livelaw

Explainers

How Long Can a Company Legally Keep Your Voiceprint Data?

If your voiceprint was legally collected, how long can a company keep it? The answer isn’t just about whether they got your consent—it’s about a separate legal duty to destroy the data on a fixed schedule, even if the recording is still useful for your case or marketing.

Key facts

  • ·Illinois law requires companies to delete biometric data—including voiceprints—within 3 years of the individual's last interaction with the entity or when the original reason for collecting it is done, whichever comes first.
  • ·That deletion deadline starts automatically, even if the company collected your voiceprint with full permission.
  • ·Companies must publish a written schedule explaining exactly when and how they will destroy biometric data, and they must follow it.
  • ·Breaking the deletion schedule can lead to lawsuits under Illinois law for violations of the retention duty, separate from whether the original collection was legal.
  • ·Other states have biometric laws, but only Illinois allows individuals to sue over violations of the deletion schedule itself. States like Texas and Washington impose retention duties without a private right of action.
  • ·General state privacy laws add another layer, requiring companies to limit how long they keep sensitive data like voiceprints, even if no biometric law applies.

Most people assume that once a company has permission to collect your voiceprint, they can keep it as long as they want. But Illinois law treats retention as a separate legal duty. It says companies must destroy biometric data—including voiceprints—when the initial purpose for collecting or obtaining such identifiers or information has been satisfied, or within 3 years of the individual's last interaction with the entity, whichever occurs first. This rule applies even if the company got your consent to collect the data in the first place. The law also requires companies to create and publish a written retention schedule that explains exactly when and how they will destroy the data. This schedule must be publicly available. The point is straightforward: consent to collect does not excuse indefinite storage. The destruction clock starts automatically after your last interaction, and the company must follow through, regardless of whether the voiceprint is still useful for marketing, analytics, or other purposes.

Why Illinois stands out: a private right to sue over retention

Most states with biometric laws govern consent to collect the data. Illinois goes further by adding a separate rule about how long the data can be kept. The law requires companies to follow their published retention schedule and destroy biometric data on time. If they don’t, Illinois allows individuals to sue for violations of this destruction duty, even if the original collection was lawful. This is different from states like Texas and Washington, which impose retention duties without giving individuals the power to sue over them. In Illinois, the destruction duty is enforceable in court, making it one of the few places where a company can be sued for keeping data too long, not just for collecting it without permission.

How the destruction clock actually works in practice

The three-year countdown begins after your last interaction with the company, not when the voiceprint was first collected. For example, if you last used a voice-activated app on March 15, 2025, the company must destroy your voiceprint by March 15, 2028, unless the original purpose for collecting it—like verifying your identity for that app—was already satisfied earlier. The law also says the company must destroy the data when the purpose is met, even if that happens before three years are up. Companies must publish a retention schedule that states these deadlines clearly. If they change how they use the data, they may need to update the schedule and shorten the destruction timeline accordingly. The key takeaway is that the clock is fixed and automatic—it doesn’t pause for investigations, litigation, or business needs.

When general privacy laws add another layer of limits

Even in states without a specific biometric law, broader privacy statutes can impose storage limits on sensitive data like voiceprints. These laws require companies to limit retention to what is necessary for the original purpose. While they don’t always set a hard deadline like Illinois does, they do require companies to justify keeping voiceprints long after the original purpose is met. For example, a company might argue it needs to keep voiceprints for fraud prevention, but regulators or courts could decide that storage is no longer necessary once the risk has passed. This means companies operating in multiple states must check both biometric-specific laws and general privacy laws to determine the shortest possible retention period that complies everywhere.

The conflict with litigation holds: what happens when the law says destroy but the case isn’t over?

A common edge case arises when a company is legally required to destroy a voiceprint under Illinois law, but the same voiceprint is also subject to a litigation hold because it’s evidence in an open lawsuit. Illinois law requires destruction on schedule, even if the data is potentially relevant to pending litigation. This creates a direct conflict: follow the law and destroy the data, or keep it for the lawsuit and risk violating the retention duty. Companies in this situation often face a tough choice—seek a protective order, negotiate with opposing counsel, or risk exposure under Illinois law. The destruction duty does not yield to litigation needs, so companies must plan ahead to avoid being caught between these obligations.

What counts as a voiceprint under these rules?

The law defines biometric identifiers as data generated by measurements of a person’s unique biological characteristics. Voiceprints—digital representations of a person’s voice—are included in this definition. The key is whether the data is used to identify or verify a person based on their unique vocal characteristics. If a company extracts a voiceprint from an audio file to create a template for authentication or identification, that template falls under the retention rules. However, raw audio recordings that aren’t used to create a biometric template may not be covered by biometric laws, though they could still be subject to other retention limits.

Hypothetical: the voiceprint that outlives its purpose

Imagine a company uses voiceprints to verify customer identity for a mobile banking app. A customer, Alex, stops using the app in January 2025 but keeps the account open. The company’s retention schedule says voiceprints will be destroyed three years after the last interaction. In January 2028, Alex files a lawsuit against the company, alleging the app misused their voiceprint data. The company still has Alex’s voiceprint on file because the litigation hold prevents destruction. Under Illinois law, the company should have destroyed the voiceprint by January 2028, regardless of the lawsuit. The company now faces a dilemma: destroy the data to comply with the law, which could weaken their defense, or keep it and risk a lawsuit over the retention duty. This scenario shows why companies need to plan for destruction deadlines even when litigation is pending.

Frequently asked questions

Does Illinois law allow companies to keep voiceprints longer than three years if I consent?

No. Illinois law sets a hard deadline of within 3 years of the individual's last interaction with the entity or when the original purpose is met, whichever comes first. Consent to collect the data does not override this destruction duty.

Can a company be sued just for keeping my voiceprint too long, even if they collected it legally?

Yes, in Illinois. The law allows individuals to sue companies for violating the destruction schedule, even if the original collection was lawful. Other states with biometric laws don’t have this private right of action.

What happens if a lawsuit is still active when the three-year deadline arrives?

The destruction duty does not yield to litigation needs. Companies must destroy the data on schedule, which can create conflicts if the data is needed as evidence. This is a common problem and often requires legal negotiation to resolve.

Do all states have the same three-year rule for voiceprints?

No. Illinois sets a strict destruction rule with a private right of action. Other states take different approaches: some impose retention duties without enforcement mechanisms, while many rely on general privacy principles to limit storage.

Does the destruction duty apply to raw audio recordings or just voiceprint templates?

The duty applies to biometric identifiers, which include voiceprint templates used for identification or verification. Raw audio recordings that aren’t used to create a biometric template may not be covered by biometric laws, though they could still be subject to other retention limits.

How do I know if a company is following the law?

Illinois law requires companies to publish a written retention schedule that explains when and how they will destroy biometric data. The schedule must be publicly available. If they don’t have one or don’t follow it, that could be a violation.

Want a lawyer already lined up before you need one?

live.law connects your smartglasses to a real attorney, live. Join the waitlist to be first in line.

Join the waitlist

Related practice areas

live.law is not a law firm and does not provide legal advice. This page is general information, not legal advice for your specific situation — for that, talk to a licensed attorney in your state.