Fingerprint data never leaves the card – it is stored offline and encrypted. The card only stores metadata about the fingerprint, not the full image.
When the card attempts a biometric match, the sensor powers up and captures a fingerprint image. This image is analysed to see how it compares against the stored fingerprint data. The sensor also detects spoof (fake) fingers, and rejects fingerprint spoofing even if the fingerprint match is successful.
A counter increments on each failed biometric match, to prevent attacks. If the counter exceeds the configured limit, the card enters a blocked state. How the block is lifted depends on the card. See: Forgotten PIN or too many wrong attempts.
On a biometric match that also passes the spoof check, the result is encrypted and delivered to the applications on the card to allow access.
See: Security and privacy architecture at a glance, Tips for a successful enrolment and Re-enrol or delete a fingerprint.