California
California Biometric Privacy Laws: Collection, Consent & Penalties (2026)

California treats biometric data as sensitive personal information under the CCPA/CPRA (Cal. Civ. Code 1798.100 et seq.) rather than through a standalone statute. This gives consumers the right to know what biometric information businesses collect, request deletion, and limit its use beyond what is reasonably necessary.
California does not have a standalone biometric privacy statute like Illinois's BIPA. Instead, the state folds biometric data into its comprehensive consumer privacy framework under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). For anyone collecting fingerprints, facial scans, or voiceprints in California, the rules are embedded throughout the California Data Privacy Laws ecosystem.
This means biometric protections in California come from multiple overlapping sources: CCPA/CPRA consumer rights, breach notification statutes, labor code restrictions, and new CPPA regulations on automated decisionmaking. Here is what you need to know.
How California Defines Biometric Information
The CCPA defines "biometric information" under Cal. Civ. Code 1798.140(c) as:
An individual's physiological, biological, or behavioral characteristics, including DNA, that can be used, singly or in combination with each other or with other identifying data, to establish individual identity.
The statute lists specific examples:
- Fingerprint, face, hand, palm, and vein pattern imagery
- Iris and retina scans
- Voice recordings from which identifiers can be extracted
- Keystroke patterns or rhythms
- Gait patterns or rhythms
- Sleep, health, or exercise data containing identifying information
Biometric information is also classified as a type of "personal information" under Section 1798.140(o)(1)(E).

Sensitive Personal Information Classification
Under the CPRA amendments, biometric information processed for the purpose of uniquely identifying a consumer qualifies as "sensitive personal information" under Section 1798.140(ae). This elevated classification triggers stronger protections than regular personal information.
One important distinction: photographs alone are not biometric information under the CCPA. However, photographs used or stored for facial recognition purposes do qualify.
Consumer Rights Over Biometric Data
Because biometric data is sensitive personal information, California consumers have several specific rights under the CCPA/CPRA:
Right to Limit Use and Disclosure. Consumers can direct businesses to limit the use of their biometric data to what is "necessary to perform the services or provide the goods reasonably expected by an average consumer." Businesses must provide a "Limit the Use of My Sensitive Personal Information" link on their websites.
Right to Know. Consumers can request that a business disclose what biometric information it has collected, the sources it collected from, the business purpose for collecting it, and the categories of third parties it has been shared with.
Right to Delete. Consumers can request deletion of their biometric data. Businesses must comply and direct service providers to delete the data as well.
Right to Correct. If biometric data is inaccurate, consumers can request correction.
Right to Opt Out of Sale or Sharing. Consumers can opt out of the sale or sharing of their biometric information with third parties.
No Retaliation. Businesses cannot discriminate against consumers who exercise these rights by denying goods, charging different prices, or providing a different quality of service.

Private Right of Action for Biometric Data Breaches
Cal. Civ. Code 1798.150 gives consumers the right to sue when their unencrypted personal information is exposed through a data breach caused by a business's failure to maintain reasonable security. This is one of the few areas where California law allows private lawsuits rather than relying solely on agency enforcement.
"Personal information" in the breach context includes a person's name combined with "unique biometric data generated from measurements or technical analysis of human body characteristics, such as a fingerprint, retina, or iris image, used to authenticate a specific individual."
What Consumers Can Recover
- Statutory damages: $100 to $750 per consumer per incident
- Actual damages if greater than statutory damages
- Injunctive or declaratory relief
- Any other relief the court deems proper
Requirements Before Filing Suit
Consumers must provide the business 30 days' written notice identifying the specific violations before filing a statutory damages claim. If the business cures the violation within 30 days and provides a written statement confirming the fix, statutory damages cannot be pursued. Actual damages claims do not require prior notice.
This private right of action applies only to data breach scenarios. For other CCPA violations involving biometric data, enforcement runs through the Attorney General and CPPA.
Breach Notification Requirements
California's breach notification statutes, Cal. Civ. Code 1798.29 (government agencies) and 1798.82 (businesses), require notification when unencrypted biometric data is compromised. Learn more in our California Data Breach Notification Laws guide.
Key requirements for biometric data breaches include:
- Timeline: Notification must occur within 30 calendar days of discovering the breach
- Attorney General notice: Required when more than 500 California residents are affected
- Special biometric instructions (optional): At the business's discretion, breach notices involving biometric data may include instructions on how to notify other entities that used the same type of biometric data as an authenticator, so those entities can stop relying on the compromised data
- Required content: Notices must follow a prescribed format with headings including "What Happened," "What Information Was Involved," "What We Are Doing," "What You Can Do," and "For More Information"
Employer Obligations for Biometric Data
California employers face specific biometric data requirements from multiple sources.
