livelaw

Explainers

Which States Have Biometric Privacy Laws Like Illinois' BIPA?

Which U.S. states have biometric privacy laws? The short answer: Illinois, Texas, and Washington have dedicated biometric laws, while a growing number of states regulate biometric data as 'sensitive data' under broader privacy laws. New York City also has a municipal biometric law requiring signage for businesses collecting biometric data.

Key facts

  • ·Illinois is the only state with a dedicated biometric privacy statute (BIPA) that includes a private right of action and strict requirements like written consent, retention schedules, and destruction timelines.
  • ·Texas and Washington also have dedicated biometric privacy laws (CUBI and RCW 19.375), but neither includes a private right of action.
  • ·A growing number of states regulate biometric data as 'sensitive data' under comprehensive consumer privacy laws, requiring opt-in consent before processing, but they lack BIPA-style mandates and private rights of action.
  • ·Most states have no dedicated biometric privacy laws, though many regulate biometrics under breach notification or other statutes. Some states have pending bills that could change this landscape.
  • ·New York City has a municipal biometric law requiring signage for businesses collecting biometric data, but it does not apply to all voice-enrollment use cases.

Illinois BIPA: The gold standard for biometric privacy laws

Illinois’ Biometric Information Privacy Act (BIPA) is the strictest and most widely enforced biometric privacy law in the U.S. It defines "biometric identifiers" to include "a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry," so voiceprints are squarely covered. Before collecting a voiceprint, a private entity must: inform the subject in writing that a biometric identifier is being collected or stored; inform the subject of the specific purpose and length of term for which it is being collected, stored, and used; and receive a written release from the subject or their legally authorized representative. BIPA also requires a written, publicly available retention schedule and destruction guidelines, with destruction required when the initial purpose is satisfied or within 3 years of the individual's last interaction, whichever occurs first. The law bars selling, leasing, trading, or otherwise profiting from the voiceprint and restricts disclosure absent consent, a completed-financial-transaction exception, legal compulsion, or a valid warrant/subpoena. BIPA’s private right of action allows individuals to sue for violations, creating significant litigation risk for companies that fail to comply.

Texas CUBI and Washington RCW 19.375: dedicated biometric laws without private rights of action

Texas’ Capture or Use of Biometric Identifier Act (CUBI) and Washington’s Biometric Privacy Act (RCW 19.375) are the only other states with dedicated biometric privacy laws. Both require notice and consent before capturing a biometric identifier for a commercial purpose, and both impose duties to protect the data and destroy it within a reasonable time. However, unlike Illinois, neither Texas nor Washington allows private individuals to sue for violations—enforcement is limited to state attorneys general. CUBI defines "biometric identifier" to include voiceprints, and Washington’s statute does too, though Washington’s definition includes an exclusion for data generated from audio recordings unless used for identification, creating a potential loophole for some voice-enrollment systems. Both laws also include exceptions for certain uses, such as security or fraud prevention, which may apply to live.law’s product depending on how it is designed and deployed.

A growing number of states regulate biometric data as 'sensitive data' under broader privacy laws

A growing number of states have comprehensive consumer privacy laws that classify biometric data as "sensitive data" requiring opt-in consent before processing. These states include California, Colorado, Connecticut, Delaware, Iowa, Kentucky, Louisiana, Maryland, Minnesota, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, and Virginia. In these states, biometric data—including voiceprints—is treated as sensitive data when processed for the purpose of uniquely identifying an individual. Controllers must obtain the consumer’s consent, provide a clear privacy notice, and allow consumers to revoke consent. However, these laws lack the strict retention/destruction schedule requirements and private rights of action found in BIPA. Some states, like Maryland, impose stricter requirements, such as a "strict necessity" standard for processing sensitive data, which may prohibit processing even if consent is obtained. Others, like Iowa, only require notice plus an opportunity to opt out, making them less stringent than BIPA-style consent regimes. Iowa’s law does not require opt-in consent, only notice plus an opt-out right.

Most states have no dedicated biometric privacy laws, though many regulate biometrics under other statutes

Most states have no dedicated biometric privacy laws applicable to private companies, meaning no consent, notice, or retention requirements apply to voiceprint collection. This includes states like Alabama, Arizona, Arkansas, Florida, Hawaii, Idaho, Kansas, Maine, Massachusetts, Michigan, Mississippi, Missouri, Montana, North Carolina, North Dakota, Ohio, Oklahoma, Pennsylvania, South Carolina, South Dakota, Tennessee, Vermont, West Virginia, Wisconsin, and Wyoming. Even in states with pending bills, such as Massachusetts or Pennsylvania, no law is currently in force. Some states, like Missouri and Mississippi, have repeatedly introduced BIPA-style bills but failed to enact them, leaving companies in a state of uncertainty. For companies operating in these states, the absence of a dedicated biometric privacy law means they are not legally required to obtain consent or follow retention schedules before collecting or processing voiceprints, though other laws (such as breach notification statutes) may still apply.

