Skip to content

WestPoint · Access · Suprema

Biometrics. And the conversation that comes first.

BioStar 2 is among the soundest things there are for identifying a person by their fingerprint or their face. Before buying a single reader you have to be able to justify why that door is not solved with a card, because a biometric is not just another piece of data.

What it is, and what problem it solves.

Suprema is a Korean house that has spent decades making fingerprint and face sensors and algorithms, and a good part of its business is selling that piece to others: there are readers with somebody else's logo and its technology inside. BioStar 2 is the software that governs its readers: it is administered from a browser, it lives on a client's server and it covers access, attendance, visitors and a little video.

The problem it solves is very specific: the credential that gets lent. A card passes from hand to hand in two seconds and the record ends up in the name of somebody who was not there. There are places where that is the whole failure of the control: the finished-goods store, the laboratory, the server aisle, the area where you have to prove to an auditor that that person went in and not their credential.

Its natural place is not the street door: it is a handful of internal doors in an installation that already has access control. And that is also the way to buy it without getting into trouble.

What you need to know before buying it.

A fingerprint and a face are not a password: they are special category data, and the RGPD treats them separately in its Article 9.

Special category means the starting point is that they cannot be processed, and that a specific exception is needed. It is not enough for the employee to sign: in an employment relationship consent is almost never valid, because somebody who has to ask their boss for permission to refuse is not consenting freely. You need a reinforced legal basis, and you have to be able to write it down.

You also need an impact assessment —Article 35— carried out before the first reader. And inside it, the uncomfortable question: why a card is not enough on THIS door. «Because biometrics is more modern» does not hold it up. «Because four people come in here and card lending is documented» is already an argument.

And a warning about the most requested use of all: the Spanish authority has been especially restrictive with biometrics for attendance. Clocking in with a fingerprint is where proportionality is hardest to defend, because knowing what time somebody comes in can be achieved in five less intrusive ways. We say this before we quote, and it sometimes costs us the sale.

None of this says that biometrics is banned. It says it is a decision you justify, document and limit to the doors where it holds up. It is not the default answer for a door.

How it's built, and the two ways of using it.

Here is the fact that changes the project, and it is the one least often explained.

The first way is the obvious one: BioStar 2 as a complete system, with its server, its doors, its schedules and its log. It scales well for a medium-sized installation, it is administered from a browser and it has a programming interface for talking to what you already have.

The second solves half the real cases: the reader hung off ANOTHER platform, the one already fitted. It compares the fingerprint inside itself and sends only a credential number upwards, exactly like a card reader. The platform you already had carries on running joiners, leavers, schedules and log. Fewer systems, fewer administrators, fewer places where the data lives.

And there is a third decision, the most important one for the RGPD: where the template lives. It can be on the server, in the reader or on the person's own card, carried in their pocket and presented along with the finger. That last one changes the whole conversation: there is no longer a central base of biometric features to steal, and whoever loses the card has lost their own template and nobody else's.

It is also worth knowing what is stored: not a photograph of the fingerprint, but a mathematical template derived from it. That reduces the harm, it does not remove it, and it does not take the data out of Article 9. Anyone who says otherwise is selling.

Who it fits, and who it doesn't.

  • It fits a few doors with a lot to protect, where credential lending is the main risk: laboratory, product store, plant room, key cabinet.
  • It fits where a real second factor is needed: card AND finger, not one or the other. There biometrics does what it does best, which is to tie the credential to the person.
  • It fits if you already have a platform that works for you and you want biometrics only on those doors, without building a parallel system.
  • It does not fit the door two hundred people come through in ten minutes. The problem is not the accuracy: it is the queue. One extra second per person at seven in the morning ends with the door wedged open.
  • It does not fit for clocking in, unless somebody can defend the proportionality in writing. And almost nobody can.
  • It does not fit where the work ruins the finger: building sites, gloves, cold. The face solves part of that and brings its own problems with light.
  • It does not fit if nobody is willing to sign the impact assessment. Without that it is not a project, it is a deferred fine.

What we do with it.

  • The proportionality conversation first, door by door. We come out with a short list of doors where it holds up and another where we propose a card and a procedure.
  • The design with the decision about where the template lives taken on purpose, the alternative for anyone who does not want to give their fingerprint, and the retention period and the deletion written down before anything is installed.
  • The installation with the reader cable encrypted and not in the clear. A biometric reader whose cable can be tapped in the frame is an expensive reader doing the job of a cheap one.
  • Enrolling people properly, which is where almost all these projects fail. A fingerprint registered in a hurry gives you a reader that fails three times a day for two years, and the technology gets the blame.
  • The commissioning, measuring what matters: how long a person really takes to get through and how many times they have to try again. With the real people, at their busiest hour.
  • The maintenance with sensor cleaning, a check on the readers that fail too often and a review of the template register: who is still enrolled and why.

Who configures it after us.

There is a line here that is not technical, and it is worth respecting.

Ordinary administration can be run by the client without difficulty: it is used from a browser, and joiners, leavers, schedules and permissions by zone hold no mystery. The security team runs it well and the IT team runs it well, and in small installations reception runs it with two hours of training.

The difference from any other platform is biometric enrolment. Registering a fingerprint is not typing a name: it is a task with technique to it, and whoever does it badly creates a problem that shows up weeks later. That task should have two or three named, trained people, not whoever is free that day.

And there is a part that should be neither the client's nor ours alone: who may consult and export the log, and for what reason. That is agreed with whoever handles data protection and reflected in the operator permissions, which are fine-grained and exist for exactly this.

What we leave in writing: the training for the people responsible for enrolment on the real system, the short manual for each week's procedures, the deletion procedure for when somebody leaves and the operator permissions documented. The administrator keys belong to the client from day one.

Migrating from something else.

The most common migration is not a migration: it is an addition. There is a card system that works and you want to raise the level on four doors. The sensible thing is to leave the platform as it is and hang the reader off it, with the usual card as the first factor: nobody changes credential and the log stays in one place.

If what is there is an old biometric system from another brand, the templates do not come with you: each manufacturer stores its own in its own format. Everybody has to be enrolled again, person by person. It is a campaign lasting weeks, and whoever does not plan it suffers it on the first Monday.

And the other way round, if you come out of biometrics: the templates have to be deleted and you have to be able to prove it was done. It is not a matter of uninstalling a server and throwing the readers in a skip.

Back to access control

Get started

Have you been offered biometrics?

Tell us on which doors and what for. We will tell you where it holds up, where we would propose something else, and what you need to have written down before buying a single reader.