Skip to content
RiskTemplates · The Daily Brief Sunday, July 26, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Data Privacy

Biometric Privacy Compliance for Fintechs: What BIPA, Texas CUBI, and the KYC Vendor Gap Actually Require

Most financial institutions assume GLBA exempts them from BIPA. It doesn't cover your KYC vendors — and Texas is enforcing its biometric law with billion-dollar settlements. Here's what your compliance program actually needs.

By Rebecca Leung · June 6, 2026 ·
Table of Contents

TL;DR:

  • Financial institutions are exempt from BIPA — but their KYC vendors generally are not. Courts have rejected the argument that a vendor collecting facial scans for a financial institution’s customers inherits the GLBA exemption (Davis v. Jumio Corp., N.D. Ill.).
  • Texas CUBI has become the new enforcement signal: the Texas AG settled with Meta for $1.4 billion (July 2024) and Google for $1.375 billion (May 2025), ending 15 years of minimal enforcement.
  • Employee biometrics — fingerprint timekeeping, facial access control — are outside GLBA’s scope and fully subject to BIPA in Illinois.
  • Compliance requires three distinct workstreams: vendor contract requirements, employee biometric consent programs, and customer-facing notice and consent flows.

Your KYC Tool Has a Biometric Problem You May Not Know About

Every modern KYC onboarding flow uses biometrics. Liveness checks. Facial matching against a government ID. Voiceprint authentication for call center verification. In most fintech stacks, these are handled by a third-party vendor — Jumio, Onfido, Persona, Socure, Stripe Identity, or one of a dozen others.

Here’s the compliance problem most teams miss: your GLBA status doesn’t protect your vendor.

Illinois’s Biometric Information Privacy Act — the most litigated biometric privacy law in the country — does contain a financial institution exemption. Banks and their affiliates subject to Title V of GLBA are broadly exempt from BIPA. That exemption is well-known and well-litigated. What’s less known: in Davis v. Jumio Corp., a federal court in the Northern District of Illinois rejected the argument that a KYC vendor serving a cryptocurrency exchange could rely on that exemption. The vendor was collecting biometric data on behalf of a financial services company. The court held the vendor wasn’t itself a GLBA-covered financial institution and couldn’t borrow its client’s status.

For most fintechs, this means the facial recognition tool doing your KYC liveness check has its own BIPA compliance obligation — independent of and not covered by yours.

The Three Places Biometric Data Shows Up in Financial Services

Biometric privacy compliance requires mapping where biometric data actually exists in your operations. For most financial institutions and fintechs, there are three distinct contexts, each with a different compliance profile.

1. Customer-Facing Identity Verification (KYC and Liveness Checks)

The most common biometric touch point. Almost every digital account opening flow includes a liveness check — a selfie matched against a government ID. Face geometry extracted from that selfie is a biometric identifier under both BIPA and CUBI.

Who typically owns the compliance obligation: The vendor, based on Davis v. Jumio Corp. and similar decisions. But the contractual responsibility for ensuring the vendor has adequate consent flows, retention schedules, and destruction procedures lands on you in vendor due diligence and contract negotiations.

2. Voice Authentication for Phone Banking

Many financial institutions use voiceprint authentication for call center verification. Voiceprints are explicitly covered under BIPA and CUBI. CUBI has a specific exemption for using voiceprints “for fraud prevention purposes” and to “complete an authorized financial transaction” — but that exemption is narrow. Using voice data for authentication (as opposed to processing the transaction itself) may not cleanly qualify, and legal counsel should evaluate whether the exemption applies to your specific implementation.

Who typically owns the compliance obligation: The financial institution directly when operating its own call center authentication system. If using a vendor (Nuance, Pindrop, and similar), the same vendor gap analysis from KYC applies.

3. Employee Biometrics (Timekeeping, Building Access, Device Authentication)

This is where the GLBA exemption most clearly does not help. Employee biometric timekeeping systems — fingerprint clocks, facial recognition entry systems, hand geometry scanners — fall entirely outside GLBA’s scope. GLBA covers your customers’ financial information, not your employees’ physical access records.

Who owns the compliance obligation: You, directly. If your Illinois locations use fingerprint timekeeping or facial recognition access control, BIPA applies in full: written employee consent before collection, a public retention and destruction policy, restrictions on third-party disclosure, and a destruction schedule triggered by the shorter of three years or when the purpose ends (typically employment termination).

BIPA class action history is dominated by employee timekeeping cases. Notable settlements include Clearview AI ($51.75 million), Speedway ($12.1 million), and Biometric Impressions ($10.85 million). A financial institution’s GLBA status provides no protection for its own employee biometric programs.

