Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- 1. Define the exact purpose
- 2. Collect only what you need
- 3. Explain it clearly to people
- 4. Review consent carefully, but do not rely on it blindly
- 5. Lock down storage and access
- 6. Set a firm retention period
- 7. Check your vendor and contract terms
- 8. Test fairness and accuracy in the real world
- 9. Align privacy documents, staff processes, and marketing claims
- 10. Know when the issue expands beyond privacy
FAQs
- Is biometric data automatically illegal for New Zealand businesses to collect?
- Do fingerprints and facial recognition count as personal information?
- Can an employer require staff to use a biometric attendance system?
- Do businesses need a privacy policy if they use biometric tools?
- What is the biggest mistake businesses make with biometric data?
- Key Takeaways
Many businesses collect more biometric information than they realise. A gym that uses fingerprint entry, a retail store trialling facial recognition for loss prevention, or a software company adding voice authentication can all end up handling highly sensitive personal information.
The common mistakes are usually the same: treating biometric data like ordinary customer details, collecting more than the business actually needs, and failing to explain clearly what is being collected and why.
That creates real risk under New Zealand privacy law, especially if your process is hard to justify or your security settings are weak. The issue often comes up before you sign a supplier agreement, before you spend money on setup, or before you launch a new app feature. This guide explains what counts as biometric data, gives practical biometric data examples, and sets out what New Zealand businesses should think about before collecting, storing, or using it.
Overview
Biometric data is information about a person's physical or behavioural characteristics that can be used to identify them, verify who they are, or classify them in a meaningful way. In New Zealand, there is no single standalone biometric data statute for most private sector businesses, but the Privacy Act 2020 still applies, and the sensitivity of biometric information raises the bar for lawful, fair, and secure handling.
- Work out whether the information can identify a person directly or indirectly.
- Check whether you genuinely need biometric data, or whether a less intrusive option would do.
- Be clear with staff, customers, and users about what you collect, why you collect it, and who you share it with.
- Set strict rules for storage, retention, access controls, and deletion.
- Review supplier contracts carefully, especially if the system uses cloud storage or offshore processing.
- Assess whether your use could feel unfair, excessive, or unexpected in the real setting where it is deployed.
What Biometric Data Examples Means For New Zealand Businesses
Biometric data usually means identifiable information taken from a person's body, behaviour, or biological patterns for recognition or analysis.
The clearest biometric data examples include fingerprints, facial geometry, iris or retina scans, voiceprints, palm vein scans, and hand geometry measurements. Some systems also use behavioural traits, such as typing rhythm, gait, or the way a user interacts with a device, if those traits are used to identify or verify that person.
Common biometric data examples in business settings
Here are some common examples that New Zealand startups and SMEs may encounter:
- Fingerprint scanners for staff attendance or access control.
- Facial recognition at entrances, reception areas, warehouses, or retail premises.
- Voice authentication in contact centres or account security tools.
- Photo analysis used to match identity documents to a live image in onboarding software.
- Iris or retina scans for high security sites.
- Behavioural biometrics in fintech, cybersecurity, or fraud detection tools.
- Wearables or health tech products that collect biological measurements capable of identifying a user.
Not every photo or audio recording is automatically biometric data. A standard staff photo on an ID card is not always being used biometrically. The legal and privacy risk increases when the image, recording, or measurement is analysed to identify someone, compare them against a database, or authenticate access.
Why businesses need to treat biometric information carefully
The main risk is that biometric information is hard to replace. If a password is exposed, it can be changed. If a fingerprint template or face template is compromised, the problem is much harder to fix.
That is why founders often get caught when they buy an off the shelf product and assume the provider has sorted everything. The supplier may offer the technology, but your business is still responsible for how and why you use it, what you tell people, and whether your collection is justified in the first place.
How the Privacy Act 2020 applies
In New Zealand, the Privacy Act 2020 and the Information Privacy Principles are the main legal framework for most private businesses handling personal information. Biometric data will usually be personal information if it is about an identifiable individual.
That means the usual privacy rules matter, including:
- Collecting information only for a lawful purpose connected with your business activities.
- Collecting only what is necessary for that purpose.
- Being open about collection and use.
