Security & privacy

Unclear results do not lead to release.

EOAS separates verification, the personnel decision and technical release. Errors or missing confirmations are handled safely.

Transparent before the check

No automatic release based on biometrics alone

A biometric match does not directly release a device. Document capture, identity match, OASIS query, StaffPad confirmation, device selection and a confirmed release signal must all be complete and unambiguous.

Local processing and controlled transmission

Where designed, capture and biometric comparison are performed locally. External transmission occurs only when required for a configured function, such as the OASIS query.

Traceability without unnecessary collection

Security-relevant events may be logged. General system logs should not contain clear-text identity data, document images or biometric features unless this is demonstrably necessary.

Access-controlled roles

Operation

Sees only the information and functions required to run the current check.

Confirmation

May confirm or reject the current process on StaffPad.

Service

Configuration, maintenance and diagnostics require separate protection.

Data categories

Only data required for the intended process is processed.

Identity data

To clearly match the person to the process.

  • First name and surname
  • Date of birth
  • Required document details

Biometric data

For the technical comparison of ID and person.

  • Document photograph
  • Live facial image
  • Biometric comparison features

Process data

For traceability of the verification and release process.

  • Identity and OASIS results
  • Technical status data
  • Personnel confirmation and device assignment

Operator responsibilities

  • Legal bases and privacy notices
  • Assessment of biometric processing
  • Retention and deletion periods
  • Access rights
  • OASIS access and site identifier
  • Personnel training
  • Handling data-subject requests
  • Documentation of technical and organisational measures

Protecting stored data

  • Encrypted storage
  • Restricted user and administrator permissions
  • Protected maintenance access
  • Defined deletion procedures
  • Logging of security-relevant events
  • Regular software updates
  • Protection against unauthorised configuration changes

The measures actually used must be specified and documented for the deployed configuration.

Retention and deletion

For every data category, define the purpose, legal basis, storage location, retention period, deletion process, access rights and statutory retention obligations.

Before production use, the site-specific privacy and operating concept must undergo professional and legal review.

Optional registration

With active registration, the ID does not need to be scanned again. A current OASIS check and staff confirmation remain required for every process.

Consent

Voluntary registration at the player's request.

Store

Biometric reference stored locally in the EOAS system; no facial photo.

Use

Recognition plus a current OASIS check and staff confirmation on every process.

End

Automatically after three months, or at any time on request via staff.

After expiry or deletion, the ID must be scanned again; a new registration is then possible. Access is limited to EOAS system administration.