CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
biometrics

How Is Biometric Data Stored? Inside the $47M Iris Suit

They Paid $10 for Her Iris Scan. Now Her City Wants $47 Million Back.
An orb-shaped iris scanner in São Paulo highlights growing questions about how is biometric data stored after a $47M lawsuit.

Imagine someone in your neighborhood offered you $10 to look into a machine. Just look. Takes two seconds. In return, you get a little money, a "verified human" badge for the internet, and, buried somewhere in the fine print, the permanent record of your iris scan sitting on a server you've never heard of, in a country you didn't know about, with no clear instructions on how to get it deleted. That is roughly what happened to 400,000 people in São Paulo, Brazil. And the city is now suing for $47 million to make it stop.

TL;DR

São Paulo is suing the company behind World ID for collecting iris scans from hundreds of thousands of low-income residents in exchange for small crypto payments, without properly explaining what would happen to that data, and the questions this lawsuit raises are about to show up in your own app downloads.

The company at the center of this is Tools for Humanity, the organization that runs World ID (previously called Worldcoin). Their product is a biometric identity system, meaning it uses your body, specifically your iris, to prove you're a real human being and not a bot. The technology itself is not science fiction. It's already running. And in São Paulo, prosecutors say the way it was rolled out crossed a serious line.


São Paulo's Biometric Data Collection Crisis

According to Biometric Update, São Paulo prosecutors opened a $47 million lawsuit against the operators of World ID after a city council investigation found that residents, concentrated in lower-income neighborhoods, were scanning their eyes into orb-shaped devices in exchange for small crypto payments.

CaraComp DailyEP.86
3 stories · 2:59
Starts at 01:01 — this story
2:59

Watch this story, in under a minute

Plays right here · jumps to 01:01
In this episode

A new briefing every weekday — three stories, three minutes.

Subscribe on YouTube

Here's the part that matters: they were not clearly told where that iris data was going. It was being stored on Amazon Web Services infrastructure. It was, potentially, being transferred outside Brazil. Those are not small details. That's your most permanent personal identifier, your iris cannot be changed the way you change a password, sitting on foreign servers under terms most people never read.

400,000
São Paulo residents had their iris data collected, many in low-income areas, in exchange for small crypto payments, before prosecutors stepped in
Source: Biometric Update / Bitcoin.com News

Brazil's national data protection authority had already told World ID to stop offering financial incentives for the scans. That order went out. And then, according to Bitcoin.com News, the company kept right on offering rewards through its app anyway. The city council investigation found this out, and the lawsuit followed. The core accusation isn't just "you collected data." It's "you collected data from vulnerable people, you didn't explain it properly, and then you kept going after regulators told you to stop." This article is part of a series, start with Your Face 47 Times A Night The New Law That Turns Your Phone.

"Regulators now understand that 'user consent' via a checkbox during signup is theater, not protection." Expert analysis, Biometric Update

That quote is doing a lot of work. Think about every app you've ever downloaded. You tapped "I agree" on a screen. You moved on with your life. Nobody expects you to read 47 pages of legal text. The problem is that courts and companies have long treated that tap as your full, informed, freely given agreement. Regulators are now saying: not anymore. Not for body data.


Biometric ID vs. Passwords: Key Differences

Biometric data, your face, iris, fingerprints, voice, the physical stuff that is uniquely yours, gets treated differently under the law for one simple reason: you can't reset it. If someone steals your password, you change it. If a company leaks your iris scan, you have that iris for the rest of your life. There is no patch, no reset, no "forgot my eye" button.

This is why lawmakers in the United States have been building specific rules around it. Illinois has had its Biometric Information Privacy Act, the one most people call BIPA, for years. States including Colorado have added similar protections, requiring companies to get your real, informed consent before collecting body data, and in some cases capping how long they can keep it (three years is one common limit). According to Reed Smith, these laws come with private rights of action, meaning individuals, not just government agencies, can sue companies that break the rules. The financial exposure is real.

The EU has its own framework. Brazil has its Lei Geral de Proteção de Dados, its version of data protection law. The specifics differ by country, but the direction is the same everywhere: consent must be freely given, specific, informed, and unambiguous. Paying someone $10 in crypto to stare into a device, with no plain-language explanation of what you're agreeing to, is not that. It is the opposite of that.

