livelaw

Explainers

Is It Legal to Record Someone's Voiceprint Without Telling Them?

Is it legal to record someone's voiceprint without telling them? The answer depends almost entirely on where you are in the U.S. and how the voiceprint will be used.

Key facts

  • ·Illinois is the only state with a dedicated biometric-privacy law that requires written consent before collecting a voiceprint.
  • ·Texas and Washington have biometric laws, but their definitions may exclude voiceprints derived from audio recordings, creating legal ambiguity.
  • ·A number of states regulate voiceprints through comprehensive privacy laws that treat them as 'sensitive data,' requiring opt-in consent before processing.
  • ·States like Colorado, Connecticut, Delaware, Kentucky, Louisiana, Minnesota, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Oklahoma, and Utah have enacted comprehensive privacy laws that include voiceprints in their 'biometric data' or 'sensitive data' definitions.
  • ·States like Alaska, Arizona, Arkansas, Florida, Georgia, Hawaii, Idaho, Iowa, Kansas, Maine, Massachusetts, Michigan, Mississippi, Missouri, Montana, North Carolina, North Dakota, Ohio, Pennsylvania, South Carolina, South Dakota, Vermont, West Virginia, Wisconsin, and Wyoming have no specific law requiring consent for voiceprint collection.

Illinois is the only state with a dedicated biometric-privacy statute that explicitly names voiceprints. The Biometric Information Privacy Act (BIPA) says a private entity must "inform the subject in writing that a biometric identifier/information is being collected or stored" and "receive a written release from the subject or their legally authorized representative." It also requires a "written, publicly available retention schedule and destruction guidelines," with destruction required when the initial purpose is satisfied or within 3 years of the individual's last interaction, whichever occurs first. BIPA bars selling, leasing, trading, or otherwise profiting from the voiceprint and restricts disclosure absent consent, a completed-financial-transaction exception, legal compulsion, or a valid warrant/subpoena. These rules apply even if the voiceprint is captured incidentally while recording an ordinary conversation. The law has no minimum-size threshold, so even a small business must comply. Violations can trigger a private right of action with statutory damages.

Texas and Washington: biometric laws with ambiguous coverage of voiceprints

Texas's Capture or Use of Biometric Identifier Act (CUBI) defines "biometric identifier" to include voiceprints, but the same definition excludes "a physical or digital photograph, video or audio recording or data generated therefrom." Because a voiceprint is derived from an audio recording, there is a real argument that CUBI does not apply to a voiceprint created from recorded audio. Separately, H.B. 149 (2025) added a carve-out for AI training/evaluation, but only if the system is not used to uniquely identify a specific individual. Washington's Biometric Privacy Act (RCW 19.375) also names voiceprints, but its definition excludes "a physical or digital photograph, video or audio recording or data generated therefrom." These exclusion clauses create genuine ambiguity about whether the statutes reach a voiceprint derived from recorded audio. If they do apply, both statutes require notice and consent before enrolling a biometric identifier for a commercial purpose, with retention limits and security obligations. Neither statute has a private right of action.

A number of states—Colorado, Connecticut, Delaware, Kentucky, Louisiana, Minnesota, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Oklahoma, and Utah—have enacted comprehensive privacy laws that treat biometric data as a category of "sensitive data." These laws require controllers to "not process sensitive data concerning a consumer without obtaining the consumer's consent." Consent must be a "clear affirmative act signifying a consumer's freely given, specific, informed and unambiguous agreement," and cannot be obtained via broad terms-of-use acceptance or dark patterns. The laws also require a revocation mechanism and generally require controllers to stop processing within 15 days of revocation. None of these states impose a BIPA-style written, publicly posted retention schedule or per-violation statutory damages. Instead, enforcement is typically Attorney General–only with a cure period. Applicability is usually gated by size thresholds, so a small deployment may fall outside the statute entirely.

Why the carve-outs for raw audio and recordings matter

Many state laws exclude "a digital or physical photograph, an audio or video recording, or any data generated from" one from the definition of "biometric data" unless that data is generated to identify a specific individual. This carve-out is critical for voiceprints. A raw audio recording itself is not "biometric data," but a voiceprint extracted from that recording specifically to identify a person is. For example, a system that captures audio for transcription but never extracts a voiceprint for identification would not trigger a biometric consent duty in these states. Conversely, a system that captures audio and immediately extracts a voiceprint template to distinguish the wearer from bystanders would trigger the duty. The line turns on whether the data is "generated to identify a specific individual," not on whether the underlying audio is recorded.

States like Alaska, Arizona, Arkansas, Florida, Georgia, Hawaii, Idaho, Iowa, Kansas, Maine, Massachusetts, Michigan, Mississippi, Missouri, Montana, North Carolina, North Dakota, Ohio, Pennsylvania, South Carolina, South Dakota, Vermont, West Virginia, Wisconsin, and Wyoming have no statute requiring written consent, advance notice, or a public retention/destruction policy before capturing or processing a voiceprint. Some of these states have pending bills, but none are currently law. In these states, the only legal exposure comes from post-collection duties—such as breach notification if the voiceprint is later compromised—or from general consumer-protection, wiretap, or unfair-competition laws. There is no state-law gate at the moment of collection.

