Biometric Identity Verification and U.S. Privacy Law: BIPA, CUBI, and the State Patchwork
Face matching is now standard in U.S. onboarding. So is the class action risk. How to run biometric KYC without creating liability.
Rodolfo Santos
Real Estate Compliance Attorney & Co-Founder, VeriKYC

The Control That Protects You From Fraud and Exposes You to Litigation
Face matching has become the default answer to a hard problem. Documents can be generated. Data can be stolen. Comparing a live capture of a person's face against the photograph on their identity document is one of the few controls that ties a specific human being to a specific credential.
So U.S. onboarding flows added it. Funds verifying investors, title companies verifying beneficial owners for federal filings, law firms onboarding clients, property managers screening tenants, all increasingly capture a face and compare it to a document.
Each of those captures may create a regulated biometric identifier. And in one American state, creating one without the right paperwork gives the individual a private right to sue, with statutory damages that do not require proof of any actual harm.
The result is a genuine tension. The control that best defends against synthetic identity fraud is also the control that generates the most concentrated litigation risk in U.S. privacy law. This article covers what the laws require, where the traps are, and how to run biometric verification without creating liability.
This is general information about a fast-moving area of law, not legal advice for any specific situation.
There Is No Federal Rule
The first thing to understand is the absence at the center. The United States has no comprehensive federal law governing commercial collection of biometric data. Whatever obligations apply to your verification flow derive entirely from state law, and they vary enormously.
Three states have dedicated biometric statutes. Roughly twenty more regulate biometric data as a category of sensitive data under comprehensive consumer privacy laws. The remainder address it only through data breach notification requirements.
The single most consequential distinction across this landscape is whether a state grants individuals a private right of action. Only one does.
Illinois BIPA: The Center of Gravity
The Illinois Biometric Information Privacy Act was enacted in 2008, years before most organizations had any biometric capability. It remains the strictest biometric law in the country and the source of the overwhelming majority of U.S. biometric litigation.
What it requires
Informed written consent before collection. A private entity must inform the individual, in writing, that a biometric identifier is being collected or stored; inform them of the specific purpose and the length of term for which it will be collected, stored, and used; and receive a written release.
A publicly available retention and destruction policy. The entity must establish and make publicly available a written policy setting a retention schedule and guidelines for permanent destruction, with destruction occurring when the initial purpose has been satisfied or within three years of the individual's last interaction, whichever occurs first.
No sale or profit. A private entity may not sell, lease, trade, or otherwise profit from biometric identifiers.
Disclosure restrictions. Disclosure to third parties generally requires consent or another enumerated basis. This matters directly for verification, because sending a face image to a vendor is a disclosure.
Reasonable security. Storage must use the reasonable standard of care within the entity's industry, and protection at least as protective as how it treats other confidential and sensitive information.
Why it produces litigation
BIPA's private right of action provides statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation, plus attorney's fees.
The Illinois Supreme Court held in 2019 that a person need not allege actual injury to be aggrieved under the statute, the violation itself is the injury. That decision removed the standing obstacle that limits most privacy litigation.
A 2023 decision then held that claims accrue with each separate scan rather than only the first, which produced damages arithmetic capable of reaching absurd totals. The Illinois legislature amended the statute in 2024 to limit recovery, generally to a single amount per person per collection method, and to clarify that an electronic signature satisfies the written release requirement. The amendment materially reduced maximum exposure but did nothing to reduce filing volume, and class certifications and substantial settlements have continued.
The financial institution exemption
BIPA Section 25 contains an exemption for financial institutions and their affiliates subject to Title V of the Gramm-Leach-Bliley Act.
This exemption is significant and frequently misunderstood. It has been read to cover entities genuinely subject to GLBA's privacy provisions, which reaches further than "banks", but it does not cover every organization that touches financial data. A private fund, a title agency, a law firm, or a property management company should not assume the exemption applies to it. Whether a particular entity falls within GLBA's scope is a specific legal question with a specific answer, and it is one worth obtaining before relying on it.
The technology vendor question is separate again. Plaintiffs frequently name both the deploying business and the biometric technology provider. A vendor that is not itself a financial institution may have no exemption even where its customer does.
Texas, Washington, and the AG-Enforced States
Texas. The Capture or Use of Biometric Identifier Act has been in force since 2009. It requires notice and consent before capturing a biometric identifier for a commercial purpose, restricts disclosure, requires reasonable care in storage, and requires destruction within a reasonable time and generally not later than one year after the purpose expires.
CUBI has no private right of action. Enforcement rests with the Attorney General, with civil penalties up to $25,000 per violation. For nearly its entire existence, that made it a theoretical risk. That changed with high-profile enforcement actions against major technology companies, and Texas has since enacted additional biometric provisions taking effect in January 2026. The combination of substantial per-violation penalties and demonstrated enforcement appetite makes Texas a genuine risk jurisdiction, notwithstanding the absence of class actions.
Washington. The state's biometric statute requires notice and consent before enrolling a biometric identifier in a database for a commercial purpose, and restricts subsequent use and disclosure. Enforcement is through the Attorney General under the Consumer Protection Act.
Colorado. Amendments to the Colorado Privacy Act added biometric-specific requirements, including consent, retention policy obligations, and provisions covering employment-context biometrics regardless of whether the entity meets the Act's general processing thresholds. Enforcement is by the Attorney General.
