Biometric data is special category personal information under POPIA. That means consent must be explicit, revocable, and gathered before the first capture. Most programmes get one of those wrong.
The defaults we ship: templates encrypted at rest with AES-256, never used in denominators for KPI calculations, revocable via a one-message request, and never sent to a third party.
The consent script is in the participant's language, gathered before any capture, and stored with a timestamp and a signed hash so it can be produced on demand for a data-subject request.
If your current provider can't produce a POPIA-safe biometric policy on request, that's not a compliance issue — that's a business risk.