Questions · Access control
When is an impact assessment needed?
Whenever the processing may entail a high risk to people's rights, and biometric processing at a certain scale is on the list of cases the Agencia Española de Protección de Datos, Spain's data protection authority, considers to require one. In access control with biometrics, the practical answer is yes.
An impact assessment is a document written beforehand that answers uncomfortable questions in writing: why a less intrusive alternative is not enough, what exact data is stored, where, for how long, who can access it, what happens if it leaks and what measures reduce that risk. If after all that the risk is still high, you have to consult the authority before you start.
It is worth knowing that doing one does not make anything lawful by itself. If the conclusion is that there is no legal basis, what the assessment does is show it before the money is spent. That is why it goes at the start of the project and not at the end: it is far cheaper to change credential on a drawing than on a wall.
Where it is set out in full.
Where you can see it working.
On the IRIS Neural website, on real scenes.
All the questions.
Five hundred and forty-four, grouped by topic. Each with its own page.
Get started
See it working.
A written answer is enough to decide whether it interests you. To know whether it works at your site you have to see it on a real scene, with the image as it is and, on top of it, what the system understands from it. That is on the IRIS Neural website, which is the group's product.