurable accuracy targets: a 10% under-18 false-positive ceiling for 16-17 year olds and 3% for 13-15. What the benchmarks mean for platforms.
News
Government Digital Credentials in 2026: Birth Records, ID Cards and Wallets
The first US digital birth credential, a new European biometric ID card and a merged national identity app all landed in one week. What state issuance means for platforms.