What Biometric Data Is and Why It Matters to Tech Companies
A banking app that recognizes customers by their face, an office attendance system that reads fingerprints, a fintech product that verifies identity through voice recognition — these have all become standard features of Israeli technology products. Behind the convenience, however, lies a category of information that carries particularly heavy legal weight.
Biometric data includes fingerprints, facial templates, iris scans, voiceprints, gait patterns, and behavioral biometric signatures. These are unique, unchangeable physical characteristics of a person — which is precisely why they are so sensitive. Unlike a password, a fingerprint exposed in a data breach cannot simply be replaced.
Israeli technology companies — from fintechs performing identity verification (KYC), through security companies developing facial recognition systems, to SaaS providers rolling out biometric login — all need to understand the Israeli legal framework governing this type of data, including the implications of Amendment 13 to the Privacy Protection Law.
Biometric Data as "Sensitive Information" Under Israeli Law
The Privacy Protection Law, 5741-1981, as amended by Amendment 13 (in force since August 14, 2025), does not contain a standalone definition of "biometric data." However, the Privacy Protection Regulations (Data Security), 5777-2017, include information used for biometric identification within the definition of "sensitive information." This classification directly affects the required security level and the permitted handling of the data.
It is worth clarifying a common misconception: Amendment 13 narrowed the database registration requirement so that it now applies mainly to public bodies and to "data brokers" — entities whose principal business is collecting personal data in order to pass it on to others — above a statutory size threshold. This obligation was not abolished entirely, and a company that is not required to register a database is still fully subject to the security, consent, and use-limitation duties that apply to sensitive information.
The practical takeaway for tech companies: the fact that a database is not subject to registration does not exempt it from implementing enhanced protective measures when collecting fingerprints, facial templates, or voice data from customers or employees.
A High Security Standard: What the Data Security Regulations Require
The Privacy Protection Regulations (Data Security) establish a tiered structure of security levels — basic, intermediate, and high — based on the sensitivity and scope of the data. A database containing biometric data will, in most cases, fall into the high security tier, which imposes significantly stricter requirements.
Key requirements under the high security tier include
- Conducting periodic risk assessments and penetration tests
- Appointing a data security officer where applicable
- Encrypting biometric data both at rest and in transit
- Implementing strict access controls and logging all access to the data
- Maintaining written procedures for database management and employee training
Beyond this, when a company relies on a third-party biometric technology provider — such as a facial recognition SDK — it must confirm, through technical due diligence and an explicit contract, that the vendor meets the required security level. Responsibility toward data subjects is not transferred to the subcontractor.
Explicit Consent and a Defined Purpose for Collecting Biometric Data
The Privacy Protection Authority's consent guidance, which took effect in February 2026, set a heightened standard for informed consent generally, along with a requirement for separate and specific consent for profiling activities and for direct mailing. As of the date of this article, this standard applies in full to the collection of biometric data — and arguably with even greater force, given the sensitivity involved.
In practice, tech companies must ensure that consent to collect biometric data is explicit, separated from other consents in the privacy policy, and clearly states the purpose of use — for example, identity verification only, as distinct from any future use for targeted advertising.
In the employment context — for instance, biometric attendance systems in the workplace — the Privacy Protection Authority has long taken the position that employees who do not wish to provide a fingerprint or facial scan must be offered a non-biometric alternative, out of concern for the limited freedom of choice inherent in employer-employee relationships. Companies operating such systems should document this alternative in their organizational policy.
Breach Notification Duties for Biometric Data
Amendment 13 added a duty to report severe security incidents affecting databases under the Privacy Protection Law, and granted the Privacy Protection Authority expanded enforcement powers, including the authority to impose administrative fines. This reporting duty applies in full to databases containing sensitive information, and biometric data falls within that category.
For tech companies, this means that a security incident exposing facial templates, fingerprints, or voice samples — for example, following a server breach or a cloud misconfiguration — may trigger a duty to notify the Privacy Protection Authority, and in certain circumstances a duty to notify the affected data subjects directly.
Given the irreversible nature of biometric data — a customer whose fingerprint has been exposed cannot simply "replace" it the way one replaces a password — companies are well advised to establish an incident response plan in advance that includes a dedicated step for assessing exposure of biometric data, and to ensure legal counsel is involved in any decision to report within the timeframe prescribed by law.
Transferring Biometric Data Abroad and to Cloud Providers
Many technology companies rely on cloud providers and international models for biometric processing — facial recognition, voiceprint authentication, or AI-based anti-fraud services. In these cases, the Privacy Protection Regulations (Transfer of Data to Databases Outside the Borders of the State), 5761-2001, govern the conditions under which personal data may be transferred outside Israel.
Where the data transferred is classified as sensitive, as is the case with biometric data, companies must take particular care to satisfy the regulations' conditions — ensuring an adequate level of protection in the destination country or entering into an appropriate agreement with the receiving party, including detailed data protection clauses.
On the European front, it is worth noting that the GDPR classifies biometric data used for unique identification as a "special category" of data requiring an enhanced legal basis for processing. Israeli companies serving European customers should ensure dual compliance — with both Israeli law and the GDPR — and document the legal basis for every biometric processing activity.
What Tech Companies Should Actually Do
Practical compliance with biometric data law requires a structured process, not merely a legal document. Below are the key steps tech companies should take.
- Map every point in the organization where biometric data is collected, processed, or stored, including subcontractors and third-party SDK tools
- Consider whether a privacy impact assessment is warranted before launching a product or feature based on biometric identification
- Update the privacy policy to clearly separate consent for biometric use from other consents
- Implement high-tier security measures — encryption, access controls, and logging — in line with the data security regulations
- Establish a clear retention and deletion policy for biometric data, limiting storage to what is necessary
- Update agreements with cloud and identification-technology vendors to include specific security commitments
- Evaluate whether appointing a data protection officer is warranted, based on the scope and nature of the company's activity
Companies that build biometric technology into their products from the design stage (privacy by design), rather than addressing it only after launch, significantly reduce their legal exposure and the operational risk of mishandling this type of sensitive data.
The legal framework surrounding biometric data in Israel continues to evolve, both through Privacy Protection Authority guidance and through enforcement. Companies that treat this area as an integral part of their compliance strategy — rather than a purely technical matter — will be better positioned to meet future regulatory requirements and maintain customer trust.
The information contained in this article is general in nature and does not constitute legal advice. For advice tailored to the specific circumstances of your company, we invite you to contact our firm.