Biometric Privacy Laws by State (2026): BIPA, CUBI & Consent
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 6 primary sources cited on this page. How we verify our legal content
Most U.S. states do not have a dedicated biometric privacy law. Only Illinois (BIPA), Texas (CUBI), and Washington have stand-alone biometric statutes. About twenty more states protect biometric data as sensitive data under a broader consumer privacy law, and the rest cover it only through data-breach notification rules. There is no federal biometric privacy law.
Jurisdiction scope: This guide covers U.S. state biometric privacy laws (fingerprints, facial geometry, voiceprints, retina and iris scans) as of 2026. It is general legal information, not legal advice.
Which States Have Biometric Privacy Laws?
A biometric identifier is a measurement of a unique physical trait, such as a fingerprint, faceprint, voiceprint, or iris scan. As of 2026, only three states regulate the collection of biometric identifiers with a dedicated statute. Everywhere else, biometric data is protected either as a category of sensitive data under a general consumer privacy law or only through data-breach notification rules. No federal law specifically governs commercial biometric data, so the protections that apply to you depend entirely on your state.
The single most important distinction is whether a state gives individuals a private right of action, meaning the ability to sue on their own. Only Illinois does. That one feature is why Illinois is the center of biometric litigation in the country.
The Three Dedicated Biometric Laws
Illinois, Biometric Information Privacy Act (BIPA), 740 ILCS 14. Enacted in 2008, BIPA is the strictest biometric law in the United States. A private entity must obtain written consent before collecting a person's biometric identifier, publish a retention and destruction schedule, and never sell biometric data. BIPA is the only biometric law with a private right of action, and it sets statutory damages of $1,000 per negligent violation and $5,000 per reckless or intentional violation, plus attorney fees. The Illinois Supreme Court has held that a person does not need to prove actual harm to sue (Rosenbach v. Six Flags, 2019).
Texas, Capture or Use of Biometric Identifier Act (CUBI), Business and Commerce Code 503.001. Texas requires informed consent before capturing a biometric identifier for a commercial purpose and limits how long it can be retained. Unlike BIPA, CUBI has no private right of action; only the Texas Attorney General can enforce it, with civil penalties up to $25,000 per violation.
Washington, RCW 19.375 and the My Health My Data Act. Washington's 2017 biometric law requires a business to provide notice, obtain consent, or offer a mechanism to opt out before enrolling a biometric identifier in a database for a commercial purpose (satisfying any one of the three is enough), enforced by the Attorney General. Washington went further in 2023 with the My Health My Data Act, which classifies all biometric data, not just data tied to health, as protected consumer health data, and includes a private right of action.
Biometric Data as Sensitive Data Under State Privacy Laws
Roughly twenty states have passed comprehensive consumer privacy laws, and nearly all of them classify biometric data as sensitive data. These include California, Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and others. Under these laws, a business generally must obtain opt-in consent before processing biometric data, though California, Utah, and Iowa instead give consumers a right to opt out rather than requiring opt-in consent, and consumers gain rights to access and delete it. Colorado went furthest in this group. HB 24-1130, signed May 31, 2024 and effective July 1, 2025, added C.R.S. 6-1-1314, which requires a controller to obtain consent before collecting biometric data, to adopt a written retention and destruction policy that deletes a biometric identifier by the earliest of the collection purpose being satisfied, twenty-four months after the consumer last interacted with the controller, or a short deadline triggered by the controller's own annual review, and which flatly bars selling, leasing, or trading biometric identifiers. It also limits the situations in which an employer may make biometric consent a condition of employment. Under the amended C.R.S. 6-1-1304(1)(b), those biometric duties reach a controller that handles any amount of biometric identifiers or biometric data, regardless of the amount, so a business too small for the act's usual 100,000 or 25,000 consumer thresholds is still bound as to biometrics. These protections are real but are enforced by the state attorney general, not through individual lawsuits.
States Without a Dedicated Biometric Law
In the remaining states, there is no statute that specifically restricts collecting biometric identifiers. Biometric data is usually still listed as protected personal information in the state's data-breach notification law, so a company that suffers a breach involving biometric data must notify affected residents. But there is generally no requirement to obtain consent before collection, and no individual right to sue over the collection itself.
Biometric Privacy Laws by State
The table below links to a detailed guide for each state. Select your state for the specific statute, consent rules, penalties, and recent changes.
