What the laws require
- Illinois BIPA: written informed consent BEFORE collection, a publicly available retention-and-destruction policy, destruction when the purpose is fulfilled (or within 3 years of the last interaction), no selling or profiting from biometric data — with a private right of action and statutory damages per violation.
- Texas CUBI: notice and consent before capture, destruction within a year of the purpose ending, no sale; enforced by the Attorney General.
- Washington HB 1493: notice and consent (or statutory exceptions) before enrolling biometric identifiers for a commercial purpose, plus retention limits.
- A growing list of city and state rules (e.g., NYC biometric notice rules, Colorado amendments) — monitor where you operate.
How NCheck supports it
- Consent capture at enrolment produces the written record BIPA-style laws expect.
- Retention automation and deletion tools implement your destruction schedule.
- On-premises deployment keeps biometric data inside your own systems — simplifying vendor-liability questions.
- Encrypted templates support the “reasonable standard of care” BIPA requires; raw images are not retained.
Practical checklist
- Collect written consent before first enrolment (use our free template).
- Publish a retention-and-destruction policy (use our free template).
- Set destruction timelines per state (BIPA: purpose fulfilled / 3 years).
- Review vendor contracts and insurance for biometric-claim coverage.
- Track new state and city laws where you have sites.
Free templates: Download the free consent-form and retention-policy templates →
This page is general information, not legal advice. Laws change — confirm current requirements with your counsel.
Where this matters most
See how NCheck handles attendance in the sectors where these rules bite hardest: Enterprise · Healthcare · Retail · Remote & hybrid teams · all industries.
Deploy it the compliant way
Run NCheck fully on your own server — data never leaves your network — or in our EU-hosted cloud. Either way, only encrypted templates are stored, never raw images. About on-premises → · Security & compliance →