started · updated
Deepfakes challenge biometric security and data privacy
The rise of deepfake technology is challenging the effectiveness of facial biometrics, a primary tool used by banks and digital services to verify customer identities. While facial recognition remains a valid authentication layer, experts suggest it can no longer serve as a standalone defense against sophisticated AI-driven fraud.
To mitigate risks, specialists recommend implementing multi-layered controls, including robust liveness detection, device analysis, behavioral patterns, and multi-factor authentication. Regulatory frameworks, such as Brazil’s CMN Resolution No. 4,753/2019, do not mandate specific technologies but require institutions to maintain controls capable of effectively validating identity.
Biometric data, including fingerprints and facial mapping, is classified as sensitive personal data under Brazil’s General Data Protection Law (LGPD). While many mobile devices process biometric data locally by converting it into mathematical codes, services that require selfies for identity verification may transmit encrypted data or geometric traits to secure servers.
Entities
Gov.br · LGPD · Syscapital