- The FDPIC obliged PostFinance to collect voiceprints for authentication purposes only with express consent and to delete non-consented profiles.
- The FDPIC found that the use of biometrics for authentication violated the principle of proportionality; PostFinance disputes this and has filed a complaint.
The FDPIC has announcedthat he had conducted an investigation into PostFinance due to authentication using voice recognition. The investigation was concluded on May 16, 2025, with a Order, Voiceprints for authentication only with express consent from the persons concerned. Voting records without such consent must be deleted.
The reasoning is not public, the ruling was filed with the Federal Administrative Court. contested. However, the FDPIC stated in his press release (it is not clear why he is making a statement on this) that voiceprints for the identification of a person are particularly sensitive personal data (correct), but that “against the background of increasing technological progress”, there are risks associated with this and the use of biometric data for authentication purposes by PostFinance Ltd violates the principle of proportionality:
The FDPIC’s investigation revealed that the processing of biometric data for authentication purposes […] violates the principle of proportionality. In addition, the voiceprints are created without the active submission of a declaration of intent by customers. This means that customers who reject the use of voice recognition must take action themselves. […]
The FDPIC considers this procedure to be in breach of data protection law and has issued an order requiring PostFinance Ltd to obtain the express consent of data subjects for the creation of voiceprints for authentication by voice recognition. PostFinance Ltd is also instructed to delete those voiceprints for which the data subject has not given their express consent. […]
The impression suggests itself that the FDPIC is proceeding according to the familiar pattern – the Proportionality of data processing should not be measured against the purpose of the processing (e.g. convenience, which may be a legitimate aim of the controller), but against a standard that is not objectified but ultimately constructed by the FDPIC (see also here and here). If this is the case – as I said, the ruling itself is not available – the Federal Administrative Court will hopefully provide clarification.
A further question would be whether PostFinance had come to the conclusion in an audit that the use of voting profiles was not appropriate. safer than other authentication methods. It can be assumed that this question was also the subject of the investigation, but that the FDPIC came to the conclusion that a security gain is not sufficiently significant.
For its part, PostFinance has issued a Media release publishedin which it states that the FDPIC had been informed of a new procedure with consent, which is based on the consent of the customers, before issuing the ruling. Apparently, the FDPIC nevertheless considered it appropriate to issue an order – perhaps to obtain the deletion of the profiles already collected, perhaps for other reasons.