Data handling and policy

Does the Applicant collect biometric information (fingerprints, voice, face, iris, etc.)?

This question exists because of a specific statute and a decade of litigation. It is asked separately because the exposure does not scale with record count in the usual way.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether you collect fingerprints, voiceprints, facial geometry, iris scans, or similar identifiers. Several technologies collect these without anyone framing it as biometric collection: fingerprint time clocks, voice authentication in a call centre, facial recognition in a security system, and video analytics.

Why it is underwritten

Biometric privacy statutes, most prominently in Illinois, create a private right of action with statutory damages per violation and no requirement to show harm. Class actions have produced very large settlements from ordinary operational uses. Carriers ask because the exposure is legal rather than technical, and because many policies exclude or sub-limit it.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Biometric collection happens in operational technology and third-party platforms rather than in the cloud tenant, so this is attested. The important work is inventory rather than measurement.

PlatformWhere the setting livesWhat has to be true
Operational systemsTime and attendance, physical access control, and security camera systemsWhether any capture biometric identifiers, including systems installed by facilities rather than by IT. Attested
ApplicationsVoice authentication, identity verification, and video analytics in customer-facing systemsWhether biometric templates are created or transmitted, including by a vendor on your behalf
Vendor contractsProcessors that handle biometric data for youContractual allocation of responsibility, since vendor collection can still create your liability
Consent recordsWritten consent, disclosure, and retention schedule where requiredThe statutory requirements: informed written consent, a published retention and destruction schedule, and no sale or profit from the data
Microsoft 365Windows Hello for Business biometric useGenerally out of scope, since the template stays on the device and is not collected by the organisation, but worth understanding before answering
Nobody decides to collect biometrics

The fingerprint time clock was a payroll decision. The facial recognition in the lobby was a facilities decision. Neither went through a privacy review, and both create the exposure this question is asking about. Ask the departments, not the IT inventory.

What a defensible yes requires

  • An inventory exists covering operational technology and vendor-operated systems, not only IT systems.
  • Where biometrics are collected, written consent and disclosure meet the applicable statute.
  • A retention and destruction schedule is published and followed.
  • Vendor contracts allocate responsibility explicitly.
  • Legal counsel has reviewed the position, since the exposure is statutory rather than technical.

How this answer goes wrong

The answer is no because the IT department does not run a biometric system, while a fingerprint time clock has been in the warehouse for six years. Litigation in this area has repeatedly arisen from exactly that system, and the incorrect answer sits on the application throughout.

Frequently asked

Does a fingerprint time clock count?

It is the archetypal case in biometric privacy litigation. If you have one, the answer is yes and counsel should look at your consent and retention practice.

What about Windows Hello or phone unlock?

Generally out of scope, because the template never leaves the device and the organisation does not collect it. Confirm with counsel rather than assuming, since statutes differ.

Is biometric liability covered by cyber policies?

Often excluded or sub-limited, and it varies considerably between markets. If you answer yes, the coverage conversation matters as much as the control conversation.

Does it matter if a vendor collects it?

Not for your exposure. Statutes have reached organisations whose vendors performed the collection on their behalf.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture