Biometric Data Privacy Compliance for Tech Companies: What BIPA and State Laws Require in 2026

Home  /  Data Privacy  /  Biometric Data Privacy Compliance for Tech Companies: What BIPA and State Laws Require in 2026

If your app, platform, or software product collects fingerprints, facial geometry, voiceprints, iris scans, or any other biometric identifier from users, you are operating under one of the most litigation-heavy areas of US privacy law. The Illinois Biometric Information Privacy Act (BIPA) alone has generated thousands of class-action lawsuits since 2019, with settlements reaching tens of millions of dollars against companies of every size. Several other states have now followed with their own biometric privacy laws, and the trend is accelerating.

Unlike general data privacy statutes, biometric privacy laws impose strict liability for procedural violations. You do not need to suffer a breach for your business to face a lawsuit. You can be sued simply for collecting biometric data without a compliant written policy in place, or for failing to notify users before collection. That makes compliance not just a legal obligation but an existential risk management issue for any tech company touching biometrics.

This article explains what biometric data privacy laws require from tech companies in 2026, which states you need to watch, what your privacy policy lawyer must address, and when you need a technology lawyer to review your compliance posture.

1. What Counts as Biometric Data Under US Law

Biometric data refers to unique physical or behavioral characteristics used to identify a person. Under BIPA and its state counterparts, this includes fingerprints and hand geometry, facial recognition geometry (not just photographs, but the underlying geometric map of facial features), retina and iris scans, voiceprints used for identification, and gait analysis and other body-based identifiers.

Crucially, BIPA does not protect photographs themselves, but it does protect the facial geometry extracted from those photographs. This distinction is why photo-processing apps, employee time-tracking software using facial scan, and consumer-facing apps with selfie-based verification are all potentially covered even if they tell users they are just taking a photo.

If your product processes any of these identifiers at any point in its data pipeline, the biometric privacy framework applies to you regardless of where your company is incorporated or headquartered.

2. The Illinois BIPA: The Standard Every Tech Company Must Know

Illinois enacted BIPA in 2008, and it remains the most expansive and most litigated biometric privacy statute in the United States. Under 740 ILCS 14/15, any private entity that collects, captures, purchases, receives through trade, or otherwise obtains a person’s biometric identifiers or biometric information must: develop, publish, and follow a written policy establishing a retention schedule and guidelines for permanently destroying biometric data; inform the subject in writing of the specific purpose and length of time for which biometric data is collected and stored; obtain a written release from the subject before collecting biometric data; not sell, lease, trade, or profit from biometric data; and not disclose or disseminate biometric data without the subject’s consent or a court order.

BIPA’s private right of action is what makes it dangerous for businesses. Any person aggrieved by a BIPA violation can sue in state court. Statutory damages are $1,000 per negligent violation and $5,000 per intentional or reckless violation, plus attorney’s fees. Class actions mean that a single non-compliant data collection event can expose a company to millions in aggregate damages.

In 2023, the Illinois Supreme Court in Cothron v. White Castle Systems, Inc. held that a separate claim accrues each time biometric data is collected or disclosed without authorization. This significantly expanded potential liability exposure per plaintiff and per class.

3. State Laws Beyond Illinois: The Growing Biometric Privacy Map

While BIPA is the most litigated law, several other states have enacted biometric-specific statutes that tech companies serving national audiences must also account for.

Texas

The Texas Capture or Use of Biometric Identifier Act (CUBI) prohibits capturing biometric identifiers for commercial purposes without prior notice and consent. Unlike BIPA, CUBI does not have a private right of action. Enforcement is handled by the Texas Attorney General with fines up to $25,000 per violation.

Washington

The Washington Biometric Privacy Act (WBPA) prohibits enrolling biometric identifiers in a database without consent and requires notice of purpose and storage duration. Like Texas, enforcement is through the Attorney General, not private lawsuits.

New York and Colorado

New York’s SHIELD Act touches biometric data as part of broader data security requirements. Colorado’s HB 23-1058 extended biometric protections under its Consumer Privacy Act effective in 2024. Several additional states have introduced biometric-specific bills in 2025-2026 legislative sessions, and the trend shows no sign of slowing.

For a tech company with users in multiple states, the practical compliance requirement is to meet the most restrictive standard, which is currently BIPA. If you satisfy BIPA’s requirements, you are generally in compliance with the less demanding frameworks in other states.