The Two Laws That Matter Most

FeatureBIPA (Illinois)CUBI (Texas)
Enacted20082009
Private right of actionYes — individuals can sueNo — AG enforcement only
Penalties$1,000/negligent; $5,000/intentional violationUp to $25,000 per violation
Consent requirementWritten consent before collectionNotice plus consent before collection
Data retention limitShorter of: 3 years, or when purpose expires1 year after purpose expires
Financial institution exemptionYes, for GLBA-covered entities; vendors excludedPartial — authorized transactions, voiceprint fraud
Recent enforcement signal$136.6M in settlements in 2025$1.4B (Meta), $1.375B (Google)

Why BIPA’s Private Right of Action Changed the Litigation Landscape

BIPA generated thousands of class actions because individuals can sue without proving actual harm — statutory damages of $1,000 to $5,000 per violation create enormous class-wide exposure when violations are systemic. A 2024 amendment redefined “repeated collection or transmission of the same biometric data by the same party” as a single violation rather than counting each capture separately, significantly limiting potential class damages. The Seventh Circuit confirmed in April 2026 that this amendment applies retroactively to pending cases. BIPA class action filings dropped to approximately 150 new lawsuits in 2025 — the lowest level in eight years — and total settlements declined to $136.6 million from $206 million in 2024. The law is still active; the exposure is just more bounded.

Why Texas CUBI Is the Enforcement Signal to Watch

CUBI had near-zero enforcement for fifteen years after its 2009 enactment. That changed with two massive settlements:

  • July 2024: The Texas AG settled with Meta for $1.4 billion over facial recognition features in Facebook and Instagram that captured face geometry from Texas users without CUBI-compliant consent.
  • May 2025: The Texas AG settled with Google for $1.375 billion over CUBI violations combined with Texas Data Privacy and Security Act claims.

These settlements — totaling nearly $2.8 billion — reflect an AG’s office that has concluded biometric data is an enforcement priority and is willing to pursue technology companies at the largest scale. Financial institutions offering account opening with facial KYC or voice authentication in Texas should evaluate their CUBI compliance against the standards these settlements imply. The AG’s theory in both cases centered on collecting face geometry without adequate notice and consent before collection — the exact mechanism used in standard fintech KYC liveness checks.

The State Patchwork Beyond BIPA and CUBI

Illinois and Texas have standalone biometric privacy laws with specific requirements. Beyond those, biometric data is increasingly classified as “sensitive data” requiring heightened protection under comprehensive state privacy laws:

StateLawBiometric TreatmentFinancial Services Exemption
IllinoisBIPA (740 ILCS 14/)Standalone biometric lawGLBA-covered entities exempt; vendors not
TexasCUBI (Bus. & Com. § 503)Standalone biometric lawPartial exemption for authorized transactions
WashingtonRCW 19.375Standalone biometric lawGLBA entities largely exempt
CaliforniaCPRASensitive data, opt-in consentGLBA exemption for Reg P-covered data
MarylandMODPA (eff. Jan. 1, 2026)Sensitive data, strict purpose limitsApplies to 35K+ resident threshold; narrow exemptions
ColoradoCPASensitive data, opt-inGLBA exemption for financial institutions
Montana, Minnesota, NebraskaVarious comprehensive lawsSensitive data categoryVarying, state-specific GLBA exemptions

According to Husch Blackwell’s 2025 State Biometric Privacy Law Tracker, multiple additional states are actively considering biometric-specific legislation. The trajectory is clear: biometric data is moving from unregulated to sensitive-data-with-opt-in across the country, with no federal preemption creating a floor.

For financial institutions with customers and employees in multiple states, the compliance obligation compounds quickly. The State Privacy Laws and the GLBA Safe Harbor analysis covers the broader question of which state laws financial institutions can rely on GLBA to preempt — and biometric laws are a significant exception to that general analysis.

What Fintechs Actually Need to Do

Biometric privacy compliance is a three-workstream problem.

Workstream 1: Vendor Assessment

For every vendor that touches biometric data on your behalf — KYC liveness checks, voice authentication, facial recognition for account access, document verification with face matching — conduct a biometric-specific vendor review:

  • What biometric identifiers does the vendor collect, in which states, from which individuals?
  • Does the vendor maintain a BIPA-compliant written policy on biometric data retention and destruction?
  • Does the vendor obtain appropriate consent — and does that consent flow satisfy requirements for each customer’s jurisdiction?
  • What happens to biometric data after account closure or end of the vendor relationship?
  • What is the vendor’s incident notification procedure if biometric data is exposed in a breach?

This due diligence should be documented and updated at each vendor review cycle. For a structured approach to the questionnaire and evidence review, our post on vendor due diligence techniques covers the framework.

