TwinEthosRequest access

Control

Biometric data disclosed to another party without consent

A face or voice template, or the image or sample it comes from, is disclosed to another company only with the person's consent or under an exception the governing law allows.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: Biometric data from AI features is collected, kept, or disclosed without consent or limits · control id cond.biometric-data-disclosed-without-consent

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in Illinois (US-IL).

The guard to add

Check a recorded consent naming the recipient (or a documented exception) before any face or voice template, or identifying image or sample, is sent to a vendor or partner.

A disclosure gate wrapped around every outbound call that carries templates, face images used for identification, or voice samples: vendor recognition APIs, partner webhooks, shared buckets, analytics events. The gate looks up a consent record for this person that names the recipient (or a documented exception such as a transaction the person requested), refuses the call without it, and writes an audit entry of what was sent, to whom, and under which consent or exception. Biometric fields are stripped from analytics and telemetry payloads entirely.

Where it goes: 1 application source code, 6 API calls and integrations, 10 logs and telemetry.

What reviewers look for: on each path from face_encoding, voiceprint, or a matching selfie to requests.post, fetch, search_faces_by_image, face identify, or s3.put_object to a shared bucket, a consent check (consent.biometric_disclosure, an approved-recipient record) or a recorded exception before the call; a disclosure audit log; no images or templates in analytics events.

Example (Python requests to an identity vendor), before:

def verify_with_vendor(user, selfie_bytes):
    r = requests.post(VENDOR_URL, files={'image': selfie_bytes}, timeout=10)
    return r.json()['match']

After:

def verify_with_vendor(user, selfie_bytes):
    consent = db.biometric_consents.get(user_id=user.id, recipient='acme-idv', purpose='disclosure')
    if consent is None or consent.withdrawn_at:
        raise ConsentRequired('no consent to share biometric data with acme-idv')
    r = requests.post(VENDOR_URL, files={'image': selfie_bytes}, timeout=10)
    disclosure_log.insert(user_id=user.id, recipient='acme-idv', data='face_image', consent_id=consent.id)
    return r.json()['match']

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)