orderConcluded
Federal Data Protection and Information Commissioner (FDPIC) — PostFinance AG
May 16, 2025 · Switzerland
The FDPIC found PostFinance's creation of customer voiceprints for biometric authentication violated proportionality and lacked explicit consent, and ordered it to obtain explicit consent before creating voiceprints and delete those lacking consent (under appeal).
Key takeaway — how to prevent this
Biometric data (faces, iris, fingerprints) needs an explicit lawful basis or consent. Scraping or capturing it without one is unlawful across the EU/UK and many US states (e.g. Illinois BIPA) — and draws the largest fines.
Inclusion does not imply wrongdoing or liability. Status reflects the latest information we have — always check the official source for current status.