TwinEthosRequest access

Control

Face or voice biometric template computed without prior notice and consent

Before a face-recognition or voice model turns a person's image or voice into an identifying template or match, the person is told what is collected and why and gives the consent the governing law requires.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: Biometric data from AI features is collected, kept, or disclosed without consent or limits · control id cond.biometric-identifier-collected-without-notice-and-consent

Reach

4items this one guard addresses
4jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in European Union (EU), Illinois (US-IL), Texas (US-TX), Washington (US-WA).

The guard to add

Check a recorded, purpose-specific biometric notice and consent before any code computes, enrolls, or matches a face or voice template.

A consent gate placed immediately before the call that turns an image, video frame, or voice sample into a template or identity match (face_encodings, DeepFace.represent, rekognition.index_faces, voice embedding). The gate reads a stored consent record for this person and purpose (what is collected, why, and how long it is kept), refuses to compute the template without it, and the template is stored with a reference to that record. The notice copy shown at enrollment lives in the capture UI.

Where it goes: 1 application source code, 2 data models, 6 API calls and integrations, 14 user-facing text.

What reviewers look for: on every path from an uploaded selfie, camera frame, or voice clip to a template or match call, a check of a stored consent or release record (not just a checkbox that is never read); the template row references the consent; templates are not built from scraped or public images without the person's consent.

Example (Python face_recognition), before:

def enroll(user_id, image):
    encoding = face_recognition.face_encodings(image)[0]
    db.templates.insert(user_id=user_id, encoding=encoding)

After:

def enroll(user_id, image):
    consent = db.biometric_consents.get(user_id=user_id, purpose='face_login')
    if consent is None or consent.withdrawn_at:
        raise ConsentRequired('biometric notice and consent needed before enrollment')
    encoding = face_recognition.face_encodings(image)[0]
    db.templates.insert(user_id=user_id, encoding=encoding, consent_id=consent.id)

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (4)