Under GDPR, how must FIDO authenticators handle biometric data collected during registration?
-
A
Store it indefinitely for audit purposes
-
B
Treat it as special category data requiring explicit consent
-
C
Share it with relying parties for identity verification
-
D
Encrypt it using FIDO-proprietary algorithms only