The comprehensive privacy law states. More than twenty states now have comprehensive consumer privacy statutes that treat biometric data used to identify an individual as sensitive personal information, generally requiring opt-in consent, honoring deletion rights, and mandating data protection assessments for high-risk processing. California's framework additionally provides a limited private right of action for breaches involving certain personal information, with statutory damages per consumer per incident.
The practical summary: Illinois drives class action risk, Texas and Washington drive regulator risk, and the comprehensive privacy laws mean biometric obligations reach far more states than most compliance teams assume.
Four Traps That Catch Sophisticated Teams
Trap one: the template, not the photograph
Every one of these statutes regulates the biometric identifier, which includes the mathematical representation derived from the source image, the face template or embedding stored in your system.
This has a consequence that surprises people. Deleting the source photograph does not delete the regulated identifier. If your vector database still holds a face embedding, and your backups still hold it, you are still storing biometric data. A destruction policy that reaches only the image files is not a destruction policy.
Trap two: consent buried in terms of service
A checkbox agreeing to general terms and conditions has repeatedly been found insufficient. The statutes contemplate specific, informed consent that identifies what is being collected, why, and for how long.
The compliant pattern is a dedicated, conspicuous biometric consent presented at the point of capture, separate from general terms, with the retention period stated, and with the consent record retained as evidence.
Trap three: no written retention schedule
The publicly available retention and destruction policy is an independent BIPA requirement. An organization can obtain perfect consent and still violate the statute by never publishing a policy.
The policy must be actually public, accessible without logging in, and must actually be followed. A published three-year retention schedule combined with templates retained indefinitely is worse than no policy, because it evidences knowledge of the obligation.
Trap four: assuming the vendor absorbs the risk
Contractual indemnities do not extinguish statutory liability to the individual. If your onboarding flow captures a face, you are collecting biometric data even if a vendor processes it. Your consent, your retention policy, and your disclosure basis all have to be correct on your side.
What the vendor relationship should do is give you control: contractual commitments on retention and deletion, the ability to configure whether templates are stored at all, documented security, and a data processing agreement that reflects the actual flow.
The Strongest Defense Is Not Retaining the Template
Here is the design insight that most reduces exposure: verification and enrollment are different operations, and only one of them requires storage.
Enrollment creates a persistent biometric record so the person can be recognized later. This is what most biometric statutes were written to address, and it carries the full weight of consent, retention, destruction, and security obligations for as long as the record exists.
One-time verification compares a live capture to a document photograph, produces a match score, and has no ongoing need for the biometric data. The comparison happens; the result is recorded; the underlying biometric material can be destroyed.
Most KYC use cases are the second kind. You need to establish, at onboarding, that the person presenting the document is the person depicted in it. You do not need the ability to recognize them again from a face database.
If your system retains only the verification result, the match confidence, the timestamp, and the audit metadata, and destroys the face template and the captured image immediately after comparison, your ongoing exposure is dramatically smaller. There is no stored biometric identifier to be breached, misused, retained too long, or disclosed improperly. The consent and notice obligations at the moment of collection still apply, but the continuing obligations largely fall away.
This is a deliberate architectural choice, not a default. Many verification systems retain templates because it is easier and because it enables features nobody asked for. In the U.S. regulatory environment, that convenience carries a real cost.
It is the approach VeriKYC takes: perform the comparison, record the evidence a compliance officer and an examiner need, and do not accumulate a biometric database that has no compliance purpose and substantial legal downside.
An Operational Checklist
Map where biometric data is created. Face matching, liveness detection, and voice authentication all potentially qualify. Include vendor systems and any internal tooling.
Determine which state laws apply. Coverage generally follows the individual's residence, not your office location. If you onboard nationally, assume Illinois applies to some subset of your users.
Assess the GLBA exemption honestly. Get a specific answer for your specific entity rather than assuming.
Deploy standalone consent. Separate from general terms, presented at capture, stating what is collected, why, and the retention period. Retain the consent record.
Publish a retention and destruction policy. Publicly accessible, with a defined schedule and destruction guidelines.
Make destruction reach everything. Templates, embeddings, cached images, logs, and backups. Test that it works.
Minimize by default. Do not store templates unless a specific business requirement justifies it and the risk has been accepted deliberately.
Contract properly with vendors. Retention configuration, deletion commitments, security standards, breach notification, subprocessor disclosure.
Document the assessment. Several comprehensive privacy laws require a data protection assessment for sensitive data processing. Produce it before deployment, not after an inquiry.
Conclusion: Both Risks Are Real
There is a version of this analysis that concludes biometric verification is too legally dangerous to use. That conclusion is wrong, and it trades a manageable risk for an unmanageable one.
The alternative to biometric verification is accepting document photographs without confirming that the person submitting them is the person depicted. In an environment where FinCEN has publicly documented the use of AI-generated identity documents to defeat verification controls, that is not a conservative choice. It is a different, larger exposure, one that manifests as sanctions violations, fraudulent investors in the register, and false federal filings.
The correct posture is to use the control and manage the legal risk deliberately: obtain proper consent, publish and follow a retention policy, choose vendors that let you configure storage, and, most importantly, do not retain biometric templates you have no operational reason to keep.
Get the paperwork right, keep the data for as short a time as the purpose allows, and biometric verification becomes what it should be: a strong control with bounded legal exposure, rather than a strong control with an open-ended one.
Rodolfo Santos
Rodolfo Santos is a real estate compliance attorney with 10+ years of experience in cross-border transactions and the co-founder of VeriKYC, an AI-powered compliance platform for real estate professionals. He has closed over 150 property transactions worth more than €50 million.