Information derived from measuring physical or behavioural characteristics allowing a person to be identified, whose decisive property for insurance is irrevocability.
All modern information security rests on an assumption so obvious it is never stated, that of revocability: a compromised password is changed, a stolen card is stopped and reissued, a corrupted certificate is revoked. The harm of a compromise is therefore not the loss of the identifier, it is the interval between discovery and revocation. A fingerprint template, a facial geometry, a voiceprint or an iris destroy that assumption, since the person can neither change them, nor stop them, nor obtain new ones. The interval between compromise and revocation becomes infinite, and the harm ceases to be a function of response time and becomes a function of the person's lifespan. A conventional cyber policy nonetheless funds a response calibrated for an exposure that closes, notification and monitoring for twelve or twenty-four months, services formally performed and materially futile against a forty-year exposure.
The typical biometric case involves neither intrusion, nor leak, nor malice: the business collected, stored and protected correctly, and failed to notify and obtain consent.
biometric data, gabarit biométrique, identifiant biométrique, BIPA