← IoT Privacy Database

Idemia Face Recognition

Idemia · Face Recognition

✓ Reviewed

4.4Surveillance
Index
Policy — what its policy permitsD
Evidence — what research provesC

Idemia is a French identity company that builds the face-recognition software governments use to search photo databases, and it is one of the largest suppliers of the photos themselves: by its own account it has "issued 70 percent of all driver's licenses and identification documents in the United States". Unlike a phone or a doorbell, this is not a product you buy or agree to. Your face enters the system when you renew your licence, get booked, or walk through an airport checkpoint — and the searching is done by police, the FBI, DMVs and border agencies, not by you. Georgetown Law's landmark investigation found that more than 117 million American adults were already in a law-enforcement face-recognition network drawn from 26 states' driver's licence photos, that not one agency required a warrant to run a search, and that two major face-recognition companies did not test for bias; EFF names Idemia's MorphoTrust subsidiary as a designer of exactly those DMV, law-enforcement, border and airport systems. Idemia does publish privacy policies, but they cover its website visitors, its business customers and people who walk into an IdentoGO enrollment centre — they do not cover the far larger population whose faces sit in the galleries its software searches, and the only "opt-out" the enrollment policy offers is to not use the service, which is not an option for a driver's licence or a police mugshot. On accuracy, the picture is more favourable than the industry's: NIST's 2019 demographic study named Idemia as one of a handful of developers whose one-to-many false-positive differentials across race and sex were undetectable, at a time when many rival algorithms were 10 to 100 times worse on some groups — though the same report also listed Idemia among exceptions to an otherwise consistent pattern in false-negative rates for Black men. Accuracy, however, is not consent: an accurate system that enrolls people who were never asked is still a mass-surveillance system.