Workstream 2: Employee Biometrics

If you operate fingerprint timekeeping, facial recognition building access, or any employee biometric system in any covered state:

  1. A written, publicly available biometric data retention and destruction policy (posted on your intranet and available to employees on request)
  2. Written informed consent from each employee before any biometric collection
  3. A destruction schedule (shorter of 3 years or when employment purpose ends under BIPA; 1 year after purpose expires under CUBI)
  4. Restrictions on third-party disclosure to only: completing the service, complying with law, or with the employee’s consent

If you use a third-party time-and-attendance vendor for fingerprint clocking, request their BIPA compliance documentation and confirm whether they’ve indemnified you against biometric privacy claims arising from their collection methodology.

Workstream 3: Customer-Facing Notice and DPA Review

Even where GLBA exemptions apply or vendor obligations control, your customer-facing privacy notices should describe biometric data collection as part of your identity verification process. The Privacy Impact Assessment process is a useful framework for assessing consent adequacy, data minimization, and vendor data processing agreement requirements for each biometric use case.

Review existing vendor DPAs to confirm they address: (a) purpose limitation for biometric data, (b) retention and destruction timelines by jurisdiction, (c) prohibition on selling or disclosing biometric data, and (d) incident notification obligations specific to biometric data breaches.

So What?

If your compliance team’s working assumption is “GLBA covers our biometric privacy obligations,” this post is the correction. GLBA covers you; it doesn’t cover your vendors, and it doesn’t cover your employee programs. The Texas AG’s enforcement wave against Meta ($1.4B) and Google ($1.375B) demonstrates that biometric privacy is active enforcement risk in states where your customers and employees live and work.

Three items to put on your compliance calendar:

  1. Map every vendor that collects biometric data in your KYC, authentication, or operations stack — and confirm they have standalone biometric compliance documentation, not borrowed financial institution status
  2. Audit employee biometric programs in Illinois, Texas, and Washington for consent, policy, and retention schedule compliance
  3. Review vendor contracts to confirm biometric data handling obligations — consent ownership, retention timelines, incident notification, destruction — are explicit and allocated

For a comprehensive privacy compliance framework covering multi-state obligations including biometric data requirements, vendor DPA checklists, and consumer rights workflows, the Data Privacy Compliance Kit includes a 19-state applicability matrix built for financial services teams navigating this landscape.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Are financial institutions exempt from BIPA?
Banks and their affiliates that are subject to Title V of GLBA are broadly exempt from BIPA's requirements. However, this exemption does not extend to third-party vendors providing services to financial institutions. In Davis v. Jumio Corp., a federal court held that a KYC vendor collecting facial scans on behalf of a financial services company could not borrow its client's GLBA status — the vendor had its own independent BIPA compliance obligation.
What does Texas CUBI require of financial services companies?
Texas CUBI (Business & Commerce Code Chapter 503) prohibits capturing biometric identifiers for commercial purposes without providing notice and obtaining consent. It applies to financial institutions subject to limited exemptions — completing authorized financial transactions and using voiceprints for fraud prevention. The Texas AG enforces CUBI with civil penalties up to $25,000 per violation. The $1.4 billion Meta settlement (July 2024) and $1.375 billion Google settlement (May 2025) demonstrate the AG's enforcement posture.
Does BIPA apply to employee biometrics at a financial institution?
Yes. The GLBA exemption covers your customers' financial information, not your employees' physical access data. A bank using fingerprint timekeeping clocks or facial recognition building access in Illinois is fully subject to BIPA and needs written employee consent, a published retention and destruction policy, and restrictions on third-party disclosure. BIPA employee timekeeping cases have produced settlements ranging from hundreds of thousands to over $50 million.
What should I put in vendor contracts for biometric data processing?
Key contract terms include: (1) which biometric laws the vendor's system triggers based on user geography; (2) which party owns the consent mechanism — vendor or you; (3) data retention and destruction timelines (BIPA: shorter of 3 years or purpose expiration; CUBI: 1 year after purpose expires); (4) incident notification procedures for biometric data breaches; (5) indemnification for biometric privacy law violations arising from vendor's collection methodology.
What biometric data is covered under these laws?
Both BIPA and CUBI cover fingerprints, voiceprints, retina or iris scans, handprints, and face geometry — meaning facial recognition analysis of an image, not merely the photograph itself. Voice recordings used for authentication (voiceprints) are covered. Photographs and surveillance video are generally not covered, but facial recognition analysis of those images typically is — which matters for account opening liveness checks and call center voice authentication.
Which states currently have biometric-specific privacy laws?
Illinois (BIPA), Texas (CUBI), and Washington (RCW 19.375) have standalone biometric laws. In addition, California, Maryland, Colorado, Montana, Minnesota, and approximately a dozen other states with comprehensive privacy laws treat biometric data as 'sensitive data' requiring opt-in consent. The threshold is expanding: multiple 2026 state laws bring new biometric requirements into effect for companies that previously had no biometric obligations.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.