Skip to content

Address privacy concerns of using biometrics #21

@denkeni

Description

@denkeni

ISSUE 2: Add Privacy Considerations section
Add privacy considerations section that includes at least the following topics:

  • Strongly advise against using biometrics for confidence methods unless absolutely required. Warn that verifiers should only require biometric photos as a last resort and should destroy the information after the transaction is complete. (source)

Once the biometric is included as part of data integrity of VC, it could be difficult for verifiers to delete the VP as soon as the transaction is complete, as verifiers may be required to keep the evidence of VP for at least months.

I would suggest the verifier SHOULD implement some prompting to the holder before the VP transmission, for example, implementing Purpose in OpenID4VP, or any similar mechanism within VCALM.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions