It would be quite straightforward to make your biometric identity a public private key kind of setup. Companies have access to your public key and you yourself carry your private key as some sort of physical identification that is unlocked with a two-factor method. This way any physical biometric thing is done on a device you own that could be mandated to be open technology completely auditable to be secure and all you do is use your physical doodad to interface with their thing to authenticate that yes you are the private key holder for this given public key.
It would be much more secure than identification cards that we have now such as driver's licenses or passports. It would also be far more secure than the biometric style authentication they want to do now with them essentially owning a copy of your biometric data. But there is no profitability in true security and privacy for the citizens.