District of Columbia
District of Columbia Biometric Privacy Laws: Collection, Consent & Penalties (2026)

The District of Columbia has no standalone biometric privacy law. DC Code 28-3851 classifies fingerprints, iris scans, and voice prints as personal information protected under the breach notification statute, which requires organizations to notify residents and the Attorney General after a breach. DC imposes no consent requirement before collecting biometric data.
The District of Columbia protects biometric data through its breach notification framework rather than a dedicated biometric privacy law. If your fingerprint, facial scan, or iris image is compromised in a data breach, DC law requires the organization holding that data to notify you and the Attorney General. But DC does not require businesses to get your permission before collecting biometric data in the first place.
This guide explains how DC law defines and protects biometric information, what rights you have when a breach occurs, how enforcement works, and where the District stands compared to states with stronger biometric privacy protections. For the full picture of DC privacy rules, see the parent guide on District of Columbia Data Privacy Laws.
How DC Law Defines Biometric Data
DC Code 28-3851 defines biometric data as information "generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, voice print, genetic print, retina or iris image, or other unique biological characteristic, that is used to uniquely authenticate the individual's identity when the individual accesses a system or account."
That definition covers a range of identifiers:
- Fingerprints and palm prints
- Retina and iris scans
- Voice prints
- Genetic prints
- Other unique biological characteristics used for authentication
One important limitation: the definition applies only to biometric data used "to uniquely authenticate" an individual's identity. Biometric data collected for purposes other than authentication, such as emotion detection or gait analysis, may fall outside this definition.
Biometric data is classified as "personal information" under the statute. That means it receives the same breach notification protections as Social Security numbers, driver's license numbers, and financial account information.
Breach Notification Requirements for Biometric Data

The Security Breach Protection Amendment Act of 2020 (D.C. Law 23-98), which took effect on June 17, 2020, significantly strengthened DC's breach notification requirements. Under DC Code 28-3852, any person or entity that conducts business in DC and discovers a breach involving biometric data must:
Notify affected residents. The notification must happen "in the most expedient time possible and without unreasonable delay." The notice must describe the categories of information compromised, provide contact details for the notifying entity, and include information about consumer reporting agencies, credit freezes, the FTC, and the DC Attorney General.
Report to the Attorney General. If the breach affects 50 or more DC residents, the entity must send written notice to the Office of the Attorney General at the same time it notifies residents.
Alert consumer reporting agencies. When 1,000 or more individuals are notified, the entity must also inform nationwide consumer reporting agencies about the breach timing and scope.
Security Requirements for Biometric Data
DC Code 28-3852.01 requires any entity that possesses personal information of DC residents, including biometric data, to "implement and maintain reasonable security safeguards, including procedures and practices that are appropriate to the nature of the personal information."
This standard applies broadly:
- Entities must assess the sensitivity of the data they hold and apply proportionate safeguards
- Third-party service providers must be bound by written agreements requiring them to maintain reasonable security procedures
- When destroying records containing biometric data, organizations must take reasonable steps to prevent unauthorized access, considering the sensitivity of the records, business size, available technology, and cost
Entities that comply with federal data security regulations under HIPAA, the HITECH Act, or the Gramm-Leach-Bliley Act are deemed to satisfy DC's security requirements under a safe harbor provision.
Enforcement and Penalties
DC Code 28-3853 classifies any violation of the breach notification subchapter as an unfair or deceptive trade practice under DC Code 28-3904. This classification opens two enforcement paths.
Consumer lawsuits. Individuals harmed by a breach notification violation can sue and recover treble damages or $1,500 per violation, whichever is greater. For violations of the data security requirements specifically (Section 28-3852.01), consumers may recover actual damages.
Attorney General enforcement. The DC Attorney General can bring actions in DC Superior Court seeking injunctive relief and restitution without having to prove damages. The AG's office has actively pursued data breach enforcement, including a settlement of over $350,000 against software firm Blackbaud in a multistate action involving a breach that affected nonprofits and schools.
The rights and remedies are cumulative, meaning consumers can pursue claims under both the breach notification statute and other applicable laws simultaneously.
What DC Law Does Not Cover

Unlike Illinois, Texas, and Washington, the District of Columbia does not have a standalone biometric privacy statute. This means DC law currently has no requirement for:
- Informed consent before collection. Businesses can collect fingerprints, facial geometry, or iris scans from DC residents without notice or consent, as long as no breach occurs.
