Skip to content
How‑To Guides

Biometric Data Privacy: Risks, Rights, and Protection

Biometric data cannot be changed once compromised. Here is the essential biometric data privacy guide covering legal frameworks, facial recognition risks, and individual decisions.

Biometric Data Privacy: Risks, Rights, and Protection

Biometric data is fundamentally different from other personal data in one critical respect: it cannot be changed. When a password database is breached, every affected user can create a new password. When biometric data is breached — fingerprint templates, facial geometry maps, iris scans, or voice prints — the affected individuals cannot replace their compromised identifiers. This fits into the wider topic we cover in our Complete Guide to Security and Privacy.

This irreversibility shapes both the legal frameworks around biometric collection and the individual decisions about where and when to provide biometric authentication. This guide covers the biometric data privacy landscape — the legal protections in place, the specific risks of biometric collection, and how individuals and organisations should approach these decisions.

Biometric data privacy is not an argument against using biometrics. Face ID and fingerprint unlock are genuinely more secure than many alternatives for device access in the threat models they address. It is an argument for being selective about which entities receive biometric data and understanding what happens if that data is compromised.

What makes biometrics different

Several properties distinguish biometrics from other personal data categories:

  • Inherently tied to the individual: biometrics cannot be separated from the person, transferred, or replaced
  • Difficult to estimate from other information: a fingerprint template cannot be guessed
  • Used in high-stakes authentication: unlocking phones, authorising payments, accessing buildings
  • Collected involuntarily in many contexts: surveillance cameras capture facial biometrics from people who never consented to any collection

Note that biometric data privacy concerns centre on the collection of biometric templates — the mathematical representations derived from physical characteristics, not necessarily the raw images. The template can often be used to reconstruct or approximate the original biometric characteristic, making it equally sensitive as the raw source.

Facial recognition raises privacy challenges that fingerprint and iris biometrics do not to the same degree, because faces are visible in public and can be captured from a distance without any interaction with the subject. Clearview AI’s database of facial biometrics scraped from social media without consent — used by law enforcement in multiple countries — illustrates the implications of comprehensive facial recognition databases. Privacy frameworks have struggled to keep pace with the capabilities of modern facial recognition technology.

Legal framework — what protections exist by jurisdiction

JurisdictionFrameworkKey requirementsEnforcement
Illinois (US)BIPA (Biometric Information Privacy Act)Informed written consent; no sale; written retention/destruction policyPrivate right of action — billions in class action settlements
Texas, Washington (US)State biometric lawsSimilar to BIPA but less enforcement-friendly; no private right of actionState AG enforcement only
European UnionGDPR Article 9 (special category); EU AI ActExplicit consent or specific legal basis; AI Act restricts real-time facial recognition in public spacesData protection authorities; significant fines
UKData Protection Act 2018 (mirrors GDPR)Same as GDPR biometric special category provisionsICO enforcement
AustraliaPrivacy ActSensitive information provisions cover biometric dataOAIC enforcement
US (federal)No comprehensive federal law (as of 2026)Sector-specific rules apply (HIPAA for health biometrics, COPPA for children)FTC enforcement for unfair/deceptive practices

Employer biometrics is one of the most active litigation areas in the US, driven by Illinois BIPA. Employers using timekeeping systems that capture fingerprints or facial scans must comply with BIPA’s consent and destruction requirements. The class action exposure for non-compliance has been enormous: the $228 million settlement against BNSF Railway, $92 million against TikTok, and $650 million against Facebook are among the largest outcomes. For any organisation considering implementing biometric data collection in employee or customer-facing applications, legal counsel familiar with the applicable frameworks is essential before deployment.

Individual risks and decisions — who should receive your biometrics

The central individual decision is which entities should receive biometric data. A useful framework: biometric data privacy is best preserved when biometrics are stored and processed on-device rather than in cloud infrastructure.

Apple’s Face ID and Touch ID implement on-device biometric storage — the biometric template is stored in the Secure Enclave chip on the device and never transmitted to Apple’s servers. Apple cannot access the biometric. A breach of Apple’s cloud infrastructure does not expose facial geometry or fingerprint data. This is the gold standard for consumer biometric privacy: authentication happens locally, and no external party receives or stores the data.

Android’s equivalent — on-device fingerprint and face authentication using Android Strongbox or TEE (Trusted Execution Environment) — provides similar properties for supported Android devices.

Third-party biometric services — where a company other than the device manufacturer stores the biometric template in their cloud infrastructure — are where biometric data privacy risks are highest. The third party holds a permanent biometric identifier, it may be subject to legal requests in any jurisdiction where the company operates, and it is at risk from data breaches that the individual cannot remediate through credential rotation.

Voluntary commercial biometric programs — the convenience trade-off

In 2026, voluntary biometric enrollment has expanded into commercial contexts: airport biometric boarding systems, concert venue facial recognition, theme park biometric access bands, grocery store checkout with palm payment. Each represents a privacy decision worth evaluating rather than treating as a minor administrative step.

The convenience offer is real: faster boarding, seamless entry, contactless payment. The trade-off: a third-party commercial entity receives and stores facial geometry or palm biometric data that will be retained beyond the immediate transaction and may be shared with law enforcement on request, used for additional purposes beyond the disclosed one, or exposed in a breach.