Why This Fight Is Coming to You

  • Age checks are going biometricGaming platforms, social media, and streaming services are already rolling out face-scan age verification. Your kids' apps will ask for this soon, if they haven't already.
  • 🔐 Account recovery is changing"Forgot your password?" is slowly being replaced with "verify with your face." Once that scan is taken, the São Paulo questions apply: where does it live, and can you delete it?
  • 💼 Employers are in this tooTimekeeping, building access, and background checks are all going biometric in workplaces. Most employees don't know what happens to those scans when they leave the job.
  • 🗺️ Regulators are watching this caseThe São Paulo lawsuit sets a template. Expect more cities and states to challenge data collection practices using the same three-question framework: what was collected, why was it needed, and can users delete it?

Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Three Questions Regulators Now Demand on Biometric Signups

The São Paulo case essentially handed regulators worldwide a checklist. According to the analysis in the lawsuit and the broader compliance picture outlined by Liminal, three failures drove this lawsuit: transparency (what exactly gets collected?), purpose limitation (why is this specific data actually necessary?), and data control (can users demand permanent deletion?). Those three failures are not unique to São Paulo. They're built into almost every biometric signup flow you've ever been through. Previously in this series: That Voice On The Phone Sounds Exactly Like Your Boss It Tak.

The transparency problem is the easiest to understand. When an app asks to "verify your identity," most people have no idea whether that means it's checking your face against a photo you uploaded, running a live scan, or storing a permanent template of your facial geometry (a digital map of your face's measurements) on a server somewhere. Those are wildly different things with wildly different risks, and the screens look almost identical.

The purpose limitation problem is sneakier. "We need your face to verify you're over 18" and "we need your face to build a permanent verified identity profile tied to your device, your account history, and your future logins" are not the same thing. But they can be presented as the same single step in an app onboarding flow. Baird Holm LLP tracks the expanding state-level legislation on this and notes that newer laws are specifically targeting this kind of scope creep, the gap between what a company says it needs and what it actually keeps.

The deletion problem is the one almost nobody talks about, and it's the most important. According to HID Global, the regulatory push in 2026 is explicitly moving toward privacy-by-design, meaning companies must build deletion rights in from the start, not bolt them on later when someone complains. The São Paulo case is a preview of what happens when deletion is an afterthought: a lawsuit, a regulator order, and 400,000 people who still don't know if their iris data is actually gone.


What You Can Actually Do Right Now

Look, nobody's saying you should refuse every biometric check. Some of this technology is genuinely useful. The issue isn't whether companies can collect your biometric data, it's whether they've earned the right to do it by being honest about what they're doing.

Before you complete any biometric verification, face scan, fingerprint, iris check, three questions are worth asking. First: what exactly is being collected and stored? Not "your identity" or "a verification." The specific data type. Second: where does it live, and is it leaving the country? Third: how do you delete it when you're done? If an app can't answer those three things in plain English before it scans you, that's not a minor inconvenience. That's a consent problem. Up next: License Plate Readers Identity Data Pennsylvania Regulation.

If you've ever worried that an account, a profile, or an online claim to be you might not actually protect your identity, that fear is exactly right. Verifying who's real and what data about real people is being used legitimately is exactly the kind of problem that services like CaraComp exist to address. Not to scare you, but to give you actual visibility into how your identity shows up online, before someone else makes decisions about it.

Key Takeaway

Convenience is not the same thing as consent. The São Paulo case is a $47 million argument that "you tapped agree" is not enough when what you agreed to was the permanent capture of your most irreplaceable physical identifier. Every app that asks for your face, your fingerprint, or your iris should be able to answer three questions before you comply: what's collected, where it lives, and how you delete it. If they can't, the answer is not your eye.

Here's the detail that should stick with you: World ID kept offering payment for iris scans even after Brazil's national data regulator told it to stop. Not a gray area. Not a misunderstanding. A direct order, ignored. And the reason it took a city-level, $47 million lawsuit to force a response is that most people who scanned their irises have no idea any of this happened. They looked into the orb, got their crypto, and moved on.

Your iris is not a password. It's not a username. It is the most permanent identifying marker your body produces, and the next app that asks for it should have to work a lot harder than a single checkbox to earn it.

