California
California Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 15 primary sources cited on this page. How we verify our legal content

California treats biometric data as sensitive personal information under the CCPA/CPRA (Cal. Civ. Code 1798.100 et seq.) rather than through a standalone statute. This gives consumers the right to know what biometric information businesses collect, request deletion, and limit its use beyond what is reasonably necessary.
California does not have a standalone biometric privacy statute like Illinois's BIPA. Instead, the state folds biometric data into its comprehensive consumer privacy framework under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). For anyone collecting fingerprints, facial scans, or voiceprints in California, the rules are embedded throughout the California Data Privacy Laws ecosystem.
This means biometric protections in California come from multiple overlapping sources: CCPA/CPRA consumer rights, breach notification statutes, labor code restrictions, and new CPPA regulations on automated decisionmaking. Here is what you need to know.
How California Defines Biometric Information
The CCPA defines "biometric information" under Cal. Civ. Code 1798.140(c) as:
Biometric information means an individual's physiological, biological, or behavioral characteristics, including information pertaining to an individual's deoxyribonucleic acid (DNA), that is used or is intended to be used singly or in combination with each other or with other identifying data, to establish individual identity.
The statute lists specific examples:
- Fingerprint, face, hand, palm, and vein pattern imagery
- Iris and retina scans
- Voice recordings from which identifiers can be extracted
- Keystroke patterns or rhythms
- Gait patterns or rhythms
- Sleep, health, or exercise data containing identifying information
Biometric information is also classified as a type of "personal information" under Section 1798.140(v)(1)(E).

Sensitive Personal Information Classification
Under the CPRA amendments, biometric information processed for the purpose of uniquely identifying a consumer qualifies as "sensitive personal information" under Section 1798.140(ae). This elevated classification triggers stronger protections than regular personal information.
One important distinction: photographs alone are not biometric information under the CCPA. However, photographs used or stored for facial recognition purposes do qualify.
Consumer Rights Over Biometric Data
Because biometric data is sensitive personal information, California consumers have several specific rights under the CCPA/CPRA:
Right to Limit Use and Disclosure. Consumers can direct businesses to limit the use of their biometric data to what is "necessary to perform the services or provide the goods reasonably expected by an average consumer." Businesses must provide a "Limit the Use of My Sensitive Personal Information" link on their websites.
Right to Know. Consumers can request that a business disclose what biometric information it has collected, the sources it collected from, the business purpose for collecting it, and the categories of third parties it has been shared with.
Right to Delete. Consumers can request deletion of their biometric data. Businesses must comply and direct service providers to delete the data as well.
Right to Correct. If biometric data is inaccurate, consumers can request correction.
Right to Opt Out of Sale or Sharing. Consumers can opt out of the sale or sharing of their biometric information with third parties.
No Retaliation. Businesses cannot discriminate against consumers who exercise these rights by denying goods, charging different prices, or providing a different quality of service.

Private Right of Action for Biometric Data Breaches
Cal. Civ. Code 1798.150 gives consumers the right to sue when their unencrypted personal information is exposed through a data breach caused by a business's failure to maintain reasonable security. This is one of the few areas where California law allows private lawsuits rather than relying solely on agency enforcement.
"Personal information" in the breach context includes a person's name combined with "unique biometric data generated from measurements or technical analysis of human body characteristics, such as a fingerprint, retina, or iris image, used to authenticate a specific individual."
What Consumers Can Recover
- Statutory damages: $107 to $799 per consumer per incident
- Actual damages if greater than statutory damages
- Injunctive or declaratory relief
- Any other relief the court deems proper
Requirements Before Filing Suit
Consumers must provide the business 30 days' written notice identifying the specific violations before filing a statutory damages claim. In the event a cure is possible, if the business actually cures the violation within 30 days and provides a written statement confirming the fix, statutory damages cannot be pursued. Actual damages claims do not require prior notice.
That cure exception is narrower than it looks. Section 1798.150(b) expressly provides that implementing and maintaining reasonable security procedures and practices under Section 1798.81.5 following a breach does not constitute a cure with respect to that breach. Because this private right of action exists only for breaches caused by a failure to maintain reasonable security, a business cannot defeat a claim by tightening its security after the fact.
This private right of action applies only to data breach scenarios. For other CCPA violations involving biometric data, enforcement runs through the Attorney General and CPPA.
Breach Notification Requirements
California's breach notification statutes, Cal. Civ. Code 1798.29 (government agencies) and 1798.82 (businesses), require notification when unencrypted biometric data is compromised. Learn more in our California Data Breach Notification Laws guide.
Key requirements for biometric data breaches include:
- Timeline: The two statutes set different standards. Businesses must disclose within 30 calendar days of discovery or notification of the breach under Section 1798.82(a)(2)(A), though that clock may be delayed for the legitimate needs of law enforcement or as necessary to determine the scope of the breach and restore the integrity of the data system. Government agencies under Section 1798.29 have no fixed day count at all: they must disclose "in the most expedient time possible and without unreasonable delay"
- Attorney General notice: Required when more than 500 California residents are affected
- Special biometric instructions (optional): At the business's discretion, breach notices involving biometric data may include instructions on how to notify other entities that used the same type of biometric data as an authenticator, so those entities can stop relying on the compromised data
- Required content: Notices must follow a prescribed format with headings including "What Happened," "What Information Was Involved," "What We Are Doing," "What You Can Do," and "For More Information"
Employer Obligations for Biometric Data
California employers face specific biometric data requirements from multiple sources.
CCPA/CPRA Employee Coverage
The employee personal information exemption under the CCPA expired on January 1, 2023. Since then, California employees have the same rights as consumers regarding their biometric data. Employers that collect fingerprints for time clocks, facial scans for building access, or other biometric identifiers must:
- Provide notice at or before the point of biometric data collection
- Honor employee requests to know, delete, correct, and limit the use of biometric data
- Allow employees to limit the use of biometric data to what is necessary for the employment relationship
- Maintain reasonable security procedures to protect biometric data
California Labor Code Section 1051
California Labor Code 1051 adds a narrower, older protection. It makes it a misdemeanor to require an employee or job applicant, as a condition of getting or keeping the job, to be photographed or fingerprinted by a third party who wants that photograph or fingerprint (or information about it) in order to furnish it to another employer or third person, where it could be used to the employee's or applicant's detriment. It is an anti-blacklisting statute aimed at third parties compiling data to share with other employers.
This means employers cannot condition a job on submitting to third-party photographing or fingerprinting intended to blacklist the worker with other employers. The statute does not, by itself, restrict how an employer shares biometric data it lawfully collects and controls for its own internal purposes, such as timekeeping.

