Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
FAQs
- Do all New Zealand businesses using biometrics need a separate biometric consent form?
- Can an employer require staff to use fingerprint or facial recognition?
- Is a privacy policy enough instead of a consent form?
- What if the biometric software provider stores data overseas?
- How long should biometric data be kept?
- Key Takeaways
If your business wants to use fingerprints, facial recognition, voiceprints or other biometric data, a vague checkbox and a copied privacy statement will not do the job. New Zealand businesses often make the same mistakes here: they collect more biometric information than they actually need, they fail to explain exactly how the data will be used, and they bundle consent into general terms so people do not have a real choice. Another common problem is keeping biometric data for too long, or sharing it with software providers without clearly telling people first.
A biometric consent form needs to do more than ask for permission. It should explain what data you collect, why you need it, how long you keep it, who you share it with, what happens if someone says no, and how they can withdraw consent or ask for access. If you are setting up staff attendance systems, customer identity checks, secure building access or app-based verification, here is what to include before you sign a contract, buy the software or roll out the process.
Overview
A biometric consent form is part privacy notice, part permission record, and part risk control. For New Zealand businesses, the main legal issue is whether your collection and use of biometric information is lawful, transparent, necessary and fair under privacy law and your wider business documents.
- Identify the exact biometric data you collect, such as a fingerprint template, face scan, voiceprint or retina scan.
- State the purpose clearly, such as site access, identity verification, fraud prevention or time and attendance.
- Explain whether providing biometric data is optional or required, and what alternative process exists if a person does not consent.
- Set out storage, security and retention, including where the data is held and when it will be deleted.
- Disclose who receives the data, including software vendors, hosting providers and related service providers.
- Tell people how to access, correct or withdraw consent, and what practical effect that has.
- Make sure the form matches your privacy policy, employment documents, customer terms and supplier agreement.
What Biometric Consent Form Means For New Zealand Businesses
A biometric consent form is the written record that shows your business has properly explained and obtained agreement for collecting and using biometric information. In New Zealand, that sits within the Privacy Act 2020 framework, especially the information privacy principles around collection, purpose, transparency, storage, access and retention.
Biometric data is usually treated as sensitive in practice because it is closely tied to a person’s identity and cannot easily be changed if something goes wrong. A password can be reset. A fingerprint or face pattern cannot really be replaced in the same way.
Why biometric data needs extra care
The main risk is not just privacy complaints. The risk also includes damaged trust, staff pushback, customer drop-off, poor procurement decisions and messy contractual problems with software providers. This is where founders often get caught, especially when a product demo makes implementation look simple.
If you collect biometric information, people will reasonably expect a higher level of explanation and care. That means your form should be easy to read, specific to your actual process and supported by real internal practices.
What counts as biometric information
The term usually covers physical or behavioural characteristics used to identify or verify someone. Common business examples include:
- fingerprint scans used for clocking in or accessing a site
- facial recognition used for entry gates or customer verification
- voice recognition used for call centre authentication
- iris or retina scans used in higher security environments
- hand geometry or other body measurement systems used for restricted access
Some systems store a direct image. Others convert the data into a template or mathematical representation. Even if your supplier says it does not keep the raw image, you still need to explain what is collected and how the system works in practical terms.
What the law expects in plain English
New Zealand privacy law does not give businesses a blank cheque to collect personal information just because technology makes it possible. You generally need a lawful purpose connected with your business, and the collection must be necessary for that purpose.
You also need to be open about what you are doing. People should know:
- that biometric information is being collected
- why it is being collected
- who will hold it
- whether it will be shared with others
- what happens if they refuse
- how they can request access or correction
In some cases, consent is central. In others, the bigger issue is whether the collection is fair and genuinely necessary at all. For example, requiring facial recognition for a low-risk, ordinary transaction where simpler identification methods work may be hard to justify.
Consent is not enough on its own
A common mistake is assuming that a signed form fixes every privacy issue. It does not. A biometric consent form helps, but it will not rescue a process that is excessive, unclear or badly secured.
If your business asks people to agree because there is no realistic alternative, the consent may be weak in practical terms. This comes up regularly in workplaces, schools, gyms and shared sites. If someone cannot realistically say no without suffering a disadvantage, your business should think carefully about fairness, necessity and alternative options.
