top of page

Biometric Authentication, Alternatives, and Consent Withdrawal : Rethinking Proportionality in an Age of Irrevocable Identity

1 day ago
10 min read

Introduction : Biometric technology has moved from being experimental to actual implementations with fingerprint scanners at entrance to workplaces, facial recognition at airports and iris scans in governmental social services. The reason is simple: biometric traits are simple to implement, recognizable and difficult to fake. However, the same reasons that make biometrics appealing are the ones that turn them into a danger. Unlike passwords or smart cards, once biometric templates get stolen, a person cannot change his/her biometric traits. This permanence does not sit easily in law that revolves around the notion of consent which implies that a data subject is in control of his/her data and has the right to withdraw it or delete it. But when the reference point has become a physical feature of the body, the issue of withdrawal of consent already assumes far more difficult implications: can the damage be undone, given that the template has already been created, stored, and passed to other operators? The present blog post analyzes the legal and practical issues that come with the implementation of biometric identification in India, clearly distinguishing between identification and authentication and arguing that the proportionality assessment of biometrics before its introduction must be performed thoroughly.


Legal Provisions


A. The Digital Personal Data Protection Act, 2023


India's Digital Personal Data Protection Act, 2023 (DPDP Act) stands as the first comprehensive regulation concerning personal data processing; the scope of biometric data fits into the definition of "personal data" as per the definition of "personal data." As elucidated in Section 6 of the DPDP Act, the consent granted should be free, specific, informed, and provided unconditionally. Furthermore, section 6(4) holds that the data principal should be able to withdraw consent as easily as it is obtained. Next, Section 8 requires data fiduciaries to erase personal data when its purpose of collection ceases, except where law obligates data retention. This provision can directly affect the usage of biometrics since it requires companies actually to build deletion and withdrawal mechanisms rather than treating consent as a formality obtained just at enrolment.


B. The Aadhaar Act and Regulations


India's biometric database managed by the Unique Identification Authority of India (UIDAI) is governed by the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016. The Act allows for the "authentication" of Aadhaar numbers on the basis of biometrics or demographic inputs as per the provisions of section 8 and Aadhaar (Authentication) Regulations, 2016 deal with the process separately. Following the Supreme Court judgement in the Aadhaar case, the section 57 of the Act which allowed for the Aadhaar-based authentication by private entities was struck down to the extent that it permitted businesses and individuals to seek authentication, thus confining mandatory biometric linkage to the welfare-based subsidies and benefits that are mandated.


C. The Information Technology Act, 2000 and SPDI Rules


Before implementing the DPDP Act, biometric data used to be regulated as "sensitive personal data or information" as per the Information Technology (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011 that were enacted according to Section 43A of the Information Technology Act, 2000. These rules prescribe obtaining prior consent, mentioning the purpose of collection and taking reasonable security measures. The rules still retain some relevance for entities and processes yet to be adapted to the DPDP Act. In addition, Section 72A of the IT Act specifically prohibits revealing information that has been obtained lawfully without consent.


D. Comparative Frameworks


Around the world, biometric information is classified as a special type of information according to the General Data Protection Regulation (GDPR) of the European Union, which means that information should be produced in accordance with Article 9. This means that collecting biometric information has to fulfill more stringent conditions to be processed. In Illinois, the Biometric Information Privacy Act (BIPA) goes even further and provides rights to sue for the collection of biometric identifiers without the informed consent of an individual. This shows that the approaches of these laws differ significantly: risk-based proportionality in reference to GDPR and the DPDP Act and rights-based approach in reference to BIPA.


Legal Analysis


A. Authentication, Identification, and Attendance Monitoring Are Not the Same


A recurring conceptual crisis in both policies and practice in the workplace is situating authentication alongside identification and monitoring for attendance, confusing the distinct legal ramifications involved in each process. Authentication is a process of one-to-one validation: a biometric input is compared with one single stored biometric template to establish a person’s identity; hence, the proof of identity may happen when a smartphone gets unlocked due to the successful identification of its registered owner's fingerprint. Identification, on the other hand, should be considered to be a one-to-many system, where the captured biometric information is verified against the entirety of the database for identification purposes; therefore, this is a process of identifying a person without establishing their previous claims of identity.The use of identification comes with a greater risk regarding privacy since it allows monitoring of people who did not give their consent and keeps a record of where and when the subjects were present.


