Last updated 20 July 2026
Biometric data is the most sensitive information the Identity Wallet handles, and it is treated differently from everything else. The protections below come from the published Biometric Data Addendum that governs the system — they are commitments, not marketing.
Four promises that never change
- Your biometric data is never sold, leased or traded — regardless of consent. It is never monetised.
- Raw biometric data is never shared with services. Services receive verification results — a level and a pass signal — never your face template or fingerprint.
- Biometric data is never stored unencrypted on the blockchain. Only encrypted references exist on-chain.
- Collection is optional. You choose whether to complete biometric verification, and you can withdraw at any time.
How the data is secured
Templates (the mathematical representations derived from your face or fingerprint — not photos) are encrypted on your device before they leave it, using X25519-XSalsa20-Poly1305 envelope encryption. In transit, everything travels over TLS 1.3. At rest, storage uses AES-256 with key rotation.
Where your phone supports it, fingerprint and iris capture happens inside the device's secure hardware, and the platform's integrity attestation (Google Play Integrity or Apple App Attest) proves the app and device have not been tampered with.
Where verification actually runs
Scoring runs inside trusted processing units — hardware-sealed enclaves (AMD SEV-SNP, Intel SGX, AWS Nitro) that the chain checks by cryptographic fingerprint before any data enters. The decryption key is derived inside the hardware and never exists outside it, so no operator, provider or foundation staff member can look in. Raw data is destroyed when scoring ends; only the result — a score and tier — remains. The full explainer is at identity.org.au/privacy/trusted-processing.
- Stage 1 Captured On your phone: document scan, selfie, liveness.
- Stage 2 Encrypted on your device Sealed before anything moves. Keys stay in your phone.
- Stage 3 Processed in a sealed enclave Hardware-attested. No operator can look inside.
- Stage 4 Raw data destroyed The enclave keeps nothing after scoring ends.
- Stage 5 Only the result remains A score and tier — never documents or biometrics.
How long biometric data is kept
- While your account is active — used only for verification and fraud prevention.
- After you close your account — up to 3 years, to prevent fraudulent re-registration.
- Absolute maximum — 7 years from last use, driven by know-your-customer laws.
- On deletion — removed from active systems within 30 days of your request, then from backups within the backup rotation period (typically 90 days). Encryption keys are destroyed, which makes any remaining encrypted copies permanently unreadable.
If something goes wrong
If a data breach ever involved biometric data, affected people would be notified within 72 hours of discovery, with a plain description of what happened, what data was involved, and what support is available. See the data breach response article for the full process.
You can request a copy of the biometric data held about you at any time by emailing dpo@virtengine.com with the subject “Biometric Data Access Request”. Responses are due within 30 days.