Who has access to your face?

Issue 6 2025 Access Control & Identity Management, AI & Data Analytics

Your face defines who you are, but in the age of AI and social media, your facial features can be used against you. This was seen with the recent Coldplay ‘kiss cam’ scandal, where social media users were able to uncover the offending CEO and the company’s chief people officer in a short time.


Lance Fanaroff.

Even if you are not guilty, AI deepfake apps give everyday people the tools to superimpose your facial features into offending situations. While you may be adjusting your privacy settings on social media or thinking twice about who is recording you at public events, the reality is that your facial features may be used in other contexts, such as identifying you when accessing your online banking.

In this time where boundaries are blurred and multiple parties seem to be vying for your data, who has access to your face? And when is it safe to use facial biometrics?

The difference between facial recognition and biometrics

Facial biometrics is being used more in banking and other highly secure environments to verify a person’s identity. This is a completely safe process where your facial identity confirms your identity, but is not held by the company in any way or used for any other purpose.

Lance Fanaroff, co-founder and chief strategy officer of iiDENTIFii says, “One of the prevailing misconceptions is that, by scanning your facial features, companies can hold onto your data and use it for surveillance or identity theft. The reality is that opt-in biometrics are the most secure way to identify someone and keep their information and identity safe from misuse – and these differ a great deal from biometrics used for surveillance.”

When facial features are used for surveillance, this is referred to as facial recognition. Facial recognition is a specific application of facial biometrics that identifies or verifies an individual by comparing a live facial image or video frame against a database of known faces.

This can be used for various purposes, including security, law enforcement and access control. For example, facial recognition has been put to use in some boroughs in the UK1 to scan the faces of ordinary citizens, triggering an alert if features match those of a person on a watch list. The boundaries of facial recognition and its applications are a growing concern and topic for global debate.

Fanaroff emphasises that, when South African consumers are asked to scan their facial features to access their personal online credentials, for example, during banking, this process is completely safe. “Remote biometric onboarding links a person’s biometric data, whether their face or fingerprint, to their personal banking profile so that they, and only they, can access the account safely and securely. Opt-in biometric onboarding with liveness detection protects institutions and their clients from fraud. Users do it on their own terms to access their accounts, as opposed to surveillance.”

Facial biometric data is not stored by the organisations using it to authenticate their clients. Fanaroff explains, “iiDENTIFii, for example, makes use of a biometric hash technology to protect identifying information. A biometric hash is a cryptographic transformation of biometric data into a string of characters that acts like a unique digital fingerprint or face print. As it is a one-way process that is achieved without using Personally Identifiable Information (PII) data, it is both secure and private.”

The safety of facial data needs to be an ongoing priority

South Africa’s private and public sector needs to work together to ensure that facial biometrics is used securely, and that the public understands the difference between this and facial recognition used in surveillance.

iiDENTIFii’s inaugural Identity Index 2024 – South Africa Edition2 says, “Despite the trend towards investing in Identity Verification (IDV) solutions, such as facial biometrics, there are still some significant barriers to implementation, with 31% citing regulatory compliance and 23% citing user acceptance as the most substantial barriers. This points towards an opportunity for more coordinated industry-wide approaches to digital identity, from stronger collaboration to a sustained commitment to investing in advanced technologies.”

The regulation of how any biometric PII data is used needs to occur frequently and rigorously. Maxine Most, principal of Acuity Market Intelligence, a thought leader on emerging identity verification technologies, says, “In the past, when digital systems have been put in place, it has opened users up to function creep with data, meaning that corrupt actors use the data for purposes for which it was not intended. Regulatory compliance is, therefore, critical in building these systems in a way that prevents this. Systems need to be built with privacy first so that they cannot be abused.”

“Our use of biometric hash technology at iiDENTIFii illustrates that it is possible to use facial data to provide secure identification, without retaining identifying personal information,” says Fanaroff.

In South Africa, consumers can protect themselves by only using opt-in biometric verification and authentication services. Businesses can collaborate with regulatory authorities to create a landscape that protects individuals and prioritises privacy and security. “From a South African perspective, the use of robust facial biometric technologies needs to be highly secure and controlled so that consumers can transact on these platforms confidently.”

For more information contact iiDentifii, +27 21 286 9104, [email protected], www.iidentifii.com

[1] tinyurl.com/2mxtpe7c

[2] tinyurl.com/54vtdpnj




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Protect More with SecuVue
Secutel Technologies Surveillance AI & Data Analytics
Whether you are responsible for electronic key management, securing safes and containers, transport operations or high-value equipment, every asset represents an investment that deserves intelligent protection.

Read more...
Amplifying the value of CCTV systems with AI
IoT & Automation Surveillance Entertainment and Hospitality (Industry) Retail (Industry) AI & Data Analytics
Smart AI platforms enable retail and hospitality organisations to turn their existing CCTV investments into proactive security systems and smart retail ecosystems that boost customer service and ROI.

Read more...
AI agents become ‘First Class Identities’
Access Control & Identity Management
AI agents are now approving transactions, accessing systems, triggering workflows, and making decisions autonomously. But uncontrolled AI agents are becoming one of the largest security gaps in modern enterprises.

Read more...
Balancing secure access control and fire safety
Editor's Choice Access Control & Identity Management Fire & Safety
In modern building management, few topics create as much tension as the intersection between security access control and fire evacuation safety. Nichola Allen of G2 Fire sheds light on this delicate balance.

Read more...
Securing water infrastructure for industry and community
Access Control & Identity Management Fire & Safety Government and Parastatal (Industry)
The Badirammogo Water User Association needed a solution that could secure remote sites, reduce reliance on physical guards, and ensure uninterrupted service delivery while remaining aligned with its values and long-term strategy.

Read more...
Malware attacks on SMBs disguised as AI services
News & Events AI & Data Analytics
From January to April 2026, Kaspersky detected more than 33 300 attacks on small and medium-sized businesses (SMBs), in which malicious or unwanted software for PCs was disguised as popular artificial intelligence (AI) services.

Read more...
Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...
Disconnect between confidence in identity security and operational reality
Access Control & Identity Management News & Events
New FIDO Alliance and HID study reveals gap between identity security confidence and reality; 94% of enterprises claim they can revoke employee access within 24 hours, yet 35% experienced delays or failures in the past two years.

Read more...
Paxton Solo training available to security installers
Paxton Access Control & Identity Management News & Events
Following the launch of Solo, Paxton’s brand-new access control system, the security manufacturer is rolling out dedicated Solo training sessions across South Africa to support security installers working with the system.

Read more...
Growing adoption of AI at work
News & Events AI & Data Analytics
AI adoption accelerates worldwide, with South Africa making gains amid uneven diffusion. Locally, South Africa ranks 46th of 147 economies measured, and its AI usage increased to 23,1% in Q1 2026.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.