← Blog
· 9 min read

Biometric Privacy: What It Actually Protects (and What It Doesn't)

Biometric privacy is one of those phrases that sounds like a guarantee. It is closer to a boundary line. Knowing where the line falls tells you which of your worries the law will handle and which ones are yours to solve.

Most people meet the term for the first time in a settlement email or a consent checkbox, which is a bad introduction. It arrives sounding absolute, as though somewhere a rule exists that keeps your face yours. There is a rule. It is narrower than the phrase suggests, and the part it leaves uncovered happens to be the part that worries people most.

A grey head silhouette enclosed in a glowing green glass dome that is open at the top, with a stream of purple facial-geometry mesh escaping through the gap and unspooling into dozens of small floating face tiles receding into the dark.
The dome is real. It is also open at the top, and what has already escaped is not coming back through it.

The useful version of this topic is not a definition. It is a map of which side of the line each of your concerns sits on, because that determines whether you file a complaint, change a setting, or do something else entirely.

What actually counts as biometric data

A biometric is a measurement of your body used to identify you. The category is broader than most people picture. Fingerprints and faces are the familiar members. So are iris and retina patterns, voiceprints, hand geometry, gait, and in some statutes the pattern of veins beneath your skin.

What unites them is not that they are physical. It is that they are involuntary and permanent. You did not choose your iris pattern and you cannot revise it. That single property is why this data gets its own body of law rather than being folded into ordinary privacy rules, and it is worth sitting with, because everything downstream follows from it.

A password is a secret you selected and can replace. An address changes when you move. A credit card number is reissued within days of a breach. Every other identifier in your life has a reset path. A faceprint does not. When one leaks, there is no equivalent of changing the locks, which is a difference in kind rather than degree.

One clarification that saves confusion later: a faceprint is not a photograph. It is a numerical description of the geometry of your face, derived from a photo and then stored separately. Deleting the photo does not delete the measurement taken from it. We wrote about that distinction in more depth in why removing a biometric is nothing like deleting a file.

What biometric privacy actually protects

Where these laws exist, they are genuinely strong, and it is worth being precise about what they do well rather than dismissing them.

The core protection is consent before collection. Under Illinois BIPA, the oldest and most tested of these statutes, a private entity cannot capture your faceprint without telling you in writing what it is collecting, why, and how long it will keep it, and then obtaining your signed agreement. Texas and Washington built variations on the same foundation. Several newer state laws, including Vermont's and Louisiana's, extend the idea further.

Alongside consent sit three related duties. Companies must publish a retention schedule and actually destroy the data when the stated purpose ends. They are barred from selling or profiting from your biometric identifiers. And they have to store the data with a reasonable standard of care, the same they would apply to other confidential information.

The reason BIPA in particular has teeth is a provision that most privacy laws lack: a private right of action. You do not need a regulator to take an interest. You can sue directly, and statutory damages apply per violation whether or not you can prove a concrete loss. That structure is what produced the settlements you have read about, and it is why companies treat Illinois as a genuine constraint on product design.

So if a gym scanned your fingerprint for entry without a signed release, or an employer put a face-recognition time clock on the wall without notice, or an app enrolled your face while claiming to sort your photo library, those are the cases this body of law was built for. It works.

What it does not protect

Now the other side, which is where the phrase oversells itself.

Biometric privacy law regulates the act of collecting and holding your identifiers. It does not regulate the public existence of your photographs. A picture of you on a conference page, a news site, a friend's public post or an old profile is not biometric data. It is a photograph, and photographs of people in public settings are broadly lawful to publish and to index.

The consequence is the part that catches people out. Face-search engines are built by scraping billions of those public photographs and computing faceprints from them. The photograph was public. The scraping happened without any interaction with you. And whether the resulting faceprint was lawfully created depends on jurisdiction, on the company's structure, and in several ongoing cases on questions courts have not finished answering.

Meanwhile the index exists now. Someone can upload a picture of your face and receive a list of everywhere else you appear, and that capability does not pause while the legal questions resolve.

Three further limits are worth naming plainly. Most of these statutes bind private companies and carve out government use, so the agency running face recognition is often outside the rule entirely. Protection depends on where you live, and most US states have no biometric statute at all. And a company operating outside the reach of a state law, on servers elsewhere, is difficult to compel regardless of what the statute says.

The short version: these laws are strong at the front door and quiet about the back. They govern who may take a new measurement of your face. They have little to say about the measurements already sitting in a searchable index.

Why the gap exists

It helps to know that the gap is not an oversight. It is a timing problem.

BIPA was written in 2008, prompted by a fingerprint-scanning payments company that went bankrupt holding a database of customer fingerprints. The concern of the moment was a business collecting biometrics directly from people who stood in front of its hardware. The remedy fit the problem: make the company ask first, keep the data carefully, and destroy it on schedule.

That framing assumes a relationship. There is a company, there is you, and there is a moment where consent can be requested. Modern face search removes the middle term. Nobody scanned you. A crawler collected a photograph that a third party had already published, and a model computed geometry from it, and you were never present for any step of it.

Laws written for the first shape do not map cleanly onto the second, which is exactly why the litigation against scraping companies has been slow and mixed rather than decisive. Newer statutes are closing the distance, and Vermont's is the most direct attempt so far. But legislation moves in years and crawlers run continuously, so the gap tends to persist even as it narrows.

Why this matters more than it did five years ago

For most of the history of this technology, the cost of finding someone by face was high enough to act as a filter. It needed specialist software, a database, and a reason worth the effort. That expense meant the capability stayed with institutions, and institutions leave records.

The price has collapsed. Face search is now a web page and a small fee. The filter that used to be provided by cost and difficulty is gone, and what remains is whether the person searching feels like it.

The result is a shift in who does the searching. It is no longer mostly investigators and agencies. It is a landlord evaluating an application, a hiring manager between interviews, a stranger who photographed you at a light, someone from a dating app deciding what else they can learn before meeting you. Their reasons are ordinary and their tools are excellent.

None of those searches is what biometric consent law was written to prevent, because none of them involves collecting anything from you. They involve querying what has already been collected.

What to do about the side the law does not cover

Two things are worth doing, and they address different halves of the problem.

The first is to use the protections that exist. If you live somewhere with a biometric statute, learn what it entitles you to, because those rights are real and companies do respond to them. We keep state-by-state summaries covering Illinois, Texas, Washington, California, Colorado, New York, Vermont and Louisiana, including what each one actually requires and how it is enforced. Refuse the optional face scan at the gym. Decline the airport face check, which you are allowed to do. Every enrollment you prevent is one that never needs removing.

The second is to deal with the copies that already exist, because no consent rule reaches backward. That means finding which face-search engines return you, filing removal requests with each, and then filing again, since indexes are rebuilt from a web that keeps republishing your photographs. It is unglamorous and repetitive, which is exactly why it tends not to get done.

Both halves matter. Consent law shrinks how much new material enters the system. Removal work reduces what is already in it. Doing only the first leaves the existing index untouched, and doing only the second means you keep clearing ground that refills behind you.

The law covers the front door. We work on the rest.

FacePrivacy finds where your face is indexed, files removal requests with the major face-search engines, and keeps filing as they re-crawl.

Start protection →