Fingerprint Devices & Data Privacy – How secure are fingerprint scanners?

- Fingerprint devices digitize fingerprints to authenticate devices and applications.
- Fingerprints are biometric data and require special protection under the GDPR.
- High security requirements for hardware and software are necessary for fingerprint devices.
- Fingerprints are not forgery-proof and do not offer absolute protection.
- Fingerprint devices increase data security when used as part of a two-factor authentication process.
Many of us use a fingerprint reader, also known as a fingerprint device, in our daily personal and professional lives: scanned fingerprints are used to unlock devices or authorize bank transfers. But what about data protection in this context? And are fingerprints really the ultimate way to secure data?
What is a fingerprint device?
In German, the term fingerprint device is translated as fingerprint reader . In short, these devices can digitize your fingerprint by scanning it. When a fingerprint device is used to unlock a smartphone, for example, you first have to place your finger on the built-in reader (also called a fingerprint sensor) so the device can scan the print and store it in the system. To unlock the laptop later, you must place your finger on the reader again to verify the print. The device then compares the newly scanned print with the originally stored fingerprint image.
Important: Fingerprint devices should not be confused with the similarly named device fingerprints, also known as browser fingerprints. The latter refers to the traces we leave behind while surfing the internet, for example via cookies, which can only be drastically reduced by browsing anonymously.
Where are fingerprint readers used?
Most people are likely familiar with fingerprint readers on smartphones or laptops, where they are used to bypass screen locks or authorize bank transfers. However, they are also used in professional and public environments, such as:
- Access control: Some buildings have digital door locks that can be opened using fingerprint scans.
- Law enforcement: When individuals are processed for identification purposes, their fingerprints are taken, among other things. To do this, the prints are scanned by the correctional authorities and stored in AFIS, the German police's automated fingerprint identification system.
- Authorities: Some German laws require that one or more fingerprints be taken for the correct processing of certain applications. For example, taking one or more fingerprints is necessary for a passport or an asylum application.
Fingerprint Devices & Data Protection Concerns: How secure are fingerprint scanners?
Fingerprints are personal data, specifically biometric data as defined in Article 4 (13) and (14) of the GDPR. According to Article 9 of the GDPR, this biometric data falls into the so-called special category of sensitive data . This means that a fingerprint makes a person so uniquely identifiable that the required level of protection is classified as particularly high. Furthermore, there are specific legal bases for processing special categories of personal data under Article 9 (2) of the GDPR, which operates under a "prohibition with reservation of authorization" principle.
Fingerprint devices must be designed with corresponding security: Security must be very high not only for the scanner (also known as a fingerprint reader) that captures the print, but also for the software that subsequently digitizes and (ideally) encrypts the scanned fingerprint. Moreover, the system that processes the fingerprint further—whether it is a smartphone operating system or AFIS—must be sufficiently protected against external attacks.
Fingerprint Devices & Data Protection
Beyond security concerns regarding the devices themselves, there remains the fact that fingerprints are not unfalsifiable: several years ago, the Chaos Computer Club famously reproduced the fingerprints of politician Wolfgang Schäuble and successfully used them via a dummy fingerprint. This security feature of fingerprint uniqueness was thus refuted, clearly demonstrating that while data protection via fingerprint can be enhanced, it cannot be guaranteed.
Conclusion: Whether you provide your fingerprint to private devices is up to you in a private context. However, you should be aware of two thing
- How each operating system handles scanned fingerprints varies from manufacturer to manufacturer. You should check this before scanning your fingerprint. In any case, you should ensure that your scanned fingerprint is not shared with apps and is stored only on your device, not on servers.
- Fingerprints are not forgery-proof and therefore do not provide absolute protection for your data.
The fact that fingerprints do not provide definitive security for access or data should be an important consideration for data security, especially in a business environment. However, using fingerprint devices as part of a two-factor authentication process can be a good solution for strengthening data protection within a company.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.













