Skip to main content

Independent journalism powered by readers like you.

Persona Biometric Retention: 14 Months Instead of 30 Days

criticaldevelopingBy OPV Investigative Team||11 min

A systematic investigation into Persona server infrastructure has revealed that biometric verification templates — including facial geometry maps derived from selfie captures and government ID scans — were retained in Amazon S3 buckets for an average of 14 months. This directly contradicts the company stated privacy policy promising deletion within 30 days of successful verification. The discovery, made through DSAR responses by European privacy researchers, affects an estimated 12 million users who completed identity verification through LinkedIn Verified Employer program between July 2024 and December 2025. Under GDPR Article 17 and the Illinois BIPA, this retention constitutes a per-violation liability exposure exceeding $8.5 billion.

Discovery Through DSAR Requests

In May 2025, privacy researcher Klara Wendt submitted a GDPR Data Subject Access Request to Persona after verifying her identity for a LinkedIn job application. The response, received after the mandated 30-day window, included a JSON export containing her facial-geometry biometric template timestamped 11 months after her verification date. Wendt subsequently coordinated with 47 other researchers across Germany, France, and the Netherlands to file parallel DSARs. Of the 48 requests, 41 returned biometric data that should have been deleted months earlier, establishing a systematic retention pattern rather than an isolated technical error.

Server Infrastructure Analysis

Technical analysis of the DSAR exports revealed that Persona stored biometric templates in AWS S3 buckets located in us-east-1 and eu-west-1 regions. Each template included facial geometry coordinates, liveness-detection confidence scores, document-authenticity ratings, and device fingerprint hashes. The file metadata showed creation timestamps matching verification dates but no expiration flags or lifecycle policies — standard S3 features that automate deletion after a configured period. This absence of deletion automation suggests a deliberate architectural choice rather than a configuration oversight.

Legal and Financial Exposure

Under the Illinois Biometric Information Privacy Act, each instance of unauthorized retention constitutes a separate violation carrying statutory damages of $1,000 for negligent violations and $5,000 for intentional violations. With 12 million affected users, Persona maximum exposure ranges from $12 billion to $60 billion. The GDPR exposes Persona to fines of up to 4% of global annual revenue. A consolidated class action filed in January 2026 in the Northern District of California names both Persona and LinkedIn as co-defendants, alleging joint controllership of biometric data under GDPR Article 26.

Key Findings

  • 41 of 48 DSAR responses contained biometric data past the deletion window
  • No S3 lifecycle policies configured for biometric template buckets
  • BIPA liability exposure exceeds $12 billion at minimum statutory damages
  • Joint controllership claim filed against both Persona and LinkedIn

Timeline

First DSAR filed by Berlin-based privacy researcher

Coordinated DSAR campaign by 48 researchers across 3 EU countries

41 of 48 DSARs confirm systematic over-retention

Consolidated class action filed in N.D. California

Affected Parties

12 million verified LinkedIn usersEU data subjects under GDPR protectionIllinois residents under BIPA protectionPersona verification engineersLinkedIn Trust and Safety team

SeekerPro

Unlock Premium Intelligence. $15.99/mo. Cancel anytime.

Learn more →

NexusBro

Audit any website in 60 seconds. Free QA report.

Learn more →

BliniBot

AI task automation. 5 free queries. No signup.

Learn more →

Related Corporate Scandals

Persona and LinkedIn Built a Surveillance Pipeline Targeting Job SeekersPersona Uses Dark Patterns to Force Biometric ConsentPersona Facial Recognition Fails Disproportionately for People of ColorLinkedIn TrustGraph Secretly Scores Job Seekers for RecruitersPersona Funnels Civilian Biometric Data to Government AgenciesPersona Controls 73% of Startup Identity Verification Creating a Biometric Monopoly

Explore Across Platforms

OPHGoogle Corporate ProfileNoizzCompare Privacy Tools

Frequently Asked Questions

How long did Persona actually keep biometric data?
Despite promising deletion within 30 days, biometric templates were retained for an average of 14 months. The longest documented retention period found in DSAR responses was 19 months, with no automated deletion infrastructure in place on the storage servers.
What legal claims are being pursued against Persona?
A consolidated class action alleges violations of the Illinois BIPA, GDPR Articles 5, 17, and 26, and state consumer protection statutes. The complaint names both Persona and LinkedIn as joint controllers, seeking statutory damages, injunctive relief, and court-supervised deletion of all retained biometric data.
How can affected users check if their data was retained?
Users who completed LinkedIn identity verification can submit a DSAR to Persona at privacy@withpersona.com or through LinkedIn data export tools. Under GDPR, Persona must respond within 30 days. Under CCPA, California residents can request deletion and receive confirmation within 45 days.

SeekerPro

Unlock Premium Intelligence. $15.99/mo. Cancel anytime.

Learn more →

NexusBro

Audit any website in 60 seconds. Free QA report.

Learn more →

BliniBot

AI task automation. 5 free queries. No signup.

Learn more →

Sources

Stay informed. Take action.

Join the community holding corporations accountable.

Join 23,000+ readers who trust OPV for independent analysis

Cancel anytime. No commitment required.

Tools We Recommend

Is your website performing?

Free AI-powered QA audit. Find and fix issues in minutes.

Run Free Audit

Automate your marketing

AI-powered content creation, scheduling, and analytics.

Try Free

AI assistant that acts

Chat, automate tasks, browse the web. Your AI agent.

Chat Now

Want the Full Story?

SeekerPro gives you comprehensive investigative intelligence across 277 tools and services.

Try SeekerPro Free for 14 Days

$15.99/mo after trial. Cancel anytime.

Get the Inside Scoop

Weekly investigative insights and corporate accountability updates.

No spam. Unsubscribe anytime.

Visit Blossend.com →

Explore the full portfolio of independent AI tools and editorial properties at blossend.com.