Back to the hub

What are the biometric privacy laws by state?

Only a few states have dedicated biometric privacy laws. Illinois (BIPA), Texas (CUBI), and Washington regulate collecting fingerprints, face, or voice data, and Colorado added biometric rules to its privacy act. Illinois is strictest, with a private right of action; Texas and Washington are enforced only by the attorney general.

Applies to: Businesses that collect, capture, or store biometric identifiers such as fingerprints, face scans, or voiceprints from residents of Illinois, Texas, Washington, or Colorado.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

There is no national biometric privacy law, so whether you can scan a fingerprint or a face without breaking the law depends entirely on which state's residents you touch. Four states do most of the work here, and one of them, Illinois, is the reason biometric compliance gets its own line item in most legal budgets. Here is how each one works.

Which states have biometric privacy laws?

Three states have a standalone biometric statute: Illinois, Texas, and Washington. Colorado added biometric provisions to its Privacy Act in 2025. Beyond these, several comprehensive state laws (including Connecticut and California) fold biometric data into their definition of sensitive data, which triggers a consent requirement rather than a separate biometric regime. This page covers the four dedicated regimes, because those carry the specific notice, consent, and retention duties.

Illinois BIPA: the one with real teeth

Illinois is strictest because individuals can sue directly. Under the Biometric Information Privacy Act (740 ILCS 14), a private entity must inform a person in writing, state the purpose and how long the data is kept, and get a written release before collecting a biometric identifier. It must publish a written retention policy and destroy the data within three years of the person's last interaction, and it may not sell or profit from the data. The enforcement teeth are in Section 20: a person can recover $1,000 for a negligent violation or $5,000 for an intentional or reckless one, or actual damages if greater. A 2024 amendment clarified that repeated identical collections from the same person are a single recovery, which lowered but did not remove the exposure. The dedicated Illinois BIPA guide covers the notice, written-release, retention, and private-lawsuit rules in full. In health care, BIPA's Section 10 carve-out can remove some clinical biometric data from the Act; see does BIPA apply to health care.

Texas and Washington: state-enforced consent laws

Texas and Washington require the same front-end consent but leave enforcement to the state. Texas's CUBI law (Section 503.001) bars capturing a biometric identifier for a commercial purpose without informing the person and getting consent, limits sale and disclosure, requires destruction within about a year of the purpose ending, and lets the attorney general seek a civil penalty of up to $25,000 per violation. Washington's law (RCW chapter 19.375) prohibits enrolling a biometric identifier in a database for a commercial purpose without notice and consent, and is enforced under the state Consumer Protection Act. Neither state gives individuals a private right of action. The Texas biometric page walks through CUBI in detail.

Colorado: biometric rules with no size threshold

Colorado's biometric provisions turn on the data, not your size. Effective July 1, 2025, any controller that collects, uses, or stores biometric identifiers of Colorado residents must give notice and obtain consent and keep a written policy for retention and deletion, with no revenue or consumer-count minimum. The Colorado biometric page walks through that trigger in detail.

What every biometric law has in common

Across all four, the pattern is the same: tell people first, get consent before you collect, do not sell the data, and delete it on a schedule. The differences are in who enforces and how much it costs. Illinois is the outlier on risk because of the private lawsuits; the others depend on a regulator acting.

Next step

If you use fingerprint time clocks, face recognition, or voiceprints and touch any of these states, the free 2-minute Obligation Scan flags which biometric rules apply and the consent, policy, and retention steps each one requires. The US state privacy laws hub shows how these data-type triggers sit alongside the comprehensive laws.

Compliance checklist

  • Map where you collect biometric identifiers (fingerprints, face or voice scans) and which states' residents they belong to.
  • Give written notice and obtain consent before collection, which all four regimes require.
  • In Illinois, publish a written retention and destruction policy and destroy the data within 3 years of the person's last interaction.
  • Do not sell, lease, or trade biometric identifiers.
  • Treat Illinois as the highest risk, because individuals can sue for $1,000 to $5,000 per violation without proving harm.
  • Remember Colorado's biometric rules apply with no revenue or headcount threshold at all.

Sources

Last verified: 2026-08-07

Informational, not legal advice.