CCPA / CPRA (CCPA)
California's consumer privacy law (as amended by the CPRA), which treats biometric information as sensitive personal information subject to disclosure, deletion and limitation rights.
The protocols, certifications and laws that govern physical access control — what each one actually requires, and who it binds.
California's consumer privacy law (as amended by the CPRA), which treats biometric information as sensitive personal information subject to disclosure, deletion and limitation rights.
The US government's Federal Identity, Credential, and Access Management framework, whose approved-products process governs which PACS components may be used in federal buildings.
The US federal standard for Personal Identity Verification (PIV) credentials, defining the interoperable smartcard identity used across federal facilities and systems.
Under the EU GDPR, biometric data used to identify a person is a special category requiring an explicit legal basis — a high bar for face or fingerprint access in Europe.
The 2004 presidential directive mandating a common, interoperable identity credential for federal employees and contractors — the policy that produced FIPS 201 and the PIV card.
The Illinois statute governing collection and storage of biometric identifiers. It requires informed written consent and provides a private right of action — the most litigated biometric-privacy law in the US.
The international standard for an information security management system (ISMS). Certification signals a systematic, audited approach to securing data — including a cloud vendor's customer data.
A federal procurement ban prohibiting agencies from buying video surveillance and telecommunications equipment from named Chinese manufacturers — a key compliance filter for security hardware.
NIST's guidance for using PIV credentials in physical access control systems, mapping authentication factors to facility security areas.
An interoperability standard for IP-based physical security. ONVIF Profile A and Profile C cover access control — configuration and door control — so components from different vendors work together.
An independent audit report on a service provider's controls for security, availability, processing integrity, confidentiality and privacy — the baseline trust artefact for cloud access control vendors.
Texas's Capture or Use of Biometric Identifier law, requiring consent before capturing biometric data. Enforced by the state Attorney General rather than by private lawsuits.
The US safety and performance standard for access control system units — the certification buyers look for on controllers, readers and power supplies.
The North American adoption of the international IEC 60839 series for alarm and electronic security systems, including access control, aligning US practice with global standards.