Only 3 of the 50 US states, Illinois, Texas, and Washington, have a dedicated biometric privacy statute in 2026, according to a fifty-state comparison published by RecordingLaw and confirmed against each state's own statute text. Just one of those three, Illinois' Biometric Information Privacy Act, actually requires a business to write down its retention and destruction schedule and make that policy publicly available. The other 17 states with comprehensive privacy laws fold biometric data into a broader "sensitive personal information" category instead of regulating it on its own.

How many US states legally require a written biometric privacy policy?

Which states require a written biometric privacy policy Illinois Texas Washington California

Three states have passed a law that names biometric data specifically, rather than treating it as one line item inside a general privacy statute. Illinois moved first in 2008 with BIPA, the country's toughest biometric law and the only one that lets an individual sue directly. Texas followed in 2009 with the Capture or Use of Biometric Identifier Act (CUBI), enforced only by the state Attorney General. Washington passed its own biometric identifier law in 2017, enforced through the state's Consumer Protection Act.

California, despite having the country's best-known comprehensive privacy law, has no dedicated biometric statute of its own; biometric data there is regulated only as a category of "sensitive personal information" under the CCPA and CPRA. Illinois sits at the opposite extreme: it has no comprehensive consumer privacy law at all, only BIPA, meaning the state with the toughest biometric rule has no general privacy law to go with it.

LawStateEnactedEnforcementPublic written policy requiredMax penalty
BIPA (740 ILCS 14)Illinois2008Private right of actionYes, retention schedule must be public$5,000 per violation
CUBI (Bus. & Com. Code 503.001)Texas2009Attorney General onlyNot required$25,000 per violation
RCW 19.375Washington2017Attorney General (Consumer Protection Act)Not required$7,500 per violation

Table 1: The entire list of dedicated US biometric privacy statutes as of 2026. Sources: 740 ILCS 14, Tex. Bus. & Com. Code 503.001, RCW 19.375.

Texas's penalty ceiling is the highest of the three precisely because individuals cannot sue under CUBI; a higher administrative penalty is meant to offset the lack of a private right of action. Illinois runs the opposite way: a lower per-violation ceiling paired with the ability for any affected person to bring a claim, which is why Illinois accounts for the overwhelming majority of US biometric privacy litigation even though its statutory damages are the smallest of the three. Any business capturing a fingerprint, face scan, or voiceprint in one of these three states needs that practice named in its privacy policy in the specific language each statute expects; a privacy policy generator built to name biometric identifiers as their own disclosed category closes that gap faster than editing a generic template.

Maximum penalty per biometric-data violation, by state law (USD) Texas CUBI25kUSDWashington RCW 19.3757,500USDIllinois BIPA5,000USD

Figure 1: Texas's Attorney-General-only penalty is the highest of the three, while Illinois pairs a lower ceiling with a private right of action. Sources: Tex. Bus. & Com. Code 503.001; RCW 19.375; 740 ILCS 14/20.

Do all state privacy laws treat biometric data as sensitive information?

Every one of the 20 US states with a comprehensive consumer privacy law in effect by 2026 defines biometric data as sensitive personal information, per RecordingLaw's 2026 state-by-state comparison. That list runs from California's original CCPA in 2020 through Indiana, Kentucky, and Rhode Island, the three newest laws that took effect on 1 January 2026. Naming biometric data as sensitive is close to universal; how a business is allowed to act on that classification is not.

Nineteen of the 20 states require a business to get affirmative opt-in consent before processing biometric data at all, meaning the default is no collection until the person says yes. California is the outlier: instead of requiring opt-in consent, the CCPA and CPRA give consumers an opt-out right to limit the use of sensitive personal information, so a California business can generally start processing biometric data first and stop only if the person exercises that right. Maryland goes a step further than either model and prohibits the sale of sensitive personal data outright, biometric identifiers included.

Consent model for biometric data among the 20 comprehensive state privacy laws (2026) 191Opt-in consent required19Opt-out right only (California)1

Figure 2: Nineteen of the 20 states default to no collection without consent; California defaults to collection unless the consumer opts out. Source: RecordingLaw's 2026 US state privacy law comparison.

California's own sensitive-data definition traces back to Civil Code Section 1798.140(ae), added by the CPRA and effective 1 January 2023, which names "the processing of biometric information... for the purpose of uniquely identifying a consumer" as one of the categories that qualifies. General privacy policy adoption still lags well behind these requirements to begin with: only 9.6% of homepage snapshots for websites ranked below 1 million even carry a detectable privacy policy link at all, long before the question of whether that policy names biometric data as its own category.