Where non-biometric alternatives remain available: opting out preserves biometric data privacy without meaningful practical cost. The questions worth asking before enrolling:

  • Is the biometric stored on-device or in the vendor’s cloud infrastructure?
  • Who has access to the stored template?
  • How long is it retained and what triggers deletion?
  • Can I withdraw consent and have the data deleted? What is the process?
  • Who does the vendor share this data with, and under what circumstances?

Children’s biometric data

Children cannot meaningfully consent to biometric collection, and data collected from a child will follow them for decades. Schools using facial recognition for attendance and gaming platforms using voice for age verification raise acute concerns. Multiple US states have enacted specific restrictions on child biometric data collection in school contexts, and GDPR requires a higher level of parental consent for processing children’s data.

For parents, when a school program requests biometric enrollment:

  • Is this enrollment mandatory or optional? (Optional programs can almost always be opted out of without consequences.)
  • What specific data is collected and stored, and in what format?
  • Who has access to it and for how long?
  • What happens to the data if the school changes vendors or closes?

A school that cannot answer these questions clearly has not adequately considered the obligations that collecting children’s biometric data entails. Asking them is both a privacy protection action and a signal that parents are paying attention.

Organisational responsibilities

For organisations collecting biometric data from employees or customers:

  • Conduct a DPIA (Data Protection Impact Assessment) before any biometric system deployment — required under GDPR Article 35 for biometric processing; a best practice regardless of jurisdiction
  • Establish written consent processes that are genuinely informed — not buried in general terms of service
  • Document retention and deletion schedules for biometric data, and enforce them technically (not just procedurally)
  • Maintain biometric data separately from other personal data, with access restricted to systems and personnel with a specific functional need
  • Provide a genuine opt-out path for both employees and customers, with a non-biometric alternative that doesn’t significantly disadvantage those who opt out
  • Have an incident response process specific to biometric data — a breach of biometric data is treated with higher urgency than a general data breach because affected individuals cannot rotate the compromised data

Our guide on protecting personal data covers the broader data minimisation practices that biometric data privacy is part of in a complete personal data protection strategy. For the IAPP’s current tracking of biometric privacy legislation across US states and internationally, the IAPP’s state comparison tool provides a current map of enacted biometric privacy laws with side-by-side comparison of their requirements.

Biometric authentication at work — the employer context

Workplace biometric systems have become a significant source of BIPA litigation and regulatory scrutiny globally. Common workplace biometric applications:

  • Timekeeping and attendance: fingerprint or facial scan clock-in systems. The most common source of BIPA class action claims. Under BIPA, employers must obtain written consent from each employee before collecting biometric identifiers for this purpose — a step many employers skipped when systems were installed.
  • Physical access control: fingerprint or iris readers for building or server room access. Same consent requirements under BIPA; similar requirements under GDPR for EU employees.
  • Continuous authentication: keystroke dynamics, mouse movement, or facial recognition to continuously verify the identity of someone accessing sensitive systems. More invasive than point-of-entry biometrics; requires careful evaluation of proportionality under GDPR.

For employees asked to enroll in workplace biometric systems: in jurisdictions with consent requirements, you have the right to see the consent form and understand what you’re agreeing to before enrolling. In Illinois specifically, employer biometric collection without written consent and a written policy is unlawful regardless of what you’re told verbally. If you’re uncertain about your rights, your state’s department of labor or a local employment attorney can clarify applicable requirements. See also Online Privacy Tools for a related case.

When biometric data is breached — what to do

If an organisation holding your biometric data discloses a breach:

  • Assess the specific data exposed: was a raw image exposed or a processed template? Were the templates stored in a form that allows direct use for spoofing, or in a one-way hash format? The breach notification should clarify this; request clarification if it doesn’t.
  • Contact the breached organisation to understand what specific biometric identifiers were in scope and what remediation they are providing.
  • Change the authentication methods on any account that used the exposed biometric identifier. If facial recognition was used for account authentication at other services, consider switching to PIN or passkey-based authentication for those accounts.
  • File a complaint with the relevant data protection authority if the organisation failed to comply with applicable biometric data privacy laws — particularly relevant in Illinois (file with the AG’s office) and the EU (file with the national DPA).

Unlike a password breach where the solution is straightforward — change the password — a biometric breach has no equivalent simple remediation. The compromised biometric identifier will remain your identifier for life. This is the fundamental asymmetry that makes biometric data privacy worth more preventive attention than other data categories: the cost of a breach is permanent in a way that other data breaches are not. The decision about which entities deserve your biometric data is worth making carefully, because it cannot be undone. You might also run into Digital Privacy for Journalists.

Nikolas Lamprou

Nikolas Lamprou (MSc; GCFR, SC-200, Security+) has been working with computers professionally since 2009 — starting with web development and e-commerce, and moving into cybersecurity over the years. Based in Greece, he brings over 15 years of real-world IT experience to SolveTechToday, where he writes about Windows fixes, software reviews, security tools, and AI applications. His goal is straightforward: cut through the noise and give readers clear, honest guidance on the tech decisions that matter.

Stay Ahead

Fix your next problem before it starts

Get the week's best Windows fixes, software picks, and security guides delivered straight to your inbox. No noise, just solutions.

Press ESC to close · Try "Windows 11" or "Chrome"