Standard: S-14Responsible Executive: Vice President for Information Technology and Chief Information OfficerResponsible Office: Office of the Vice President for Information TechnologyDate Issued: July 15, 2019Date Last Revised: September 1, 2026
ContactsIndividuals and Entities AffectedStatement of StandardResponsibilitiesDefinitions (defined terms are capitalized throughout the document)Related Documents, Forms and ToolsHistory and UpdatesAppendix
Purdue Systems Security (PSS)765-494-4000 | itpolicyanswers@purdue.edu
University students, faculty, staff and all other individuals or entities using University IT Resources.
This standard is not intended to apply to those departments and/or personnel conducting research on Biometric Technologies or Biometric Data for academic purposes. Refer to the Human Research Protection Program for requirements and approvals related to such activities.
Due to the unique and immutable nature of Biometric Data, any deployment of technologies using Biometric Data for identification and/or authentication purposes must be specifically approved by the University’s Chief Information Security Officer. Deployment of Biometric Technologies must comply with the following requirements:
An individual’s Biometric Data may not be collected or otherwise obtained by Purdue University without prior written explicit consent of the individual. Consent forms must inform the individual of the reason the Biometric Data is being collected and the length of time the data will be stored. The unit of the University that owns or oversees the administration of the system retains the associated consent forms.
The University does not disclose or disseminate any Biometric Data to anyone other than the biometric system vendor(s) and/or the unit of the University that owns or oversees the administration of the system(s), unless:
The University uses a reasonable standard of care to store, transmit and protect from disclosure any Biometric Data collected or retained. This standard of care is the same as or more protective than the manner in which the University stores, transmits, and protects from disclosure other Sensitive and Restricted Data that is used to uniquely identify an individual.
In circumstances where Purdue retains Biometric Data, the University permanently destroys the Biometric Data within 12 months of when the initial purpose for collecting or obtaining it has been satisfied, such as:
If any university vendors and/or licensees require access to Biometric Data in order to fulfill the purpose of collecting such information, the University requires that they follow the above destruction schedule.
Centralized and Departmental IT Units and IT Resource Owners (and designees)
Purdue Systems Security (PSS) – Chief Information Security Officer
University students, faculty, staff and all other individuals or entities granted use of University IT Resources
All defined terms are capitalized throughout the document. Additional defined terms may be found in the policy on Acceptable Use of IT Resources and Information Assets (VII.A.4) and in the central Policy Glossary.
Biometric DataThe unique physical attributes, including but not limited to, fingerprints, hand geometry, retina and iris patterns, voice waves, signatures, and facial patterns, that are used to identify a person.
Biometric Hash(es)A numeric value produced by running Biometric Data through a mathematical algorithm. The numeric value is representative of the Biometric Data.
Biometric TechnologiesTechnologies using a person’s Biometric Data for identification and/or authentication purposes.
End User DeviceA physical or virtual Device (e.g., cellphones, tablets, laptops, etc.) equipped with an operating system that can be leveraged by a user to establish a local or network connection to Purdue IT Resources.
This standard is issued in support of the policies on Acceptable Use of IT Resources and Information Assets (VII.A.4), as amended or superseded.
Request to Use Biometric Data Form
Office of the Registrar FERPA information
Purdue IT policies, standards and guidelines
National Institute of Standards and Technology (NIST) resources related to biometrics use:
September 1, 2026: Requirements for deploying Biometric Technologies updated. Added sections in the Statement of Standard on consent, disclosure, storage and retention. Added definitions for Biometric Hashes and End User Devices.
February 10, 2026: Standard reviewed, no changes.
December 12, 2024: Document reviewed; minor administrative updates made to titles, offices and links.
July 15, 2019: This standard supersedes Biometric Technologies Implementation Standard issued December 21, 2009 from the Purdue University Security Officer’s Group, University Data Stewards, and IT Networks and Security (ITNS).
There are no appendices to this standard.