New York City's "Biometric Identifier Information" law requires commercial establishments that collect biometric identifier information to post a "clear and conspicuous sign near all of the commercial establishment's customer entrances notifying customers" that biometric identifier information is being collected. The law does not require written consent. It also makes it unlawful to sell, lease, trade, share in exchange for anything of value, or otherwise profit from the transaction of biometric identifier information. The law targets brick-and-mortar venues and may not reach a technology company capturing its own users' voiceprints for an enrollment feature. Whether it applies to a smartglasses company is an open question with no case law resolving it.

Virginia's Consumer Data Protection Act (VCDPA) treats biometric data as "sensitive data" that may not be processed without "the consumer's consent," where "consent" means "a clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement." The law applies only to persons conducting business in Virginia or targeting Virginia residents that during a calendar year "control or process personal data of at least 100,000 consumers," or "control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data." A small deployment may fall below this threshold and not be independently subject to VCDPA. The law has no biometric-specific retention schedule and no private right of action.

Hypothetical scenario: a law firm equips attorneys with smartglasses that enroll a voiceprint to route calls

Imagine a mid-sized law firm in Illinois equips its attorneys with smartglasses that capture audio and extract a voiceprint to distinguish the attorney from bystanders. Under BIPA, the firm must provide written notice that a biometric identifier is being collected and obtain a written release from each attorney before the glasses are used. The firm must also publish a written retention schedule and destroy the voiceprints within 3 years of the attorney's last interaction with the system, unless the purpose is satisfied sooner. If the firm instead operates in Connecticut, the glasses must obtain opt-in consent before processing the voiceprint as sensitive data, and the firm must provide a revocation mechanism with processing ceasing within 15 days of revocation. In a state like Arizona with no biometric law, the firm has no state-law consent duty, though it still must comply with federal and general consumer-protection principles.

Frequently asked questions

Does recording someone's voice without telling them violate wiretap laws?

That depends on state wiretap law, not on biometric-privacy law. One-party consent states generally allow recording if at least one party to the conversation consents; all-party consent states require every party's consent. Biometric-privacy laws are a separate legal layer that can impose additional duties even if wiretap law is satisfied.

If I only keep a voiceprint for 30 seconds and then delete it, do I still need consent?

Possibly. Many states' biometric laws focus on whether the data is "generated to identify a specific individual," not on how long it is stored. If the voiceprint is extracted for identification purposes—even briefly—it may trigger the consent duty. Illinois BIPA explicitly requires consent regardless of retention duration. Other states' comprehensive privacy laws typically require consent before processing sensitive/biometric data, regardless of retention.

Can I use a voiceprint to identify employees without their consent in Texas?

Texas's CUBI requires notice and consent before capturing a biometric identifier for a commercial purpose. However, CUBI's definition excludes "a physical or digital photograph, video or audio recording or data generated therefrom," which may mean a voiceprint derived from recorded audio is not a "biometric identifier" under CUBI at all. If it is covered, consent is required. If not, CUBI does not apply. This is a genuinely unresolved legal question with no Texas case law yet.

Do I have to publish a retention schedule for voiceprints in every state?

No. Only Illinois BIPA requires a "written, publicly available retention schedule and destruction guidelines" for biometric identifiers. Other states fold biometric data into general data-protection duties and do not impose a biometric-specific retention schedule. Even in states that require consent for biometric/sensitive data, the consent mechanism itself—not a separate published schedule—is the operative gate.

What happens if I get consent via a buried terms-of-use checkbox?

Most states that require consent for biometric/sensitive data define consent as a "clear affirmative act" that cannot be obtained via broad terms-of-use acceptance or dark patterns. In Connecticut, "consent" must be "a clear affirmative act signifying a consumer's freely given, specific, informed and unambiguous agreement," excluding blanket ToS acceptance. Similar definitions appear in states like Delaware, Kentucky, Louisiana, Minnesota, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, and Oklahoma. Consent obtained via a buried checkbox is unlikely to satisfy these standards.

If my app is used by people in multiple states, which law applies?

This depends on where each user is located and how your processing is structured. Some states' laws apply based on the user's location, while others apply based on the controller's business presence or revenue. Illinois BIPA has no minimum-size threshold, so it can apply even to a small app with Illinois users. Other states' comprehensive privacy laws typically have size thresholds, so a small deployment may fall outside the statute. The safest approach is to obtain opt-in consent from all users before processing voiceprints, unless you can confirm the user's state has no applicable law.

Want a lawyer already lined up before you need one?

live.law connects your smartglasses to a real attorney, live. Join the waitlist to be first in line.

Join the waitlist

Related practice areas

live.law is not a law firm and does not provide legal advice. This page is general information, not legal advice for your specific situation — for that, talk to a licensed attorney in your state.