US

Biometric Privacy Laws

The short answer. There is no US federal biometric privacy statute. The law is state by state, and only a handful of states have one. Illinois, Texas and Washington are the long-standing three, Colorado joined with an amendment effective July 1, 2025, and more states are adding biometric provisions to general privacy acts rather than writing standalone statutes. Which ones matter depends on two things: whether the statute names voiceprints, and whether it is triggered by collection or only by identification. Illinois and Texas name voiceprints. Washington expressly excludes audio recordings.

The law

740 ILCS 14/15(b)

No private entity may collect, capture, purchase, receive through trade, or otherwise obtain a person's or a customer's biometric identifier or biometric information, unless it first: (1) informs the subject or the subject's legally authorized representative in writing that a biometric identifier or biometric information is being collected or stored; (2) informs the subject or the subject's legally authorized representative in writing of the specific purpose and length of term for which a biometric identifier or biometric information is being collected, stored, and used; and (3) receives a written release executed by the subject of the biometric identifier or biometric information or the subject's legally authorized representative.

This is the strictest of the state provisions for a voice dataset, because BIPA defines biometric identifier to include a voiceprint and the three requirements are cumulative: written notice, a stated purpose and retention term, and a signed release. The 2024 amendment confirmed that an electronic signature can satisfy the release requirement.

Tex. Bus. & Com. Code §503.001(b)

A person may not capture a biometric identifier of an individual for a commercial purpose unless the person: (1) informs the individual before capturing the biometric identifier; and (2) receives the individual's consent to capture the biometric identifier for a commercial purpose.

Texas also names voiceprints, but the requirement is lighter than Illinois: notice and consent before capture, with no written-release formality. Section 503.001(c)(3) adds a destruction duty, requiring the identifier to be destroyed no later than the first anniversary of the date the collection purpose expires.

RCW 19.375.010(1)

Biometric identifier does not include a physical or digital photograph, video or audio recording or data generated therefrom.

This is the most important sentence in the Washington statute for anyone buying speech data. The chapter covers voiceprints and similar measurements used to identify an individual, but it carves out audio recordings and data derived from them. A voice dataset assembled from recordings is outside the definition, the opposite of Illinois and Texas.

RCW 19.375.020(1)

A person may not enroll a biometric identifier in a database for a commercial purpose, without first providing notice, obtaining consent, or providing a mechanism to prevent subsequent use of the identifier for a commercial purpose.

Washington's trigger is enrollment in a database for a commercial purpose, not collection as such, and the three conditions are alternatives joined by "or" rather than cumulative. Combined with the audio exclusion, this means the analysis turns on whether you hold a biometric template or a recording.

Who it applies to

State biometric statutes reach you based on where the people are, not where your company is. A dataset of Illinois speakers triggers BIPA obligations for a buyer in any state or country, and the practical consequence is that a supplier has to know the speakers' locations and be able to prove them.

Colorado added biometric provisions to its privacy act through HB 24-1130, effective July 1, 2025, codified at C.R.S. §6-1-1314. It requires controllers to maintain a written policy with a retention schedule and an incident response protocol, requires disclosure and consent before collection, and gives consumers rights of access and correction. Enforcement is by the Attorney General only.

The private right of action question is the one that changes behavior. Illinois has one, which is why BIPA generates most of the litigation. Texas has none, and enforcement runs through the Attorney General, which is a slower but larger exposure: the Texas Attorney General settled with Meta for 1.4 billion dollars in 2024 and with Google for 1.375 billion dollars in 2025 over biometric claims. Washington's chapter is enforced under the Consumer Protection Act. Colorado is Attorney General only.

Finally, most biometric provisions are drafted around identification or authentication rather than around collection for training. That does not remove them from a voice deal, but it does mean the analysis turns on what the dataset is used for, which is a fact you control and can write down.

