Layer27 is now part of Katalyst.

Read the announcement
Layer27, a Katalyst Company

Blog

Biometric Data and the Law: What U.S. Businesses Must Know Before Collecting a Single Fingerprint

Biometric data laws are multiplying fast. Here's what businesses collecting fingerprints, facial scans, or voice data must do to stay compliant and avoid costly lawsuits.

June 18, 2026Layer27
Data SecurityComplianceBusiness StrategyPrivacy
Biometric Data and the Law: What U.S. Businesses Must Know Before Collecting a Single Fingerprint

Biometric data was once the domain of spy thrillers and airport security checkpoints. Today, it's embedded in everyday business operations — employees clocking in with a fingerprint scan, customers verifying identity with a selfie, and time-tracking software logging facial geometry without a second thought.

The problem? The legal landscape governing how businesses collect, store, and ultimately destroy biometric data has matured faster than most compliance programs. In 2026, biometric data is one of the most heavily regulated categories of personal information in the United States — and one of the most frequently mishandled.

Lawsuits are no longer hypothetical. Settlements are in the hundreds of millions. And regulators across multiple states are watching.

This post breaks down what biometric data laws actually require, which businesses are most at risk, and what practical steps you can take right now to protect your organization.


What Counts as Biometric Data — and Why It's Different

Before diving into compliance requirements, it's worth being precise about what "biometric data" actually means under the law.

Most statutes define biometric identifiers broadly, including:

  • Fingerprints and palm prints
  • Facial geometry (the spatial mapping of facial features used in facial recognition systems)
  • Retina and iris scans
  • Voiceprints (audio patterns used in voice authentication)
  • Hand geometry
  • Gait analysis and behavioral biometrics
  • DNA, in some jurisdictions

What makes biometric data categorically different from other personal information is immutability. If a hacker steals your password, you change it. If they steal your credit card number, you cancel the card. But if someone compromises your facial geometry or fingerprint data, there is no reset button. Your biometrics follow you for life.

That irreversibility is exactly why regulators treat biometric data as a higher-stakes category — and why the legal consequences for mishandling it are so severe.


The Patchwork of U.S. Biometric Laws in 2026

The United States still lacks a single federal biometric privacy law, though that conversation is ongoing in Congress. What has emerged instead is a complex, state-by-state patchwork that creates significant compliance complexity for any business operating across multiple states.

Illinois: The Gold Standard — and the Biggest Litigation Risk

Illinois passed the Biometric Information Privacy Act (BIPA) back in 2008, and it remains the most consequential biometric law in the country. BIPA gives individuals a private right of action — meaning any person can sue a company directly for violations, without needing to wait for a government agency to act. Statutory damages run from $1,000 per negligent violation to $5,000 per intentional or reckless violation.

When you multiply those per-incident damages across an entire workforce or customer base, the exposure is staggering. In 2023, BNSF Railway settled a BIPA class action for $75 million. In 2022, Facebook (Meta) settled its Illinois facial recognition case for $650 million. Neither of those numbers is a typo.

BIPA requires businesses to:

  1. Have a written, publicly available policy establishing a retention schedule and deletion guidelines
  2. Obtain written informed consent before collecting biometric identifiers
  3. Not profit from or sell biometric data
  4. Protect biometric data with the same standard of care used for other sensitive data
  5. Destroy biometric data when its purpose has been fulfilled, or within three years — whichever comes first

Illinois courts have repeatedly held that BIPA applies to employment contexts, meaning time-and-attendance systems, access control scanners, and even some remote work monitoring tools fall squarely in scope.

Texas and Washington: No Private Right of Action — But Don't Relax

Texas (Capture or Use of Biometric Identifier Act) and Washington (HB 1493) have biometric laws on the books, but enforcement is handled exclusively by state attorneys general. This absence of a private right of action significantly reduces litigation risk compared to Illinois — but these laws still carry civil penalties and are being actively enforced as data privacy enforcement budgets grow.

The New Wave: 2025–2026 State Legislation

The legislative pace has accelerated sharply. As of mid-2026, more than 15 states have either enacted biometric-specific privacy statutes or incorporated biometric data protections into broader comprehensive privacy laws. Colorado, Virginia, and Connecticut now treat biometric data as a "sensitive data category" under their comprehensive privacy frameworks, requiring opt-in consent rather than opt-out.

Several states — including Maryland, New York, and Massachusetts — have bills under active consideration that mirror or exceed BIPA's private right of action model. If your business is currently outside BIPA's reach, that window may be closing.

Federal Movement: The ADPPA and What to Watch

The American Data Privacy and Protection Act (ADPPA) has made incremental progress in Congress, and biometric data is explicitly called out as a "sensitive covered data" category requiring affirmative consent. A federal bill, if passed, could preempt some state laws — but it would also establish a federal floor that all businesses must meet. IT and compliance teams should be tracking this closely.


