Privacy-Preserving Verification: Biometric Data Without the Surveillance Footprint
Consumer trust in biometric data security has collapsed from 28% to 5% in two years, yet fraud volumes and regulatory requirements are pushing organizations to verify more. Privacy-preserving architectures using on-device processing, zero-knowledge proofs, and decentralized storage resolve this tension by confirming identity at high assurance without retaining biometric data on the other side of the exchange.
Consumer confidence in organizations’ ability to protect biometric data has collapsed over the past several years. According to a 2024 GetApp survey reported by Security Magazine, just 5% of consumers trust that their biometric data is secure with technology companies, down from 28% in 2022. Trust in specific modalities has followed the same trajectory: confidence in face scans has dropped from 44% to 33%, voice scans from 34% to 20%, and fingerprints from 63% to 50%. Nearly half of Americans report concern that facial recognition technology is tracking them beyond their personal devices. Researchers have identified the core anxieties as unchangeable data breaches, potential misuse by authorities, and algorithmic bias.
What makes this a strategic problem for CISOs and fraud leaders, not just a public relations one, is that organizations are simultaneously under pressure to verify more. Fraud volumes are rising. Regulatory frameworks are tightening. Synthetic identity attacks are scaling at a pace that makes knowledge-based authentication increasingly untenable. The answer to that pressure cannot be to collect and retain more biometric data, because that approach is precisely what eroded consumer trust in the first place.
The core problem is that verification has historically required accumulating far more personal data than any single transaction demands. That accumulation is what creates the surveillance footprint, the regulatory liability, and the trust deficit measured in those statistics. Fortunately, the architecture to verify identity rigorously without building a dossier is already in production.
Past Identity Models Were Built to Collect
Legacy identity verification systems were designed around a simple premise: the more an organization knew about a user, the more confident it could be in that user’s identity. In a paper-based world, that logic was defensible. In a digital one, it creates centralized databases of irreplaceable biometric data, attractive breach targets, and verification architectures that resemble surveillance more than they resemble authentication.
The “identity dossier” model treats identity as a record to be built, stored, and referenced indefinitely. An organization onboards a customer, collects their biometric data, stores it centrally, and references it repeatedly across every subsequent transaction. The data accumulates. The retention period extends. The attack surface grows. Centralized biometric databases have become priority targets for fraud actors precisely because of the data they contain. Litigation under Illinois’s Biometric Information Privacy Act (BIPA) reflects this reality, with organizations facing average costs of $1.2M per violation when their retention and consent practices fall short. GDPR enforcement in Europe follows a parallel logic. Data that shouldn’t have been retained in the first place becomes a liability the moment a breach or audit occurs.
A separate but equally serious failure mode lives at the other end of the spectrum. Device-based authentication that confirms a registered device without verifying the person holding it creates a deceptively clean record: no stored biometric data, no retention liability, no centralized database to breach. We call this approach “lazy biometrics.” It sidesteps the accumulation problem while leaving the fundamental question of identity unanswered. An authenticated device is not an authenticated person. Neither excessive collection nor surface-level verification is the right answer.
Regulation is pushing organizations to verify smarter. The data minimization requirements embedded in GDPR, BIPA’s retention limits, and the selective disclosure architecture of eIDAS 2.0 point in the same direction. Collect what you need to verify the claim, prove the claim, and retain nothing beyond what the transaction requires.
What eIDAS 2.0 Is Actually Telling Organizations
The European Union’s eIDAS 2.0 regulation is frequently discussed as a compliance framework. It’s more usefully understood as a directional signal about where identity infrastructure is heading globally, and that direction points decisively toward selective disclosure and user-controlled credentials. The concept at the center of eIDAS 2.0 is straightforward once you examine it. A user can prove they are over 18 without revealing their birthdate. They can confirm employment eligibility without exposing their full work history. They can verify citizenship without disclosing their home address. The underlying data stays with the user. What passes to the verifying organization is a cryptographically confirmed claim that this assertion is true. Nothing more is transmitted, and nothing more is stored on the other side of the exchange.