- Storing information securely and limiting access.
- Allowing access and correction rights where applicable.
- Taking care with disclosure, cross border sharing, and retention.
The Office of the Privacy Commissioner has also signalled that biometric information deserves particularly careful treatment because of its sensitivity and the potential for misuse, exclusion, or unfair surveillance.
When This Issue Comes Up
Biometric privacy questions usually arise at the design and procurement stage, not after the system has gone live. That is the best time to pause and test whether the idea is lawful, proportionate, and worth the risk.
Staff attendance and workplace access
A common founder scenario is replacing swipe cards with fingerprint or facial recognition systems. The pitch is usually convenience, fewer buddy punching problems, and better site security.
But employment context matters. Staff may not feel they have a real choice, especially where refusal could affect shifts, entry, or payroll. Before rollout, think carefully about whether the biometric option is genuinely necessary and whether a less intrusive alternative should be offered.
Customer authentication and account security
Apps, platforms, and service providers often want faster login or stronger identity checks. Voice ID, selfie matching, and behavioural biometrics are increasingly common in fintech, software, online services, and regulated sectors.
This is where contracts, privacy wording, and product design need to line up. If your app says one thing, your vendor does another, and your internal process retains data longer than expected, that mismatch can create both legal and trust issues.
Retail monitoring and loss prevention
Facial recognition is one of the highest risk use cases. A retailer may want to identify repeat offenders, monitor banned persons, or improve security in stores.
The problem is not just collection. It is also fairness, accuracy, and whether people would reasonably expect that level of monitoring. A false match can create obvious commercial and reputational damage, and a broad surveillance approach may be difficult to justify.
Health, wellness, and wearable products
Health tech businesses can collect highly sensitive biological information through devices, apps, or connected services. Some data may be both health information and biometric information, which raises the stakes further.
Before you launch online, check what data the product collects by default, what is processed on the device versus in the cloud, and whether users understand the full scope of collection.
Visitor management and building security
Landlords, co working spaces, logistics operators, and industrial businesses may use biometric entry systems for convenience or security. This often intersects with commercial leases, site rules, contractor access, and third party providers.
Before you sign a contract for the system, clarify who controls the data, who can access it, and what happens when your contract ends. That point often gets missed until a business wants to switch vendors.
Practical Steps And Common Mistakes
The safest approach is to treat biometric data as high risk personal information and design your process carefully before collection starts.
1. Define the exact purpose
If you cannot explain in one or two sentences why you need biometric data, you probably are not ready to collect it. A vague goal like improving experience is usually not enough on its own.
Write down:
- the business problem you are solving
- why biometric collection is being considered
- whether a less intrusive tool could solve the same issue
- who will be affected, including staff, contractors, customers, and visitors
This matters before you spend money on setup, because your justification should drive the system design, your collection notice, and your internal rules.
2. Collect only what you need
Many products gather more information than the business actually requires. A vendor may offer video recording, template storage, behavioural tracking, and analytics, even though you only wanted door access.
That is a classic over collection problem. Limit the fields, features, and retention settings to what is genuinely necessary.
3. Explain it clearly to people
People should not have to guess that your business is using biometric systems. Transparency is one of the first things regulators and customers will look at.
Your privacy policy or collection notice should clearly cover:
- what biometric information is collected
- how it is captured, such as a scan, image analysis, or voice sample
- why it is needed
- whether providing it is mandatory or optional
- what alternatives exist, if any
- how long it is kept
- whether third party technology providers are involved
- whether information is stored or processed overseas
If the collection happens in person, signage and point of collection messaging may also matter. If it happens through an app or website, the flow should be easy to understand before the user submits data.
4. Review consent carefully, but do not rely on it blindly
Consent can help, but it is not a magic fix. In some settings, especially employment, consent may not be fully voluntary in practice.
Even where a person agrees, your collection still needs a clear lawful purpose and must not be excessive. Businesses often make the mistake of assuming a tick box solves everything.
5. Lock down storage and access
Security should be stricter than for ordinary contact details. The practical standard depends on your business, but the expectation is that sensitive information receives stronger protection.