- Written biometric data policies. There is no obligation to publish a retention schedule or destruction policy for biometric data.
- Purpose limitations. Organizations face no restrictions on how they use biometric data once collected.
- Sale or sharing restrictions. DC law does not prohibit selling biometric data to third parties.
- Private right of action for collection. You cannot sue a company simply for collecting your biometric data without permission. Legal action is available only after a breach or a failure to notify.
For DC residents, this gap means that the law kicks in after something goes wrong, not before.
Employer Use of Biometric Data in DC

DC employers increasingly use fingerprint scanners, facial recognition, and other biometric tools for timekeeping and building access. Because the District lacks a dedicated biometric privacy statute, employers have broad latitude to implement these systems.
No DC-specific law requires employers to:
- Inform employees before collecting biometric data
- Obtain written consent for fingerprint or facial recognition use
- Publish a biometric data retention and destruction policy
- Limit the use of collected biometric data to stated purposes
However, employers must still maintain reasonable security safeguards for any biometric data they hold under DC Code 28-3852.01. A breach of employee biometric data would trigger the same notification obligations and potential penalties as any other breach of personal information.
Employers subject to federal regulations such as HIPAA in healthcare settings may face additional biometric data obligations beyond DC law.
Pending Legislation and Future Outlook
The DC Council has shown interest in expanding data privacy protections beyond breach notification. The Personal Health Data Security Amendment Act of 2025 (Bill 26-0525), introduced in December 2025, would require consent before collecting personal health data, establish deletion rights, and prohibit geofencing around health care facilities. While this bill focuses on health data rather than biometrics specifically, its consent and deletion framework signals a potential direction for future DC privacy legislation.
As of March 2026, the bill had progressed to a roundtable hearing in the DC Council. No standalone biometric privacy bill has been introduced in the current (26th) Council session.
The national trend is moving toward stronger biometric protections. Over a dozen states now have comprehensive privacy laws that cover biometric data, and dedicated biometric privacy statutes continue to proliferate. DC residents and businesses should monitor the Council for future legislation that may impose consent requirements, retention limits, or a private right of action for biometric data collection.
This article provides general legal information about District of Columbia biometric privacy laws and is not legal advice. Biometric privacy law is evolving rapidly at the state and federal level. Consult a licensed attorney in DC for guidance on your specific situation.
Frequently Asked Questions
Does DC require consent before collecting fingerprints or facial recognition data?
No. The District of Columbia does not have a law requiring consent before collecting biometric data. DC law protects biometric information only through its breach notification statute (DC Code 28-3851 et seq.), which imposes obligations after a data breach occurs, not at the point of collection.
What happens if a company loses my biometric data in a breach?
The company must notify you without unreasonable delay, describing what information was compromised and providing contact information for the company, consumer reporting agencies, the FTC, and the DC Attorney General. If the breach affects 50 or more DC residents, the company must also report it to the Attorney General. You can sue for treble damages or $1,500 per violation, whichever is greater.
Can my employer require me to use a fingerprint scanner for timekeeping in DC?
Yes. DC has no law that prevents employers from requiring biometric data collection for timekeeping, building access, or other workplace purposes. Employers must maintain reasonable security safeguards for that data, and a breach would trigger notification obligations, but there is no consent requirement for initial collection.
How does DC compare to Illinois for biometric privacy protection?
DC offers significantly less protection. Illinois BIPA requires informed written consent before collecting biometric data, mandates written retention and destruction policies, prohibits the sale of biometric data, and provides a private right of action for any violation. DC law only addresses biometric data in the breach notification context, with no consent, retention, or purpose limitation requirements.
Can I sue a company in DC for collecting my biometric data without permission?
No. DC law does not provide a cause of action for collecting biometric data without consent. Legal remedies are available only when a company fails to notify you after a breach involving your biometric data, or when it fails to maintain reasonable security safeguards. A violation of these requirements is treated as an unfair or deceptive trade practice.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 4 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Code of the District of Columbia, Title 28: Commercial Instruments and Transactions. - Chapter 38: Consumer Protections. - Subchapter II: Consumer Security Breach Notification.