What does Illinois' BIPA actually require before you collect a fingerprint or face scan?

BIPA's structure is stricter than a simple disclosure requirement. Before a private entity in Illinois collects, captures, or otherwise obtains a person's biometric identifier, Section 15(b) requires written, informed consent from that specific person, not a blanket clause buried in a longer privacy policy. Section 15(a), separately, requires the entity to develop a written policy, made available to the public, establishing a retention schedule and guidelines for permanently destroying biometric identifiers.

Figure 3: The two-part test BIPA applies before and after biometric collection. Source: 740 ILCS 14/15.

The destruction deadline itself is a hard backstop, not just a best practice: BIPA requires permanent destruction of a biometric identifier within 3 years of the individual's last interaction with the entity, or sooner if the purpose for collecting it is satisfied first, whichever comes first. Texas's CUBI sets a shorter, purpose-based deadline of its own, requiring destruction within a reasonable time and no later than the first anniversary of the date the purpose for collection expires. Neither Texas's CUBI nor Washington's RCW 19.375 requires the retention schedule to be written into a standalone, publicly posted document the way BIPA does; both require consent and a destruction deadline without BIPA's separate public-policy mandate.

How has BIPA litigation changed since the 2024 damages-cap reform?

BIPA's private right of action is the reason Illinois dominates US biometric litigation, and a 2024 statutory change has already reshaped the volume of new cases. Trial lawyers filed 150 new BIPA class actions in 2025, down sharply from 427 in 2024, according to Duane Morris' 2026 Class Action Review. The drop followed an August 2024 amendment that capped damages at one violation per person per method of collection, rather than allowing damages to multiply with every individual scan, which had previously let a single company's fingerprint time clock generate hundreds of millions of dollars in potential exposure.

New BIPA class actions filed in Illinois, before and after the 2024 reform 2024 (pre-reform, full year)4272025 (post-reform, full year)150

Figure 4: New BIPA filings fell 65% the year after Illinois capped per-scan damages. Source: Duane Morris' 2026 Class Action Review, as reported by Legal Newsline.

Total settlement value fell alongside the filing count, from more than $206 million in 2024 to $136.6 million in 2025, per the same report. That decline is specific to Illinois' damages formula, not evidence that biometric litigation risk has disappeared: Texas's Attorney General retains sole enforcement power over CUBI with no comparable reform limiting penalty exposure, and Washington's law remains enforceable through Consumer Protection Act civil penalties regardless of what Illinois lawmakers changed.

How does GDPR's biometric data rule compare to US state law?

Outside the United States, GDPR sets a stricter default than any single American state law does on its own. Article 9(1) classifies biometric data processed "for the purpose of uniquely identifying a natural person" as a special category of personal data, and processing special category data is prohibited by default unless a business can point to one of a short, closed list of exceptions in Article 9(2), most commonly the individual's explicit consent.

Figure 5: Eighteen years separate Illinois' first-mover statute from a landscape where every comprehensive US state law treats biometric data as sensitive. Sources: 740 ILCS 14; Tex. Bus. & Com. Code 503.001; RCW 19.375; Cal. Civ. Code 1798.140; RecordingLaw's 2026 comparison.

RequirementGDPR (EU/UK)Illinois BIPAOther 19 opt-in sensitive-data states
Default before collectionProhibited absent an Article 9 exceptionAllowed with written consentAllowed with opt-in consent
Who can enforce itData protection authorities, plus court claimsAny affected individualState Attorney General only
Public retention policy requiredNo standalone requirementYes, Section 15(a)Not required

Table 2: No single US state law currently matches GDPR's default-prohibited posture for biometric data. Sources: gdpr-info.eu, 740 ILCS 14, RecordingLaw's 2026 comparison.

Regulators outside the US have already used that stricter default against a single company at scale. Clearview AI's facial-recognition database holds more than 30 billion scraped photos, and the Dutch Data Protection Authority fined the company 30.5 million euros in a decision dated 16 May 2024 for building that database without a lawful basis under GDPR. The UK's Information Commissioner's Office separately fined Clearview 7,552,800 pounds for the same underlying conduct, a penalty an Upper Tribunal reinstated in 2025 after ruling that UK GDPR applies to the company's processing of UK residents' data even without a UK office.

