Biometric Data Laws: Consent, Retention, and Your Right to Sue

Biometric data laws in the United States are a state-by-state patchwork rather than a single federal rulebook. Illinois, Texas, and Washington have dedicated biometric privacy statutes; California, Colorado, Connecticut, and Virginia fold biometric protections into broader consumer privacy laws; and the Federal Trade Commission covers some of the gap under its authority over unfair and deceptive business practices. The practical result is that your rights over your fingerprints, face scan, or voiceprint depend heavily on where you live and which company is holding the data.

What Counts as Biometric Data Under These Laws

The legal definitions matter because they decide whether a given scan triggers any protection at all. Illinois defines biometric identifiers narrowly: scans of hand or face geometry, retina or iris scans, fingerprints, and voiceprints. Texas mirrors that list almost exactly. California takes a much broader approach, covering any physiological, biological, or behavioral characteristic that can establish identity, and sweeping in sleep, health, and exercise data when it contains identifying information.

Most statutes deliberately exclude physical photographs, handwriting samples, written signatures, tattoo descriptions, and basic physical details like height and hair color. Data collected in a healthcare setting and governed by federal health privacy rules is also typically excluded. The legal focus stays on the digital templates that could be used to impersonate you, not on traditional records.

Why Biometric Data Gets Stricter Rules

The core problem is permanence. A stolen credit card number can be reissued and a leaked password can be changed, but you cannot change your fingerprints, your retinal pattern, or the geometry of your face. Once biometric data is compromised, the identifier is burned for life. That reality is why legislators treat biometric information as more sensitive than most other personal data, and why storage and destruction rules tend to be tighter than those for financial records.

Which State’s Law Applies to You

There is no comprehensive federal biometric privacy statute. What you get instead is a handful of state laws with very different enforcement mechanisms and coverage. Figuring out which framework applies is the starting point.

Illinois

Illinois enacted the Biometric Information Privacy Act in 2008, and it remains the strongest biometric privacy law in the country. Its defining feature is a private right of action: any person whose biometric data is mishandled can sue the company directly, without waiting for a government agency to act. That provision has driven thousands of class action lawsuits and forced major settlements from employers and tech companies.

Texas

The Texas Capture or Use of Biometric Identifier Act dates from around the same period, but only the state attorney general can bring enforcement actions. Individuals cannot sue on their own. The attorney general can seek civil penalties of up to $25,000 per violation, and companies must destroy biometric data within a year after the purpose for collecting it expires.

Washington

Washington requires notice and consent before enrolling biometric identifiers in a database for commercial purposes, with a notable carve-out: companies collecting biometric data for security purposes do not need to follow the standard notice-and-consent process. General enforcement runs through the attorney general’s office under the state’s consumer protection act. Separately, Washington’s My Health My Data Act added a private right of action for biometric-related violations, making the state the second after Illinois to let individuals bring their own lawsuits over biometric data.

States With Broader Privacy Laws

California, Colorado, Connecticut, and Virginia address biometric data inside their general consumer privacy laws rather than through standalone statutes. These frameworks offer some protection but were not built specifically for the risks biometric identifiers create. About 22 states now explicitly include biometric data in their data breach notification laws, meaning companies must tell you if your biometric information is exposed in a security incident even where no other biometric-specific rules exist.

What Companies Must Do Before Collecting Your Data

Under Illinois law, a company must give written notice that it is collecting or storing your biometric identifier, explain the specific purpose and how long the data will be kept, and obtain your signed written release before any scanning begins. Collecting first and asking permission later is not allowed.

Texas similarly requires notice and consent before capture, though its statute does not specify that consent must be in writing. Washington requires some combination of notice, consent, or a mechanism letting you prevent later commercial use of your identifier, with the exact mix depending on the context.

Every organization holding biometric data under the Illinois model must also maintain a publicly available written policy setting a retention schedule and explaining when and how the data will be permanently destroyed. This is not an internal document. It has to be accessible to anyone whose data the company holds.

One thing these laws generally do not guarantee is a non-biometric alternative. If your employer installs fingerprint scanners for time tracking, most biometric statutes do not explicitly require the company to offer a PIN or badge swipe instead. Employers who refuse alternatives may still face exposure under federal employment discrimination law if workers object on religious grounds or if the biometric system could reveal medical conditions.

How Long Companies Can Keep the Data

The general principle across state laws is consistent: biometric data should not outlive the reason it was collected.

In Illinois, a company must destroy biometric identifiers either when the original purpose has been satisfied or within three years of your last interaction with the company, whichever comes first. If you leave a job in January 2026 and your former employer collected your fingerprint for time tracking, that data must be gone by January 2029 at the latest, and sooner if there is no ongoing reason to keep it. Texas is tighter: destruction must happen within a reasonable time, but no later than one year after the purpose for collection expires.

Destruction must be permanent. Archiving to a backup server or flagging a record as inactive does not satisfy these requirements. The methods used must render the identifiers unreadable and unrecoverable.

Stored biometric data must also be protected with at least the same care the company gives to other sensitive information. Under Illinois law, the standard must match or exceed how the company protects data like Social Security numbers or financial account information. In practice, that means encryption in storage and in transit, access controls that limit who can view raw biometric templates, and audit trails covering every access event.

Penalties and Your Right to Sue

Enforcement varies widely, and the differences shape whether these laws actually change corporate behavior.

