← Blog
· 8 min read

Biometric Privacy Laws Don't Have a Delete Button

Most people come to biometric privacy law looking for an off switch. There isn’t one. What these laws give you is a say in what happens next — worth having, and a different problem from the one that sent you looking.

You search your own name, or a friend tells you what came up when they searched it, and there you are: a photo you had forgotten, sitting on a list of sites you did not know it had reached. The first instinct is to find the law that makes it stop. There is a law. It does not do that.

That is not an argument that biometric privacy law is useless. It is an argument that it answers a different question than the one you arrived with, and that mixing the two up costs people months of waiting on a remedy that was never coming.

What people are hoping for

The hope makes sense. Biometric data gets described as uniquely sensitive. Several states have passed laws saying exactly that. Companies have paid very large settlements over it. From outside, that looks like a system with an enforcement arm you could point at your problem.

So the question becomes: which law do I cite, and who do I cite it to, to get my face out of these search engines?

No US biometric statute is built to produce that outcome. Understanding why takes about five minutes and saves a great deal more than that.

What the laws cover

Illinois passed BIPA in 2008 and it is still the strongest of them. Texas and Washington followed with their own versions. Colorado, California, Vermont and Louisiana have since added biometric provisions of varying reach. We keep plain-language summaries for each state if you want the specifics for where you live.

All of them aim at the same instant: the moment a company takes a measurement of your body. Before that can happen, you have to be told in writing what is being collected and why, and you have to agree. From there the company owes you a published retention schedule, real destruction once the purpose ends, a bar on selling the data, and reasonable care while it holds it.

BIPA adds the part that gives the whole category its reputation. You can sue directly, without waiting for a regulator to act, and damages attach per violation whether or not you can show you were harmed. That is why the headline settlements exist, and it genuinely shapes how products get built.

Every duty in that list lands on a company at the point it captures or holds your biometric identifier. Hold on to that pattern, because it is also the limit.

Where they stop

Read the list again and notice what is absent: any obligation to remove a faceprint a company built from a photograph nobody asked you about.

Face-search engines are assembled by crawling public photographs at scale. A conference bio. A news article. A friend’s public post. A staff directory from a job you left years ago. Those photographs are lawfully published. The engine measures the facial geometry in them and keeps the result. You were never in the room, so there was no consent moment to get wrong, and in most places no statute clearly hands you a right to demand deletion after the fact.

Even where a claim is plausible, the route is a lawsuit rather than a request. That takes years, and it targets how a company behaves in general rather than what its index holds about you specifically. The index keeps answering queries the whole time.

Three limits compound it:

  • Government use is usually exempt. Law-enforcement systems sit outside most of these statutes entirely.
  • Coverage depends on your state. Most states have no biometric law at all.
  • Servers move. A company operating beyond the reach of a state statute is hard to compel, however clearly the text applies.
These laws govern permission to take a new measurement. They are not a deletion mechanism for measurements that already exist. Two different problems, and only one of them has a legal remedy.

Why the settlements didn’t help

The large biometric settlements are worth understanding, because they are the main reason people expect more from these laws than the laws deliver.

The shape is always similar. A class action alleges a company collected biometrics without proper consent. It settles for a substantial figure. Class members who file a claim get a payment, usually modest once it is divided. The company agrees to change specific practices going forward.

What it almost never does is remove your face from anywhere it currently appears, because that was never what the case was about. The claim was a consent failure, and the remedy for a consent failure is compensation plus a commitment to get consent right next time.

Which is how someone can cash a settlement cheque over a biometric violation in the morning and still be returned by a face-search query that afternoon. Both things are true at once. They describe different halves of the problem.

What actually removes a face

The thing that works is unglamorous, and it is not legal in nature. It is a request made directly to each engine, in whatever form that engine accepts, followed by checking, followed by doing it again.

Start by finding out which engines actually return you. The answer is rarely uniform. Some hold dozens of images of a person and others hold none, and the set differs depending on where a person’s photographs have circulated. Guessing burns effort on engines that were never your problem.

Then send each one what it accepts. This is the tedious part, because they are genuinely inconsistent. Some run an opt-out form. Some want an email citing a specific legal basis. Several ask you to prove who you are by supplying a photograph, which is an uncomfortable request in the circumstances and is best answered with a document redacted down to only what is needed.

Then check. A confirmation email is a claim, not evidence. The only way to know a record is gone is to search again yourself.

Then do it again, which is the step almost everyone skips. These indexes are rebuilt from a web that has not stopped publishing photographs of you. A removal confirmed in March can quietly reverse by August because a crawler found the same face on a page nobody was thinking about. Removal is not a task that finishes. It is a cycle that has to keep turning.

Using both halves

The sensible position is not to write off biometric privacy law. It is to use it for the thing it is good at.

Consent rules limit how much new material enters these systems in the first place. Decline the optional face scan. Refuse the airport face check, which you are entitled to do. Know what your state gives you and say so when a company oversteps, because these statutes work precisely when somebody invokes them. Every enrollment you prevent is one nobody has to undo later.

Removal work deals with the copies already circulating, which no consent rule reaches backward to touch.

Do only the first and the existing index sits exactly where it is. Do only the second and you keep clearing ground that fills in behind you. They are complements, and the mistake worth avoiding is waiting on the law to deliver something it was never built to produce.

The statute stops at the front door.

FacePrivacy finds which engines return your face, files removal requests with each of them, checks the result, and keeps filing as they re-crawl.

Start protection →