Face matching and biometric verification
One-to-one face matching compares a live or captured applicant image with a portrait from identity evidence. It can support proof that the applicant owns the evidence, but it creates biometric, accuracy, spoofing and exclusion questions that must be governed explicitly.
GDPR treatment depends on the purpose and processing operation. Do not assume every photograph is special-category biometric data or that calling a process 'verification' removes biometric obligations; analyse the actual technical use.
For: privacy, fraud, security, product and procurement teams. This is independent information, not legal, compliance or security advice.
How a match becomes a decision
- Acquire a reference portrait from validated evidence.
- Capture an applicant image through a protected path.
- Check presence and attack signals appropriate to risk.
- Produce a similarity score.
- Apply a configured threshold and exception policy.
- Combine the result with other evidence rather than treating it as identity truth.
Threshold trade-offs
A stricter threshold may reduce some false matches while increasing legitimate rejection. Published aggregate accuracy does not describe performance at your threshold, on your population, devices, lighting, documents or attack conditions.
Governance questions
- Purpose and legal basis for image and template processing.
- Whether templates are created, retained or reused.
- Accuracy and demographic evidence at deployed settings.
- Liveness, injection and replay protection.
- Human review, alternatives and appeal.
- Deletion and separation from unrelated model training.
Safe wording
Describe the result as evidence contributing to an identity decision. Avoid saying the system 'proves' a person is genuine or is free from bias, spoofing or error.
Evidence and limits
MyID separates enacted rules, official implementation material, testing and vendor claims. A source can establish what its publisher says; it does not prove that every product, deployment or interpretation works as claimed. Where Irish implementation remains unsettled, this page says so.
- General Data Protection Regulation
- NIST SP 800-63A-4 identity proofing
- ENISA Remote Identity Proofing: Attacks and Countermeasures
Sources checked 22 August 2026. Re-check the linked primary material before making a consequential decision.
Next useful pages
Follow the Irish evidence
Get the business briefing when Irish wallet, verification and age-assurance evidence changes.
Join the business briefing