CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
Podcast

Biometric Verification: India Kills Shared Face Database

Biometric Verification: India Kills Shared Face Database

Biometric Verification: India Kills Shared Face Database

0:00-0:00

This episode is based on our article:

Read the full article →

Biometric Verification: India Kills Shared Face Database

Full Episode Transcript


When you scan your face to prove who you are, that scan doesn't have to be saved. Not for a day. Not for a second. And India's government just made that distinction official policy — they kept mandatory face verification for phone customers, but they threw out the shared database that would have stored it all in one place.


If you've ever taken a selfie to open a bank

If you've ever taken a selfie to open a bank account, unlock an app, or activate a phone line, you've already lived this moment. And most of us assume the same thing when it happens — that our face just got filed away somewhere forever. That assumption feels reasonable. It's also, technically, not how it has to work. What India did splits one scary idea into two separate decisions, and once you see the split, you'll never look at a verification screen the same way. So how does that actually work?

Start with what happens in those few seconds after you tap the camera button. Biometric verification is what engineers call a one-to-one check. Your live selfie gets converted into a biometric template — basically a string of numbers describing the shape of your face. That string gets compared against one specific thing. The photo on the I.D. document you just handed over. That's it. One face, one document, one comparison. The system isn't searching a crowd. It's answering a yes-or-no question about you and the paper you already provided. Which means something a lot of people never realize. That check doesn't require a new database at all. It only needs what you already gave them.

Now the second decision — the one nobody announces. After the comparison finishes, the company chooses what to do with your scan. According to guidance from the U.K.'s Information Commissioner's Office, systems can be built to process a face scan transiently and delete it the instant the comparison is done. That's called a zero-retention approach. Or the company can keep your template indefinitely and compare against it later. Same verification. Completely different privacy outcome. And you almost never get told which one you're in.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Here's where the misconception lives

So here's where the misconception lives. Most people believe that if a company scans your face, they must be storing it. That belief makes sense — you experience verification as a single event. Scan, approved, done. Nobody shows you the second choice happening behind the glass. The industry doesn't tend to explain it, so "verified" and "stored" collapse into one thing in your head. They're not one thing. Storage duration is a policy choice, not a technical requirement.

There's a simple way to picture it. A bank teller looks at your driver's license, checks the photo against your face, and opens your account. That's verification. What the teller does not do is photograph you, add you to a national registry, and share it with every other bank in the country. The check and the database were always two different things. And that's exactly what India's original draft would have created. The proposed Biometric Identity Verification System would have given every telecom customer a unique I.D. and let carriers check identities against each other's records. One shared pool of faces across every mobile operator in the country. The final rules — the Telecommunications User Identification Rules of 2026 — dropped it. Each carrier now verifies on its own, using electronic and digital know-your-customer checks. You still can't get a SIM card without proving you're you. Which makes it much harder for someone to open a phone line in your name. But no cross-company face repository gets built.

And for anyone wondering whether this distinction actually matters in dollars — under the U.S. Biometric Information Privacy Act, class action settlements have topped a hundred million dollars. Those cases weren't about companies verifying people. They were about companies being unclear on what they kept afterward.


The Bottom Line

The real privacy question was never "will they scan my face." It's "what happens to that scan after it says yes." Verification is the visible part. Retention is the invisible part. And the invisible part is the one that determines everything.

So, three sentences to carry with you. Checking your face against your own I.D. takes seconds and doesn't need to be saved. Whether a company keeps that scan afterward is a completely separate choice they make. India just proved a government can say yes to the first and no to the second. The next time a screen asks for your face, you're not powerless — you just know the better question to ask. Not "are they checking me." But "are they keeping me." The written version goes deeper — link's below.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search