Guidelines on the Use of Biometric Data
Biometric Data User refers to any person who collects or use biometric data utilizing ZKTeco’s device, hardware and software


1. The purpose of biometric data collection
1.1.   Use of biometric data & related activities
  It is data user’s responsibility to inform all users or persons whose biometric data are collected, that all the collected biometric data are only used for time attendance and access control purposes.
   
1.2.  Lawful and fair means
  Data User must collect users’ biometric templates only on a legal and fair basis.
   
1.3.  Adequate but not excessive
  ZKTeco’s devices and all biometric templates stored in its management software are built with precise algorithms and may be in various methods encrypted, in order to prevent data leakage of users to the greatest extent.



2. Accuracy and Duration of Retention
2.1.   Accuracy of personal data held
  ZKTeco, with rich experience of software and hardware development, to the greatest extent ensures that all biometric data and personal data are stored accurately, in order to provide customers best user experience.
   
2.2.  Personal data not being kept longer than is necessary
  When using ZKTeco’s software and hardware, data user is responsible for ensuring that all users’ data are not stored in ZKTeco’s software and hardware unless necessary.
   
2.3.  Prevent any personal data transferred to the data processor from being kept longer than necessary
  ZKTeco’s hardware applies different biometric templates during operation, but all templates are not remained in the CPU of the hardware, and after users’ biometric templates are deleted in ZKTeco’s hardware and software (according to actual situation), the templates are permanently deleted and not remained in any format.



3. Use of Personal Data
3.1. Not being used for a new purpose without prescribed consent
  If data user wishes to apply the collected biometric templates to any purpose other than any use authorized, they are responsible for reintroducing to the users and obtain their consents before doing so.



4. Security of Personal Data
4.1.  Practicable steps being taken to ensure no unauthorized or accidental access, processing, erasure, loss, use and transfer
  ZKTeco’s applied biometric algorithms do not collect complete biometric features of the collected persons, instead only 10 to 50 feature points are collected for calculation. Even if biometric templates are illegally obtained, it is not possible to reorganize them into complete biometric features. In ZKTeco’s software and hardware, various advanced electronic encryption techniques have been applied for the greatest extent of protection to data security.



5. Openness – Information be Generally Available
5.1.   Data User should provide policies and practices in relation to personal data.
5.2.  Data User should publicize the kinds of biometric data held.
5.3.  Data User should inform the main purposes for which biometric data are used.



6. Access to Personal Data
6.1.   Data user should know that, all data subjects have the rights to access and correct his or her personal data.
Frequently ask question of biometric data

I. What is Biometric Data?
  Physiological data born with an individual
  DNA samples, fingerprint, palm veins, iris, retina, facial images and hand geometries
   
  Behavioral data developed by an individual
  DNA samples, fingerprint, palm veins, iris, retina, facial images and hand geometries


II. Is Biometric Data Personal Data?
  Biometric data alone is not regarded as personal data according to law, as it may not reveal identities. However, if biometric data is stored in a database that links customers/staff members, they are personal data.
   
  《Guidelines on the Use of Biometric Data》 For document download please click here.