Biometric Information: What Actually Counts as Collected Data

When people hear "biometric data collection," they usually picture just a face scan or a fingerprint. In reality, biometric information covers a much wider range: iris patterns, voiceprints, hand geometry, gait, even the way you type. Any physical or behavioral trait that can identify you specifically falls under this umbrella, and each one carries the same core problem, once collected, it cannot be reissued like a password.

Data Privacy and Why Biometric Data Protection Rules Differ From Other Data

Data privacy law generally treats biometric data as a special category, separate from your name, address, or purchase history. That's because biometric data protection isn't just about keeping a database secure, it's about protecting something you cannot replace if it leaks. A leaked password is an inconvenience. Leaked biometric data is closer to a leaked identity, which is exactly why regulators are drafting rules that go further than typical data protection standards.

Biometric Data Collected Through Everyday Apps

Biometric data gets collected far more often than most people realize, well beyond headline cases like World ID. Photo storage apps that auto-tag your friends, phones that unlock with your face, and fitness trackers that read your heart rhythm are all engaged in some form of biometric data collection. The São Paulo lawsuit is unusual mainly because of its scale and its payment scheme, not because the underlying practice of collecting biometric data is rare.

Facial recognition specifically deserves its own mention, since it's the biometric data type most people encounter daily. Facial recognition systems are built into phone unlock features, airport security lines, and increasingly, retail stores checking for repeat shoplifters. Each of those systems is, functionally, a biometric data collection point, and each one raises the same three questions this article keeps returning to: what's collected, where it's stored, and whether it can be deleted.

Security is the word companies use most often to justify biometric data collection, and often for good reason, biometric authentication really can be more secure than a password that can be guessed, stolen, or reused across sites. But security for the company and security for the individual aren't automatically the same thing. A system can be well protected against outside hackers while still giving the company itself far too much freedom to keep, sell, or transfer your biometric data without your meaningful input.

That distinction matters because biometric data protection isn't only about preventing breaches. It's also about limiting what a company is allowed to do with your information even when nothing goes wrong technically. Personal information laws increasingly require businesses to state a specific, narrow purpose for biometric data collection and forbid using it for anything beyond that stated purpose, which is precisely the "purpose limitation" failure regulators flagged in the São Paulo case.

Systems that rely on biometric identifiers are also spreading into places most people never think to question, like building access badges, school lunch lines, and time-clock systems at work. Each new system is another place where biometric data is collected, stored, and, in the best case, eventually deleted according to a clear policy. In the worst case, as São Paulo shows, that data just sits somewhere indefinitely while the person it belongs to has no idea it's even there.

Personal control over biometric data collection ultimately comes down to the same three questions raised earlier in this article: what specific biometric information is being gathered, where does it physically live, and what is the actual mechanism for deleting it. Any company that can't answer all three in plain language hasn't earned the right to your face, your iris, or your fingerprint, regardless of how convenient the sign-up screen makes it feel.

It helps to be precise about what a scanner is actually doing when it reads you. A fingerprint reader, an iris camera, and a voice-match microphone are each a process that identifies a person by comparing a fresh sample against a stored template, not by checking a document or a code you memorized. That is the plain-English definition worth keeping in mind every time a screen says "verify with biometrics" instead of "verify with a password."

Regulators and vendors increasingly describe fingerprint and iris systems as recognizing human characteristics rather than checking possessions like a card or a phone. A password proves you know something; a key card proves you have something; a biometric scan proves you are something, because it recognizes human characteristics that are physically attached to you and cannot be handed to someone else or left at home.

That same logic explains why an iris scanner is different from a photo ID check. An iris scanner uses unique physical traits, the specific pattern in the colored part of your eye, that are effectively impossible to duplicate, unlike a name or a birthdate that plenty of other people might share. Fingerprints work the same way: they rely on unique physical traits that stay constant for most of a person's life, which is exactly why leaking them is so much more permanent than leaking a Social Security number that can eventually be reissued.

Hand geometry systems, once common at gyms and factories, measure unique bodily features like finger length and hand width rather than a picture of your face. They're a good reminder that "biometric" doesn't only mean cameras; any system built around unique bodily features, including vein patterns in your palm, counts as biometric data collection under most modern privacy laws.

