What the laws require
- •Illinois BIPA: written informed consent BEFORE collection, a publicly available retention-and-destruction policy, destruction when the purpose is fulfilled (or within 3 years of the last interaction), no selling or profiting from biometric data — with a private right of action and statutory damages per violation.
- •Texas CUBI: notice and consent before capture, destruction within a year of the purpose ending, no sale; enforced by the Attorney General.
- •Washington HB 1493: notice and consent (or statutory exceptions) before enrolling biometric identifiers for a commercial purpose, plus retention limits.
- •A growing list of city and state rules (e.g., NYC biometric notice rules, Colorado amendments) — monitor where you operate.
How NCheck supports it
- •Consent capture at enrolment produces the written record BIPA-style laws expect.
- •Retention automation and deletion tools implement your destruction schedule.
- •On-premises deployment keeps biometric data inside your own systems — simplifying vendor-liability questions.
- •Encrypted templates support the “reasonable standard of care” BIPA requires; raw images are not retained.
Practical checklist
- ✓Collect written consent before first enrolment (use our free template).
- ✓Publish a retention-and-destruction policy (use our free template).
- ✓Set destruction timelines per state (BIPA: purpose fulfilled / 3 years).
- ✓Review vendor contracts and insurance for biometric-claim coverage.
- ✓Track new state and city laws where you have sites.
Download the free consent-form and retention-policy templates →
This page is general information, not legal advice. Laws change — confirm current requirements with your counsel.
← All regulations