Biometric law reference
Biometric Privacy Laws Covered by State
Dedicated biometric laws create the highest risk because they regulate biometric identifiers directly. Comprehensive state privacy laws usually reach biometric data through sensitive-data consent, privacy-notice, assessment, and retention duties.
| State | Law | Consent rule | Retention rule | Enforcement |
|---|---|---|---|---|
| Illinois | BIPA (740 ILCS 14) | Informed written release before collection | Public retention/destruction schedule; destroy when purpose is satisfied or within 3 years of last interaction | Private lawsuits; $1,000 negligent / $5,000 intentional or reckless statutory damages, with 2024 single-recovery limits for repeated same-method scans |
| Texas | CUBI (Bus. & Com. Code Chapter 503) | Inform and obtain consent before commercial capture | Destroy within a reasonable time, no later than one year after the purpose expires | Texas Attorney General; up to $25,000 per violation |
| Washington | RCW 19.375 | Notice and consent before enrollment in a database for commercial purposes | Provide a mechanism to prevent retention beyond the stated commercial purpose | Washington Consumer Protection Act enforcement |
Comprehensive State Laws That Treat Biometrics as Sensitive Data
These states generally require opt-in consent before processing biometric data for identification, plus privacy-notice and data-protection-assessment controls where applicable.
BIPA 2024 amendment
Illinois Public Act 103-0769 limits repeated collection or disclosure of the same biometric identifier from the same person using the same method to one recovery, but the notice, written-release, retention-policy, and security requirements remain.
Read Public Act 103-0769Biometric Privacy FAQ
What are biometric privacy laws?
Biometric privacy laws regulate the collection, storage, use, and sharing of biometric data such as fingerprints, facial geometry, voiceprints, retina scans, and other unique biological identifiers. Dedicated biometric laws typically require notice, consent, retention limits, and safeguards. Comprehensive state privacy laws often classify biometric data as sensitive data that requires opt-in consent.
Which states have biometric privacy laws?
Three states have dedicated biometric privacy laws: Illinois (BIPA), Texas (CUBI), and Washington (RCW 19.375). Many comprehensive state privacy laws also regulate biometric data as sensitive data, including California, Colorado, Connecticut, Virginia, Montana, Oregon, Delaware, New Jersey, Nebraska, Maryland, Minnesota, New Hampshire, Indiana, Kentucky, Rhode Island, Tennessee, and Iowa.
What is Illinois BIPA and why is it important?
The Illinois Biometric Information Privacy Act (BIPA) is the strongest biometric privacy law in the United States because it includes a private right of action, meaning individuals can sue companies directly. Statutory damages are $1,000 per negligent violation and $5,000 per intentional or reckless violation. A 2024 amendment limits repeated collection or disclosure of the same biometric identifier from the same person using the same method to one recovery, but it does not remove the notice, written-consent, retention-policy, or security obligations. BIPA has produced major settlements including Facebook/Meta ($650 million) and Google ($100 million).
Do I need written consent to collect fingerprints?
In Illinois, yes — BIPA requires informed written consent before collecting any biometric identifiers, including fingerprints. In Texas and Washington, you must obtain consent (though not necessarily written) before capturing biometric identifiers. In states with comprehensive privacy laws like California, Colorado, and Virginia, biometric data is classified as sensitive data requiring opt-in consent. If you operate across multiple states, implementing written consent for fingerprint collection is a best practice that satisfies the strictest requirements.
What are the penalties for violating biometric privacy laws?
Penalties vary by state. Illinois BIPA allows $1,000-$5,000 per violation with a private right of action, subject to the 2024 same-person/same-method single-recovery amendment. Texas CUBI penalties are up to $25,000 per violation enforced by the Attorney General. Washington enforces its biometric law through the Consumer Protection Act. Most comprehensive privacy laws impose $7,500-$20,000 per violation through Attorney General enforcement.
Sources checked May 31, 2026: Illinois Biometric Information Privacy Act (740 ILCS 14), Illinois Public Act 103-0769, Texas Business & Commerce Code Chapter 503, and Washington RCW 19.375. The Facebook/Meta settlement amount is cross-checked against the federal In re Facebook Biometric Information Privacy Litigationsettlement record.