Feature Data Privacy
Biometric Privacy Compliance for Fintechs: What BIPA, Texas CUBI, and the KYC Vendor Gap Actually Require
Most financial institutions assume GLBA exempts them from BIPA. It doesn't cover your KYC vendors — and Texas is enforcing its biometric law with billion-dollar settlements. Here's what your compliance program actually needs.
Table of Contents
TL;DR:
- Financial institutions are exempt from BIPA — but their KYC vendors generally are not. Courts have rejected the argument that a vendor collecting facial scans for a financial institution’s customers inherits the GLBA exemption (Davis v. Jumio Corp., N.D. Ill.).
- Texas CUBI has become the new enforcement signal: the Texas AG settled with Meta for $1.4 billion (July 2024) and Google for $1.375 billion (May 2025), ending 15 years of minimal enforcement.
- Employee biometrics — fingerprint timekeeping, facial access control — are outside GLBA’s scope and fully subject to BIPA in Illinois.
- Compliance requires three distinct workstreams: vendor contract requirements, employee biometric consent programs, and customer-facing notice and consent flows.
Your KYC Tool Has a Biometric Problem You May Not Know About
Every modern KYC onboarding flow uses biometrics. Liveness checks. Facial matching against a government ID. Voiceprint authentication for call center verification. In most fintech stacks, these are handled by a third-party vendor — Jumio, Onfido, Persona, Socure, Stripe Identity, or one of a dozen others.
Here’s the compliance problem most teams miss: your GLBA status doesn’t protect your vendor.
Illinois’s Biometric Information Privacy Act — the most litigated biometric privacy law in the country — does contain a financial institution exemption. Banks and their affiliates subject to Title V of GLBA are broadly exempt from BIPA. That exemption is well-known and well-litigated. What’s less known: in Davis v. Jumio Corp., a federal court in the Northern District of Illinois rejected the argument that a KYC vendor serving a cryptocurrency exchange could rely on that exemption. The vendor was collecting biometric data on behalf of a financial services company. The court held the vendor wasn’t itself a GLBA-covered financial institution and couldn’t borrow its client’s status.
For most fintechs, this means the facial recognition tool doing your KYC liveness check has its own BIPA compliance obligation — independent of and not covered by yours.
The Three Places Biometric Data Shows Up in Financial Services
Biometric privacy compliance requires mapping where biometric data actually exists in your operations. For most financial institutions and fintechs, there are three distinct contexts, each with a different compliance profile.
1. Customer-Facing Identity Verification (KYC and Liveness Checks)
The most common biometric touch point. Almost every digital account opening flow includes a liveness check — a selfie matched against a government ID. Face geometry extracted from that selfie is a biometric identifier under both BIPA and CUBI.
Who typically owns the compliance obligation: The vendor, based on Davis v. Jumio Corp. and similar decisions. But the contractual responsibility for ensuring the vendor has adequate consent flows, retention schedules, and destruction procedures lands on you in vendor due diligence and contract negotiations.
2. Voice Authentication for Phone Banking
Many financial institutions use voiceprint authentication for call center verification. Voiceprints are explicitly covered under BIPA and CUBI. CUBI has a specific exemption for using voiceprints “for fraud prevention purposes” and to “complete an authorized financial transaction” — but that exemption is narrow. Using voice data for authentication (as opposed to processing the transaction itself) may not cleanly qualify, and legal counsel should evaluate whether the exemption applies to your specific implementation.
Who typically owns the compliance obligation: The financial institution directly when operating its own call center authentication system. If using a vendor (Nuance, Pindrop, and similar), the same vendor gap analysis from KYC applies.
3. Employee Biometrics (Timekeeping, Building Access, Device Authentication)
This is where the GLBA exemption most clearly does not help. Employee biometric timekeeping systems — fingerprint clocks, facial recognition entry systems, hand geometry scanners — fall entirely outside GLBA’s scope. GLBA covers your customers’ financial information, not your employees’ physical access records.
Who owns the compliance obligation: You, directly. If your Illinois locations use fingerprint timekeeping or facial recognition access control, BIPA applies in full: written employee consent before collection, a public retention and destruction policy, restrictions on third-party disclosure, and a destruction schedule triggered by the shorter of three years or when the purpose ends (typically employment termination).
