Last updated 20 July 2026
Biometric data is the most sensitive information the Identity Wallet handles, and it is treated differently from everything else. The protections below come from the published Biometric Data Addendum that governs the system — they are commitments, not marketing.
Four promises that never change
- Your biometric data is never sold, leased or traded — regardless of consent. It is never monetised.
- Raw biometric data is never shared with services. Services receive verification results — a level and a pass signal — never your face template or fingerprint.
- Biometric data is never stored unencrypted on the blockchain. Only encrypted references exist on-chain.
- Collection is optional. You choose whether to complete biometric verification, and you can withdraw at any time.
How the data is secured
Templates (the mathematical representations derived from your face or fingerprint — not photos) are encrypted on your device before they leave it, using X25519-XSalsa20-Poly1305 envelope encryption. In transit, everything travels over TLS 1.3. At rest, storage uses AES-256 with key rotation.
Where your phone supports it, fingerprint and iris capture happens inside the device's secure hardware, and the platform's integrity attestation (Google Play Integrity or Apple App Attest) proves the app and device have not been tampered with.
Where verification actually runs
Original identity document images stay on your device and are not sent to an enclave or the network. The wallet processes them locally. If you approve a VEID scope, only its minimum derived data may be sent encrypted; that scope notice explains where it is processed and its lifecycle. See identity.org.au/privacy/trusted-processing.
- Stage 1 Captured On your phone: document scan, selfie, liveness.
- Stage 2 Original stays local The document image never leaves your device. OCR and checks run locally.
- Stage 3 Derived data, if approved Only minimum user-approved fields may leave, encrypted for VEID processing.
- Stage 4 Transient data cleared Temporary processing data is cleared under the scope lifecycle; source images remain local.
- Stage 5 Selective result The network records the verification result and required encrypted references, never source images.
How long biometric data is kept
- While your account is active — used only for verification and fraud prevention.
- After you close your account — up to 3 years, to prevent fraudulent re-registration.
- Absolute maximum — 7 years from last use, as stated in the Biometric Data Addendum.
- On deletion — removed from active systems within 30 days of your request, then from backups within the backup rotation period (typically 90 days). Encryption keys are destroyed, which makes any remaining encrypted copies permanently unreadable.
If something goes wrong
If a data breach ever involved biometric data, affected people would be notified within 72 hours of discovery, with a plain description of what happened, what data was involved, and what support is available. See the data breach response article for the full process.
You can request a copy of the biometric data held about you at any time by emailing dpo@virtengine.com with the subject “Biometric Data Access Request”. Responses are due within 30 days.