PROMETRIC’S* BIOMETRIC IDENTITY MANAGEMENT SYSTEM PRIVACY NOTICE FOR CANDIDATES The Biometric Identity Management Service (BIMS) is designed to protect test candidate privacy and improve the security and integrity of the testing process. While the Internal Revenue Service is the responsible organization for this test, the use of the BIMS for candidate authentication and identification is performed by Prometric. This Privacy Notice describes the privacy and security practices that have been established by Prometic for the Biometric Information Management Service. References to “you” or “your” in this notice refers to a test candidate or applicant. How does BIMS work? To use the BIMS, you must place your finger on the scanner. The BIMS equipment will create a digitized representation of your fingerprint. This representation is called a template. This template is an algorithm that represents your fingerprint. The system does not actually store the fingerprint image but rather stores an encrypted algorithm that represents your fingerprint. This template will be stored with other personal information you provide to Prometric, your identification document picture, and with information from your identification documents, allowing Prometric to identify you accurately during the testing process. As you move around the test center, you will be able to use your finger to authenticate yourself at the scanners located throughout the test center, avoiding the need to provide additional identification to supervisory personnel. What information is collected in the Biometric Identity Management Service? The BIMS contains a digitized representation of your fingerprint, along with your name, address, telephone number (if you provided one), date of birth or age, identification document number, and a scanned copy of your identification document (such as your driver’s license), which will include your digitized image. How is the information in the BIMS used? Personal information in the BIMS is used by Prometric to: (1) administer tests and verify your identity on an ongoing basis as you participate in this test by positively identifying you as you move in and out of the test lab during the examination, (2) protect your privacy by enabling you to move around the test center without the requirement that identification documents be presented regularly, (3) identify and prevent testing fraud and maintain the integrity of the testing process by detecting and preventing test taking by unauthorized candidates, (4) improve security of test centers by detecting and preventing unauthorized access of candidates to secure areas, and (5) if needed, for legal compliance. For example, when you are taking your IRS exam, Prometric would be able to determine if another individual returned after a break and pretended to be you in order to access the test content. How long is my personal information retained by the BIMS? The fingerprint template is permanently erased from the BIMS database within forty-eight (48) hours after your test is completed. The information from your identification document, the digital image, and digitized representation of your identification document is retained for fraud investigation or other legal purposes for a reasonable period of time required for potential legal or fraud investigations. That period will not exceed five (5) years. This information is not transferred to the IRS. When is the information in the BIMS disclosed to third parties? Please keep in mind that the fingerprint template is deleted in its entirety within 48 hours after completion of your test. Prometric will not disclose the demographic information to any third party except as required by law or as necessary to complete a fraud investigation directly related to a particular test Candidate. What choices do I have regarding the BIMS? All Candidates are required to provide identification documents and individuals who fail to provide valid identification will be refused admission to test. Candidates are also required to provide a fingerprint as that provides a higher level of security during the testing experience, is more efficient during check in/check out during breaks, and requires less presentation of identification documents and exposure of that information. Because the fingerprint template is deleted within 48 hours of the completion of the test, there is no issue with risks of long term retention. A Candidate will be refused an examination if he or she does not wish to provide a fingerprint. Can I access my information in the BIMS? Upon request and confirmation of your identity, Prometric will determine if you have a record in the BIMS. If so, Prometric will provide you with a copy of the personal information maintained in the system. Note that the fingerprint template is not retained and is deleted from the system within 48 hours of the completion of a test by you. The only information retained is that obtained from your identification document. How is the information in the BIMS secured? Prometric has implemented appropriate technical, physical and administrative safeguards to help protect your personal information against unauthorized access or loss. Prometric’s workers who access the information are trained on these procedures and bound by appropriate confidentiality obligations. Who do I contact if I have a question or compliant? If you have questions about BIMS and how it works you can contact: Anthony R. Scicchitano Data Protection Officer Prometric 1515 S Clinton St Baltimore, MD 21224 USA Telephone: 1-443-455-8493 E-Mail: anthony.scicchitano@prometric.com