FB pixel

FIDO Alliance stresses differences in MFA technologies, sensitivity of biometric data as GDPR takes effect

 

As the EU’s General Data Protection Regulation (GDPR) comes into effect, the FIDO Alliance has published a post outlining its perspective on the law, sharing three things that every organization should know about it.

The data protection safeguards GDPR requires of companies doing business with EU citizens are only complete, in FIDO’s view, if they include multi-factor authentication (MFA). The group says 81 percent of all breaches last year were due to weak or stolen passwords, but also warns that hackers have learned how to bypass first-generation MFA technologies, making it important to chose the right MFA solution.

GDPR’s requirement of consent from individuals to process their data also requires that organizations authenticate the identity of those individuals, FIDO points out. In the case of sensitive data, that consent must be explicit.

Finally, while biometrics can deliver strong personal authentication to help meet GDPR requirements, biometric data is classified as “sensitive” by GDPR. Therefore, any entity using biometrics must make sure that use is compliant, and that data is robustly protected.

FIDO also offers a whitepaper about using FIDO authentication for GDPR compliance (PDF).

Professors of Accounting Paul Sheldon Foote and Sumantra Chakravarty examined issues relating to biometrics and GDPR compliance in a recent guest post for Biometric Update.

Article Topics

 |   |   |   | 

Latest Biometrics News

 

Stop treating identity as a compliance step. It’s infrastructure now

By Harry Varatharasan, Chief Product Officer, ComplyCube The UK governmentʼs digital identity consultation is closing, and for most commentators, this…

 

If you build it, they will leave: experts warn UK gov’t on digital ID approach

The UK Cabinet Office’s consultation on digital identity closed on Tuesday, Digital systems built by governments tend to decline over…

 

Shufti biometric PAD clears iBeta Level 3 with 0 errors across iOS, Android

London-based global identity verification and fraud prevention provider Shufti has passed a Level 3 evaluation of its biometric Presentation Attack…

 

OpenID draft spec for extended identity claims assurance up for approval

Voting is open for approval of a draft specification to extend OpenID Connect to cover new features for requesting and…

 

EES troubles ignite speculation of further suspensions

Crowds, chaos and cranky travelers: The EU’s biometric border management scheme, the Entry-Exit System (EES), continues to fill headlines as…

 

UK Home Office eyes suppliers for SCBP biometrics platform

The Home Office is hosting a preliminary market engagement event to engage with potential suppliers for two not-yet-guaranteed future procurements…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events