Iris Biometrics and the Classroom: Exploring with Students the Reality Behind Digital Identity (and Its Implications)
The growing digitization of society has fueled the search for more efficient and secure digital identity systems (ones that cannot be hacked by people or bots). However, behind the promises of innovation and democratization lies a complex web of economic interests, the surrender of rights, and risks to individual privacy.
One of the most concerning issues is the way in which companies obtain users’ consent to collect and use their biometric data. Often, the Terms of Use are lengthy, complex, and written in legal language, with an expiration date. This situation makes it difficult to understand the rights and obligations involved.
By accepting these terms, users may be waiving important rights, such as the right to privacy, data protection, and compensation for damages in the event of misuse of their personal information.
The issue becomes even more sensitive when a financial incentive is involved. In exchange for an iris scan, for example, some companies offer a monetary reward. This offer can be tempting, especially for people in vulnerable socioeconomic situations, who may not be fully aware of the risks and implications of sharing their biometric data.
If profit is one of the main drivers behind the collection of biometric data, and if every real invested is motivated by the expectation of a return, how much is your iris really worth?
For that reason, I analyzed hundreds of pages of Terms of Service, other documents such as hardware and software development documentation, and the LGPD with the help of AI.
Before we continue, why the iris?
| Feature | Iris Scanning | Passwords | Fingerprints |
| Uniqueness | Extremely high. The iris has more variation points than a fingerprint. | Low ( can be shared, reused, etc.). | High, but lower than that of the iris. |
| Security | High. Difficult to counterfeit or replicate. | Relatively low (vulnerable to phishing, breaches, etc.). | Passphrase (can be forged, although it's harder to do so than with passwords). |
| Convenience | Average. Requires a specific device (Orb) and proper placement. | Sign Up. Easy to set up and use on a variety of devices. | High. Found in many modern devices. |
| Privacy |
Greater concerns due to the sensitive nature of biometric data and the potential for tracking. | Fewer direct concerns regarding biometric data. | Concerns about data storage and use. |
| Modifiability |
Remains unchanged throughout life (except in rare cases of trauma). | It can be easily changed. | Unchanging. |
| Fraud resistance | High. Difficult to cheat. | Low. Vulnerable to brute-force attacks, phishing, etc. | Average. Prone to forgery, but more secure than passwords. |
Companies can use this data for a variety of purposes, such as:
- Personalization of ads and services:Biometric datacan be combined with other personal information to create detailed user profiles, enabling the delivery of targeted ads and the provision of personalized services.
- Development of new products and technologies:Biometric datacan be used to train artificial intelligence algorithms and develop new technologies for facial recognition, voice recognition, and other individual characteristics.
- Data sales:Biometric datamay be sold to third parties, such as marketing companies, security agencies, and governments.
The development of hardware and software for iris scanning represents a significant technological advance, but it also raises important ethical and legal questions. It is essential that users be fully aware of the risks and benefits involved before consenting to the collection of their biometric data. Companies must be transparent about their data collection and usage practices, and governments must implement strict regulations to protect citizens’ privacy.
See also:
- Why are science fairs important for students, educators, and Brazil?
- Online Gambling: From Literacy to Literacy, Education Can Make a Difference
- What's Left for Education After the Metaverse Hype?
The debate on digital identity, biometrics, and data protection is essential for the future of society. It is important that all individuals, regardless of their background or level of knowledge, participate in this debate and contribute to building a more just, secure, and democratic digital future.
Risks and Challenges
Despite the potential advantages, a universal digital identity system based on biometrics and cryptocurrencies presents a number of risks and challenges that must be carefully considered:
• Privacy: Thecollection and storage of biometric data are extremely sensitive matters. The system must ensure the protection of users’ privacy by preventing unauthorized access, misuse, and discrimination.
• Security:Biometric data must be stored securely to prevent leaks, theft, and forgery. The system must implement robust security measures, such as encryption, multi-factor authentication, and regular audits.
• Centralization: Acentralized digital identity system can lead to mass control and surveillance. The system should be designed to be decentralized, allowing users to control their own data and identities.
