What Happens to a Student’s Face Data? Inside the Template
Where does my face go? The specific answer: converted on-device into a non-reconstitutable template, never stored as an image, deleted when consent is revoked.
Biometrics on campus only work if students, faculty, and staff can say yes to them — and understand exactly what they are saying yes to. This category covers the privacy side of facial authentication for higher education: the line between facial authentication and facial recognition (consent is that line), opt-in enrollment done honestly, encrypted templates that cannot be reconstituted into a face, edge processing that keeps biometric data on the device, and deletion the moment someone opts out. It also covers the regulatory landscape universities operate in — BIPA in Illinois, CCPA, GDPR for international students, FERPA’s boundaries — and the governance questions review boards and student governments will rightly ask. Written for the teams who have to defend a deployment in a town hall, not just in a security review.
Where does my face go? The specific answer: converted on-device into a non-reconstitutable template, never stored as an image, deleted when consent is revoked.
The sharpest CISO question deserves an attack-surface analysis, not reassurance. Four threats against an edge-processed system, and the five questions to ask any vendor.
The most dangerous forum is the one you didn't organize. A practical run-of-show for the biometric town hall — five predictable questions, answered with specifics.
Same reader, opposite outcomes. Why consent architecture — chosen versus imposed — decides campus biometric programs more than any technical property of the system.
The two terms get used interchangeably. They describe opposite technologies — and the difference decides whether your campus biometric project earns trust or opposition.