What's Happening?
Pegasystems, including its affiliates, has issued a U.S. Biometric Information Privacy Notice and Release outlining its policies for collecting, using, storing, and disclosing biometric information from job applicants and employees. This notice is designed
to comply with various state and federal biometric privacy laws, such as the Illinois Biometric Information Privacy Act (BIPA), the Colorado Privacy Act (CPA), and the Texas Capture Or Use Of Biometric Identifier Act (CUBI). The company may collect biometric information, including facial geometry, during the hiring, onboarding, and employment processes. The stated purposes for this collection include identity verification, prevention of unauthorized system and facility access, protection of confidential information, compliance with contractual obligations, and security requirements for facility visits. Pegasystems utilizes third-party vendors like Incode Technologies, Inc. and First Advantage Corporation to process this data, ensuring these vendors adhere to equivalent data security and retention standards. The notice clarifies that submitting an application to Pegasystems constitutes agreement with these terms.
Why It's Important?
This notice from Pegasystems highlights the increasing importance of biometric data privacy in the U.S. employment landscape. As more companies adopt biometric technologies for security and identity verification, compliance with a patchwork of state-specific privacy laws becomes critical. For employees and job applicants, understanding these policies is essential to protect their personal biometric information. The notice underscores the legal obligations companies face regarding data retention limits, disclosure practices, and security measures for sensitive biometric data. Non-compliance with laws like BIPA can lead to significant legal repercussions, including class-action lawsuits and substantial financial penalties. This move by Pegasystems reflects a broader trend where businesses are proactively addressing biometric privacy concerns to mitigate legal risks and build trust with their workforce, emphasizing transparency in their data handling practices.
What's Next?
Pegasystems' biometric data retention policy stipulates that biometric information will be stored only as long as necessary for its stated purpose, or for a maximum of three years from the last interaction, whichever is shorter. For unsuccessful applicants, data is typically destroyed within three years after the application process concludes, or immediately after identity verification in most cases. For employees, facial templates are retained for the duration of employment and destroyed within three years after employment ends. The company also states that it does not sell, lease, trade, or profit from biometric information, disclosing it only with prior written consent, to engaged vendors under data processing agreements, for financial transactions, or when legally required. Future developments may include further state-level legislative actions regarding biometric privacy, potentially leading to more standardized federal regulations, which would impact how companies like Pegasystems manage such data across different jurisdictions.
Beyond the Headlines
The detailed biometric privacy notice from Pegasystems reflects a growing tension between technological advancement and individual privacy rights. The requirement for job applicants and employees to provide biometric data as a condition of employment or access raises ethical questions about consent and potential coercion. While companies cite security and efficiency as primary drivers for biometric adoption, the inherent risks of data breaches and misuse of immutable personal identifiers remain a significant concern. The varying state laws create a complex legal environment, pushing companies to adopt comprehensive, albeit often state-specific, compliance frameworks. This situation could eventually lead to calls for a unified federal biometric privacy law in the U.S., similar to GDPR in Europe, to provide clearer guidelines for businesses and stronger protections for individuals, thereby shaping the future of digital identity and privacy in the workplace.













