Biometric Privacy

Biometric Privacy Statutes Outside Illinois, and Who Gets to Enforce Them

Key Takeaways

  • Texas, Washington and Colorado all restrict the capture of biometric identifiers, and all three reserve enforcement to the state. Washington's RCW 19.375.030 says the chapter "may be enforced solely by the attorney general"; the Texas Attorney General's office describes its own authority under CUBI as exclusive.
  • Texas carries the largest recorded number in this area: a $1.4 billion settlement with Meta announced July 30, 2024, described by the Attorney General as the first settlement obtained under the Capture or Use of Biometric Identifier Act.
  • Washington's definition excludes a physical or digital photograph, video or audio recording, and any data generated from them — a carve-out with no counterpart in the Texas definition.
  • Colorado did not pass a standalone statute. House Bill 24-1130 amended the Colorado Privacy Act, adding a written-policy and retention-schedule duty and restricting when an employer may seek an employee's consent, effective July 1, 2025.
  • Texas requires destruction of a captured biometric identifier within a reasonable time and no later than one year after the purpose of collection has expired.

Three Statutes, One Structural Choice

The received wisdom that biometric privacy is an Illinois problem is half right. Illinois is where the litigation is. It is not where the only statute is.

Texas, Washington and Colorado each regulate biometric identifiers, and their substantive requirements — notice before capture, consent, limits on disclosure, a duty to destroy — would look familiar to anyone who has read the Illinois act. What differs is the enforcement clause, and it differs in all three the same way: the claim belongs to a state official rather than to the person whose biometrics were captured.

That is the organising fact of this guide. Read the three statutes with it in mind and much of what looks like drafting detail turns out to be a consequence of it: who the duties run to, how the penalties are denominated, and why the reported enforcement in these three states consists of a small number of very large matters rather than a large number of ordinary ones.

This guide covers those three states. It does not chart fifty. Most states have no biometric-specific statute, and several more address biometrics only as one entry in a comprehensive privacy law's list of sensitive data — a narrower treatment noted at the end of this guide rather than folded into the comparison as though it were equivalent.

Texas: Exclusive Authority and a $25,000 Unit

The Capture or Use of Biometric Identifier Act sits at Texas Business and Commerce Code section 503.001. The Texas Attorney General's published overview of the act sets out both the duties and the enforcement structure.

A biometric identifier under CUBI is "a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry." The act prohibits capturing one for a commercial purpose unless the person capturing it informs the individual and obtains consent before the capture. Four further duties attach to anyone who captures or possesses such an identifier:

  • No sale, lease or other disclosure of the identifier, except to law enforcement in response to a warrant, to complete a financial transaction, or to identify an individual in the event of their disappearance or death where the individual consents
  • Reasonable care in maintaining and transmitting the identifier to protect it from disclosure
  • Destruction within a reasonable time following capture, and no later than one year after the purpose of collection has expired, unless an exception applies
  • Notice and consent obtained before the capture rather than at any later point

On enforcement the Attorney General's office is unambiguous: it "has exclusive authority to enforce CUBI and may obtain relief including civil penalties of up to $25,000 per violation."

A per-violation figure of that size, multiplied across a consumer population and pursued by a state with subpoena power, produces numbers that no individual claim reaches. In July 2024 the office announced a $1.4 billion settlement with Meta, payable over five years, describing it as the first lawsuit brought and first settlement obtained under CUBI. The underlying allegation was that from 2011 the company ran facial recognition software on photographs uploaded to Facebook — capturing records of facial geometry — after automatically enabling a tagging feature for Texas users without explaining how it worked. The release characterised the amount as the largest settlement ever obtained from an action brought by a single state.

Washington: A Narrower Definition, the Same Monopoly

Washington's chapter, RCW 19.375, was enacted in 2017 and is built around a different verb. Where Texas regulates capture, Washington regulates enrolment — defined at RCW 19.375.010(5) as capturing an identifier, converting it into a reference template that cannot be reconstructed into the original image, and storing it in a database that matches it to a specific individual.

RCW 19.375.020(1) provides that a person may not enrol a biometric identifier in a database for a commercial purpose without first providing notice, obtaining consent, or providing a mechanism to prevent the subsequent commercial use of the identifier. Subsection (3) restricts onward disclosure absent consent, with an exception for disclosure to a third party who contractually promises not to disclose it further or enrol it inconsistently with the original notice. Subsection (5) prohibits using or disclosing an identifier in a manner materially inconsistent with the terms under which it was originally provided, without consent to the new terms.

