orderConcluded

Federal Data Protection and Information Commissioner (FDPIC) PostFinance AG

May 16, 2025 · Switzerland

The FDPIC found PostFinance's creation of customer voiceprints for biometric authentication violated proportionality and lacked explicit consent, and ordered it to obtain explicit consent before creating voiceprints and delete those lacking consent (under appeal).

Key takeaway — how to prevent this

Biometric data (faces, iris, fingerprints) needs an explicit lawful basis or consent. Scraping or capturing it without one is unlawful across the EU/UK and many US states (e.g. Illinois BIPA) — and draws the largest fines.

Inclusion does not imply wrongdoing or liability. Status reflects the latest information we have — always check the official source for current status.