Why this rating

POLICY 50 = 100 -15 sensitive-collection (IDEMIA Group Privacy Policy, "Material scope": the categories of personal data in scope expressly include "Health data, including medical, genetic and biometric data"; the IdentoGO policy's stated purpose includes "Provide products or services you have purchased or requested, including fingerprint-based background checks" — irrevocable biometric identifiers, collected at population scale) -10 no-opt-out (IdentoGO privacy policy offers only "If you do not wish to permit that use, you can choose not to use the particular service"; the policy's one enumerated choice mechanism is a California Civil Code §1798.83 opt-out covering direct-marketing disclosures, not the biometric collection itself. Declining the service is not available to someone who must hold a state driver's licence, is booked into a mugshot gallery, or passes a checkpoint, and no Idemia policy governs those people at all) -8 indefinite-retention (IdentoGO privacy policy: "We will retain your personal information as needed to fulfill the purposes for which it was collected" — purpose-bound with no stated period and no separate limit for biometric/fingerprint data; the Group policy's concrete periods (five years' intermediary storage after a customer relationship, three for prospects, ten for ex-employees) apply to commercial and HR relationships, not to biometric subjects) -7 policy-vagueness (Group Privacy Policy, "Sharing data": "We may share Personal data within IDEMIA and also with third parties in the legitimate interest of our customers and partners" — recipients and categories unenumerated; neither published policy describes what happens to face images processed on behalf of government customers, which is the product's actual function) -5 unilateral-change (Group Privacy Policy: "This Group Privacy Policy is a living document that may be periodically updated by IDEMIA", with no notification commitment; the IdentoGO policy contains no amendment clause at all) -5 law-enforcement-loose (IdentoGO privacy policy: "Information provided by you to IDEMIA for the purpose of submitting to a background check will be shared with one or more government agencies as part of the background check process", plus disclosure to "comply with requests for information from police or government authorities"; Group policy: disclosure where "required – by law, legal process, litigation, and/or requests from public and governmental authorities" — neither states a warrant threshold, notice duty, or transparency reporting). Not applied: sells-data (IdentoGO privacy policy states "We will not sell, rent or lease your personal information to others" and no fetched Idemia policy reserves a sale or cross-context-advertising right); broker-disclosure (no fetched policy names data brokers, insurers, or partners for scoring or marketing); no-deletion-right (Group Privacy Policy grants the right "To delete his/her Personal data" with a named route to the Group DPO at dpo@idemia.com); forced-arbitration (no arbitration or class-waiver clause found in the policies fetched — not verified either way, so no deduction). EVIDENCE 63 = 100 -25 undisclosed-collection (the population whose faces populate the galleries Idemia's systems search was never notified and is covered by no Idemia policy. Georgetown Law's Center on Privacy & Technology documented that "Half of American adults – more than 117 million people – are in a law enforcement face recognition network" assembled from 26 states' driver's licence and ID photos, with no consent step and no notice; EFF's Street Level Surveillance file names MorphoTrust — "a subsidiary of Idemia" — stating it "has designed systems for state DMVs, federal and state law enforcement agencies, border control and airports (including TSA PreCheck), and the state department"; and Idemia's own press release states it has "issued 70 percent of all driver's licenses and identification documents in the United States". Ongoing, not decayed: Idemia's own 2022 announcement of a California award describes "a contract that will last up to 12 years") -12 law-enforcement-pipeline (Georgetown found "Not one agency required warrants, and many agencies did not even require an officer to suspect someone of committing a crime before using face recognition", and that "With only a few exceptions, there are no laws governing police use of the technology, no standards ensuring its accuracy, and no systems checking for bias"; EFF records that the FBI's FACE Services unit "can access more than 400 million non-criminal photos from state Departments of Motor Vehicles (DMV) and the State Department" — bulk, warrantless government searching of civil photo galleries). Not applied: regulatory-action (no FTC, state AG, ICO, CNIL or Garante enforcement against Idemia was found on searching; the Nairobi High Court's Huduma Namba DPIA ruling ran against the Kenyan government, not Idemia); class-action-credible (the Paris action over Kenya's NIIMS, brought by the Kenya Human Rights Commission, Nubian Rights Forum and Data Rights under the French Duty of Vigilance Act 2017, went to mediation and settled with Idemia agreeing to revise its Vigilance Plan — a settled civil suit, but not a class action and with no finding of liability); security-negligence (CVE-2021-35522, CVSS 9.8, allowed pre-auth firmware hijack and biometric bypass on VisionPass facial-recognition, MorphoWave, MorphoAccess and SIGMA devices, but Positive Technologies disclosed it responsibly and Idemia shipped patches — no evidence of unpatched exposure or hostility to researchers); major-breach (no confirmed breach of Idemia-held biometric data was verified); measurement-clean bonus (not applied — NIST FRVT Part 3 is an accuracy study, not a data-exposure measurement). Characterised precisely, and deliberately NOT scored as a privacy deduction: NIST IR 8280 (Grother, Ngan, Hanaoka, Dec 2019) is a technical accuracy evaluation, and its Idemia-specific findings are mostly favourable — "One important exception is that some developers supplied identification algorithms for which false positive differentials are undetectable. Among those is Idemia, who publicly described how this was achieved", against an industry backdrop where false-positive rates varied by "a factor of 100 more false positives between countries". The one adverse Idemia mention is a nuance, not a bias headline: NIST found "black men invariably give lower false negative identification rates than white men... The are some exceptions including algorithms from 3DiVi, Aware, Eyedea, Idemia, Kedacom, Tevian and Vocord." Surveillance Index 4.3 = round((100 - (0.45*50 + 0.55*63)) / 10, 1), the formula stated at lines 11 and 77 of docs/rating-methodology.md, which was opened and checked during this verification pass; grades per the same document's line 8 (A ≥ 90, B ≥ 75, C ≥ 60, D ≥ 40, F < 40, higher = more privacy-respecting), giving policy 50 → D and evidence 63 → C. This is the convention that makes the corpus's policy_score 45 → D. NOT VERIFIED, therefore omitted: the "259 deployments across 13 states" figure in the research brief could not be substantiated in any source that was actually loaded. Also omitted: any claim that Idemia built the FBI's NGI Interstate Photo System — no loaded source confirmed an Idemia/MorphoTrust build role. Also omitted: a 2021 wrongful-termination suit in which a former executive alleged CFIUS violations and exposure of Americans' data — the allegation is unproven, denied by Idemia, and unconfirmed by any regulator. Removed during adversarial verification: the assertion that travellers may decline the TSA CAT-2 facial match and that CAT-2 performs 1:1 comparison against the presented ID photo — TSA's own pages returned HTTP 403 and no archive snapshot existed, so neither gloss is traceable to a source a reader can open.

What it is

Manufacturer
Idemia
Category
Face Recognition
Model years
2017-present (Idemia formed 2017; MorphoTrust/MorphoTrak product lineage predates it)
Market status
Current
Companion app
None for the matching system itself — it is agency-deployed. Idemia's public-facing enrollment arm is IdentoGO (identogo.com), which captures fingerprints, photographs and identity documents on behalf

The evidence 9

Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.