Two definitional limits narrow the chapter considerably, and neither has a Texas counterpart.

The first is the photograph exclusion. RCW 19.375.010(1) states that a biometric identifier "does not include a physical or digital photograph, video or audio recording or data generated therefrom." A statute that excludes data generated from a photograph reaches a materially smaller set of practices than one whose enumerated list includes a record of face geometry however derived.

The second is the definition of commercial purpose at RCW 19.375.010(4), which covers sale or disclosure to a third party for marketing goods or services unrelated to the initial transaction, and which expressly "does not include a security or law enforcement purpose." RCW 19.375.020(7) reinforces the point: nothing in the section requires notice and consent to collect, capture or enrol a biometric identifier in furtherance of a security purpose, and "security purpose" is itself defined broadly at subsection (8) to include preventing shoplifting, fraud and other misappropriation.

RCW 19.375.040 then excludes financial institutions subject to Title V of Gramm-Leach-Bliley and activities subject to the federal health insurance rules, and provides that the chapter neither expands nor limits a law enforcement officer's authority. RCW 19.375.030 supplies the enforcement answer: violations are unfair or deceptive acts for the purpose of the state Consumer Protection Act, and the chapter "may be enforced solely by the attorney general" under that act.

Colorado: Folded Into a Comprehensive Statute Instead

Colorado took the third available route, which is not to write a biometric statute at all. House Bill 24-1130, titled "Privacy of Biometric Identifiers & Data" and concerning "protecting the privacy of an individual's biometric data," amended the existing Colorado Privacy Act. The legislature's summary of the act as enacted records an effective date of July 1, 2025.

The act requires a controller of biometric identifiers to adopt a written policy that establishes a retention schedule for biometric identifiers and biometric data, includes a protocol for responding to a data security incident that may compromise their security, and includes guidelines requiring deletion of a biometric identifier on or before certain dates. It prohibits collecting a biometric identifier unless the controller first satisfies disclosure and consent requirements, imposes further requirements on controllers that process such data, requires disclosure to consumers about collection and use, and authorises the Attorney General to promulgate implementing rules.

One clause in that summary is worth isolating because it addresses the setting where biometric collection is most routine and consent least meaningful: the act "restricts an employer's permissible reasons for obtaining an employee's consent for the collection of biometric identifiers." A statute that limits the grounds on which consent may even be sought is doing something a notice-and-consent regime cannot, since in an employment relationship the request itself carries pressure.

Placing the duties inside the Colorado Privacy Act rather than in a standalone chapter also settles the enforcement question by inheritance: the biometric provisions arrive attached to that act's existing enforcement structure rather than carrying a new private claim of their own.

How Long the Data May Be Kept, and on What Terms

Retention is where the three statutes are most concrete, and where they diverge in an instructive way: Texas sets a deadline, Washington sets a purpose test, and Colorado requires the controller to write its own schedule.

Texas is the only one of the three to name a period. Under the Attorney General's account of CUBI, a captured biometric identifier is destroyed within a reasonable time after capture and no later than one year after the purpose of collection has expired. There is an outer limit that can be measured against a calendar.

Washington instead ties retention to necessity. RCW 19.375.020(4) provides that a person who knowingly possesses an enrolled biometric identifier must take reasonable care to guard against unauthorized access and acquisition, and may retain the identifier no longer than reasonably necessary to comply with a court order, statute or public records retention schedule; to protect against or prevent actual or potential fraud, criminal activity, claims, security threats or liability; and to provide the services for which the identifier was enrolled. The permitted grounds are broad enough that the practical limit depends heavily on what an entity says it needs the template for.

Subsection (6) then removes both the disclosure and retention limits for identifiers that have been unenrolled — so the chapter's restrictions attach to the enrolled template rather than to the underlying biological fact.

Washington's disclosure exceptions at RCW 19.375.020(3) are similarly enumerated rather than open-ended. Absent consent, a disclosure for a commercial purpose is permitted where it is necessary to provide a product or service the individual requested; necessary to effect, administer, enforce or complete a financial transaction the individual initiated, where the recipient maintains confidentiality and does not further disclose; required or expressly authorized by statute or court order; made to a third party who contractually promises no further disclosure and no inconsistent enrolment; or made to prepare for litigation or to respond to or participate in judicial process.

