HomeCan Companies Collect Your Biometric Data Without Written Consent?All CategoriesCan Companies Collect Your Biometric Data Without Written Consent?

Can Companies Collect Your Biometric Data Without Written Consent?

 By Sudeep T.R. – Senior Associate, Legal

A fingerprint used to clock into work. A facial scan used to enter a building. A voiceprint used to verify a customer’s identity.

Biometric technology is increasingly used for convenience and security. But unlike a password, biometric characteristics cannot simply be changed if they are compromised. That raises an important legal question: Can a business collect biometric data without first obtaining written consent?

The answer depends largely on where the collection occurs and which law applies. There is no single nationwide rule requiring written consent for every collection of biometric data.

What is Biometric Data?

Biometric data generally refers to unique physical or behavioral characteristics that can be used to identify an individual. Depending on the applicable law, this may include fingerprints, retina or iris scans, voiceprints, facial geometry, or similar identifying information. Importantly, an ordinary photograph or recording is not always treated as biometric data. Some laws distinguish between the image itself and data generated by analyzing that image to identify a person.

That distinction can determine whether a biometric privacy statute applies at all.

Illinois: Written Consent is Required

Illinois has one of the most prominent biometric privacy laws in the United States, the Biometric Information Privacy Act (BIPA). Under BIPA, a private entity generally may not collect or obtain a person’s biometric identifier or biometric information unless it first:

  • Informs the person in writing that biometric information is being collected or stored;
  • Explains in writing the purpose of the collection and how long the information will be used or stored; and
  • Obtains a written release from the person.

740 Ill. Comp. Stat. Ann. 14/15(b).

A “written release” can include an electronic signature, meaning consent need not necessarily be given with pen and paper. 740 Ill. Comp. Stat. Ann. 14/10.

For businesses using fingerprint time clocks, facial-recognition systems, or similar technology in Illinois, consent therefore should generally be obtained before the biometric information is collected.

Why BIPA Has Significant Consequences

BIPA is particularly important because it allows individuals to bring private lawsuits for statutory violations.

In Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186, ¶¶ 33–34, 129 N.E.3d 1197, 1206, the Illinois Supreme Court held that a person need not show an additional injury beyond the violation of BIPA’s statutory rights to qualify as an “aggrieved” person under the Act. In other words, failure to follow the required biometric privacy procedures can itself create legal exposure even without a separate allegation that the biometric information was stolen or misused.

Illinois subsequently amended BIPA in 2024 so that repeated collection of the same person’s biometric data using the same method constitutes a single violation for purposes of recovery under the relevant provision. The amendment also expressly recognized electronic signatures as written releases. The amendment changed potential damages exposure, but it did not eliminate BIPA’s notice-and-consent requirements.

Other States Apply Different Rules

Texas

Texas generally prohibits collecting a biometric identifier for a commercial purpose unless the individual is informed beforehand and gives consent. Tex. Bus. & Com. Code § 503.001 (b).Unlike Illinois BIPA, however, the Texas statute does not use the same requirement of a “written release.” Texas law also now makes clear that merely finding someone’s image or other biometric-containing material online does not automatically mean that the person consented to biometric capture.

Washington

Washington also regulates the commercial enrollment of biometric identifiers. Its law requires notice and consent in covered situations, but expressly provides that the exact notice and type of consent required may depend on the context. Wash. Rev. Code Ann. § 19.375.020.

Colorado

Colorado’s biometric privacy protections, effective since July 1, 2025, likewise impose disclosure and consent requirements before certain biometric identifiers may be collected. The law also regulates retention, deletion, security, and certain uses of employee biometric information. HB24-1130: Privacy of Biometric Identifiers & Data.

These differences highlight an important point:

“Consent required” does not always mean “written consent required.”

The governing statute must be examined carefully.

Is Clicking “I Agree” Enough?

Sometimes, but not automatically.

Whether electronic consent is legally sufficient depends on the applicable law and how the consent was obtained. A clear disclosure explaining that facial or fingerprint information will be collected for a specific purpose presents a different situation from a biometric provision buried deep within lengthy terms and conditions. Businesses should therefore consider whether the individual was clearly told:

  • What biometric information will be collected;
  • Why it is being collected;
  • How it will be used;
  • Whether it will be shared with third parties;
  • How long will it be retained; and
  • When will it be destroyed.

Where written consent is required, businesses should also ensure that the method of electronic acceptance satisfies the statute’s definition of a valid written release or signature.

Consent is Not the Only Issue

Obtaining consent does not necessarily end the legal inquiry. Biometric privacy laws may also regulate how information is stored, protected, shared, sold, retained, and destroyed.

For example, Illinois BIPA requires covered entities to maintain a publicly available retention and destruction policy and requires reasonable protection of biometric information. 740 Ill. Comp. Stat. Ann. 14/15(a), (e).

At the federal level, the Federal Trade Commission has also warned that unfair or deceptive practices involving biometric technologies, including inadequate disclosures and unreasonable security practices may violate Section 5 of the Federal Trade Commission Act.

Thus, the absence of a BIPA-style written-consent requirement does not necessarily mean that biometric data may be collected without legal risk.

What Should be Examined?

Before using fingerprint scanners, facial recognition, voice authentication, or similar technology, it is prudent to ask:

  • What information is actually being collected?
  • Does it qualify as biometric information under the applicable law?
  • Which jurisdiction’s law applies?
  • Is consent required before collection?
  • Must the consent be written?
  • Has the purpose and retention period been disclosed?
  • Will the information be shared with a vendor or third party?
  • How will the information be secured and eventually deleted?

These issues are best addressed before biometric technology is deployed rather than after litigation or a regulatory inquiry begins.

Written Consent? The Answer Depends on the Law

There is no universal rule requiring written consent before every collection of biometric data in the United States.

The important question is therefore not simply: “Did the individual consent?”

It is: “Did the business obtain the type of consent required by the law that applies?”

For companies adopting biometric technology, that distinction can be critical.

A password can be reset. A fingerprint cannot.

This article provides general information and does not constitute legal advice. Biometric privacy requirements differ significantly among jurisdictions, and businesses and counsel should review the applicable statutes, regulations, exemptions, and current case law before collecting or processing biometric information.

For more practical litigation drafting tips, pleading and legal research insights, follow LawCompany.