CCPA/CPRA Employee Coverage
The employee personal information exemption under the CCPA expired on January 1, 2023. Since then, California employees have the same rights as consumers regarding their biometric data. Employers that collect fingerprints for time clocks, facial scans for building access, or other biometric identifiers must:
- Provide notice at or before the point of biometric data collection
- Honor employee requests to know, delete, correct, and limit the use of biometric data
- Allow employees to limit the use of biometric data to what is necessary for the employment relationship
- Maintain reasonable security procedures to protect biometric data
California Labor Code Section 1051
California Labor Code 1051 adds a narrower, older protection. It makes it a misdemeanor to require an employee or job applicant, as a condition of getting or keeping the job, to be photographed or fingerprinted by a third party who wants that photograph or fingerprint (or information about it) in order to furnish it to another employer or third person, where it could be used to the employee's or applicant's detriment. It is an anti-blacklisting statute aimed at third parties compiling data to share with other employers.
This means employers cannot condition a job on submitting to third-party photographing or fingerprinting intended to blacklist the worker with other employers. The statute does not, by itself, restrict how an employer shares biometric data it lawfully collects and controls for its own internal purposes, such as timekeeping.

Enforcement and Penalties
Two agencies share enforcement authority over biometric data violations in California.
California Privacy Protection Agency (CPPA)
The CPPA was created by the CPRA in 2020 and has primary enforcement authority. As of 2025, the CPPA can impose:
- $2,663 per unintentional violation (adjusted annually for inflation)
- $7,988 per intentional violation
- $7,988 per violation involving a minor's data
The CPPA has been active. In 2025 alone, it issued a $632,500 fine against Honda, a $345,178 fine against Todd Snyder, and launched a Data Broker Enforcement Strike Force. While none of these actions specifically targeted biometric data misuse, they demonstrate the agency's willingness to pursue meaningful penalties.
Attorney General
The California Attorney General retains concurrent enforcement authority under Cal. Civ. Code 1798.199.90. The AG can bring civil actions for CCPA violations, including those involving biometric data.

New CPPA Regulations Effective 2026
The CPPA finalized new regulations on September 22, 2025, effective January 1, 2026, covering automated decisionmaking technology (ADMT), risk assessments, and cybersecurity audits. These regulations have direct implications for biometric data:
Automated Decisionmaking Technology. Businesses that use ADMT to process biometric information for profiling or identity verification must comply with new requirements starting January 1, 2027. This includes providing pre-use notices, offering opt-out options, and conducting accuracy evaluations and nondiscrimination audits.
Risk Assessments. Processing biometric data for profiling or identity verification qualifies as "significant risk" processing. Businesses engaged in such processing must complete risk assessments and submit attestations to the CPPA by April 1, 2028.
Cybersecurity Audits. Businesses that process sensitive personal information, including biometric data, at scale may need to conduct annual cybersecurity audits. Deadlines are tiered by revenue, with the largest companies (over $100 million) required to submit certifications by April 1, 2028.
Recent Legislative Expansions
California continues to expand the scope of biometric-adjacent protections through new legislation.
SB 1223: Neural Data Protection (Effective January 1, 2025)
SB 1223 added "neural data" to the definition of sensitive personal information under Section 1798.140(ae). Neural data means information generated by measuring the activity of a consumer's central or peripheral nervous system, and that is not inferred from non-neural information.
This gives brainwave data from EEG headsets, neurofeedback devices, and brain-computer interfaces the same level of protection as fingerprints and facial scans. California became the first state to explicitly protect neural data under a consumer privacy law.
AB 1008: AI Model Coverage (Effective January 1, 2025)
AB 1008 clarified that biometric data collected without a consumer's knowledge can never be considered "publicly available" information, regardless of context. The bill also expanded the definition of "personal information" to cover abstract digital formats, including AI model weights and tokens derived from a consumer's personal data.
For biometric data specifically, this means a facial recognition model trained on a consumer's face images without their knowledge cannot claim that data was "publicly available" and therefore exempt from CCPA requirements.