When This Issue Comes Up
Biometric consent forms matter most when you are introducing a system that identifies people using their body or behaviour rather than an ordinary password, card or manual check. The best time to deal with this is before you sign a contract with the software vendor or spend money on setup.
Staff attendance and workplace access
Many SMEs first encounter this issue when they install fingerprint or facial recognition systems for staff attendance. These systems are often marketed as efficient, but employment context creates extra sensitivity.
If staff feel they have no genuine choice, a short form tucked into onboarding paperwork is unlikely to be enough. You should think about consultation, whether a swipe card or PIN is a workable alternative, how the data will be used in performance or disciplinary processes, and what your employment contracts and workplace policies say.
Customer identity verification
Some businesses use face matching or voice verification to reduce fraud, verify age, confirm identity remotely or secure high-value accounts. This commonly arises in fintech, online services, membership platforms, health-related services and higher-risk retail models.
Here, your form needs to explain the customer journey clearly. If a customer uploads an image for matching, they should know whether it is checked in real time, stored for future use, compared against third party databases or used to train any system.
Site security and visitor access
Businesses with warehouses, labs, shared commercial sites or sensitive stock sometimes use biometric entry systems. The issue is not limited to employees. It can also affect contractors, delivery personnel, visitors and tenants in a shared building.
That means your biometric consent form may need different versions, or at least different wording, depending on who is being asked to provide data and why.
Apps, platforms and online products
Tech startups sometimes build biometric verification into an app from day one. That can create privacy obligations well before launch, especially if you are selling online and collecting data at scale.
At that point, the biometric consent form is only one piece of the puzzle. You may also need aligned customer terms, a privacy policy, supplier agreements, data hosting terms, product copy that does not mislead users, and internal decision-making around retention and deletion. This is similar to other early stage legal requirements when you start a business in New Zealand, where company setup, contracts, privacy settings, trade mark planning and business structure all need to line up rather than being handled one by one in isolation.
Third party vendor rollouts
A lot of businesses do not build biometric tools themselves. They buy a platform from a vendor, often offshore, then discover the vendor’s default consent wording is too generic for New Zealand use.
This is where procurement and privacy overlap. Before you sign, check whether the vendor contract says:
- where data is stored and processed
- whether subcontractors are involved
- who owns or controls derived biometric templates
- what happens at termination
- how deletion is handled
- whether data is used for analytics, model training or product improvement
- what security standards apply
Practical Steps And Common Mistakes
A workable biometric consent form is specific, readable and backed by systems your business can actually follow. The right drafting approach starts with your real data flow, not a template copied from another market.
What to include in the form
Your form should spell out the essentials in plain language. A useful biometric consent form usually includes:
- the identity of the business collecting the information
- the exact type of biometric data collected
- the purpose of collection and why biometric processing is being used instead of a less intrusive option
- whether collection is mandatory or optional
- any available alternative if the person does not want to provide biometric data
- how the information will be collected, used, stored and protected
- who the information will be disclosed to, including technology providers and hosting providers
- whether any information is stored or accessed outside New Zealand
- how long the data will be kept and when it will be deleted or de-identified
- how the individual can request access, ask for correction or withdraw consent
- the practical consequences of refusing or withdrawing consent
- a clear statement of agreement, with date and method of acceptance
If the form is digital, keep evidence of the version shown to the user and the wording they accepted. Version control matters if you later need to show what disclosures were made at the time.
Match the form to the real process
The biggest drafting mistake is describing a simple process when the actual system is more complex. If your supplier stores face templates in the cloud, uses sub-processors or keeps logs for analytics, your form and privacy documents should not suggest the data stays only on a local device.
Put simply, your paperwork has to match your operations. If it does not, the problem is not just legal. It also creates trust and reputation risk.
Offer a genuine alternative where appropriate
In many settings, offering a practical alternative is the difference between a fair process and a risky one. That alternative might be:
- a PIN or password
- a swipe card or key fob
- manual identity verification
- a different attendance recording method
An alternative may not always be possible, especially in higher security environments. But if you decide not to offer one, make sure you can explain why the biometric method is reasonably necessary.
