What you really need to know about biometric privacy compliance, data, and separating fact from fiction
At NZTeco, we believe transparency builds trust. In an age where facial recognition, fingerprint scanners, and biometric attendance are becoming more common, many New Zealanders are asking: "Where does my data go? Who sees it? Is it safe?" — This article aims to clear that up.
Biometric privacy in New Zealand is not just about where data is hosted. It also depends on how biometrics are used, what information the system collects, which features are enabled, how the system is secured, how long information is retained, and who is responsible for it.
At NZTeco, we believe clear information builds trust. Facial recognition, fingerprint readers, and palm-based access systems can offer security and convenience, but they need to be selected, configured, and managed carefully. This article explains what New Zealand organisations should know, what ZKTeco officially says about its technology, and which details must be confirmed for each deployment.
Quick facts
- A biometric template is different from a photograph or raw fingerprint image, but it is still biometric information and personal information under New Zealand privacy law.
- ZKTeco products commonly use templates for biometric matching. Some products can also store or transfer user photos, biometric photos, and event snapshots.
- Encryption and secure communications depend on the product, software, firmware, and configuration. HTTPS is optional and configurable on some ZKTeco devices.
- Systems may be deployed on a device, on a customer-managed server, through on-premises software, or through a cloud service. The actual data location must be confirmed for the chosen deployment.
- The Privacy Act 2020 and the Biometric Processing Privacy Code 2025 can apply. A supplier statement about an encrypted template does not, by itself, make a deployment compliant.
New Zealand’s biometric privacy rules
The Biometric Processing Privacy Code 2025 establishes specific privacy rules for organisations that collect biometric information for automated verification, identification, or categorisation. The Code came into force on 3 November 2025. The transition period for organisations already using covered biometric systems ended on 3 August 2026.
Before collecting biometric information, an organisation generally needs to establish that:
- collection serves a lawful purpose connected with its functions or activities;
- biometric processing is necessary for that purpose;
- reasonable privacy safeguards have been adopted and implemented; and
- the benefit is proportionate to the privacy risks and impacts, including cultural impacts and effects on Māori.
Organisations also need to tell people clearly that biometric information is being collected, explain each purpose of collection, and state whether a non-biometric alternative is available. The Code also covers security, access, correction, retention, use, disclosure, and disclosure outside New Zealand. The Office of the Privacy Commissioner provides detailed biometrics guidance and examples. Organisations should consider completing a Privacy Impact Assessment before deploying or materially changing a biometric system.
What ZKTeco officially says
ZKTeco publishes Guidelines on the Use of Biometric Data. In that guidance, ZKTeco states that its biometric algorithms extract selected feature points for matching rather than collecting complete biometric features. It also says that its hardware and software apply encryption techniques, and that templates are deleted from hardware and software permanently according to the applicable situation.
ZKTeco’s guidance also places important responsibilities on the organisation using the system. It says the data user is responsible for informing people, collecting templates lawfully and fairly, avoiding unnecessary retention, and controlling any new use of information. These are ZKTeco’s official statements. They should be read alongside the documentation for the exact device, software version, and deployment; they do not substitute for checking the actual configuration or meeting New Zealand legal obligations.
Templates, photos, and event snapshots are not the same thing
During enrolment, a biometric system obtains a sample—such as a face scan or fingerprint—and extracts information used to create a template for matching. That does not mean every ZKTeco system operates on template data alone. Official ZKTeco specifications show that some devices have separate capacities for face templates, user photos, and event photos, and may support event snapshots. ZKTeco software documentation also describes transferring and retrieving user photos and biometric photos in supported configurations.
For that reason, the right questions are:
- Does the model retain an enrolment image or user photo?
- Is event snapshot capture supported and enabled?
- Can photos be uploaded or downloaded from management software?
- Which information is stored on a device, server, backup system, or cloud service?
- What is deleted when a person is removed, including from backups and exported files?
The answers vary by model, firmware, software, and configuration.
Encryption and secure communications
ZKTeco’s current ZKBio CVSecurity product information claims 256-bit AES data protection. Some ZKTeco device specifications also list encrypted HTTPS communications, but on certain models HTTPS is described as optional. ZKTeco’s support guidance instructs administrators to select HTTP or HTTPS to match the software configuration.
This means it is not accurate to assume every ZKTeco system is encrypted at every stage automatically. A deployment review should confirm:
- whether HTTPS is supported and enabled between devices, software, and browsers;
- whether information is encrypted at rest and which component performs the encryption;
- how encryption keys and certificates are created, stored, renewed, and revoked;
- whether backups, exports, APIs, and mobile integrations receive equivalent protection;
- which administrator roles can view, export, or delete biometric and identity information; and
- whether device and software versions remain supported and current.
Encryption is an important safeguard, but it is one part of a broader security and privacy programme.
Where information can be stored
Depending on the selected system, information may be held:
- locally on a biometric terminal;
- on software installed on a customer-managed server;
- in a private-cloud environment operated for the customer;
- in a vendor or third-party cloud service; or
- in backups, exports, integrations, or connected workforce-management systems.
For example, ZKTeco describes ZKBio Time as web-based software that can operate as a private cloud, while ZKBio Time Cloud is a separate AWS-based service. An AWS reference alone does not establish the country or region in which a particular customer’s data is stored. Before deployment, organisations should document the real data flow and confirm every hosting region and service provider contractually.
If biometric information is disclosed outside New Zealand, rule 12 of the Biometric Processing Privacy Code may require additional grounds and protections.
Who is responsible for the information?