The Bottom Line

The honest answer to how many privacy policies cover biometric data starts with the law, not a scan of company websites: only 3 states require a dedicated biometric statute at all, and only Illinois requires the retention policy itself to exist as a public document. Every other state that touches biometric data does so by folding it into a broader sensitive-data category, with 19 of 20 comprehensive state laws now requiring opt-in consent before that data can be processed and California alone relying on an opt-out right instead. GDPR sets the strictest baseline of any jurisdiction covered here, prohibiting biometric processing by default until a business meets a specific legal exception. For a business collecting fingerprints, face scans, or voiceprints anywhere in the US, the safest assumption in 2026 is that biometric data needs its own named disclosure, its own consent language, and its own retention deadline, not a line buried inside a general "personal information" clause.

Frequently Asked Questions

How many US states require a written biometric privacy policy? Only 3 of the 50 US states, Illinois, Texas, and Washington, have a dedicated biometric privacy statute as of 2026, and Illinois' BIPA (740 ILCS 14) is the only one of the three that requires the retention and destruction schedule itself to be written down and made publicly available.

Do all state privacy laws treat biometric data as sensitive information? Yes. All 20 US states with a comprehensive consumer privacy law in effect by 2026 classify biometric data as sensitive personal information, per RecordingLaw's 2026 fifty-state comparison, though 19 of the 20 require affirmative opt-in consent before a business can process it, while California alone uses an opt-out right to limit instead.

What happens if a company violates Illinois' BIPA? An individual can sue directly for statutory damages of $1,000 per negligent violation or $5,000 per reckless or intentional violation, since BIPA is the only one of the three dedicated state biometric laws with a private right of action. Illinois recorded 150 new BIPA class actions in 2025, down from 427 in 2024, after an August 2024 damages-cap reform, per Duane Morris' 2026 Class Action Review.

Does GDPR require special protection for biometric data? Yes. GDPR Article 9 classifies biometric data processed to uniquely identify a person as a special category of personal data, meaning processing is prohibited by default unless a business meets one of a short list of exceptions such as explicit consent, a stricter default than any single US state law currently applies on its own.

Where the Numbers Come From

  1. Illinois General Assembly. Biometric Information Privacy Act, 740 ILCS 14. Written consent (Section 15(b)), public retention and destruction policy (Section 15(a)), statutory damages of $1,000 to $5,000 per violation (Section 20).
  2. Texas Constitution and Statutes. Business and Commerce Code Section 503.001, Capture or Use of Biometric Identifier Act. Enacted 2009, Attorney-General-only enforcement, penalties up to $25,000 per violation, destruction required within one year of purpose expiring.
  3. Washington State Legislature. Revised Code of Washington 19.375, Biometric Identifiers. Enacted 2017, notice and consent required before commercial enrollment, enforced through the state Consumer Protection Act.
  4. RecordingLaw. (2026). "US State Privacy Laws Comparison." 20 states with comprehensive privacy laws in effect by 2026, all classifying biometric data as sensitive personal information; 19 requiring opt-in consent, California using an opt-out model.
  5. LegiScan, California Legislature bill text. California Civil Code Section 1798.140(ae), defining sensitive personal information to include biometric information processed for unique identification, effective 1 January 2023 under the CPRA.
  6. gdpr-info.eu. General Data Protection Regulation, Article 9. Biometric data processed for unique identification classified as special category data, processing prohibited by default absent an Article 9(2) exception.
  7. Legal Newsline, reporting on Duane Morris' 2026 Class Action Review. (2026). 150 new BIPA class actions filed in 2025, down from 427 in 2024; settlement value $136.6 million in 2025 versus more than $206 million in 2024.
  8. Autoriteit Persoonsgegevens (Dutch DPA). (2024). "Decision fine Clearview AI." 30.5 million euro fine, decision dated 16 May 2024, database described as containing more than 30 billion photos.
  9. Stephenson Harwood, reporting on the UK Upper Tribunal ruling. (2025). "Information Commissioner v Clearview AI Inc." UK fine of 7,552,800 pounds reinstated on appeal.

Note: All figures verified as of August 2026. The 20-state count and the state-by-state consent-model breakdown come from RecordingLaw's 2026 comparison chart rather than an independent review of all 20 statutes by this publication; readers building a compliance program should confirm current statutory language directly. Figures are refreshed at least twice a year as state legislatures amend existing laws or pass new ones.