Biometric Data and AI Facial Recognition: The Privacy Law Landscape in 2026
A retail chain deploys facial recognition technology at its store entrances to identify repeat shoplifters. The technology is accurate — but the chain did not obtain consent from shoppers, did not post required notices under applicable state law, and is processing biometric data of Illinois residents under an Illinois-based vendor's platform. Within six months, three class action lawsuits have been filed under the Illinois Biometric Information Privacy Act. Each lawsuit carries potential damages of $1,000–$5,000 per violation per person — multiplied across millions of store visits. The litigation exposure exceeds the chain's annual technology budget.
Biometric data — fingerprints, facial geometry, iris scans, voice prints — is among the most legally sensitive category of personal information in the 2026 privacy landscape. Unlike a password or email address, biometric data is permanent: it cannot be changed if compromised. This permanence drives the elevated legal standards that apply to its collection, storage, and use.
Biometric Data — Data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a person that allows the unique identification of that person. Includes facial recognition templates, fingerprints, iris scans, voice prints, and gait recognition data.
BIPA (Illinois Biometric Information Privacy Act) — Illinois' 2008 biometric privacy law, which requires explicit written consent before collecting biometric identifiers, mandates a publicly available data retention and destruction schedule, prohibits sale or profit from biometric data, and provides a private right of action with statutory damages of $1,000 per negligent violation and $5,000 per intentional violation.
The US Biometric Privacy Patchwork: State Laws Create Compliance Complexity
The United States has no comprehensive federal biometric privacy law. Instead, a growing number of states have enacted their own biometric privacy legislation, creating a compliance patchwork that is particularly challenging for companies operating nationally.
Illinois BIPA is the most litigated biometric privacy law in the world. Its private right of action — allowing individual plaintiffs and class actions without requiring proof of actual harm — has generated hundreds of class action lawsuits since 2019. Major settlements include $650 million (Facebook/Meta, 2021), $17 million (Clearview AI), and numerous eight-figure settlements with retail, hospitality, and technology companies. Courts have held that each individual scan or template capture constitutes a separate violation, meaning class exposure can be exponential.
Texas enacted its Capture or Use of Biometric Identifier Act (CUBI), which prohibits collection of biometric identifiers without prior informed consent. Texas enforcement is conducted by the Attorney General — there is no private right of action. Washington's My Health MY Data Act, enacted in 2023, covers biometric data in health contexts and includes a private right of action. New York City has an ordinance requiring businesses to post notices when using biometric identification systems.
For companies using facial recognition or other biometric AI: compliance must be assessed per jurisdiction. A national deployment requires a comprehensive map of applicable state and local laws, their notice and consent requirements, and their enforcement mechanisms.
The EU AI Act: Facial Recognition Prohibitions and Restrictions
The EU AI Act (Regulation 2024/1689) introduces the most significant legal restrictions on facial recognition technology to date, as part of a tiered risk classification system for AI.
Prohibited (Article 5): Real-time remote biometric identification systems (RTBII) in publicly accessible spaces for law enforcement purposes are prohibited, with narrow exceptions for specific serious crimes (search for missing children, specific imminent threats, prosecution of serious offences with judicial authorisation). This prohibition applies to law enforcement — not private sector use, which is addressed differently.
High-Risk (Annex III): Biometric identification and categorisation systems — including most commercial facial recognition applications — are classified as high-risk AI systems. High-risk systems must undergo conformity assessment, maintain technical documentation, implement human oversight mechanisms, and register in an EU database before market deployment. For companies deploying facial recognition for access control, attendance monitoring, or customer identification, high-risk classification means significant compliance investment.
GDPR Article 9 interaction: Even before the AI Act applies, GDPR's Article 9 treats biometric data processed for unique identification as a special category requiring explicit consent or another specific legal basis. The AI Act layered on top of GDPR means facial recognition operators must satisfy both frameworks simultaneously.
What Biometric AI Compliance Requires in Practice
For companies using or considering AI facial recognition or other biometric technology, 2026 compliance requires:
- Legal basis assessment: In the EU, identify a specific Article 9 GDPR basis for biometric processing (typically explicit consent for private sector applications). In US states with biometric laws, obtain written informed consent before collection — with a description of the purpose, retention period, and third-party sharing policies.
- Data minimisation: Collect only the biometric data necessary for the specific purpose. If the purpose can be achieved without biometric identification (e.g., using a PIN or ID card), the necessity of biometric collection is questionable.
- Retention limits: Define and document a retention schedule. BIPA in Illinois requires a published retention policy — destruction of biometric data no later than three years after the last interaction with the individual or when the purpose has been satisfied, whichever comes first.
- Security: Store biometric data with the highest applicable level of technical security. Biometric data breaches create particularly severe individual harm because the data cannot be changed. Encryption in transit and at rest, access controls, and breach notification procedures are minimum requirements.
- Third-party vendor management: If biometric processing is performed by a third-party vendor, conduct due diligence on their data protection practices. Under BIPA, the company that deploys the technology bears direct liability — not just the vendor. Under GDPR, the deploying company is the data controller, responsible for the processor's compliance.
Frequently Asked Questions
Does Illinois BIPA apply to companies outside Illinois?
Yes, if the company collects biometric data of Illinois residents. Federal courts have confirmed that BIPA applies to any collection of biometric data from individuals in Illinois, regardless of where the collecting company is headquartered or where the data is stored. A New York retail company with Illinois stores must comply with BIPA for all Illinois customer facial scans.
What does the EU AI Act require for companies using facial recognition?
Most commercial facial recognition applications are classified as 'high-risk' AI systems under the EU AI Act. High-risk systems require conformity assessment, technical documentation, human oversight mechanisms, and registration in an EU database before deployment. Real-time remote biometric identification by law enforcement in public spaces is generally prohibited, with narrow exceptions. Compliance with both the AI Act and GDPR Article 9 is required simultaneously.
Can biometric data be used without consent for security or loss prevention?
Not in most regulated jurisdictions. Illinois BIPA requires written informed consent before collection for any purpose. EU GDPR requires explicit consent or another specific Article 9 basis for biometric processing — and 'legitimate interests' is generally insufficient for biometric data. Some law enforcement exceptions exist, but these do not apply to private sector security deployments. Alternatives to biometric identification should be evaluated before deploying facial recognition for loss prevention.
What are the damages for a BIPA violation?
Illinois BIPA provides statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation — per person, per scan in some interpretations. Class action multipliers mean a single deployment can generate hundreds of millions in potential exposure. Major settlements have ranged from $14 million (employee time-tracking cases) to $650 million (Facebook/Meta facial recognition settlement in 2021).
This article is published by an independent news publication for informational purposes only and does not represent or claim affiliation with any government body, international organization, or official authority.