Regulators typically define a biometric identifier as any measurable physical characteristic used to confirm identity, iris patterns, fingerprints, voiceprints, and facial geometry all qualify as a measurable physical characteristic under laws like Illinois's BIPA. The word "measurable" matters here: it has to be something a machine can actually record and compare, not just a general impression of what someone looks like.

Not every trait companies collect is purely physical, either. Some systems track a personal behavioral trait, such as typing rhythm, gait, or the pressure you apply on a touchscreen, and treat that pattern the same way they'd treat a fingerprint. A personal behavioral trait can be just as identifying as a physical one, which is why newer biometric technologies increasingly fold behavior-based signals into the same legal category as iris and face scans.

Understanding biometric technologies as a category, rather than just "face scanning" or "fingerprints" one at a time, makes it easier to ask the right questions of any app or employer. The common thread across all biometric technologies is that they turn something about your body or behavior into data that can be stored, copied, and, if a company is careless, exposed or sold without your ongoing input.

When a company writes up what it collected, that record is usually called biometric information in its own privacy notice, and that phrase is worth searching for directly. If a privacy policy never uses the words biometric information at all, that's often a sign the company hasn't thought carefully about how its verification feature actually works under the law.

Some documents use the plural form, referring to biometric identifiers collected from multiple points on the body, a fingerprint plus a face scan plus a voiceprint, for instance. Companies that gather several biometric identifiers at once carry a bigger risk if their systems are breached, because a single leak can expose more than one irreplaceable trait belonging to the same person.

The broader field that studies all of this is called biometric recognition, which covers everything from unlocking a phone to airport screening lines. Biometric recognition systems are graded on accuracy, but accuracy alone doesn't answer the consent and deletion questions raised throughout this article, a highly accurate system can still be an unfair or poorly disclosed one.

Privacy law scholars often place biometric data inside a broader bucket called sensitive personal information, alongside health records and financial account numbers. Treating iris scans as sensitive personal data, rather than ordinary personal data like an email address, is exactly why regulators expect stricter consent, tighter storage rules, and clearer deletion paths for biometric programs like World ID's.

Every privacy policy that covers a biometric feature should state, in plain language, what personal data it gathers beyond the scan itself, your name, device ID, or location, for example, since that surrounding personal data can be combined with a biometric identifier to build a far more detailed profile than either piece could create alone.

Taken together, these are the words worth watching for the next time you read a privacy policy before agreeing to a scan: biometric identifier, biometric information, sensitive personal data, and a plain description of the process that identifies you. If a policy uses vague marketing language instead of these specific terms, treat that vagueness itself as an answer to the question of whether the company has really earned your trust.

A biometric sample is the raw input a sensor captures before any matching happens, the actual image of your iris, the actual recording of your voice, the actual scan of your fingertip. That biometric sample is usually converted into a mathematical template right away, but the original biometric sample itself can still be stored, and whether a company keeps that raw biometric sample or discards it after processing is a question worth asking directly.

A biometric characteristic is simply the underlying trait a system is designed to read, whether that's the ridges on a finger or the texture of an iris. Every biometric characteristic used for identification shares two qualities: it stays fairly stable over a person's lifetime, and it is difficult for someone else to copy convincingly, which is exactly why a stolen biometric characteristic is so much harder to recover from than a stolen password.

Automated recognition is the actual mechanical step that turns a scan into a decision, the software comparing your fresh sample against a stored template and returning a match or no-match result in a fraction of a second. Automated recognition is what makes biometric verification feel instant to the user, but that speed can also hide how much sensitive data is moving in the background without a clear explanation.

Sensitive data protections generally apply once a system starts handling biometric characteristic information, because that category of sensitive data carries consequences a leaked email address never would. A company that treats biometric information as ordinary sensitive data, filed alongside routine account details, is usually underestimating how much scrutiny that data protects when regulators come looking, which is a core reason cases like São Paulo's keep surfacing around the world.

Consent forms increasingly separate programs by whether they process data for individuals based on a one-time check or an ongoing profile, since the two carry very different risks. A one-time age check for individuals based on a simple yes-or-no answer is a much smaller footprint than an ongoing verified-identity system tied to a person's device and history, and regulators now expect companies to say clearly which one they're actually running.