| State | Dedicated biometric law? | Key statute | How biometric data is protected |
|---|---|---|---|
| Alabama | No | None | Mainly data-breach notification coverage |
| Alaska | No | None | Mainly data-breach notification coverage |
| Arizona | No | None | Mainly data-breach notification coverage |
| Arkansas | No | None | Mainly data-breach notification coverage |
| California | No | None | Sensitive data, consumer right to limit use (opt-out), not opt-in consent, under California's privacy law |
| Colorado | Partial | C.R.S. 6-1-1314 (HB 24-1130) | Biometric-specific duties inside the state privacy act: consent before collection, a public written retention and deletion policy, a ban on selling or leasing biometric identifiers, and limits on employer use |
| Connecticut | No | None | Sensitive data, opt-in consent under Connecticut's privacy law |
| Delaware | No | None | Sensitive data, opt-in consent under Delaware's privacy law |
| District of Columbia | No | None | Mainly data-breach notification coverage |
| Florida | No | None | Sensitive data, opt-in consent under Florida's privacy law (FDBR, effective July 1, 2024), plus a sensitive-data sale-notice requirement |
| Georgia | No | None | Mainly data-breach notification coverage |
| Hawaii | No | None | Mainly data-breach notification coverage |
| Idaho | No | None | Mainly data-breach notification coverage |
| Illinois | Yes | BIPA (740 ILCS 14) | Dedicated statute (strongest protection) |
| Indiana | No | None | Sensitive data, opt-in consent under Indiana's privacy law |
| Iowa | No | None | Sensitive data, opt-out right (notice and opportunity to opt out) under Iowa's privacy law |
| Kansas | No | None | Mainly data-breach notification coverage |
| Kentucky | No | None | Sensitive data, opt-in consent under Kentucky's privacy law |
| Louisiana | No | None | Mainly data-breach notification coverage |
| Maine | No | None | Mainly data-breach notification coverage |
| Maryland | No | None | Sensitive data, opt-in consent under Maryland's privacy law |
| Massachusetts | No | None | Mainly data-breach notification coverage |
| Michigan | No | None | Mainly data-breach notification coverage |
| Minnesota | No | None | Sensitive data, opt-in consent under Minnesota's privacy law |
| Mississippi | No | None | Mainly data-breach notification coverage |
| Missouri | No | None | Mainly data-breach notification coverage |
| Montana | No | None | Sensitive data, opt-in consent under Montana's privacy law |
| Nebraska | No | None | Sensitive data, opt-in consent under Nebraska's privacy law |
| Nevada | No | None | Mainly data-breach notification coverage |
| New Hampshire | No | None | Sensitive data, opt-in consent under New Hampshire's privacy law |
| New Jersey | No | None | Sensitive data, opt-in consent under New Jersey's privacy law |
| New Mexico | No | None | Mainly data-breach notification coverage |
| New York | No | None | Mainly data-breach notification coverage |
| North Carolina | No | None | Mainly data-breach notification coverage |
| North Dakota | No | None | Mainly data-breach notification coverage |
| Ohio | No | None | Mainly data-breach notification coverage |
| Oklahoma | No | None | Mainly data-breach notification coverage |
| Oregon | No | None | Sensitive data, opt-in consent under Oregon's privacy law |
| Pennsylvania | No | None | Mainly data-breach notification coverage |
| Rhode Island | No | None | Sensitive data, opt-in consent under Rhode Island's privacy law |
| South Carolina | No | None | Mainly data-breach notification coverage |
| South Dakota | No | None | Mainly data-breach notification coverage |
| Tennessee | No | None | Sensitive data, opt-in consent under Tennessee's privacy law |
| Texas | Yes | CUBI (Bus. & Com. Code 503.001) | Dedicated statute (strongest protection) |
| Utah | No | None | Sensitive data, opt-out right (notice and opportunity to opt out) under Utah's privacy law |
| Vermont | No | None | Mainly data-breach notification coverage |
| Virginia | No | None | Sensitive data, opt-in consent under Virginia's privacy law |
| Washington | Yes | RCW 19.375 + My Health My Data Act | Dedicated statute (strongest protection) |
| West Virginia | No | None | Mainly data-breach notification coverage |
| Wisconsin | No | None | Mainly data-breach notification coverage |
| Wyoming | No | None | Mainly data-breach notification coverage |
What About BIPA Specifically?
Because Illinois BIPA drives most biometric litigation in the country, it is worth understanding on its own. For the statute's consent and retention requirements, the landmark cases, and how the per-scan damages question affects employers, see our detailed BIPA explainer, and for the Illinois state context, our Illinois biometric privacy guide.
Frequently Asked Questions
Which states have biometric privacy laws?
Only Illinois (BIPA), Texas (CUBI), and Washington have stand-alone biometric statutes. Colorado is a partial fourth: its privacy act now carries biometric-specific duties at C.R.S. 6-1-1314. About twenty more states protect biometric data as sensitive data under a comprehensive consumer privacy law, and the rest cover it through data-breach notification rules only.
Is there a federal biometric privacy law?
No. There is no federal law that specifically regulates commercial collection of biometric identifiers. Protection depends entirely on the state where the data is collected.
Can I sue a company for collecting my biometric data?
Only in Illinois. BIPA is the only biometric law with a private right of action, allowing individuals to sue for statutory damages of $1,000 or $5,000 per violation. Texas and Washington laws are enforced only by the state attorney general.
What counts as a biometric identifier?
Generally a measurement of a unique physical characteristic used to identify a person, such as a fingerprint, faceprint or facial geometry, voiceprint, or retina or iris scan. Exact definitions vary by state.
Do comprehensive privacy laws protect biometric data?