At a minimum, think about:
- encryption in transit and at rest
- role based access controls
- separation between operational staff and full database access
- logging and monitoring of access
- secure deletion processes
- incident response planning
If a privacy breach occurs and it creates a risk of serious harm, the notifiable privacy breach rules may apply. That is another reason not to keep biometric information longer than necessary.
6. Set a firm retention period
Do not keep biometric data forever just because storage is cheap. If a former employee leaves, a customer closes an account, or a project ends, your retention rules should tell your team what happens next.
This is where founders often get caught. The collection process is built, but nobody owns deletion. A system with no end date creates unnecessary risk.
7. Check your vendor and contract terms
If you use a software platform, hardware provider, or managed security service, the supplier contract matters a lot. The technology may sit with a third party, but the business relationship and reputational risk sit with you.
Before you sign, check:
- who owns or controls the biometric templates and related data
- whether the vendor can reuse data to train models or improve its product
- where the data is hosted
- what subcontractors are involved
- how quickly the vendor must notify you of a breach
- what happens to the data at termination
- whether the contract matches your privacy statements and internal process
Cross border storage and access need particular care under New Zealand privacy rules. If data will be disclosed overseas, make sure the arrangement is appropriate and properly documented.
8. Test fairness and accuracy in the real world
A biometric system can be technically impressive and still be a poor fit for your business. False positives, false negatives, poor performance across demographics, and uncomfortable user experience can all become legal and commercial problems.
Ask practical questions:
- What happens if the system misidentifies someone?
- What is the backup process if the scan fails?
- Can a person still access your service or workplace in a reasonable way?
- Would your customers or staff find this use excessive or unexpected?
That is especially important in customer facing environments where trust is part of the product.
9. Align privacy documents, staff processes, and marketing claims
Your privacy policy, internal procedure, app wording, HR materials, and customer messaging should all say substantially the same thing. Misalignment is a common compliance issue.
The Fair Trading Act 1986 also matters if your business makes misleading claims about security, anonymity, or how data is used. If you say a system does not store biometric data, make sure that is true in practice and true in your vendor setup.
10. Know when the issue expands beyond privacy
Biometric systems can also touch contracts, employment obligations, procurement, leasing arrangements, cybersecurity commitments, and brand trust. If you are developing your own product, intellectual property and trade mark considerations may also come into the picture.
For startups building biometric features into software, this is not just a privacy checkbox. It can affect your sales terms, customer terms, investor diligence, and product rollout decisions.
FAQs
Is biometric data automatically illegal for New Zealand businesses to collect?
No. It is not automatically illegal, but it is sensitive and needs a clear lawful purpose, careful transparency, and strong security. The fact that technology allows collection does not mean the collection is justified.
Do fingerprints and facial recognition count as personal information?
Usually, yes. If the fingerprint, facial template, or related scan identifies a person or can reasonably be linked to them, it will generally be personal information under the Privacy Act 2020.
Can an employer require staff to use a biometric attendance system?
That depends on the context and how the system is implemented. The employer should be able to justify why the biometric method is needed, consider whether a less intrusive option is available, and make sure employment contracts and workplace processes are handled properly.
Do businesses need a privacy policy if they use biometric tools?
Most businesses collecting personal information should have a clear privacy policy, and biometric use usually calls for more specific explanations at the point of collection as well. A general policy on its own may not be enough if it does not accurately describe the system.
What is the biggest mistake businesses make with biometric data?
The biggest mistake is collecting it because the technology is available, not because the business has clearly justified the need. Close behind are poor vendor contracts, weak notices, and no deletion plan.
Key Takeaways
- Biometric data examples include fingerprints, facial recognition templates, voiceprints, iris scans, and some behavioural identification data.
- In New Zealand, biometric information will often be personal information regulated by the Privacy Act 2020.
- Your business should have a clear reason for collection and should consider less intrusive alternatives first.
- Transparency matters, especially around what is collected, why it is used, who handles it, and how long it is kept.
- Supplier contracts, cross border arrangements, storage security, and deletion rules are key risk areas.
- High risk uses, such as facial recognition in retail or staff monitoring, need especially careful review before rollout.
- If your business is dealing with biometric data examples and wants help with privacy compliance, supplier contracts, workplace rollout issues, or customer terms, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.