Illinois stands alone in offering a robust private right of action. Any person whose biometric data is collected, stored, or used in violation of the law can sue for $1,000 in liquidated damages per negligent violation or $5,000 per intentional or reckless violation, plus attorney’s fees and injunctive relief. Those figures are statutory minimums; courts can award actual damages when they run higher. The private right of action has made Illinois the epicenter of biometric privacy litigation.

A significant change arrived in 2024 when the Illinois legislature amended the law to clarify that repeated collection of the same person’s biometric data by the same method counts as a single violation rather than a separate violation for each scan. Before the amendment, a worker who scanned a fingerprint twice a day for three years could theoretically claim thousands of individual violations. In April 2026, the Seventh Circuit Court of Appeals held that the amendment applies retroactively to pending cases, substantially reducing the financial exposure for companies defending older lawsuits.

Texas takes a different route: only the attorney general can enforce, with civil penalties of up to $25,000 per violation. Washington also limits general enforcement to the attorney general, though its My Health My Data Act creates a separate private right of action for biometric-related claims. Most states that address biometric data through broader privacy laws rely primarily on attorney general enforcement.

The FTC as a Federal Backstop

While no dedicated federal biometric statute exists, the Federal Trade Commission has stepped in under Section 5 of the FTC Act, which prohibits unfair or deceptive business practices. The FTC issued a formal policy statement making clear that it considers biometric data collection and use to fall within its enforcement authority.1Federal Trade Commission. Policy Statement of the Federal Trade Commission on Biometric Information and Section 5 of the Federal Trade Commission Act

Under the FTC’s framework, a company engages in deceptive practices when it makes false claims about the accuracy or reliability of its biometric technology, misrepresents how much biometric data it collects, or discloses some purposes for data use while hiding others. A practice is unfair when it causes substantial consumer harm that people cannot reasonably avoid, such as collecting biometric data without telling anyone or failing to test whether a facial recognition system produces higher error rates for certain demographic groups.

The FTC has identified several specific failures it considers potentially unfair: skipping a risk assessment before deploying biometric technology, not evaluating third-party vendors who handle biometric data, not training employees who interact with the systems, and not monitoring whether the technology works as intended over time.

Enforcement is not theoretical. The FTC banned Rite Aid from using facial recognition technology for security or surveillance purposes for five years after finding that the pharmacy chain deployed the technology in hundreds of stores without reasonable safeguards. The order required Rite Aid to implement comprehensive protections before using any automated biometric system in the future and to shut down existing systems it could not adequately control.2Federal Trade Commission. Rite Aid Corporation, FTC v.

If Your Biometric Data Is Breached

When biometric data is compromised, the consequences are more severe than in a typical data breach precisely because the identifiers cannot be changed. A company can issue you a new account number. Nobody can issue you new fingerprints.

About 22 states explicitly include biometric identifiers within the definition of personal information that triggers breach notification. If a company holding your biometric data suffers a breach in one of those states, it must notify you. Timelines vary: some states require notice within 30 days, others allow up to 60 days, and many use open-ended language like “without unreasonable delay.” A majority also require the breached entity to report to the state attorney general.

Your practical response is limited compared to other breach types. You cannot rotate a fingerprint the way you rotate a password. What you can do is monitor accounts that use biometric authentication, ask the breached company to permanently delete any remaining copies of your data, confirm it is following its legal destruction obligations, and consider switching sensitive accounts to a different authentication method. If you live in a state with a private right of action, a breach involving inadequate security may give you grounds for a lawsuit.

Biometrics at Work

The most common place Americans run into biometric collection is at work. Fingerprint and facial recognition time clocks have largely replaced traditional punch cards in industries ranging from manufacturing to healthcare. In states with biometric privacy laws, employers must follow the same notice-and-consent rules as any other private entity: written notice, disclosure of the purpose and retention period, and a signed release before the first scan, not buried in a handbook distributed after the hire date. Companies that skipped these steps have been defendants in some of the largest biometric privacy settlements on record.

Federal employment law can also apply on top of state biometric statutes. An employee who refuses fingerprint scanning on religious grounds may be entitled to a reasonable accommodation under Title VII, and biometric systems that could detect certain medical conditions may raise disability discrimination issues. These risks exist even in states with no biometric-specific privacy protections.

Two Areas Where These Laws Do Not Reach

DNA sits at the intersection of biometric privacy and genetic discrimination law. Several state statutes include DNA in their definition of biometric identifiers, and California’s law explicitly lists it alongside fingerprints and iris scans. Federally, the Genetic Information Nondiscrimination Act prohibits employers and health insurers from using genetic information, including genetic test results and family medical history, as a basis for employment or coverage decisions.3U.S. Equal Employment Opportunity Commission. Fact Sheet – Genetic Information Nondiscrimination Act That law does not regulate biometric collection broadly, but it creates a floor of protection for genetic data specifically.

The federal government’s most visible biometric program operates at airports and border crossings, where Customs and Border Protection uses facial recognition to verify travelers. Non-citizens may be required to participate as a condition of entry or departure. U.S. citizens can opt out and request a manual document review instead, though the process for doing so is not always clearly posted.4Federal Register. Collection of Biometric Data From Aliens Upon Entry to and Departure From the United States State biometric privacy laws do not apply here. They govern private entities, not federal agencies conducting border security, so opting out of CBP’s system does not involve the consent mechanisms that apply to a private employer or retailer collecting your fingerprints.