Loading...

Biometric law reference

Biometric Privacy Laws Covered by State

Dedicated biometric laws create the highest risk because they regulate biometric identifiers directly. Comprehensive state privacy laws usually reach biometric data through sensitive-data consent, privacy-notice, assessment, and retention duties.

StateLawConsent ruleRetention ruleEnforcement
IllinoisBIPA (740 ILCS 14)Informed written release before collectionPublic retention/destruction schedule; destroy when purpose is satisfied or within 3 years of last interactionPrivate lawsuits; $1,000 negligent / $5,000 intentional or reckless statutory damages, with 2024 single-recovery limits for repeated same-method scans
TexasCUBI (Bus. & Com. Code Chapter 503)Inform and obtain consent before commercial captureDestroy within a reasonable time, no later than one year after the purpose expiresTexas Attorney General; up to $25,000 per violation
WashingtonRCW 19.375Notice and consent before enrollment in a database for commercial purposesProvide a mechanism to prevent retention beyond the stated commercial purposeWashington Consumer Protection Act enforcement

Comprehensive State Laws That Treat Biometrics as Sensitive Data

These states generally require opt-in consent before processing biometric data for identification, plus privacy-notice and data-protection-assessment controls where applicable.

CaliforniaColoradoConnecticutVirginiaMontanaOregonDelawareNew JerseyNebraskaMarylandMinnesotaNew HampshireIndianaKentuckyRhode IslandTennesseeIowa

BIPA 2024 amendment

Illinois Public Act 103-0769 limits repeated collection or disclosure of the same biometric identifier from the same person using the same method to one recovery, but the notice, written-release, retention-policy, and security requirements remain.

Read Public Act 103-0769

Biometric Privacy FAQ

What are biometric privacy laws?

Biometric privacy laws regulate the collection, storage, use, and sharing of biometric data such as fingerprints, facial geometry, voiceprints, retina scans, and other unique biological identifiers. Dedicated biometric laws typically require notice, consent, retention limits, and safeguards. Comprehensive state privacy laws often classify biometric data as sensitive data that requires opt-in consent.

Which states have biometric privacy laws?

Three states have dedicated biometric privacy laws: Illinois (BIPA), Texas (CUBI), and Washington (RCW 19.375). Many comprehensive state privacy laws also regulate biometric data as sensitive data, including California, Colorado, Connecticut, Virginia, Montana, Oregon, Delaware, New Jersey, Nebraska, Maryland, Minnesota, New Hampshire, Indiana, Kentucky, Rhode Island, Tennessee, and Iowa.

What is Illinois BIPA and why is it important?

The Illinois Biometric Information Privacy Act (BIPA) is the strongest biometric privacy law in the United States because it includes a private right of action, meaning individuals can sue companies directly. Statutory damages are $1,000 per negligent violation and $5,000 per intentional or reckless violation. A 2024 amendment limits repeated collection or disclosure of the same biometric identifier from the same person using the same method to one recovery, but it does not remove the notice, written-consent, retention-policy, or security obligations. BIPA has produced major settlements including Facebook/Meta ($650 million) and Google ($100 million).

Do I need written consent to collect fingerprints?

In Illinois, yes — BIPA requires informed written consent before collecting any biometric identifiers, including fingerprints. In Texas and Washington, you must obtain consent (though not necessarily written) before capturing biometric identifiers. In states with comprehensive privacy laws like California, Colorado, and Virginia, biometric data is classified as sensitive data requiring opt-in consent. If you operate across multiple states, implementing written consent for fingerprint collection is a best practice that satisfies the strictest requirements.

What are the penalties for violating biometric privacy laws?

Penalties vary by state. Illinois BIPA allows $1,000-$5,000 per violation with a private right of action, subject to the 2024 same-person/same-method single-recovery amendment. Texas CUBI penalties are up to $25,000 per violation enforced by the Attorney General. Washington enforces its biometric law through the Consumer Protection Act. Most comprehensive privacy laws impose $7,500-$20,000 per violation through Attorney General enforcement.

Sources checked May 31, 2026: Illinois Biometric Information Privacy Act (740 ILCS 14), Illinois Public Act 103-0769, Texas Business & Commerce Code Chapter 503, and Washington RCW 19.375. The Facebook/Meta settlement amount is cross-checked against the federal In re Facebook Biometric Information Privacy Litigationsettlement record.