Samsung · Samsung Privacy Policy · View original document ↗

On-Device Biometric Data and Face-Clustering

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Samsung changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Samsung recorded 7 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Samsung Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that Samsung's services may automatically generate biometric data including face-clustering data that groups images of the same face across photos stored on the device, and that this data remains on-device and is not accessed, transferred to, or shared by Samsung. Deletion of this data is the user's responsibility through device settings, factory reset, or photo deletion.

This analysis describes what Samsung's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The automatic generation of face-clustering data from stored photos may implicate state biometric privacy laws such as the Illinois Biometric Information Privacy Act (BIPA), which imposes specific notice, consent, and retention requirements for biometric identifiers generated from facial geometry. The policy's assertion that Samsung does not access this data limits Samsung's ability to fulfill deletion requests on behalf of users.

Interpretive note: Whether automatic on-device generation of face-clustering data constitutes biometric data collection under BIPA or analogous statutes is a question subject to ongoing litigation and regulatory interpretation; the policy's assertion that Samsung does not access the data does not resolve the notice and consent question under all applicable state frameworks.

Recent Activity

This document changed recently

Medium Jul 22, 2026

The updated policy expands Samsung's data collection authority to include device registration, verification for repairs, and configuration of device settings. The terms now explicitly state that Samsung may collect card and transaction information if you apply for a Samsung-branded payment card. Samsung clarified that it will only send personalized marketing when you have provided consent, where required by law. The policy removed its previous statement that defective devices are wiped of personal information before analysis; the updated terms now state Samsung will analyze returned defective devices without that explicit pre-analysis data deletion commitment. For US residents, the policy now discloses rights to opt out of sale of personal information, sharing for cross-context behavioral advertising, targeted advertising processing, sensitive data collection or processing, and to request lists of third parties receiving your information.

View change record →

Consumer impact (what this means for users)

The policy discloses that Samsung services may automatically generate face-clustering biometric data on-device without explicit user initiation, and that this data persists unless the user clears the device cache, performs a factory reset, or deletes the relevant photos. Because Samsung states it does not access this data, users must manage its deletion directly through device-level actions.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    To remove face-clustering biometric data, clear the cache in your system settings, reset your device to factory settings, or delete the relevant photos. To remove registered biometric data or Bixby Voice wake-up command, go to the applicable settings on your device.

Cross-platform context

See how other platforms handle On-Device Biometric Data and Face-Clustering and similar clauses.

Compare across platforms →

Monitoring

Samsung has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Samsung also may generate certain biometric data automatically when certain Services are used (e.g., Samsung's face-clustering technology may group together images of the same face from different photographs stored on your device ("Face-Clustering Data")). This biometric data remains on your device and is not transferred to or accessed or obtained by Samsung. Samsung does not share this biometric data with third parties. Face-Clustering Data will remain on your device unless you clear the cache in your system settings, reset your device to its factory setting, or delete the relevant photos from your device. You can delete your registered biometric data or your Bixby Voice wake-up command from your device at any time in the applicable settings. Because Samsung does not have access to this data, Samsung cannot delete it for you.

Excerpt from Samsung's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision implicates the Illinois Biometric Information Privacy Act (BIPA), which requires informed written consent before collecting or generating biometric identifiers including facial geometry data, and imposes specific retention and destruction schedules. Washington State's My Health MY Data Act and other state biometric privacy statutes may also apply. The FTC exercises enforcement authority over deceptive or unfair biometric data practices at the federal level. Whether automated on-device face-clustering constitutes collection under BIPA or analogous state statutes is a question that has been actively litigated and may not be resolved by the policy's assertion that Samsung does not access the data. 2. GOVERNANCE EXPOSURE: High. The automatic generation of facial biometric data, even when retained on-device, may trigger notice and consent obligations under BIPA and comparable state laws. The absence of an opt-in consent mechanism described in the policy for face-clustering generation creates exposure in jurisdictions with strict biometric privacy frameworks. The policy's position that Samsung cannot fulfill deletion requests because it lacks access to the data may be viewed as a limitation on user rights where applicable law requires the data controller to facilitate deletion. 3. JURISDICTION FLAGS: Illinois creates the highest exposure due to BIPA's private right of action and liquidated damages provisions. Texas and Washington have state biometric privacy laws that may also be implicated. California's CCPA and CPRA include biometric information as a category of sensitive personal information with opt-out rights. Enterprise deployments of Samsung devices in Illinois or other biometric-sensitive jurisdictions warrant additional review. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations deploying Samsung devices in Illinois or other jurisdictions with biometric privacy laws should evaluate whether the automatic generation of face-clustering data on employee or customer devices creates organizational liability exposure. The policy's statement that Samsung cannot delete this data on behalf of users may create tension with data subject deletion request workflows in enterprise environments. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate whether the disclosure of automatic face-clustering data generation satisfies notice and consent requirements under BIPA and analogous statutes. Data mapping should reflect on-device biometric data as a distinct category not subject to Samsung's deletion capability. User-facing documentation and device setup flows should be audited to confirm adequate disclosure of face-clustering data generation prior to use of the relevant Samsung services.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • State AG
    State attorneys general in Illinois and other states with biometric privacy laws (including Texas and Washington) enforce statutes that may govern the automatic generation of facial biometric data on consumer devices.
    File a complaint →
  • FTC
    The FTC exercises federal enforcement authority over unfair or deceptive practices in biometric data collection and disclosure, including practices that generate biometric data without adequate consumer notice.
    File a complaint →

Provision details

Document information
Document
Samsung Privacy Policy
Entity
Samsung
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015902
Document ID
CA-D-00571
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
e01714c2c34eae93eda17ae527749f29c680226685f02265732d48266b771396
Analysis generated
July 9, 2026 09:05 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Samsung
Document: Samsung Privacy Policy
Record ID: CA-P-015902
Captured: 2026-07-09 09:05:37 UTC
SHA-256: e01714c2c34eae93…
URL: https://conductatlas.com/platform/samsung/samsung-privacy-policy/provision/CA-P-015902/on-device-biometric-data-and-face-clustering/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Samsung's On-Device Biometric Data and Face-Clustering clause do?

The automatic generation of face-clustering data from stored photos may implicate state biometric privacy laws such as the Illinois Biometric Information Privacy Act (BIPA), which imposes specific notice, consent, and retention requirements for biometric identifiers generated from facial geometry. The policy's assertion that Samsung does not access this data limits Samsung's ability to fulfill deletion requests on behalf of users.

How does this clause affect you?

The policy discloses that Samsung services may automatically generate face-clustering biometric data on-device without explicit user initiation, and that this data persists unless the user clears the device cache, performs a factory reset, or deletes the relevant photos. Because Samsung states it does not access this data, users must manage its deletion directly through device-level actions.

Is ConductAtlas affiliated with Samsung?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Samsung.