Do not collect more than you need
Another common mistake is collecting biometric data because the software includes the feature, not because the business actually needs it. If a lower-risk method does the job, a biometric system may be hard to justify.
Ask practical questions before rollout:
- What problem are we solving?
- Is there a less intrusive option?
- Do we need ongoing storage, or only one-off verification?
- Do we need the raw image, or only a template?
- Who in the business can access the information?
- When exactly will the data be deleted?
Get supplier contracts right
Your biometric consent form should never carry the full risk on its own. If a vendor handles the data, your contract with that vendor matters just as much.
Before you sign, check the supplier terms for:
- privacy and confidentiality obligations
- data security commitments
- breach notification timeframes
- cross-border disclosure terms
- deletion and return obligations at termination
- audit rights or information rights
- limits on secondary use of the data
- liability allocation if something goes wrong
If the vendor contract is silent on these points, your business may be left trying to make promises to customers or staff that your supplier is not actually obliged to support.
Train staff and set internal rules
A good form can still fail in practice if managers and frontline staff say inconsistent things. Anyone collecting consent or handling objections should know:
- what the business collects
- why it collects it
- what alternatives exist
- how to respond to access or deletion requests
- when to escalate privacy concerns
You should also decide internally who owns the process. In a small business, that might be a founder, operations lead or HR manager. Someone needs to be accountable for keeping the form, privacy wording, contracts and real system settings aligned.
Common mistakes New Zealand businesses make
The same issues appear again and again. Watch for these:
- using overseas template wording that does not match New Zealand privacy expectations
- burying consent inside employment contracts or general terms without clear standalone wording
- failing to explain whether data is kept in New Zealand or offshore
- not offering an alternative where one is realistic
- keeping biometric data indefinitely
- collecting biometric information for convenience rather than necessity
- forgetting contractors, visitors or casual workers who also use the system
- marketing the system as secure or private without verifying what the vendor actually does
The Fair Trading Act can also matter if your product or service claims overstate privacy or security features. If you tell customers their face scan is never stored, or that data is kept only on-device, those statements need to be true.
Think about your wider legal documents
Your biometric consent form should not sit alone. Depending on your setup, you may also need to update or review:
- your privacy policy
- customer terms and conditions
- employment agreements
- workplace policies
- contractor terms
- software and hosting agreements
- commercial lease or site access arrangements if the technology affects building entry
This matters particularly for growing businesses that are still formalising their legal foundations. Founders often focus on product build and registration first, then discover later that privacy, contracts, trade mark strategy, online terms and supplier documents all interact.
FAQs
Do all New Zealand businesses using biometrics need a separate biometric consent form?
Not always as a standalone document, but clear and specific consent wording is often the safest approach. If biometric data is being collected, relying only on a generic privacy clause is risky.
Can an employer require staff to use fingerprint or facial recognition?
Sometimes, but the business should be able to justify why the method is necessary and fair in that workplace. A practical alternative may be needed, especially if the impact on staff is significant.
Is a privacy policy enough instead of a consent form?
No, not by itself in many cases. A privacy policy explains your general handling of personal information, while a biometric consent form focuses on the specific collection and use of biometric data and records the person’s agreement.
What if the biometric software provider stores data overseas?
Your business should tell people about that and review the vendor arrangement carefully. Cross-border handling raises extra privacy questions, and your contract should address security, access, retention and deletion.
How long should biometric data be kept?
Keep it only for as long as you genuinely need it for the stated purpose. Indefinite retention is a common risk point, so set a deletion rule and make sure your systems can actually carry it out.
Key Takeaways
- A biometric consent form should clearly explain what biometric data your business collects, why it is needed and how it will be used.
- Consent wording must match the real system, including storage, suppliers, offshore processing, retention and deletion.
- New Zealand businesses should think about necessity and fairness, not just whether they can get a signature or checkbox.
- Where appropriate, offer a genuine alternative to biometric collection and explain the consequences of refusal or withdrawal.
- Your form should line up with your privacy policy, employment documents, customer terms and vendor contracts.
- Before rollout, review security, staff training, data retention settings and supplier obligations, so the process works in practice as well as on paper.
If your business is dealing with biometric consent form and wants help with privacy compliance, consent wording, supplier contracts, employment and customer documents, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.