Put simply, biometric data protects highly private information about your body that you cannot reissue, replace, or hide once it's exposed, and that permanence is the entire reason lawmakers keep carving out special rules for it. Every question this article has raised, what's collected, where it lives, and how it gets deleted, exists because ordinary data protection rules were never built for information this personal.

On-Device Storage Versus Centralized Servers

How is biometric data stored once a scan is complete? There are really only two paths, and they carry very different risks. With on-device storage, your fingerprint or face template stays locked on your own phone or laptop, inside a secure chip, and it never travels to a company server at all. That is the model most phone unlock features use, and it is a big part of why losing your phone is scary but a company data breach involving that same fingerprint is much less likely.

The other path is centralized storage, where a company collects biometric samples from many people and keeps them together on its own servers or in a cloud provider like Amazon Web Services. World ID's iris data followed this second path, which is exactly why São Paulo prosecutors could ask where the data physically sat and whether it crossed a border. Newer decentralized approaches try to split the difference, storing pieces of a template across multiple locations so no single breach exposes a complete, usable copy.

What a Biometric Template Actually Is

A biometric template is not a photograph of your face or a picture of your iris. It is a mathematical summary, a set of numbers pulled from the unique points on your fingerprint, iris, or face, that a system uses to compare future scans against. Because a biometric template is math rather than an image, some vendors argue it is safer to store than the raw biometric samples it was built from, though privacy advocates note that biometric templates can still be reverse-engineered under the wrong conditions.

This distinction matters for storing biometric information responsibly. A company that only keeps biometric templates, and deletes the original scan right after processing, has a smaller attack surface than one that keeps both the raw image and the derived template sitting on the same server indefinitely.

Encrypted Templates and Template Protection in Practice

Encrypted templates are how most responsible biometric systems try to answer the storage question. Instead of keeping a plain, readable template file, the system scrambles it with encryption, so that even if a server is breached, the stolen file is useless without the matching key. Template protection is the broader term for these techniques, and it can include encryption, splitting a template into separate encrypted pieces, or converting it into a "cancelable" version that can be reissued if it's ever exposed.

Fingerprint data specifically is often stored this way in modern phones and laptops, using hardware-level encryption inside a dedicated security chip rather than in the phone's general storage. That hardware separation means even apps running on the same device typically cannot pull raw fingerprint data out directly; they only receive a yes-or-no answer about whether a match occurred.

How Cornell and Similar Institutions Approach Biometric Storage

Universities offer a useful, lower-drama example of how storing biometric data is supposed to work when privacy is taken seriously. Cornell does not maintain a central photo-and-fingerprint database tied to every campus access card in the way São Paulo's iris program did; instead, many campus systems favor on-device storage or heavily restricted, purpose-limited databases with strict retention limits. That kind of setup, narrow purpose, short retention, encrypted templates, and clear deletion rules, is close to what regulators now expect from any organization that touches biometric data, whether it is a university, an employer, or a company like Tools for Humanity.

The lesson from comparing these approaches is simple: how is biometric data stored says more about a company's priorities than any privacy policy headline. On-device storage, encrypted templates, and hardware protection all reduce risk. Centralized, otherwise store biometric data centrally systems without those safeguards recreate the exact conditions that led to the São Paulo lawsuit, and the next headline like it.

Frequently asked questions

How is biometric data stored after an iris scan in the World ID system?

According to the article, once residents scanned their eyes into orb-shaped devices, the resulting iris data ended up on servers with no clear instructions provided on how to get it deleted. The lawsuit centers on the fact that people were not properly told what would happen to that data or where it would sit afterward.

Why is São Paulo suing over how iris data is collected and stored?

São Paulo prosecutors filed a $47 million lawsuit against the operators of World ID after a city council investigation found that roughly 400,000 residents, concentrated in lower-income neighborhoods, scanned their irises for small crypto payments without a proper explanation of what would happen to their data.

Can people get their biometric data deleted once it's collected?

The article notes that people who scanned their irises were left with no clear instructions on how to get their data deleted, buried in fine print alongside the crypto payment and verified human badge. This lack of a clear deletion path is central to why prosecutors say the rollout crossed a serious line.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search