• Exclusion:Not all individuals have access to the technology needed to participate in the system. The system must be inclusive and ensure that all individuals, regardless of their location, income, or level of education, can benefit from it.
• Legislation: Thesystem must comply with data protection laws in all countries where it is implemented. This includes obtaining informed consent from users, informing them of the purpose of data collection, and ensuring their right to access, correct, delete, and transfer their data.
LGPD Compliance Analysis
Brazil’s General Data Protection Law (LGPD) establishes strict guidelines for the processing of personal data, especially sensitive data such as biometric information. A universal digital identity system based on biometrics and cryptocurrencies must be fully compliant with the LGPD to operate legally in Brazil. The key points to consider regarding the LGPD are:
- Consent:Consent to the collection of biometric data must be freely given, informed, unambiguous, and specific to each purpose.
- Purpose:The purpose of data collection must be clear, specific, and legitimate.
- Transparency: Usersmust be informed about how their data will be collected, used, stored, and shared.
- Data Subjects' Rights:Users must have the right to access, correct, delete, and transfer their data.
- Security:The system must implement robust security measures to protect data against unauthorized access, misuse, and leakage.
A Quick Comparison Between Compiled Generic Terms of Acceptance and the LGPD, and Difficulty in Understanding Them
| Terms of Acceptance (Generic) | LGPD (General Data Protection Law) | Potential conflicts and difficulties for users in understanding the system |
| Collection of personal data, including biometric data (iris scan), with the Privacy Policy explaining how the data is used. By using the app, you consent to this collection. | Article 7: Free, informed, and unambiguous consent for the processing of personal data. Article 11: Specific and distinct consent for sensitive (biometric) data. | General consent, without specifying the purpose, retention period, and risks associated with biometric processing. The Privacy Policy may not be sufficient to constitute informed consent. |
| The Terms may be amended from time to time, and your continued use of the app constitutes your acceptance of the updated Terms. | Article 8, Paragraph 5: Consent may be revoked at any time, free of charge and in a straightforward manner. | Lack of awareness regarding changes to the Terms, forcing users to accept them in order to continue using the service. Difficulty in revoking consent and discontinuing use of the service. |
| Non-custodial wallet: The user controls the digital tokens, and the service provider does not have access to the private keys. Losing the keys means losing the tokens. | Art. 46: Adoption of security measures to protect personal data against unauthorized access and unlawful destruction, loss, alteration, disclosure, or any form of inappropriate or unlawful processing. |
The service provider is not liable for the loss of private keys, even if the user lacks the technical knowledge to protect them. |
| The user is responsible for ensuring that use of the app is legal in their location. | Article 6: Compliance with the principles of good faith, purpose, proportionality, necessity, free access, data quality, transparency, security, prevention, non-discrimination, and accountability. | Lack of awareness of data protection laws, leading users to violate the law when using the app. |
| The company may share data with third parties, including business partners and service providers. | Art. 33: The international transfer of personal data shall be permitted only when adequate safeguards are in place. | A lack of clarity regarding with whom the data is shared, for what purposes, and what security measures are in place. |
To begin understanding
A universal digital identity system based on biometrics and cryptocurrencies has the potential to bring significant benefits to society—such as financial inclusion, participation in decentralized projects, and access to public services—and is inevitable.
However, it is essential that these systems be designed and implemented in an ethical, secure, and transparent manner, ensuring the protection of users' privacy and compliance with data protection laws.
This is a very interesting and important topic, one that holds great promise: more secure passwords. Just by looking at the screen of a cell phone, computer, or even a smart glass (yes, your bathroom mirror or car windshield), your profile will automatically appear. But if your data has to be used for this purpose, it must be treated with the respect and security it deserves.
About the author:
-
Francisco Tupy
Ph.D. from the University of São Paulo with a focus on video games
*This text does not necessarily reflect the opinion of Bett Brasil.
Share on social media:
Categories
- Innovation
- Teaching Methodologies