How California Compares to Illinois BIPA
California's approach differs significantly from Illinois's Biometric Information Privacy Act (BIPA), which is the most aggressive standalone biometric privacy law in the country.
| Feature | California (CCPA/CPRA) | Illinois (BIPA) |
|---|---|---|
| Law Type | Comprehensive privacy law | Standalone biometric statute |
| Consent Required | Notice + right to limit use | Written informed consent before collection |
| Private Right of Action | Data breaches only (1798.150) | Any violation of the statute |
| Damages | $100-$750 per breach incident | $1,000-$5,000 per violation |
| Retention/Destruction | General deletion rights | Mandatory written retention policy |
| Enforcement | CPPA + AG + limited private action | Private lawsuits + AG |
California provides broader coverage since biometric protections are part of a comprehensive data privacy framework. However, the private right of action is far more limited than Illinois, where individual plaintiffs have driven billions of dollars in settlements.
Sources and References
This article references California statutes, regulatory materials, and official agency publications. For the full text of the CCPA/CPRA, visit the California Legislative Information website. For current CPPA enforcement activity and rulemaking, visit cppa.ca.gov.
This article provides general legal information about California biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official California government sources.
More California Laws
Frequently Asked Questions
Does California have a biometric privacy law like Illinois BIPA?
No. California does not have a standalone biometric privacy statute. Instead, biometric data is protected as 'sensitive personal information' under the CCPA/CPRA (Cal. Civ. Code 1798.100 et seq.). This gives consumers the right to know what biometric data is collected, request deletion, limit its use, and opt out of its sale. The protections are comprehensive but embedded within the broader privacy law rather than existing as a separate biometric-specific statute.
Can I sue a company in California for collecting my fingerprints without consent?
The private right of action under Cal. Civ. Code 1798.150 is limited to data breach scenarios where a business failed to maintain reasonable security and your unencrypted biometric data was exposed. You cannot sue under the CCPA simply for collecting biometric data without adequate notice. For non-breach violations, you would need to file a complaint with the CPPA or the Attorney General, who can pursue enforcement on your behalf.
What biometric data do California employers need to protect?
Since the employee exemption expired on January 1, 2023, California employers must treat employee biometric data the same as consumer biometric data under the CCPA/CPRA. This includes fingerprints from time clocks, facial scans for access control, and voiceprints. Employers must provide notice before collection, honor deletion and access requests, and allow employees to limit the use of their biometric data. California Labor Code 1051 separately makes it a misdemeanor to condition a job on being photographed or fingerprinted by a third party that intends to furnish that data to another employer to the worker's detriment.
What are the penalties for mishandling biometric data in California?
The CPPA can impose fines of $2,663 per unintentional violation and $7,988 per intentional violation or violations involving minors (2025 amounts, adjusted annually). For data breaches involving biometric data, consumers can sue for $100 to $750 per incident per consumer under Cal. Civ. Code 1798.150. The Attorney General can also bring civil enforcement actions. Employers who condition employment on photographing or fingerprinting by a third party intending to furnish that data to another employer, in violation of Labor Code 1051, face misdemeanor charges.
Does California law cover facial recognition and AI-based biometric systems?
Yes. The CCPA covers biometric data extracted from facial recognition technology, and photographs stored for facial recognition purposes qualify as biometric information. AB 1008 (effective January 2025) clarified that biometric data collected without a consumer's knowledge cannot be classified as publicly available, closing a potential loophole for facial recognition systems. New CPPA regulations effective January 1, 2026, impose additional requirements on automated decisionmaking technology that processes biometric data for profiling or identity verification.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the Labor Code 1051 description (it is a narrow anti-blacklisting provision about third-party fingerprinting as a condition of employment, not a general ban on employers sharing internally-collected biometric data) and fixed the CCPA breach-notice bullet that presented the optional biometric cross-notification instruction (Civ. Code 1798.82(d)(3)(C)) as mandatory.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 5 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
California Civil Code
§ 1798.140In forcecited in 3 of our articles
Definitions For purposes of this title: (a) “Advertising and marketing” means a communication by a business or a person acting on the business’ behalf in any medium intended to induce a consumer to obtain goods, services, or employment. (b) “Aggregate consumer information” means information that relates to a group or category of consumers, from which individual consumer identities have been removed, that is not linked or reasonably linkable to any consumer or household, including via a device. “Aggregate consumer information” does not mean one or more individual consumer records that have been deidentified. (c) “Biometric information” means an individual’s physiological, biological, or behavioral characteristics, including information pertaining to an individual’s deoxyribonucleic acid (DNA), that is used or is intended to be used singly or in combination with each other or with other identifying data, to establish individual identity.