Yes. States with comprehensive consumer privacy laws, such as Virginia, Colorado, and Connecticut, treat biometric data as sensitive data and generally require opt-in consent before processing, along with rights to access and delete it. Colorado goes further than the rest, adding biometric-specific consent, written policy, retention, and no-sale duties at C.R.S. 6-1-1314 that apply no matter how much biometric data a controller handles. California, Utah, and Iowa are exceptions: their privacy laws treat biometric data as sensitive personal information but give consumers an opt-out style right to limit its use rather than requiring opt-in consent.
Updates
Corrected the Colorado entry: the state table now cites C.R.S. 6-1-1314 (HB 24-1130, effective July 1, 2025) and describes its biometric-specific consent, retention-policy, no-sale and employer rules instead of reporting no biometric statute.
Corrected the 51-state comparison table: Florida's Digital Bill of Rights (effective July 1, 2024) treats biometric data as sensitive data requiring opt-in consent and a sale notice, so Florida no longer shows as breach-notification-only; Utah and Iowa were relabeled from opt-in consent to their actual opt-out standard. Also fixed the Washington section to reflect that its 2017 biometric law is satisfied by notice, consent, or an opt-out mechanism (any one suffices, not all), and that the My Health My Data Act covers all biometric data, not only health-related biometric data.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected a comparison-table row and an FAQ answer that mischaracterized California's CCPA/CPRA biometric-data protection as an opt-in consent requirement. California's Cal. Civil Code section 1798.121 actually gives consumers an opt-out style right to limit use and disclosure of sensitive personal information (including biometric data used for unique identification, per section 1798.140), which is legally distinct from the opt-in consent model used by Virginia, Colorado, Connecticut, and other Virginia-model states.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Texas Business & Commerce Code
§ 503.001CAPTURE OR USE OF BIOMETRIC IDENTIFIERIn forcecited in 9 of our articles
(a) In this section: (1) "Artificial intelligence system" has the meaning assigned by Section 551.001. (2) "Biometric identifier" means a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry. (b) A person may not capture a biometric identifier of an individual for a commercial purpose unless the person: (1) informs the individual before capturing the biometric identifier; and (2) receives the individual's consent to capture the biometric identifier. (b-1) For purposes of Subsection (b), an individual has not been informed of and has not provided consent for the capture or storage of a biometric identifier of an individual for a commercial purpose based solely on the existence of an image or other media containing one or more biometric identifiers of the individual on the Internet or other publicly available source unless the image or other media was made publicly available by the individual to whom the biometric identifiers relate.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
Also relied on in: Amazon Ring Sued Over "Familiar Faces" Facial Recognition (2026), Alabama Smart Glasses Recording Laws, Oklahoma Smart Glasses Recording Laws 2026
California Civil Code
§ 1798.140In forcecited in 3 of our articles
Definitions For purposes of this title: (a) “Advertising and marketing” means a communication by a business or a person acting on the business’ behalf in any medium intended to induce a consumer to obtain goods, services, or employment. (b) “Aggregate consumer information” means information that relates to a group or category of consumers, from which individual consumer identities have been removed, that is not linked or reasonably linkable to any consumer or household, including via a device. “Aggregate consumer information” does not mean one or more individual consumer records that have been deidentified. (c) “Biometric information” means an individual’s physiological, biological, or behavioral characteristics, including information pertaining to an individual’s deoxyribonucleic acid (DNA), that is used or is intended to be used singly or in combination with each other or with other identifying data, to establish individual identity.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 12 court opinionsMost recently applied by a court: 2026
Leading cases:
- Untitled California Attorney General Opinion (California Attorney General Reports 2022)“…e business uses and shares that information. 26 21 Civ. Code, § 1798.140, subd. (c)(1)(A)-(C). 22 Civ. Code…”
- Netchoice, LLC v. Bonta (Court of Appeals for the Ninth Circuit 2026)“…cisionmaking, or choice, as further defined by regulation.” Cal. Civ. Code § 1798.140(l); id. § 1798.99.30(a). 40…”
- Keown v. International Association of Sheet Metal Air Rail Transportation Workers (District Court, District of Columbia 2024)“…or financial benefit of its shareholders or other owners.” Cal. Civ. Code § 1798.140(d)(1). As for the UCL, both state and f…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: California Biometric Privacy Laws: Collection, Consent & Penalties (2026), California Data Privacy Laws: CCPA, CPRA & Consumer Rights (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Illinois Biometric Information Privacy Act, 740 ILCS 14(ilga.gov).gov
- Texas Business and Commerce Code 503.001 (CUBI)(statutes.capitol.texas.gov).gov
- Washington RCW 19.375 (Biometric Identifiers)(app.leg.wa.gov).gov
- Washington My Health My Data Act, RCW 19.373(app.leg.wa.gov).gov
- California Civil Code 1798.140 (CCPA sensitive personal information)(leginfo.legislature.ca.gov).gov
- Colorado HB24-1130 (biometric amendment to the Colorado Privacy Act)(leg.colorado.gov).gov
- Colorado HB 24-1130 signed act text (adds C.R.S. 6-1-1314; amends 6-1-1304(1))(content.leg.colorado.gov)