4. What Your Privacy Policy Must Say About Biometric Data

Your privacy policy must address biometric data collection clearly and specifically. A generic “we collect certain personal information” policy is not sufficient and will not satisfy BIPA’s written policy requirement. A compliant biometric data section must include: a clear statement that biometric identifiers are collected and the specific types collected; the purpose for collection; the retention period and criteria for destruction; whether data is shared with third parties; and the security measures used to protect biometric data.

Beyond the privacy policy, you also need a standalone written consent mechanism. BIPA requires that you obtain written informed consent before collection, separate from your general terms of service acceptance. This is commonly implemented as a dedicated biometric consent screen with an affirmative checkbox, presented before the facial scan or fingerprint capture occurs.

Working with a privacy policy lawyer who understands biometric-specific requirements can make the difference between a policy that satisfies BIPA and one that creates class-action exposure. You may also want to review data privacy laws every startup must comply with for a broader compliance picture.

5. Vendor and Third-Party SDK Risk

Many tech companies integrate facial recognition or biometric verification through third-party SDKs, identity verification APIs, or time-and-attendance platforms. Under BIPA, the company using the biometric data is responsible for compliance regardless of whether collection is outsourced to a vendor.

Your SaaS agreements or vendor contracts must require any third party that processes biometric data on your behalf to comply with applicable biometric privacy laws. Contracts should include specific provisions covering consent requirements, data retention limits, prohibition on secondary use, security standards, and liability allocation in the event of a BIPA violation.

6. What Technology Lawyers Review in a Biometric Compliance Audit

A biometric compliance review by a technology lawyer typically covers the product’s data flow to determine exactly where biometric data enters and exits the system; the consent mechanism and whether it legally precedes collection; the privacy policy language for specificity and BIPA adequacy; the data retention and destruction schedule; vendor and data processor agreements; and any existing arbitration clauses in your terms of service that might impact class-action exposure.

For companies expanding into Illinois, Texas, or Washington with a biometric product, this review should happen before launch, not after a lawsuit notice letter arrives. The cost of a legal review is a fraction of the cost of a BIPA class-action settlement.


Frequently Asked Questions

Does BIPA apply to companies outside Illinois?

Yes. BIPA applies when biometric data is collected from Illinois residents, regardless of where your company is based. If your app is available in Illinois and collects biometric data from Illinois users, you are subject to BIPA. Courts have consistently applied BIPA to out-of-state companies serving Illinois consumers.

Does adding a biometric consent checkbox to an existing ToS acceptance flow satisfy BIPA?

Not reliably. BIPA requires informed written consent that is specific to biometric data collection, provided before collection occurs. Burying it in a general ToS agreement or presenting it simultaneously with a service agreement acceptance has been challenged in litigation. A separate, dedicated consent screen is the defensible approach.

How long can my company retain biometric data under BIPA?

BIPA requires permanent destruction of biometric data when the initial purpose is fulfilled, or three years from the company’s last interaction with the subject, whichever is sooner. Your written policy must define this retention schedule, and your actual practices must match what the policy says.

Are employee biometrics covered by BIPA?

Yes. BIPA covers employee biometric data collection, and many of the largest BIPA class actions have targeted employers using fingerprint-based time and attendance systems. The employer must obtain written consent from employees before scanning, which is not the same as having employees sign an at-will employment agreement.

Do I need a biometric privacy policy if I use a third-party API that processes the facial data?

Yes. Routing biometric data through a third-party API does not transfer your BIPA obligations to that vendor. You must also ensure your vendor agreement with the API provider allocates responsibility clearly and requires the vendor to comply with BIPA on your behalf.

Conclusion

Biometric data privacy compliance is not optional for tech companies operating in the United States in 2026. Whether you use facial recognition for user authentication, fingerprint scanning for employee access, or voiceprint identification for customer service, BIPA and state biometric laws impose strict requirements on consent, policy documentation, data retention, and vendor management. The class-action risk is real and has already resulted in nine-figure settlements against well-resourced companies.

If your product touches biometric data and your privacy policy, consent mechanisms, or vendor contracts have not been reviewed by a technology lawyer familiar with biometric privacy law, now is the time to fix that. Contact Hansen Tong at TOSLawyer.com for a consultation on biometric compliance for your platform.


Comments are closed.