July 29, 2026

Face and palm payments arrive commercially before most markets even pilot them

A woman makes a contactless payment at a stylish Berlin café, emphasizing technology and modern retail.

New Zealand jumps to the front of the biometric queue

Eftpos New Zealand has launched biometric-capable payment terminals built on Verifone’s Victa platform, allowing customers to pay by facial recognition or palm vein hand scan, with New Zealand among the first markets in the world to receive them commercially this month. The single terminal can handle age verification, digital identity confirmation and payment in one interaction, with no card required.

The commercial logic is easy to read. Card spending is flattening: electronic retail card spending rose just 1.3% year-on-year in June 2026, down from 3.3% the month before, with month-on-month spending actually falling 1.4%. A maturing payments market goes looking for the next efficiency lever, and shaving seconds off high-throughput checkouts in liquor stores and hospitality venues is exactly that. Verifone says it stores no images, only encrypted biometric data, and the same technology is already being trialled at Starbucks overseas.

This is not a bolt from the blue. Back in 2024, Stuff reported that Paymark, now part of the Eftpos NZ ecosystem, was experimenting with facial recognition at Spark’s 5G innovation hub. The pipeline has been building for years. It has now arrived at the counter.

Why this is not the Foodstuffs story

The first reference point most customers and journalists will reach for is Foodstuffs North Island’s 2024 facial recognition trial. That matters, but the two models are fundamentally different. Foodstuffs ran passive scanning of every shopper for loss prevention across 25 stores. The Eftpos NZ payment model is opt-in: customers actively enrol their biometric data to use the feature.

That distinction is the whole ballgame under the Privacy Act 2020, which is built on consent. Opt-in enrolment is far more defensible than scanning everyone who walks through the door. But the Foodstuffs experience set the public and regulatory temperature. Its trial prevented an estimated 100 serious harm events and cut serious harm by around 16% in trial stores, yet it also produced nine misidentifications, two wrongly asked to leave, and a Rotorua woman pursuing a discrimination case at the Human Rights Review Tribunal. Foodstuffs’ lawyer said in December 2024 that all nine errors were human, not software. The nuance rarely survives the headline.

The regulator is already watching

The Privacy Commissioner has not been passive on retail biometrics. In February 2024, Commissioner Michael Webster said he would use inquiry powers to monitor the Foodstuffs trial, noting that New Zealanders “deserve to shop for their milk and bread without having their faces scanned unless it’s really justified.” He flagged that global evaluations show false matches are more likely for people of colour, particularly women, and that software trained overseas is not calibrated for New Zealand’s population, raising specific risk for Māori, Pasifika, Indian and Asian customers.

In June 2025, the office issued updated guidance for retailers on deploying facial recognition. More significantly, it is developing a dedicated Biometrics Processing Privacy Code, having received 250 public submissions expressing concerns about biometric use. The signal is clear: the existing Privacy Act framework applies, but the regulator considers it insufficient on its own. Merchants adopting now operate under today’s rules with the near-certainty that more specific obligations are coming. Early adopters may need to retrofit compliance.

Who actually carries the risk

Here is the part boardrooms need to internalise. Under the Privacy Act 2020, the merchant collecting the biometric data is the responsible agency. Verifone and Eftpos NZ are processors. If a customer is misidentified, if data is breached, or if a complaint lands with the Privacy Commissioner, the merchant is the first point of accountability, not the terminal vendor.

The encrypted-template model helps. A breach of encrypted biometric data is less catastrophic than a leaked image database. But merchants still need clear answers on what is held, where, by whom, and under what retention and deletion policies before they switch it on. Consumer research from the University of Auckland in 2024 found adoption hinges on trust in the brand offering the system, with smaller, less-known businesses facing the steepest hurdle and privacy fears a genuine barrier. The researchers recommended explanatory signage, in-store support and clear communication.

The opportunity is real: faster queues, cleaner age verification, a genuine point of difference. But this is a technology decision that cannot be separated from a compliance decision. The merchants who win with biometric payments will be the ones who treat consent, transparency and data governance as the product, not the paperwork. Switching the terminal on is the easy part. Owning what happens next is the job.

Sources

Community

Join the discussion

Add useful context, ask a good question, or challenge an idea — keep it specific and respectful.

Create a commenter account

Enter the name you want shown publicly and your email. We will email you a password-set link; you cannot comment until you use it.

Your email is used for sign-in and account security. It is not published with comments.

Subscribe for weekly news

Subscribe For Weekly News

* indicates required