New York City’s biometric signage law: a municipal exception

New York City has a municipal biometric law that requires commercial establishments to post a sign near customer entrances if they collect, retain, convert, store, or share biometric identifier information, including voiceprints. The law does not require written consent but mandates clear and conspicuous signage. It also prohibits selling, leasing, trading, or otherwise profiting from biometric identifier information. However, the law’s scope is limited to brick-and-mortar retail, food, and entertainment venues, and it is unclear whether it applies to a technology company like live.law that captures voiceprints from its own app users. The law’s applicability to digital or remote enrollment features remains an unresolved question, and no case law has yet clarified this point.

Why these laws exist and what they aim to prevent

Biometric privacy laws exist to address the unique risks posed by biometric data, which is immutable and cannot be changed if compromised. Unlike passwords or credit card numbers, a voiceprint or fingerprint cannot be canceled or reissued if stolen, making it a high-value target for identity theft and fraud. These laws aim to prevent companies from collecting, storing, or sharing biometric data without explicit consent, and to ensure that data is destroyed once it is no longer needed. They also seek to prevent companies from profiting from biometric data by selling or disclosing it to third parties without consent. The laws reflect growing public concern about the collection and use of biometric data, particularly as technology like smart glasses and voice assistants becomes more widespread. For companies like live.law, compliance with these laws is critical to avoid litigation, regulatory penalties, and reputational harm.

Real-world edge cases and open questions

Even in states with biometric privacy laws, there are unresolved questions about what counts as "biometric data" and when consent is required. For example, Washington’s statute excludes "data generated from an audio recording" from the definition of "biometric identifier," creating a potential loophole for systems that derive a voiceprint from recorded audio. Similarly, Tennessee’s statute includes an exclusion for audio recordings, but the law’s text creates a genuine tension between its inclusion and exclusion clauses, leaving the issue unresolved. In Iowa, the statute excludes "a video or audio recording or data generated therefrom" from the definition of "biometric data," but it is unclear whether a voiceprint derived from audio for identification purposes falls outside the statute. These ambiguities highlight the importance of consulting legal counsel to interpret how these laws apply to specific products and use cases.

Frequently asked questions

Does my product need to get consent from users before collecting their voiceprints?

It depends on the state and how your product uses the voiceprint. In Illinois, you must get written consent before collecting a voiceprint. In states with comprehensive privacy laws (e.g., California, Colorado, Connecticut), you must get opt-in consent if the voiceprint is processed for identification purposes. In Texas and Washington, you must get consent before capturing a biometric identifier for a commercial purpose. In most other states, there is no legal requirement to obtain consent before collecting or processing a voiceprint.

What happens if I collect a voiceprint without consent in a state with a biometric privacy law?

In Illinois, you could face a private lawsuit with statutory damages of up to $1,000 per negligent violation or $5,000 per intentional or reckless violation. In Texas and Washington, you could face enforcement by the state attorney general, but not private lawsuits. In states with comprehensive privacy laws, you could face enforcement by the attorney general, but the penalties are typically less severe than in Illinois.

Do I need to publish a retention and destruction schedule for voiceprints?

Only in Illinois. BIPA requires a written, publicly available retention schedule and destruction guidelines, with destruction required when the initial purpose is satisfied or within 3 years of the individual's last interaction. Other states with biometric privacy laws do not require a separate retention and destruction schedule.

Can I sell or share voiceprints with third parties?

In Illinois, you cannot sell, lease, trade, or otherwise profit from a voiceprint without consent. In Texas and Washington, you cannot sell or disclose a biometric identifier for a commercial purpose without consent. In states with comprehensive privacy laws, you cannot sell sensitive data without consent. In most other states, there is no restriction on selling or sharing voiceprints.

What if my product only uses voiceprints for a short time and doesn’t store them?

Even if you don’t store voiceprints, you may still be processing biometric data, which triggers consent requirements in states with biometric privacy laws. For example, if your product uses a voiceprint to identify a user in real time but doesn’t store it, you may still need consent under Illinois BIPA or other applicable laws. The rules depend on how your product is designed and where your users are located.

How do I know if my product is covered by a state’s biometric privacy law?

Coverage depends on the state, the product’s design, and the user’s location. For example, some laws only apply if the product is used in a commercial setting, while others apply to any processing of biometric data. Some laws have size thresholds, so small deployments may not be covered. The best approach is to consult legal counsel to determine which laws apply to your specific product and use case.

Want a lawyer already lined up before you need one?

live.law connects your smartglasses to a real attorney, live. Join the waitlist to be first in line.

Join the waitlist

Related practice areas

live.law is not a law firm and does not provide legal advice. This page is general information, not legal advice for your specific situation — for that, talk to a licensed attorney in your state.