BIPA class action history is dominated by employee timekeeping cases. Notable settlements include Clearview AI ($51.75 million), Speedway ($12.1 million), and Biometric Impressions ($10.85 million). A financial institution’s GLBA status provides no protection for its own employee biometric programs.
The Two Laws That Matter Most
| Feature | BIPA (Illinois) | CUBI (Texas) |
|---|---|---|
| Enacted | 2008 | 2009 |
| Private right of action | Yes — individuals can sue | No — AG enforcement only |
| Penalties | $1,000/negligent; $5,000/intentional violation | Up to $25,000 per violation |
| Consent requirement | Written consent before collection | Notice plus consent before collection |
| Data retention limit | Shorter of: 3 years, or when purpose expires | 1 year after purpose expires |
| Financial institution exemption | Yes, for GLBA-covered entities; vendors excluded | Partial — authorized transactions, voiceprint fraud |
| Recent enforcement signal | $136.6M in settlements in 2025 | $1.4B (Meta), $1.375B (Google) |
Why BIPA’s Private Right of Action Changed the Litigation Landscape
BIPA generated thousands of class actions because individuals can sue without proving actual harm — statutory damages of $1,000 to $5,000 per violation create enormous class-wide exposure when violations are systemic. A 2024 amendment redefined “repeated collection or transmission of the same biometric data by the same party” as a single violation rather than counting each capture separately, significantly limiting potential class damages. The Seventh Circuit confirmed in April 2026 that this amendment applies retroactively to pending cases. BIPA class action filings dropped to approximately 150 new lawsuits in 2025 — the lowest level in eight years — and total settlements declined to $136.6 million from $206 million in 2024. The law is still active; the exposure is just more bounded.
Why Texas CUBI Is the Enforcement Signal to Watch
CUBI had near-zero enforcement for fifteen years after its 2009 enactment. That changed with two massive settlements:
- July 2024: The Texas AG settled with Meta for $1.4 billion over facial recognition features in Facebook and Instagram that captured face geometry from Texas users without CUBI-compliant consent.
- May 2025: The Texas AG settled with Google for $1.375 billion over CUBI violations combined with Texas Data Privacy and Security Act claims.
These settlements — totaling nearly $2.8 billion — reflect an AG’s office that has concluded biometric data is an enforcement priority and is willing to pursue technology companies at the largest scale. Financial institutions offering account opening with facial KYC or voice authentication in Texas should evaluate their CUBI compliance against the standards these settlements imply. The AG’s theory in both cases centered on collecting face geometry without adequate notice and consent before collection — the exact mechanism used in standard fintech KYC liveness checks.
The State Patchwork Beyond BIPA and CUBI
Illinois and Texas have standalone biometric privacy laws with specific requirements. Beyond those, biometric data is increasingly classified as “sensitive data” requiring heightened protection under comprehensive state privacy laws:
| State | Law | Biometric Treatment | Financial Services Exemption |
|---|---|---|---|
| Illinois | BIPA (740 ILCS 14/) | Standalone biometric law | GLBA-covered entities exempt; vendors not |
| Texas | CUBI (Bus. & Com. § 503) | Standalone biometric law | Partial exemption for authorized transactions |
| Washington | RCW 19.375 | Standalone biometric law | GLBA entities largely exempt |
| California | CPRA | Sensitive data, opt-in consent | GLBA exemption for Reg P-covered data |
| Maryland | MODPA (eff. Jan. 1, 2026) | Sensitive data, strict purpose limits | Applies to 35K+ resident threshold; narrow exemptions |
| Colorado | CPA | Sensitive data, opt-in | GLBA exemption for financial institutions |
| Montana, Minnesota, Nebraska | Various comprehensive laws | Sensitive data category | Varying, state-specific GLBA exemptions |
According to Husch Blackwell’s 2025 State Biometric Privacy Law Tracker, multiple additional states are actively considering biometric-specific legislation. The trajectory is clear: biometric data is moving from unregulated to sensitive-data-with-opt-in across the country, with no federal preemption creating a floor.
For financial institutions with customers and employees in multiple states, the compliance obligation compounds quickly. The State Privacy Laws and the GLBA Safe Harbor analysis covers the broader question of which state laws financial institutions can rely on GLBA to preempt — and biometric laws are a significant exception to that general analysis.
What Fintechs Actually Need to Do
Biometric privacy compliance is a three-workstream problem.