§ 28-3851Definitions.In forcecited in 4 of our articles
For purposes of this subchapter, the term: (A) "Breach of the security of the system" means unauthorized acquisition of computerized or other electronic data or any equipment or device storing such data that compromises the security, confidentiality, or integrity of personal information maintained by the person or entity who conducts business in the District of Columbia. (B) The term "breach of the security of the system" does not include: (i) A good-faith acquisition of personal information by an employee or agency of the person or entity for the purposes of the person or entity if the personal information is not used improperly or subject to further unauthorized disclosure; (ii) Acquisition of data that has been rendered secure, including through encryption or redaction of such data, so as to be unusable by an unauthorized third party unless any information obtained has the potential to compromise the effectiveness of the security protection preventing unauthorized access; or (iii) Acquisition of personal information of an individual that the person or entity reasonably determines, after a reasonable investigation and consultation with the Office of the Attorney General for…
Official text (excerpt) · as of 2026-07-30 · Read the full section at github.com
Also relied on in: District of Columbia Data Privacy Laws: Breach Rules & Consumer Rights (2026), District of Columbia Data Breach Notification Laws: Reporting Rules & Timelines (2026), DC Employee Monitoring Laws: Notice, GPS, and Privacy Rules (2026)
§ 28-3852Notification of security breach.In forcecited in 4 of our articles
(a) Any person or entity who conducts business in the District of Columbia, and who, in the course of such business, owns or licenses computerized or other electronic data that includes personal information, and who discovers a breach of the security of the system, shall promptly notify any District of Columbia resident whose personal information was included in the breach. The notification shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (d) of this section, and with any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
Official text (excerpt) · as of 2026-07-30 · Read the full section at github.com
§ 28-3853Enforcement.In forcecited in 3 of our articles
(a) [Repealed]. (b) A violation of this subchapter, or any rule issued pursuant to the authority of this subchapter, is an unfair or deceptive trade practice pursuant to § 28-3904(kk). (c) The rights and remedies available under this section are cumulative to each other and to any other rights and remedies available under law.
Official text (excerpt) · as of 2026-07-30 · Read the full section at github.com
Code of the District of Columbia, Title 28: Commercial Instruments and Transactions. - Chapter 39: Consumer Protection Procedures.
§ 28-3904Unfair or deceptive trade practices.In forcecited in 2 of our articles
It shall be a violation of this chapter for any person to engage in an unfair or deceptive trade practice, whether or not any consumer is in fact misled, deceived, or damaged thereby, including to: (a) represent that goods or services have a source, sponsorship, approval, certification, accessories, characteristics, ingredients, uses, benefits, or quantities that they do not have; (b) represent that the person has a sponsorship, approval, status, affiliation, certification, or connection that the person does not have; (c) represent that goods are original or new if in fact they are deteriorated, altered, reconditioned, reclaimed, or second hand, or have been used; (d) represent that goods or services are of particular standard, quality, grade, style, or model, if in fact they are of another; (e) misrepresent as to a material fact which has a tendency to mislead; (e-1) represent that a transaction confers or involves rights, remedies, or obligations which it does not have or involve, or which are prohibited by law; (f) fail to state a material fact if such failure tends to mislead; (f-1) use innuendo or ambiguity as to a material fact, which has a tendency to mislead; (g)…
Official text (excerpt) · as of 2026-07-30 · Read the full section at github.com
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- DC Code 28-3851 - Definitions (biometric data definition)(code.dccouncil.gov).gov
- DC Code 28-3852 - Notification of security breach(code.dccouncil.gov).gov
- DC Code 28-3852.01 - Security requirements(code.dccouncil.gov).gov
- DC Code 28-3852.02 - Remedies(code.dccouncil.gov).gov
- DC Code 28-3853 - Enforcement(code.dccouncil.gov).gov
- DC Code 28-3904 - Unfair or deceptive trade practices(code.dccouncil.gov).gov
- Security Breach Protection Amendment Act of 2020 (D.C. Law 23-98)(code.dccouncil.gov).gov
- DC Attorney General - Consumer Alert: Online Privacy(oag.dc.gov).gov
- AG Schwalb secures over $350,000 from Blackbaud for data breach(oag.dc.gov).gov
- Personal Health Data Security Amendment Act of 2025 (B26-0525)(legiscan.com)