EU Member States are required to offer European Digital Identity (EUDI) Wallets by end of 2026. In parallel, Apple Wallet and Google Wallet have expanded mobile driving license support across an increasing number of U.S. states, with TSA accepting mobile driving licenses (mDLs) from participating jurisdictions. The infrastructure for digital wallets is scaling under enforceable governance frameworks, with liability rules and certified conformance programs attached. Organizations still architecting verification systems around data collection are building against the direction of regulation. GDPR, BIPA, CPRA, and eIDAS 2.0 are not four separate compliance obligations. They are four expressions of the same underlying principle: collect what you need, prove the claim, and give users meaningful control over what happens next.
Prove the Claim, Not the Data
Three architectural approaches, each already in production, allow organizations to verify identity at high assurance levels without retaining the underlying biometric data. None requires sacrificing fraud detection capability for privacy.
Zero-knowledge proofs (ZKPs) allow a system to cryptographically confirm that a claim is true without the verifying party ever receiving or storing the data that proves it. The proof is the credential. A device can demonstrate to a server that a biometric match occurred, at what confidence level, and on what hardware, without transmitting the biometric template itself. The server receives a verified signal, not a data record. There is nothing to breach because there is nothing stored. On-device processing keeps biometric templates on the user’s device entirely. Liveness detection, facial matching, and age assurance run locally. The result transmitted to the server is a confirmed outcome, for example that the person presenting themselves matches the enrolled identity, and the presentation is live.
Daon’s “no phone home” architecture embodies this principle, ensuring that authentication events are not reported back to central monitoring systems and no behavioral profile is assembled from the aggregated pattern of a user’s verification activity. Decentralized storage addresses scenarios where some data must leave the device. Rather than aggregating biometric templates in a single database, the architecture separates biometric data from personally identifiable information and distributes encrypted fragments across multiple storage nodes. A breach of any single node yields mathematically unusable data. There is no central repository from which a comprehensive identity record could be reconstructed, because no such repository exists.
Together, these approaches resolve what has long been framed as an unavoidable trade-off. An organization can verify a transaction, satisfy a regulator, and tell a user truthfully that their biometric data was never retained on the other side of the exchange. That statement is both a privacy commitment and an accurate technical description of what happened.
Trust as Competitive Architecture
For fraud leaders and CISOs, privacy-preserving verification is a risk calculation and a market position. Organizations that minimize biometric data retention reduce their exposure to BIPA litigation, GDPR enforcement, and breach-related remediation costs. Data you do not hold cannot be stolen, and it cannot be subpoenaed. The regulatory trajectory across every major jurisdiction points toward stricter retention requirements, not looser ones. Building minimization into the architecture now is less expensive than retrofitting it after an enforcement action.
The competitive case is equally direct. In markets where roughly 41% of consumers already report little to no trust in organizations’ ability to handle biometric data responsibly, the ability to make a genuine claim that biometric verification leaves no data footprint on the organization’s side is a differentiator. Organizations that have built that capability can lead with it in enterprise procurement conversations, consumer-facing onboarding, and regulatory engagement alike. Privacy-first architecture also accelerates time-to-market across jurisdictions. When GDPR data minimization, BIPA retention compliance, and eIDAS 2.0 selective disclosure capability are embedded in the system’s architecture rather than added afterward, expansion into a new market does not trigger a compliance reengineering project. The system already works the way the regulation requires.
Daon’s Identity Continuity framework reflects this logic at its foundation. Strong biometric verification enables personalization through security, not through surveillance. Customers become active participants in their own protection, not passive subjects of an authentication infrastructure they can neither see nor control. That distinction is what the trust numbers are measuring, and it’s what organizations can change, not through messaging, but through architecture.
Verification Without the Footprint
Digital identity is shifting from an accumulated record to a momentary, consent-bound signal. The architectural choice is available to organizations now, and eIDAS 2.0 has given that choice a regulatory frame. Zero-knowledge proofs and on-device processing have provided it a technical foundation. The consumer trust deficit gives it a business imperative. Organizations that make the architectural transition deliberately, building minimization into verification systems rather than treating it as a compliance afterthought, will not need to retrofit for the regulatory requirements already on the horizon.