There is a third category of attendance verification that is too often ignored—as it utilizes one-to-one or limited matching for administrative purposes, it is frequently used with unnecessarily long retention periods, constant logging, and for purposes unknown to employees during the process of obtaining their consent. Legal and compliance departments not being able to make the necessary distinctions may apply the same standard used for authorization to identification or monitoring systems.


B. Consent in Conditions of Asymmetry: The Employee Coercion Problem


The DPDP Act stipulates that consent must be "freely given," which is a term that is difficult to comply with given that employment relationships always involve a different level of power in favour of the employer. This issue becomes particularly relevant since many employers require to use biometric systems as a condition of continued employment and in this case, if the employee refuses to give the consent, that is not usually regarded as a genuine choice. Some jurisdictions solve the issue by insisting that employers provide their workers with options other than biometric systems, such as cards or PIN-based systems. Though Indian legislation does not exactly state that it is incumbent upon an employer to give such non-biometric alternatives, the requirement that consent be freely given and the right to withdraw consent (Section 6(4) of the DPDP Act) imply that by failing to provide such non-biometric reasonable alternative, the employer does not allow the employee to exercise the statutory right to give or withdraw consent.


C. The Permanence Problem and the Limits of "Deletion"


Potentially, it is possible to alter or change passwords, tokens, and even Aadhaar numbers if compromised. But that isn’t possible in the case of fingerprints, iris patterns and facial geometry. This asymmetry leads to the fact that if the biometric templates get breached, the individual is left exposed to risks for a lifetime due to the long-term usage of the same identifier across banking, government and private systems. The DPDP Act’s erasure obligation under Section 8 sounds good, but does not really solve the problem, since the moment a biometric template is turned into a mathematical representation and transmitted to or copied by the third-party vendors for cloud storage, training of models or back up of files, technical deletion performed by the first data fiduciary does not guarantee that the same deletion would apply to the whole processing chain. In addition to that, the majority of consent infrastructures were created specifically for revocable credits rather than for biologically permanent identifiers.


D. Vendor Access and the Outsourcing Risk


Typically, biometric systems rely heavily on third-party equipment, services, and applications. Devices for enrollment and matching, as well as cloud storage, are frequently supplied by different companies. Such companies usually have access to data for maintenance or analytics and can collect raw template biometric data in order to improve their products. However, according to the DPDP Act, the data fiduciary must ensure that the third-party processor only processes personal data according to a binding contract and act as a processor on behalf of the end data fiduciary and does not assume any independent power over the data. In practice, the contracts of the vendors that supply biometric systems are often standardized and do not leave much room for negotiation over data retention, sub-processing, or storage. This allows a loophole since the party that receives consent from the person concerned may not know how the vendor manipulates the biometric data received.


E. Security Versus Convenience: An Honest Trade-off


The advocates of the biometric systems are absolutely certain that biometrics helps to minimize certain types of fraud such as buddy-punching at attendance mechanisms or impersonation of one's identity while onboarding financially, and that properly worked biometric systems create only the irrecoverable mathematical templates instead of images thus minimizing the risk (though not getting rid of it totally) of misuse in case these templates are stolen. The opponents point out that this benefit is exaggerated compared to the financial risks that arise after centralizing unique identifiers that can't be changed, adding that the same level or even better fraud defense can be provided with the help of a layered authentication system such as PIN and some kind of a token. Ultimately, it depends on the context: the low-risk environment of a simple office attendance system can't be compared with the biometric data used for financial operations.


Relevant Case Laws


Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1: A nine-judge bench of the Supreme Court held that the right to privacy, including informational privacy over one's body and identity, is a fundamental right under Article 21 of the Constitution. The judgment is the doctrinal foundation for evaluating any biometric collection scheme, since it establishes that state (and, by extension, private) intrusion into bodily and informational privacy must satisfy legality, legitimate aim, and proportionality.


Justice K.S. Puttaswamy (Retd.) v. Union of India (Aadhaar judgment), (2019) 1 SCC 1: A five-judge bench upheld the constitutional validity of the Aadhaar scheme for welfare delivery but struck down Section 57 of the Aadhaar Act to the extent it permitted private bodies to mandate Aadhaar-based authentication, and read down certain data-retention provisions. The judgment remains the leading Indian authority distinguishing permissible state use of biometric identification for subsidy delivery from impermissible mandatory extension into private commercial relationships.


Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186 (Illinois Supreme Court): The court held that a plaintiff need not allege actual injury beyond the statutory violation itself to bring a claim under the Illinois Biometric Information Privacy Act, affirming that unauthorised collection of biometric identifiers is itself a cognisable harm. This reasoning serves as valuable guidance for Indian regulators in determining if harm-based enforcement is more effective than violation-based enforcement in limiting damage to biometric identifiers.


In the case of Patel v. Facebook, 932 F.3d 1264 (9th Cir. 2019), the Ninth Circuit found that Facebook's act of gathering facial recognition data through their photo-tagging tools without the consent of users represented a real injury sufficient enough to satisfy the conditions of Article III of BIPA which reinforces the fact that the technology of biometric recognition triggers a higher standard of privacy compared to the technology of authentication due to the absence of individual's consent.


Practical Implications


When it comes to businesses and employers, it means that decisions about the implementation of biometrics are not solely operational considerations, but have compliance obligations under the DPDP Act; there are also vendor-related risks as per contracts and labour law for situations where individuals are unable or unwilling to give consent. Organizations should perform data protection impact assessments before using biometric technologies, provide real alternatives beside biometrics, negotiate contracts with vendors that specify retention periods and prohibit secondary use, and acquire technical capabilities of safely destroying data, including backups and copies.


The challenge for policymakers is that there are no rules related to authentication, identification, and attendance monitoring, or a legal requirement for employers to have an alternative to biometric technologies. With laws being framed to operationalise the DPDP Act, it would be advisable to treat biometric data as a special category of data that requires additional protection, like the one suggested in Article 9 of the GDPR, instead of passing it off as personal data.


For people, the reality is that once they consent to biometric data collection and the data is stored, their capacity for overcoming the exposure of their personal information is restricted because of technology and multiple parties processing those data. This inequality demonstrates why ex-ante oversight before the use of biometric technology is more advantageous than any ex-post remedy following an incident of misuse.


Conclusion


Biometric authentication has real ease of use and great security advantages in the correct circumstances but the unavoidable nature of fingerprints as a form of identification means that they can be very dangerous if they fall into the wrong hands. Existing (withdrawal) mechanisms, which are made for a world with resettable passwords, are only somewhat capable of modifying this situation. The introduction of the DPDP Act in India is a positive aspect as it mandates unambiguous consent and the right to withdrawal (along with the right to delete certain information). However, the law fails to deal with some significant issues relating to biometric identification technologies, such as the need for a number of improvements in devices used under the system, including the necessary safeguards and other attractive methods of identification.


In the case of organizations contemplating the use of biometrics and regulators drafting the laws based on the measures proposed in the DPDP Act, the best decision is to perform a structured proportionality analysis before making use of biometrics. This analysis should concentrate on determining if biometrics are truly necessary for a specific purpose while also checking for a less invasive and reversible means of reaching the same goal. There must also be an assurance of an appropriate level of biometric processing in relation to the actual risk. Finally, attention should be drawn to the retention of biometric data, access of the vendors, and the mechanism of denial of their access.


Author: Aaliya Noorudheen in case of any queries please contact/write back to us via email to content@khuranaandkhurana.com or at  Khurana & Khurana, Advocates and IP Attorney


Endnotes


  1. Digital Personal Data Protection Act, 2023, s. 6 (India).

  2. Digital Personal Data Protection Act, 2023, s. 6(4) (India).

  3. Digital Personal Data Protection Act, 2023, s. 8 (India).

  4. Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, s. 8 (India).

  5. Aadhaar (Authentication) Regulations, 2016 (India).

  6. Information Technology Act, 2000, s. 43A (India).

  7. Information Technology (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011 (India).

  8. Information Technology Act, 2000, s. 72A (India).

  9. General Data Protection Regulation (EU) 2016/679, art. 9.

  10. Biometric Information Privacy Act, 740 ILCS 14 (Illinois, USA).

  11. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (India).

  12. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2019) 1 SCC 1 (India).

  13. Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186 (Illinois Supreme Court, USA).

  14. Patel v. Facebook, Inc., 932 F.3d 1264 (9th Cir. 2019) (USA).

  15. UIDAI, Aadhaar Authentication Ecosystem: Framework and Guidelines (2021).

Comments


bottom of page