  1. Advocacy report · Center on Privacy & Technology, Georgetown Law (Alvaro Bedoya, Clare Garvie, Jonathan Frankle) · 2016-10-18

    Investigation drawing on "over 17,000 pages of official documents obtained by the Center". Found that "Half of American adults - more than 117 million people - are in a law enforcement face recognition network", assembled by scanning driver's licence and ID photos across 26 states, and that "one in four law enforcement agencies can access face recognition." On regulation it states: "With only a few exceptions, there are no laws governing police use of the technology, no standards ensuring its accuracy, and no systems checking for bias." On process: "Not one agency required warrants, and many agencies did not even require an officer to suspect someone of committing a crime before using face recognition." It reports that "face recognition is less accurate on African Americans, women and young people", and that "two major face recognition companies do not test for bias" - a finding about vendors, not about agencies.

    Why it matters here: Establishes the involuntary mass-enrollment fact and the absence of any warrant control over the DMV photo galleries that Idemia-supplied systems search. Basis for the -25 undisclosed-collection and -12 law-enforcement-pipeline deductions.

  2. Advocacy report · Electronic Frontier Foundation

    EFF's technology file states that "MorphoTrust, a subsidiary of Idemia (formerly known as OT-Morpho or Safran), is another large vendors of face recognition and other biometric identification technology in the United States. It has designed systems for state DMVs, federal and state law enforcement agencies, border control and airports (including TSA PreCheck), and the state department." It records that "More than half of all adults in the United States have their likeness in at least one face recognition database", that "At least 20 of 42 federal agencies with policing powers have their own or use another government agency's face recognition system", and that the FBI's FACE Services unit "can access more than 400 million non-criminal photos from state Departments of Motor Vehicles (DMV) and the State Department." EFF notes the compounding harm that the software "is particularly bad at recognizing Black people and other ethnic minorities, women, young people, and transgender and nonbinary individuals", and that "unlike passwords, people can't easily change their faces."

    Why it matters here: The source that ties Idemia specifically to the involuntary-enrollment infrastructure, and quantifies the federal pipeline into civil DMV photo databases. Co-basis for the -25 and -12 deductions.

  3. News · IDEMIA (company press release) · 2022-03-24

    Company press release announcing support for state IDs and driver's licences in Apple Wallet at TSA checkpoints. In describing itself, IDEMIA states it has "issued 70 percent of all driver's licenses and identification documents in the United States." This is a self-reported vendor figure, not an independently audited one, but it is a direct admission by the vendor and it establishes that the photographs feeding the DMV galleries described by Georgetown and EFF are overwhelmingly captured through Idemia-supplied credential systems.

    Why it matters here: Added during verification to close a citation gap: the submitted record quoted the 70% market-share figure in both the summary and the -25 deduction while supplying no url for it. Idemia's own admission of the scale of its credential-issuance footprint, in its own words.

  4. News · IDEMIA (company press release) · 2022-03-08

    Company press release announcing that California entered "a contract that will last up to 12 years and cover delivery of not only traditional driver's licenses, but also services and technologies" moving the state toward a digital DMV. Coverage includes physical driver's licence and ID card production, mobile DMV tablets extending enrolment into remote areas, and new card design and security features. Demonstrates that a single US state has locked in Idemia credential issuance on a horizon extending into the 2030s, which is why the involuntary-enrollment finding is treated as live rather than time-decayed.

    Why it matters here: Added during verification to close a second citation gap: the record argued the enrollment practice is "ongoing, not decayed" by quoting a 12-year California award with no url. Establishes that the arrangement is current and long-dated rather than historical.

  5. Independent review · National Institute of Standards and Technology (Patrick Grother, Mei Ngan, Kayee Hanaoka) · 2019-12

    NIST processed "18.27 million images of 8.49 million people through 189 mostly commercial algorithms from 99 developers." Industry-wide it found false positives "between 2 and 5 times higher in women than men", highest in West and East African and East Asian people, with "a factor of 100 more false positives between countries" on high-quality application photos, and that on mugshot images "the highest false positives are in American Indians." On Idemia specifically the finding is favourable: "One important exception is that some developers supplied identification algorithms for which false positive differentials are undetectable. Among those is Idemia, who publicly described how this was achieved." One adverse nuance: reporting that "black men invariably give lower false negative identification rates than white men", NIST adds "The are some exceptions including algorithms from 3DiVi, Aware, Eyedea, Idemia, Kedacom, Tevian and Vocord." NIST cautions that naming a commercial entity "is not intended to imply recommendation or endorsement."

    Why it matters here: The definitive independent accuracy evaluation naming Idemia. Included to characterise the NIST findings precisely rather than to justify a deduction - NIST's Idemia-specific one-to-many result is favourable, and technical accuracy is not a privacy violation. Explicitly scored at zero deduction.