Responsibility depends on the roles each party performs—not simply on who manufactured or installed the equipment. Under the Office of the Privacy Commissioner’s section 11 guidance, a provider that stores or processes personal information solely for a customer may be acting on the customer’s behalf. The customer can still be treated as holding the information and remain responsible for meeting privacy obligations. If a provider also uses or discloses information for its own purposes, both organisations may have responsibilities.
Contracts should therefore identify who controls the information, who can access it, what each party may do with it, how incidents are managed, and what happens when the service ends. NZTeco’s role can differ between supply-only, installation, support, and hosted-service arrangements. Responsibilities and data flows should be documented for the actual service provided.
Privacy-relevant features may vary and be configurable
Official ZKTeco documentation shows that features vary between products and may require configuration:
- User and profile photos: Supported by some models and software. Display of a user photo can be enabled in device settings on supported products.
- Event photos and snapshots: Some facial and fingerprint terminals list event-photo capacity or an Event Snapshot feature.
- HTTP or HTTPS: HTTPS is optional and configurable on some products and must be enabled consistently with server configuration.
- Remote face enrolment and photo transfer: Available only on supported device, firmware, and software combinations.
- User-ID masking and verification-name display: Supported devices can expose settings controlling which identifying information appears after verification.
- Server connectivity: Device settings can specify a customer server or cloud/ADMS endpoint.
- Authentication methods: Face, fingerprint, palm, card, and PIN options depend on the device and can be selected to suit the use case.
These controls are useful, but availability should never be assumed. NZTeco recommends recording the device model, firmware, software version, and agreed configuration during installation handover.
Correcting common biometric privacy myths
Myth: “A biometric terminal always stores my photograph forever.”
Reality: Many systems use biometric template matching, but some devices and software can also retain user photos, biometric photos, and event snapshots. Retention depends on product configuration. An organisation should disclose what is collected, why it is needed, and when it will be deleted.
Myth: “A template cannot be abused, so a breach would not matter.”
Reality: Templates are intended to be different from raw images, and ZKTeco describes its template process as non-reversible. However, biometric information remains sensitive. A compromised password can be changed; a person’s face or fingerprint generally cannot. Organisations must still prevent unauthorised access, use, disclosure, and linking of biometric information.
Myth: “All ZKTeco information is automatically stored in China.”
Reality: Storage location depends on the chosen device, software, hosting service, and integrations. Some deployments are entirely on-premises; other services use cloud infrastructure. The actual hosting country, backups, and overseas support access must be confirmed for each deployment.
Myth: “If a system is encrypted, it is automatically compliant.”
Reality: Encryption is only one safeguard. New Zealand’s rules also address lawful purpose, necessity, proportionality, transparency, alternatives, access, correction, retention, use, and disclosure.
A practical deployment checklist
- What is the exact purpose, and is biometric processing necessary and proportionate?
- Is a workable non-biometric alternative available?
- Which samples, templates, photos, identifiers, and logs are collected?
- Which optional photo, snapshot, cloud, and integration features are enabled?
- Where is each category of information stored and backed up?
- Is HTTPS enabled on every supported connection, and what other encryption applies?
- Who has administrator access, and how are privacy breaches handled?
- Are firmware, software, architecture, and configuration records maintained?
NZTeco’s role
NZTeco can help customers identify appropriate ZKTeco products, document relevant product capabilities, and configure supported security and privacy features for the agreed deployment. Depending on the project, this can include:
- confirming device, firmware, and software versions;
- documenting whether photos, event snapshots, and cloud connectivity are enabled;
- configuring HTTPS and role-based access where supported;
- supporting on-premises or agreed hosted architectures;
- providing administrator handover and product documentation; and
- helping customers understand matters that require their own privacy, employment, or legal assessment.
No supplier, product, or certificate can guarantee compliance for every use case. Compliance depends on the organisation’s purpose, decisions, configuration, and ongoing operation of the system.
Frequently asked questions
Yes. When it relates to an identifiable person, it is personal information. Under the Biometric Processing Privacy Code, both biometric samples and biometric templates can be biometric information.
No universal rule can be applied to every product and configuration. Many systems create templates for matching, but ZKTeco devices and software can also support user photos, biometric photos, and event snapshots. Check the exact model and enabled features.
Individuals can request access to and correction of biometric information; a correction request can include a request for deletion. Whether and how an organisation must act depends on the applicable law and circumstances. Organisations must not retain biometric information longer than it may lawfully be used.
Often, but the available options depend on the selected product and service. Confirm the primary region, backups, disaster recovery, integrations, and any overseas support access before deployment.
Generally, organisations covered by the Code must provide clear information before biometric information is collected, including that collection is occurring, the purposes, and whether an alternative is available. Additional details may also be required under rule 3.
No. Authorisation may be relevant in some situations, but it does not replace the need to establish lawful purpose, necessity, proportionality, safeguards, transparency, and compliance with other applicable rules.
Final thoughts
Biometric systems can improve access control, attendance, and security, but privacy depends on the complete deployment—not a single feature or marketing statement. The best approach is to document the purpose, select the least intrusive effective option, understand exactly what the chosen product collects, configure it securely, and review it throughout its lifecycle.
Need help assessing a ZKTeco deployment? Contact NZTeco to discuss the device, software, hosting, and configuration that fit your site.
Primary sources
- Office of the Privacy Commissioner — Biometric Processing Privacy Code 2025
- Office of the Privacy Commissioner — Overview of Code rules
- Office of the Privacy Commissioner — Collection of biometric information
- Office of the Privacy Commissioner — Third-party providers
- ZKTeco — Guidelines on the Use of Biometric Data
- ZKTeco — ZKBio CVSecurity
-
ZKTeco — ProFace X
;ZKTeco — ProFace (DS);ZKTeco — ZKBio Time;ZKTeco — ZKBio Time Cloud




