The policy states that smart lock biometric data including facial, palm print, and fingerprint information is stored locally on the device and not uploaded to the cloud, and places responsibility on the user to ensure explicit consent has been obtained from individuals whose biometric data is collected.
This analysis describes what Eufy's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision delegates to users the legal obligation to obtain explicit consent from third parties whose biometric data is enrolled in smart lock systems, which may be insufficient to satisfy BIPA, GDPR, and analogous statutory requirements that impose direct obligations on data collectors rather than permitting delegation to end users.
Interpretive note: Whether user-delegated consent obligations satisfy Anker's direct statutory obligations under BIPA and analogous statutes requires jurisdiction-specific legal analysis and may not be resolved by the policy's current language.
Under this provision, users who enroll biometric data for smart lock access, including data belonging to family members or other authorized individuals, bear the stated responsibility for ensuring explicit consent has been obtained from those individuals, and the policy asserts that this data will remain on-device unless the user provides explicit consent for cloud upload.
Cross-platform context
See how other platforms handle Smart Lock Biometric Data Local Storage and Consent Obligation and similar clauses.
Compare across platforms →"Password, Facial, Palm Print, and Fingerprint Information: When using our smart locks, you may set a password to lock or unlock the device. Some models also support unlocking via facial recognition, palm vein or fingerprint recognition. All such information—including passwords, facial, palm print, and fingerprint data—is securely stored locally on your device and not uploaded to the cloud. These biometric data may belong to you or to individuals authorized by you. Please ensure that the collection of such data has been explicitly authorized. Unless you provide explicit consent, this information will remain stored on the device and will not be shared with any third party.Excerpt from Eufy's Privacy Policy
(1) REGULATORY LANDSCAPE: This provision engages BIPA for facial, fingerprint, and palm print data, CPRA sensitive personal information provisions, GDPR Article 9 explicit consent requirements, and analogous state biometric privacy statutes.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision delegates to users the legal obligation to obtain explicit consent from third parties whose biometric data is enrolled in smart lock systems, which may be insufficient to satisfy BIPA, GDPR, and analogous statutory requirements that impose direct obligations on data collectors rather than permitting delegation to end users.
Under this provision, users who enroll biometric data for smart lock access, including data belonging to family members or other authorized individuals, bear the stated responsibility for ensuring explicit consent has been obtained from those individuals, and the policy asserts that this data will remain on-device unless the user provides explicit consent for cloud upload.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Eufy.