Take-Aways (AI)
  • The FDPIC obli­ged Post­Fi­nan­ce to coll­ect voice­prints for authen­ti­ca­ti­on pur­po­ses only with express con­sent and to dele­te non-con­sen­ted profiles.
  • The FDPIC found that the use of bio­me­trics for authen­ti­ca­ti­on vio­la­ted the prin­ci­ple of pro­por­tio­na­li­ty; Post­Fi­nan­ce dis­pu­tes this and has filed a complaint.

The FDPIC has announ­cedthat he had con­duc­ted an inve­sti­ga­ti­on into Post­Fi­nan­ce due to authen­ti­ca­ti­on using voice reco­gni­ti­on. The inve­sti­ga­ti­on was con­clu­ded on May 16, 2025, with a Order, Voice­prints for authen­ti­ca­ti­on only with express con­sent from the per­sons con­cer­ned. Voting records wit­hout such con­sent must be deleted.

The rea­so­ning is not public, the ruling was filed with the Fede­ral Admi­ni­stra­ti­ve Court. con­te­sted. Howe­ver, the FDPIC sta­ted in his press release (it is not clear why he is making a state­ment on this) that voice­prints for the iden­ti­fi­ca­ti­on of a per­son are par­ti­cu­lar­ly sen­si­ti­ve per­so­nal data (cor­rect), but that “against the back­ground of incre­a­sing tech­no­lo­gi­cal pro­gress”, the­re are risks asso­cia­ted with this and the use of bio­me­tric data for authen­ti­ca­ti­on pur­po­ses by Post­Fi­nan­ce Ltd vio­la­tes the prin­ci­ple of proportionality:

The FDPIC’s inve­sti­ga­ti­on reve­a­led that the pro­ce­s­sing of bio­me­tric data for authen­ti­ca­ti­on pur­po­ses […] vio­la­tes the prin­ci­ple of pro­por­tio­na­li­ty. In addi­ti­on, the voice­prints are crea­ted wit­hout the acti­ve sub­mis­si­on of a decla­ra­ti­on of intent by cus­to­mers. This means that cus­to­mers who reject the use of voice reco­gni­ti­on must take action themselves. […] 

The FDPIC con­siders this pro­ce­du­re to be in breach of data pro­tec­tion law and has issued an order requi­ring Post­Fi­nan­ce Ltd to obtain the express con­sent of data sub­jects for the crea­ti­on of voice­prints for authen­ti­ca­ti­on by voice reco­gni­ti­on. Post­Fi­nan­ce Ltd is also ins­truc­ted to dele­te tho­se voice­prints for which the data sub­ject has not given their express consent. […]

The impres­si­on sug­gests its­elf that the FDPIC is pro­ce­e­ding accor­ding to the fami­li­ar pat­tern – the Pro­por­tio­na­li­ty of data pro­ce­s­sing should not be mea­su­red against the pur­po­se of the pro­ce­s­sing (e.g. con­ve­ni­ence, which may be a legi­ti­ma­te aim of the con­trol­ler), but against a stan­dard that is not objec­ti­fi­ed but ulti­m­ate­ly cons­truc­ted by the FDPIC (see also here and here). If this is the case – as I said, the ruling its­elf is not available – the Fede­ral Admi­ni­stra­ti­ve Court will hop­eful­ly pro­vi­de clarification.

A fur­ther que­sti­on would be whe­ther Post­Fi­nan­ce had come to the con­clu­si­on in an audit that the use of voting pro­files was not appro­pria­te. safer than other authen­ti­ca­ti­on methods. It can be assu­med that this que­sti­on was also the sub­ject of the inve­sti­ga­ti­on, but that the FDPIC came to the con­clu­si­on that a secu­ri­ty gain is not suf­fi­ci­ent­ly significant.

For its part, Post­Fi­nan­ce has issued a Media release publishedin which it sta­tes that the FDPIC had been infor­med of a new pro­ce­du­re with con­sent, which is based on the con­sent of the cus­to­mers, befo­re issuing the ruling. Appar­ent­ly, the FDPIC nevert­hel­ess con­side­red it appro­pria­te to issue an order – per­haps to obtain the dele­ti­on of the pro­files alre­a­dy coll­ec­ted, per­haps for other reasons.