Workstream 1: Vendor Assessment
For every vendor that touches biometric data on your behalf — KYC liveness checks, voice authentication, facial recognition for account access, document verification with face matching — conduct a biometric-specific vendor review:
- What biometric identifiers does the vendor collect, in which states, from which individuals?
- Does the vendor maintain a BIPA-compliant written policy on biometric data retention and destruction?
- Does the vendor obtain appropriate consent — and does that consent flow satisfy requirements for each customer’s jurisdiction?
- What happens to biometric data after account closure or end of the vendor relationship?
- What is the vendor’s incident notification procedure if biometric data is exposed in a breach?
This due diligence should be documented and updated at each vendor review cycle. For a structured approach to the questionnaire and evidence review, our post on vendor due diligence techniques covers the framework.
Workstream 2: Employee Biometrics
If you operate fingerprint timekeeping, facial recognition building access, or any employee biometric system in any covered state:
- A written, publicly available biometric data retention and destruction policy (posted on your intranet and available to employees on request)
- Written informed consent from each employee before any biometric collection
- A destruction schedule (shorter of 3 years or when employment purpose ends under BIPA; 1 year after purpose expires under CUBI)
- Restrictions on third-party disclosure to only: completing the service, complying with law, or with the employee’s consent
If you use a third-party time-and-attendance vendor for fingerprint clocking, request their BIPA compliance documentation and confirm whether they’ve indemnified you against biometric privacy claims arising from their collection methodology.
Workstream 3: Customer-Facing Notice and DPA Review
Even where GLBA exemptions apply or vendor obligations control, your customer-facing privacy notices should describe biometric data collection as part of your identity verification process. The Privacy Impact Assessment process is a useful framework for assessing consent adequacy, data minimization, and vendor data processing agreement requirements for each biometric use case.
Review existing vendor DPAs to confirm they address: (a) purpose limitation for biometric data, (b) retention and destruction timelines by jurisdiction, (c) prohibition on selling or disclosing biometric data, and (d) incident notification obligations specific to biometric data breaches.
So What?
If your compliance team’s working assumption is “GLBA covers our biometric privacy obligations,” this post is the correction. GLBA covers you; it doesn’t cover your vendors, and it doesn’t cover your employee programs. The Texas AG’s enforcement wave against Meta ($1.4B) and Google ($1.375B) demonstrates that biometric privacy is active enforcement risk in states where your customers and employees live and work.
Three items to put on your compliance calendar:
- Map every vendor that collects biometric data in your KYC, authentication, or operations stack — and confirm they have standalone biometric compliance documentation, not borrowed financial institution status
- Audit employee biometric programs in Illinois, Texas, and Washington for consent, policy, and retention schedule compliance
- Review vendor contracts to confirm biometric data handling obligations — consent ownership, retention timelines, incident notification, destruction — are explicit and allocated
For a comprehensive privacy compliance framework covering multi-state obligations including biometric data requirements, vendor DPA checklists, and consumer rights workflows, the Data Privacy Compliance Kit includes a 19-state applicability matrix built for financial services teams navigating this landscape.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Are financial institutions exempt from BIPA?
What does Texas CUBI require of financial services companies?
Does BIPA apply to employee biometrics at a financial institution?
What should I put in vendor contracts for biometric data processing?
What biometric data is covered under these laws?
Which states currently have biometric-specific privacy laws?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
Oregon's Privacy Law Has a Feature No Other State Has — and Financial Services Companies Are Probably in Scope
The Oregon Consumer Privacy Act's 30-day cure period ended January 1, 2026. The AG can now sue without notice. More importantly for financial services: the GLBA exemption is narrower than most assume, fintechs have significant exposure on non-NPI data, and Oregon requires something no other state does — a list of the specific named third parties that received consumer data.
Jul 17, 2026
Data Privacy
Connecticut's CTDPA Just Got a Lot Bigger — And Fintechs May Not Know They're Covered
Connecticut's CTDPA expanded on July 1, 2026 — lower thresholds, narrowed GLBA exemption, eliminated cure period, new profiling impact assessments. Here's what fintechs and nonbank lenders need to do now.
Jul 16, 2026
Data Privacy
NYDFS Part 500 in 2026: What 27 Consent Orders and $144M in Fines Tell You About Examiner Priorities
All Part 500 amended requirements are now in effect. NYDFS has 27 consent orders and $144M in fines under its belt. Here's what examiners are finding — and what to do before they show up at your door.
Jul 15, 2026