A facial recognition smart lock can reduce the need to carry a key, card or phone, but buyers should understand where biometric information is processed, who can enroll users and how access is removed. Privacy is not a single feature—it is a combination of product architecture, administrator practices and applicable law.
What does a facial recognition smart lock store?
Biometric systems generally create a mathematical template from an enrolled face or fingerprint. A template is used for comparison when a person attempts to unlock the door. It should not be treated as an ordinary password because a person's biometric characteristics cannot simply be replaced after a security incident.
Ora FacePass product documentation states that supported biometric templates are stored on the device rather than in a remote cloud biometric database. Connected features can still involve other information, such as account details, device status, notifications or video functions, depending on the model and configuration.
On-device processing versus cloud storage
On-device biometric storage keeps the supported biometric template at the lock for local matching. This can reduce dependence on a remote biometric database and can support selected local access functions.
Cloud-connected features may provide remote management, alerts, app access or video capabilities. Buyers should review which data each connected feature uses, who controls the administrator account and what happens when the network is unavailable.
Ask vendors to distinguish biometric templates, photos or video, account information, access logs and diagnostic data. These categories have different purposes and should not be grouped together as “biometric data.”
Privacy questions to ask before installation
- Where are facial and fingerprint templates stored?
- Is the original enrollment image retained?
- Which functions continue without Wi-Fi or internet access?
- Who can enroll, view, disable or delete users?
- How are administrator credentials protected?
- What information is visible in the mobile application?
- How are users removed after employment, tenancy or authorized access ends?
- What notice, consent, retention or deletion obligations apply in the project location?
Good biometric-access operating practices
- Assign named administrators instead of sharing a general account.
- Use the minimum number of administrators required.
- Remove former residents, employees and vendors promptly.
- Keep a documented mechanical-key and emergency-access process.
- Review access permissions on a regular schedule.
- Protect phones and accounts used for remote administration.
- Document how a user can ask questions or request removal where applicable.
- Update written policies when the deployment or connected features change.
Facial recognition, fingerprints and alternative credentials
Not every authorized user will want or be able to use the same credential. A multi-method lock can offer alternatives such as fingerprint, PIN, key fob, mobile app or mechanical key. The available methods and capacities vary by model, so accessibility and backup needs should be included in the selection process.
Compare the credential and hardware options in the FP01 vs FP02 vs FP03 guide.
Privacy considerations for businesses and properties
Businesses, employers, landlords and property operators may have additional duties when they request biometric enrollment. Rules can vary by state, country, relationship and use case. Ora FacePass does not provide legal advice; organizations should obtain qualified guidance for their privacy notices, consent process, retention schedule and deletion procedures.
Frequently asked questions
Does Ora FacePass store supported biometric templates in a cloud database?
Ora FacePass product documentation states that supported biometric templates are stored on the device. Review the selected model and enabled connected features for the complete data flow.
Can users choose a non-biometric access method?
Ora FacePass models support multiple access methods. The specific mix varies by model and can include PIN, key fob, app access and mechanical key in addition to biometric methods.
Does local biometric storage mean the lock never uses the internet?
No. Local biometric matching and connected services are different functions. Remote access, notifications, video or app features can require network connectivity even when supported biometric templates remain on the device.
Should a company enroll employees without a policy?
Organizations should establish a documented policy and obtain appropriate legal guidance before collecting biometric information. The policy should address notice, consent, access, retention and deletion.
Choose a privacy-conscious smart-lock setup
Explain the users, door type, desired access methods and connected features in the project consultation. Ora FacePass can help identify the product questions that need to be resolved before deployment.
Request a privacy and compatibility consultation
Related resources: Smart Lock FAQs, Biometric Smart Lock Buying Guide and Commercial Access Guide.