Biometric Technologies (S-14)

Standard: S-14
Responsible Executive: Vice President for Information Technology and Chief Information Officer
Responsible Office: Office of the Vice President for Information Technology
Date Issued: July 15, 2019
Date Last Revised: September 1, 2026

Table of Contents

Contacts
Individuals and Entities Affected
Statement of Standard
Responsibilities
Definitions (defined terms are capitalized throughout the document)
Related Documents, Forms and Tools
History and Updates
Appendix 

Contacts

Clarification of Standard

Purdue Systems Security (PSS)
765-494-4000 | itpolicyanswers@purdue.edu

Individuals and Entities Affected

University students, faculty, staff and all other individuals or entities using University IT Resources.

This standard is not intended to apply to those departments and/or personnel conducting research on Biometric Technologies or Biometric Data for academic purposes. Refer to the Human Research Protection Program for requirements and approvals related to such activities.

Statement of Standard

Due to the unique and immutable nature of Biometric Data, any deployment of technologies using Biometric Data for identification and/or authentication purposes must be specifically approved by the University’s Chief Information Security Officer. Deployment of Biometric Technologies must comply with the following requirements:

  • No Biometric Data in image formats may be stored on University IT Resources.
  • Biometric Data must be encrypted via the use of an algorithmic process to transform the data into a form in which there is a low probability of assigning meaning to that Biometric Data without use of a confidential process or key.
  • Biometric Hashes are considered Restricted Data under the University’s data classification schema and must be handled in accordance with the University’s Data Handling Procedures.
  • Biometrics may be used only for identification of an individual.
  • Biometrics may not be used for authentication alone. An additional factor is required, such as a PIN, password or other user credential unless approved by Purdue Systems Security (PSS).
  • Biometric Technologies may be used as single-factor authentication to unlock an End User Device that was previously authenticated via non-biometric means. In this case, Biometric Data may only be stored locally on an End User Device if stored with industry accepted encryption.
  • Student Biometric Data are education records that include personally identifiable information under the Family Educational Rights and Privacy Act of 1974 (FERPA). Departments and units considering implementation of Biometric Technologies involving student Biometric Data must consult with the FERPA data steward in the West Lafayette Office of the Registrar.
  • Prior to implementation of Biometric Technologies, a Request to Use Biometric Data Form must be submitted to the Chief Information Security Officer.

Consent

An individual’s Biometric Data may not be collected or otherwise obtained by Purdue University without prior written explicit consent of the individual. Consent forms must inform the individual of the reason the Biometric Data is being collected and the length of time the data will be stored. The unit of the University that owns or oversees the administration of the system retains the associated consent forms.

Disclosure

The University does not disclose or disseminate any Biometric Data to anyone other than the biometric system vendor(s) and/or the unit of the University that owns or oversees the administration of the system(s), unless:

  1. Disclosure is required by state or federal law or municipal ordinance;
  2. Disclosure is required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction;
  3. The disclosed data completes a financial transaction requested or authorized by the individual to whom the Biometric Data pertains; or
  4. The individual to whom the Biometric Data pertains has consented to such disclosure or dissemination.

Storage

The University uses a reasonable standard of care to store, transmit and protect from disclosure any Biometric Data collected or retained. This standard of care is the same as or more protective than the manner in which the University stores, transmits, and protects from disclosure other Sensitive and Restricted Data that is used to uniquely identify an individual.

Retention

In circumstances where Purdue retains Biometric Data, the University permanently destroys the Biometric Data within 12 months of when the initial purpose for collecting or obtaining it has been satisfied, such as:

  1. The faculty or staff member’s employment ends;
  2. The student graduates or otherwise leaves the University;
  3. The employee transfers to a position for which the Biometric Data is not used; and/or
  4. The University no longer uses the Biometric Data.

If any university vendors and/or licensees require access to Biometric Data in order to fulfill the purpose of collecting such information, the University requires that they follow the above destruction schedule.

Responsibilities

Centralized and Departmental IT Units and IT Resource Owners (and designees)

  • Implement and support compliance with this standard and any related policies, standards and best practices for University IT Resources within their areas of responsibility.
  • Establish additional guidelines, procedures or other requirements that exceed this standard, as necessary, to secure Biometric Technologies and Biometric Data.
  • Consult the Purdue Office of the Registrar FERPA consultant or data steward when considering use of student Biometric Data.
  • Prior to implementation of Biometric Technologies, submit to the Chief Information Security Officer a Request to Use Biometric Data Form.

Purdue Systems Security (PSS) – Chief Information Security Officer

  • Review and make determinations on requests to use Biometric Data.

University students, faculty, staff and all other individuals or entities granted use of University IT Resources

  • Comply with the requirements of this standard and any related policies, standards or security guidelines and procedures that may be issued by their departmental IT units and/or owners of the IT Resource(s) they access.

Definitions

All defined terms are capitalized throughout the document. Additional defined terms may be found in the policy on Acceptable Use of IT Resources and Information Assets (VII.A.4) and in the central Policy Glossary.

Biometric Data
The unique physical attributes, including but not limited to, fingerprints, hand geometry, retina and iris patterns, voice waves, signatures, and facial patterns, that are used to identify a person.

Biometric Hash(es)
A numeric value produced by running Biometric Data through a mathematical algorithm. The numeric value is representative of the Biometric Data.

Biometric Technologies
Technologies using a person’s Biometric Data for identification and/or authentication purposes.

End User Device
A physical or virtual Device (e.g., cellphones, tablets, laptops, etc.) equipped with an operating system that can be leveraged by a user to establish a local or network connection to Purdue IT Resources.

Related Documents, Forms and Tools

This standard is issued in support of the policies on Acceptable Use of IT Resources and Information Assets (VII.A.4), as amended or superseded.

Request to Use Biometric Data Form

Office of the Registrar FERPA information 

Purdue IT policies, standards and guidelines

National Institute of Standards and Technology (NIST) resources related to biometrics use:

History and Updates

September 1, 2026: Requirements for deploying Biometric Technologies updated. Added sections in the Statement of Standard on consent, disclosure, storage and retention. Added definitions for Biometric Hashes and End User Devices.

February 10, 2026: Standard reviewed, no changes.

December 12, 2024: Document reviewed; minor administrative updates made to titles, offices and links.

July 15, 2019: This standard supersedes Biometric Technologies Implementation Standard issued December 21, 2009 from the Purdue University Security Officer’s Group, University Data Stewards, and IT Networks and Security (ITNS).

Appendix

There are no appendices to this standard.