Which Businesses Are Most Exposed

You might assume biometric data compliance is primarily a concern for large tech companies or healthcare organizations. That assumption is wrong — and dangerously so.

Businesses at Elevated Risk Include:

Employers using biometric time-and-attendance systems. This is currently the highest-volume litigation category. If your employees clock in via fingerprint scan or facial recognition, you are collecting biometric data. Period. Many businesses using commercial timekeeping platforms — including some widely used mid-market HR software — have discovered this only after receiving a demand letter.

Retailers and hospitality businesses using facial recognition for loss prevention. The use of facial recognition cameras in stores, hotels, and event venues is growing, but the legal requirements for notice and consent are rarely met.

Healthcare and senior care facilities using biometrics for patient or resident access. These organizations often face overlapping obligations under HIPAA and state biometric laws simultaneously.

Financial services firms using voice authentication for call center access. Voiceprints are covered biometric identifiers in most statutes. If your contact center uses voice-based authentication, you likely have consent obligations you haven't addressed.

Remote work monitoring tools with facial recognition or "liveness detection." Since the pandemic, many businesses adopted remote proctoring and employee monitoring tools. Some of these collect facial geometry. Most businesses don't know it.


The Technical Side: Where Biometric Data Actually Lives

Here's where the IT infrastructure conversation becomes critical — and where many compliance programs break down.

Biometric data is rarely stored as a simple image. Modern biometric systems convert raw physical characteristics into mathematical templates — hashed or encrypted representations stored in databases. But those templates are still biometric data under most state laws, and they're governed by the same rules as a literal fingerprint image.

The challenge is knowing where all of that data lives:

  • On-premises biometric scanners with local databases
  • Third-party time-and-attendance SaaS platforms processing data in the vendor's cloud
  • HR information systems that sync biometric records alongside payroll data
  • Access control systems tied to building security infrastructure
  • Remote monitoring tools running client-side on employee devices

For most organizations, this data is scattered across a combination of on-premises infrastructure, public cloud environments, and third-party SaaS platforms — often with no centralized inventory of where biometric records actually reside.

This is where working with a managed services partner pays dividends. Layer27's Infrastructure Pro and Cloud Services teams frequently conduct data mapping exercises for clients discovering, for the first time, exactly how many systems are touching sensitive or regulated data categories. Without that map, you can't build a compliant retention and deletion schedule — and you can't respond to regulatory inquiries or litigation holds accurately.


Building a Compliant Biometric Data Program

Compliance with biometric data laws isn't a one-time checkbox. It's an ongoing operational discipline. Here's what a functional program looks like.

1. Conduct a Biometric Data Inventory

Before you can comply, you need to know what you have. Map every system that collects, processes, stores, or transmits biometric data. Include:

  • The specific biometric identifiers being collected
  • The business purpose for collection
  • Where the data is stored (vendor name, geography, cloud or on-premises)
  • Who has access
  • Current retention period

If you're using any third-party platforms, review their data processing agreements carefully. Many SaaS vendors' biometric data handling practices are addressed only in dense subprocessor lists buried in their privacy policies.

2. Establish Written Policies and Retention Schedules

Every biometric data program needs a written policy that covers:

  • What data is collected and why
  • How long it will be retained (with specific, enforceable timelines)
  • How it will be securely destroyed when no longer needed
  • Who internally is responsible for managing the program

Illinois BIPA requires this policy to be publicly available. Even in states that don't explicitly require public posting, having a documented, auditable policy is your first line of defense in litigation.

3. Build a Consent Management Process

For most biometric data collection in employment contexts, you need written informed consent before you collect a single data point. That means:

  • A standalone consent form (not buried in a general employment agreement)
  • Plain-language disclosure of the specific data being collected
  • Explanation of the purpose and duration of collection
  • A signature or affirmative digital acknowledgment

Document everything. If you cannot produce signed consent forms for every person whose biometric data you hold, you have a compliance gap.

4. Apply Appropriate Technical Security Controls

Biometric data requires strong security controls. At minimum:

  • Encryption at rest and in transit for all biometric templates and raw data
  • Access controls limiting biometric data to systems and personnel with a legitimate need
  • Audit logging of who accesses biometric data and when
  • Multi-factor authentication protecting systems that store biometric records

Layer27's Protect Pro and Safe Start services include data-at-rest encryption, access control configuration, and audit logging capabilities that directly support these requirements. For organizations needing continuous oversight, our Managed Detection & Response (MDR) and 24x7 SOC services provide real-time monitoring to detect unauthorized access to sensitive data stores.

5. Implement Deletion Workflows

One of the most operationally difficult requirements is timely deletion. When an employee leaves, when a customer relationship ends, or when the retention period expires — biometric data must be securely and verifiably destroyed.