Official text (excerpt) · as of 2026-07-28 · Read the full section at leginfo.legislature.ca.gov
Also relied on in: Biometric Privacy Laws by State (2026): BIPA, CUBI & Consent, California Data Privacy Laws: CCPA, CPRA & Consumer Rights (2026)
§ 1798.150In forcecited in 5 of our articles
Personal Information Security Breaches (a) (1) Any consumer whose nonencrypted and nonredacted personal information, as defined in subparagraph (A) of paragraph (1) of subdivision (d) of Section 1798.81.5, or whose email address in combination with a password or security question and answer that would permit access to the account is subject to an unauthorized access and exfiltration, theft, or disclosure as a result of the business’ violation of the duty to implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information may institute a civil action for any of the following: (A) To recover damages in an amount not less than one hundred dollars ($100) and not greater than seven hundred and fifty ($750) per consumer per incident or actual damages, whichever is greater. The amounts in this subdivision shall be adjusted pursuant to subdivision (d) of Section 1798.199.95. (B) Injunctive or declaratory relief. (C) Any other relief the court deems proper.
Official text (excerpt) · as of 2026-07-28 · Read the full section at leginfo.legislature.ca.gov
Also relied on in: California Data Breach Notification Laws: Reporting Rules & Timelines (2026), What Is CCPA? California Consumer Privacy Act Explained (2026), GDPR vs CCPA: Key Differences Explained (2026)
§ 1798.29In forcecited in 2 of our articles
(a) Any agency that owns or licenses computerized data that includes personal information shall disclose any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of California (1) whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, or, (2) whose encrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the encryption key or security credential was, or is reasonably believed to have been, acquired by an unauthorized person and the agency that owns or licenses the encrypted information has a reasonable belief that the encryption key or security credential could render that personal information readable or usable. The disclosure shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subdivision (c), or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
Official text (excerpt) · as of 2026-07-28 · Read the full section at leginfo.legislature.ca.gov
§ 1798.82In forcecited in 3 of our articles
(a) (1) An individual or business that conducts business in California, and that owns or licenses computerized data that includes personal information, shall disclose a breach of the security of the system following discovery or notification of the breach in the security of the data to a resident of California whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, or whose encrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the encryption key or security credential was, or is reasonably believed to have been, acquired by an unauthorized person, and the person or business that owns or licenses the encrypted information has a reasonable belief that the encryption key or security credential could render that personal information readable or usable. (2) (A) Subject to subparagraph (B), the disclosure required by this subdivision shall be made within 30 calendar days of discovery or notification of the data breach.
Official text (excerpt) · as of 2026-07-28 · Read the full section at leginfo.legislature.ca.gov
California Labor Code
§ 1051In force
Except as provided in Section 1057, any person or agent or officer thereof, who requires, as a condition precedent to securing or retaining employment, that an employee or applicant for employment be photographed or fingerprinted by any person who desires his or her photograph or fingerprints for the purpose of furnishing the same or information concerning the same or concerning the employee or applicant for employment to any other employer or third person, and these photographs and fingerprints could be used to the detriment of the employee or applicant for employment is guilty of a misdemeanor.
Official text (excerpt) · as of 2026-07-28 · Read the full section at leginfo.legislature.ca.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- California Consumer Privacy Act full text(leginfo.legislature.ca.gov).gov
- Cal. Civ. Code 1798.140 - CCPA Definitions including biometric information(leginfo.legislature.ca.gov).gov
- Cal. Civ. Code 1798.150 - Private right of action for data breaches(leginfo.legislature.ca.gov).gov
- Cal. Civ. Code 1798.82 - Breach notification requirements(leginfo.legislature.ca.gov).gov
- Cal. Civ. Code 1798.29 - Agency breach notification requirements(leginfo.legislature.ca.gov).gov
- California Labor Code Section 1051 - Employer fingerprint sharing prohibition(leginfo.legislature.ca.gov).gov
- SB 1223 - Neural data as sensitive personal information(leginfo.legislature.ca.gov).gov
- AB 1008 - AI model coverage and biometric data clarifications(leginfo.legislature.ca.gov).gov
- CPPA About Us - Agency authority and mission(cppa.ca.gov).gov
- CPPA 2025 penalty amount increases announcement(cppa.ca.gov).gov
- CPPA finalized ADMT, risk assessment, and cybersecurity audit regulations(cppa.ca.gov).gov
- CPPA Honda settlement enforcement action(cppa.ca.gov).gov
- CPPA Todd Snyder enforcement action(cppa.ca.gov).gov
- California Attorney General CCPA information(oag.ca.gov).gov
- OAG data breach reporting requirements(oag.ca.gov).gov