  6. Cve · The Record (Recorded Future News), Catalin Cimpanu, reporting research by Positive Technologies · 2021-07-26

    Positive Technologies found a buffer overflow in the Thrift protocol network packet design of Idemia biometric devices, rated CVSS 9.8 (critical). Affected products include the VisionPass facial-recognition terminal, SIGMA fingerprint terminals, and MorphoWave and MorphoAccess vein/fingerprint units. An attacker with LAN or WAN access could "bypass the biometric identification provided by the IDEMIA devices" and "remotely open doors controlled by the device and enter secured areas." Idemia released firmware patches addressing this and two further issues found by the same team, and urged customers to update immediately.

    Why it matters here: Independently documented critical vulnerability in a fielded Idemia facial-recognition product. Listed for the record but explicitly NOT scored as security-negligence, because disclosure was coordinated and Idemia shipped patches.

  7. Privacy analysis · CIPIT, Strathmore University (Nelson Otieno Okeyo) · 2024-12-13

    The Kenya Human Rights Commission, the Nubian Rights Forum and Data Rights brought suit against Idemia in a Paris court under the French Duty of Vigilance Act 2017. The article alleges the company "failed to identify the human rights risks associated with its digital identity products when it supplied hardware for the Kenyan National Integrated Identification Management System (NIIMS) between 2019 and 2021", and did not adequately assess or mitigate human rights impacts. The proceedings were referred to mediation and settled, with Idemia agreeing to revise its Vigilance Plan to enhance safeguards in digital identity management; the article records that the filing NGOs "had mixed reactions as to the inadequacy of the IDEMIA's revised Vigilance Plan." Separately, the Nairobi High Court declared Kenya's Huduma Namba project unconstitutional and illegal for failure to conduct a DPIA. Caveat noted on verification: the article is internally inconsistent about the filing year, stating both that the NGOs filed "In 2020" after unanswered notices and that "The case against IDEMIA was filed in a Paris court in 2021."

    Why it matters here: The only substantiated legal accountability action against Idemia found. Deliberately NOT scored as regulatory-action or class-action-credible: it settled in mediation with no liability finding, and the Kenyan constitutional ruling ran against the government rather than the vendor.

  8. Privacy policy · Idemia / IdentoGO

    The policy covering members of the public who are fingerprinted and photographed at Idemia enrollment centres. Data is collected to "Provide products or services you have purchased or requested, including fingerprint-based background checks", and "Information provided by you to IDEMIA for the purpose of submitting to a background check will be shared with one or more government agencies as part of the background check process." It reserves disclosure to "comply with requests for information from police or government authorities" without stating a warrant threshold. Retention is open-ended - "We will retain your personal information as needed to fulfill the purposes for which it was collected" - with no separate limit for biometric data. The only alternative offered to the collection itself is "If you do not wish to permit that use, you can choose not to use the particular service"; the sole enumerated choice mechanism is a California Civil Code §1798.83 opt-out/opt-in framework covering direct-marketing disclosures, which does not reach the biometric processing. It does affirm that "We will not sell, rent or lease your personal information to others", and it contains no clause describing how the policy may be amended.

    Why it matters here: Primary source for the no-opt-out (-10), indefinite-retention (-8) and law-enforcement-loose (-5) deductions, and for declining the sells-data deduction.

  9. Privacy policy · Idemia

    Idemia's group-level policy. Its "Material scope" expressly brings "Health data, including medical, genetic and biometric data" within the categories processed. Under "Sharing data" it reserves broad, unenumerated disclosure: "We may share Personal data within IDEMIA and also with third parties in the legitimate interest of our customers and partners", plus transfers to group entities in countries where it has data centres and to third-party suppliers under European Union Model Clauses (SCC) where outside the EU. It reserves disclosure where "required – by law, legal process, litigation, and/or requests from public and governmental authorities." Retention periods are given for commercial and HR relationships (five years' intermediary storage after a customer relationship ends, three years for prospects, ten years after an employee leaves) but not for biometric subjects. It grants GDPR-style rights including "To delete his/her Personal data", routed to a local or Group Data Protection Officer at dpo@idemia.com. On amendment it says only: "This Group Privacy Policy is a living document that may be periodically updated by IDEMIA", with no notification mechanism.

    Why it matters here: Primary source for the sensitive-collection (-15), policy-vagueness (-7), unilateral-change (-5) and law-enforcement-loose (-5) deductions, and for declining broker-disclosure and no-deletion-right.

Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.

← Back to the IoT Privacy Database