This requires:

  • Automated or calendar-triggered deletion workflows
  • Vendor contractual obligations to delete data on your behalf within specified timeframes
  • Deletion certificates or audit logs confirming destruction

Layer27's Backup-as-a-Service (BaaS) clients often discover during onboarding that biometric data has been captured in routine backups — where it sits indefinitely if deletion workflows don't extend into the backup environment. This is a common and serious compliance gap.

6. Train Your Team

Your biometric data compliance program is only as strong as the employees who operate it. HR managers who onboard new hires, IT administrators who manage access control systems, and managers who approve new software tools all need to understand the rules.

Layer27's Security Awareness Training program includes customizable modules covering data privacy obligations — including scenarios relevant to biometric data collection in the workplace. Regular training ensures your team isn't inadvertently creating liability through uninformed decisions.

7. Review Third-Party Vendor Contracts

If a vendor is collecting, processing, or storing biometric data on your behalf, your compliance obligations don't stop at your own front door. Under most biometric statutes, you are responsible for ensuring your vendors meet the same standards you do.

Review every vendor contract involving biometric data to confirm:

  • The vendor acknowledges their role as a data processor
  • They are contractually obligated to comply with applicable biometric data laws
  • They will delete data on your instruction within required timeframes
  • They will notify you in the event of a data breach

This is also where Layer27's Compliance advisory services can add significant value — helping businesses assess vendor agreements for data privacy gaps before they become litigation exposure.


What Happens When You Get It Wrong

The litigation history is instructive and sobering.

Beyond the blockbuster settlements mentioned earlier, BIPA class actions have targeted mid-size employers using fingerprint time clocks with workforces as small as 50 people. At $1,000 to $5,000 per violation, a 100-person workforce with two years of non-compliant biometric collection can generate eight-figure theoretical exposure before a case ever reaches a jury.

Even in states without private rights of action, attorney general enforcement is increasing. State privacy regulators are staffing up, and biometric data violations are politically visible issues that AGs are actively pursuing.

Reputational damage compounds financial exposure. A biometric data breach — or even a publicized compliance failure — signals to customers and employees that your organization cannot be trusted with their most irreplaceable personal information.


The Intersection of Biometric Data and Artificial Intelligence

One emerging development that every compliance professional should be watching: the growing integration of biometric data with AI-powered analytics.

Facial recognition systems are increasingly paired with behavioral analytics tools that track employee movement patterns, engagement levels, and productivity signals. Voice authentication systems are being combined with sentiment analysis. These AI-augmented applications may trigger compliance obligations under both biometric data statutes and emerging AI governance regulations.

In states like Colorado and Illinois, AI systems that make consequential decisions using biometric inputs may trigger additional disclosure and bias audit requirements. This is a fast-moving area of law that will create new compliance obligations for businesses adopting AI-powered workforce management tools — likely within the next 18 to 24 months.


A Practical Timeline for Getting into Compliance

If you're starting from scratch, here's a realistic roadmap:

| Timeframe | Priority Actions | |---|---| | Weeks 1–4 | Complete biometric data inventory; identify all systems and vendors | | Weeks 4–8 | Draft written policy; establish retention schedule and deletion procedures | | Weeks 8–12 | Audit existing consent records; collect missing consents from active employees and customers | | Weeks 12–16 | Review and update all vendor contracts for biometric data obligations | | Ongoing | Implement deletion workflows; train staff; monitor state legislative developments |

This is not a project you want to begin reactively — after a lawsuit is filed or a regulatory inquiry arrives.


The Bottom Line for Business Leaders

Biometric data compliance in 2026 is not a niche concern for enterprise legal teams. It's a practical operational and legal obligation for thousands of U.S. businesses — including many that have no idea they're already collecting regulated biometric data.

The businesses that get this right share a few characteristics: they know where their data lives, they have documented policies and consent processes, they've trained their teams, and they've built deletion workflows that actually run. They've also made sure their IT infrastructure — including their backup environments, cloud storage, and third-party vendors — is operating in alignment with their compliance commitments.

That's not a description of a compliance program designed by lawyers. It's a description of an organization with mature, integrated IT and data governance practices.


How Layer27 Can Help

At Layer27, we work with businesses across industries to identify and close data privacy compliance gaps — including biometric data obligations — before they become legal and financial problems.

From data mapping and infrastructure audits through our Infrastructure Pro and Co-Managed IT services, to compliance advisory and vendor contract reviews, to the technical security controls built into Protect Pro, MDR, and our 24x7 SOC — we help organizations build the operational foundation that compliant data handling requires.

If you're not sure whether your current IT environment is aligned with your biometric data obligations, that uncertainty is worth resolving now.

Contact Layer27 today to schedule a consultation. We'll help you understand where you stand — and build a plan to get where you need to be.

Ready to transform your IT?

Get a free consultation and discover how Layer27 can help your business thrive with proactive IT management, advanced cybersecurity, and scalable cloud solutions.