Skip to main content

Security and GDPR Compliance in ZKTeco Devices

Data handled by ZKTeco biometric devices is kept secure and confidential via extensive data encryption.

Written by Marie Claire Saliba

Table of Contents


About ZKTeco Biometric Devices

Indigo uses biometric clocking devices provided by ZKTeco. These devices allow employees to log in and out of work using personal identifying features such as face, fingerprint, and palm recognition.


GDPR Compliance

Both the clocking devices and the storage of data retrieved by these devices are GDPR compliant. This ensures that users' identifying information is kept private and secure.

Moreover, ZKTeco use templates that anonymise this data, effectively safeguarding users' identities with high standards of data security measures.

Data Encryption

ZKTeco's methods of data encryption ensure template irreversibility: the original biometric image within a ZKTeco biometric template cannot be reverse-engineered, not even by ZKTeco staff themselves.

  1. The original biometric (your face, fingerprint, etc) is 'seen' by ZKTeco's algorithm, which then makes calculations based on what it sees. The results of these calculations create a unique template of scrambled data, effectively making the ZKTeco biometric template irreversible.

  2. This biometric template–and all data associated with the template like name, user ID, photo–is then encrypted using both AES-256 and RSA1024/2048 encryption algorithms to guarantee secure storage and transmission of the scrambled data.

This means that:

  • Without the right key for the AES-256 encryption and RSA1024/2048 encryption, no-one can access the biometric template.

  • Even with the keys for the RSA encryption and the AES-256 encryption, the biometric template 1. is unreadable, and 2. cannot be used to recreate images of the original biometrics.


Links to Further Information


Did this answer your question?