Colorado's approach shifts the work to the controller. Rather than legislating a period, House Bill 24-1130 requires a written policy that establishes a retention schedule and includes guidelines requiring deletion of a biometric identifier on or before certain dates. The obligation is to have a defensible schedule and follow it, which is a documentation duty as much as a data-handling one.

One further Washington provision is worth quoting because it declines to specify: RCW 19.375.020(2) states that notice is a disclosure, not considered affirmative consent, given through a procedure reasonably designed to be readily available to affected individuals, and that "the exact notice and type of consent required to achieve compliance with subsection (1) of this section is context-dependent." The legislature's stated intent, recorded at RCW 19.375.900, was that a business collecting attributable biometric data disclose how it uses that data and obtain consent before enrolling or changing the use of an identifier.

Why the Litigation Is Somewhere Else

Set the three statutes side by side and the substantive obligations converge more than they diverge. Notice before collection, consent, constrained disclosure, a retention limit and a destruction duty appear in all three in some form. If the duties are broadly similar, the volume of litigation ought to be broadly similar too. It is not, and the reason is procedural rather than substantive.

Illinois attached a private right of action to its biometric statute. Texas, Washington and Colorado did not. The consequence is not that biometric collection goes unchallenged in those three states — the Meta settlement is larger than any single Illinois judgment — but that a challenge requires a state official to choose to bring it.

That produces a different distribution of enforcement. Claims are fewer, larger, and concentrated on defendants big enough to justify a multi-year state action. Conduct affecting a small number of people, or a defendant too small to be worth an attorney general's docket, generates no case at all. The Illinois pattern — many suits, many defendants, most of them ordinary employers running fingerprint time clocks — has no analogue in a state where the only available plaintiff is the government.

Anyone comparing exposure across these states is therefore comparing two different variables at once: what the statute forbids, and who is in a position to complain about it. The second has done more to shape the reported record than the first.

Where This Survey Stops

Three states are described here because three are what the research behind this guide could read in a source it retrieved and read in full. That is a survey of the states with a dedicated biometric regime that the session could source, not a claim that no other state addresses biometrics.

Several comprehensive state privacy statutes list biometric data among their sensitive-data categories and condition its processing on consent. That treatment is real but it is not equivalent to the statutes above: it typically attaches only where the controller meets the comprehensive law's applicability thresholds, and it defines biometric data by reference to identification rather than by an enumerated list of modalities. Those provisions are covered in this site's comparison of the comprehensive statutes rather than being merged into the table here, where they would suggest a uniformity that does not exist.

This guide also does not describe the Illinois act. Illinois is the subject of a separate guide on this site, and the comparison drawn above deliberately uses Illinois only as the contrasting case on enforcement design rather than restating its requirements.

Finally, facial recognition is addressed here only as one modality within these statutes — a record of face geometry under the Texas definition, and an exclusion under Washington's. The distinct body of law governing facial recognition specifically, including government and law enforcement deployment, is covered separately.

Frequently Asked Questions

Can an individual sue a company under the Texas or Washington biometric statutes?
Neither statute provides for it. RCW 19.375.030(2) states that the Washington chapter "may be enforced solely by the attorney general" under the state Consumer Protection Act, and the Texas Attorney General's office describes its authority to enforce CUBI as exclusive, with civil penalties of up to $25,000 per violation.
Does a photograph count as a biometric identifier?
It depends on the state. Washington's RCW 19.375.010(1) expressly excludes a physical or digital photograph, video or audio recording, and data generated from them. The Texas definition enumerates a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry, without a parallel photograph carve-out.
How long may a company keep a biometric identifier in Texas?
The Attorney General's overview of CUBI states that a captured biometric identifier is to be destroyed within a reasonable time following capture and no later than one year after the purpose of its collection has expired, unless an exception applies.
What did Colorado's House Bill 24-1130 change?
It amended the Colorado Privacy Act rather than creating a standalone statute. Per the legislature's summary of the enacted act, it requires controllers of biometric identifiers to adopt a written policy with a retention schedule, incident protocol and deletion guidelines, conditions collection on disclosure and consent, and restricts an employer's permissible reasons for seeking an employee's consent. It took effect July 1, 2025.
Does a security or anti-theft use trigger the Washington notice requirement?
RCW 19.375.020(7) provides that nothing in the section requires notice and consent to collect, capture or enrol a biometric identifier in furtherance of a security purpose, and RCW 19.375.010(8) defines security purpose to include preventing shoplifting, fraud, and other misappropriation or theft.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.