  • Illinois, Texas: voiceprint is named, so a voice dataset is in scope. Illinois has a private right of action.
  • Washington: audio recordings are expressly excluded, so the trigger is enrollment of a template rather than holding audio.
  • Colorado: biometric provisions apply from July 1, 2025, enforced by the Attorney General, up to 20,000 dollars per violation.

What it costs to get wrong

Illinois sets statutory damages per violation under 740 ILCS 14/20: 1,000 dollars or actual damages, whichever is greater, for a negligent violation, and 5,000 dollars or actual damages for an intentional or reckless one, plus attorney's fees and costs and injunctive relief. Those figures are why BIPA is the most litigated biometric statute in the country.

The 2024 amendment, Public Act 103-0769, cut the multiplier that made the numbers frightening. It added subsections to Section 20 providing that repeated collection of the same identifier from the same person by the same method is a single violation rather than one per scan, and it amended the definition of written release to include an electronic signature. The Seventh Circuit held in Clay v. Union Pacific in April 2026 that the damages limitation applies retroactively to pending cases.

Texas carries no private right of action, which sounds reassuring until the numbers arrive. The Attorney General's settlements with Meta at 1.4 billion dollars and Google at 1.375 billion dollars were the largest biometric outcomes on record, and they were reached under a statute with no damages clause at all.

Colorado treats a violation as a deceptive trade practice with civil penalties of up to 20,000 dollars per violation, enforced by the Attorney General, and the cure period for Colorado Privacy Act violations ended on January 1, 2025. The reputational and contractual consequence is common to all of these states: a dataset with Illinois speakers and no written release is not sellable to an enterprise buyer.

How to comply when you are buying data

The work here is geographic and documentary. You need to know which states your speakers were in, and you need a form that satisfies the strictest one that applies.

One structural point makes the rest easier. Almost every biometric statute is written around identification, and a training corpus is usually not used for identification. That does not remove the statutes from a voice deal, but it does mean the analysis turns on what the dataset trains, which is a fact you can write down and a supplier can warrant.

Where a project includes speakers in states with biometric statutes, we collect the release in the form the strictest applicable state requires rather than the cheapest one, and the state of each speaker is recorded in the manifest. We are a sourcing company rather than a law firm, so this is documentation of what the speakers agreed to, not a legal opinion on whether a statute applies to your product.

  • Get the speaker state in the manifest. Without it you cannot tell which statutes are in play, and reconstructing it later from a delivery list is often impossible.
  • Use a written release for every speaker regardless of state. Drafting one form to the Illinois standard means the same document works everywhere, and it removes the need to segment a corpus by jurisdiction.
  • Check that the release states the specific purpose and the retention term, not just the fact of collection. That is the requirement most often missed, and it is the one a reviewer reads for.
  • Confirm whether your intended use is identification or authentication. That is what triggers most biometric provisions, and it is a fact about your product rather than about the dataset.
  • Ask the supplier what happens to the biometric identifiers at the end of the term. Illinois and Texas both impose destruction duties, and the answer should be a documented schedule rather than an intention.

How we handle consent and licensing →

Related compliance topics

Not legal advice

We are a sourcing company, not a law firm. Nothing on this page is legal advice, and it does not create a lawyer–client relationship. Whether a particular dataset is permissible in your jurisdiction depends on your use case, where you operate, and where the people in the recordings are located. Our role is to document the chain of consent accurately so that your counsel can assess it.

Sourcing data under Biometric Privacy Laws?

Tell us the language, the hours, and what the data needs to look like. You will get a real number and a real timeline — not a range. If we cannot source it well, we will tell you that instead.

  • Pilot batch before the full run, so problems surface early.
  • Consent documentation delivered with the data.
  • No medical or clinical data. No recorded telephone calls.

We reply within two business days. Your details are used only to answer this request. See our privacy policy.

Contact

Talk to a human

Send a specification and we will come back with a real number and timeline.

Submit a sourcing request

Or email hello@linguacorpus.com