Enforcement and Penalties
Two agencies share enforcement authority over biometric data violations in California.
California Privacy Protection Agency (CPPA)
The CPPA was created by the CPRA in 2020 and has primary enforcement authority. As of 2025, the CPPA can impose:
- $2,663 per unintentional violation (adjusted annually for inflation)
- $7,988 per intentional violation
- $7,988 per violation involving a minor's data
The CPPA has been active. In 2025 alone, it issued a $632,500 fine against Honda, a $345,178 fine against Todd Snyder, and launched a Data Broker Enforcement Strike Force. While none of these actions specifically targeted biometric data misuse, they demonstrate the agency's willingness to pursue meaningful penalties.
Attorney General
The California Attorney General retains concurrent enforcement authority under Cal. Civ. Code 1798.199.90. The AG can bring civil actions for CCPA violations, including those involving biometric data.

New CPPA Regulations Effective 2026
The CPPA finalized new regulations on September 23, 2025, effective January 1, 2026, covering automated decisionmaking technology (ADMT), risk assessments, and cybersecurity audits. These regulations have direct implications for biometric data:
Automated Decisionmaking Technology. Businesses that use ADMT to process biometric information for profiling or identity verification must comply with new requirements starting January 1, 2027. This includes providing pre-use notices, offering opt-out options, and conducting accuracy evaluations and nondiscrimination audits.
Risk Assessments. Processing biometric data for profiling or identity verification qualifies as "significant risk" processing. Businesses engaged in such processing must complete risk assessments and submit attestations to the CPPA by April 1, 2028.
Cybersecurity Audits. Businesses that process sensitive personal information, including biometric data, at scale may need to conduct annual cybersecurity audits. Deadlines are tiered by revenue, with the largest companies (over $100 million) required to submit certifications by April 1, 2028.
Recent Legislative Expansions
California continues to expand the scope of biometric-adjacent protections through new legislation.
SB 1223: Neural Data Protection (Effective January 1, 2025)
SB 1223 added "neural data" to the definition of sensitive personal information under Section 1798.140(ae). Neural data means information generated by measuring the activity of a consumer's central or peripheral nervous system, and that is not inferred from non-neural information.
This gives brainwave data from EEG headsets, neurofeedback devices, and brain-computer interfaces the same level of protection as fingerprints and facial scans. California became the first state to explicitly protect neural data under a consumer privacy law.
AB 1008: AI Model Coverage (Effective January 1, 2025)
AB 1008 clarified that biometric data collected without a consumer's knowledge can never be considered "publicly available" information, regardless of context. The bill also expanded the definition of "personal information" to cover abstract digital formats, including AI model weights and tokens derived from a consumer's personal data.
For biometric data specifically, this means a facial recognition model trained on a consumer's face images without their knowledge cannot claim that data was "publicly available" and therefore exempt from CCPA requirements.
How California Compares to Illinois BIPA
California's approach differs significantly from Illinois's Biometric Information Privacy Act (BIPA), which is the most aggressive standalone biometric privacy law in the country.
| Feature | California (CCPA/CPRA) | Illinois (BIPA) |
|---|---|---|
| Law Type | Comprehensive privacy law | Standalone biometric statute |
| Consent Required | Notice + right to limit use | Written informed consent before collection |
| Private Right of Action | Data breaches only (1798.150) | Any violation of the statute |
| Damages | $107-$799 per breach incident | $1,000-$5,000 per violation |
| Retention/Destruction | General deletion rights | Mandatory written retention policy |
| Enforcement | CPPA + AG + limited private action | Private lawsuits + AG |
California provides broader coverage since biometric protections are part of a comprehensive data privacy framework. However, the private right of action is far more limited than Illinois, where individual plaintiffs have driven billions of dollars in settlements.
Sources and References
This article references California statutes, regulatory materials, and official agency publications. For the full text of the CCPA/CPRA, visit the California Legislative Information website. For current CPPA enforcement activity and rulemaking, visit cppa.ca.gov.
This article provides general legal information about California biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official California government sources.
More California Laws
Frequently Asked Questions
Does California have a biometric privacy law like Illinois BIPA?
No. California does not have a standalone biometric privacy statute. Instead, biometric data is protected as 'sensitive personal information' under the CCPA/CPRA (Cal. Civ. Code 1798.100 et seq.). This gives consumers the right to know what biometric data is collected, request deletion, limit its use, and opt out of its sale. The protections are comprehensive but embedded within the broader privacy law rather than existing as a separate biometric-specific statute.
Can I sue a company in California for collecting my fingerprints without consent?
The private right of action under Cal. Civ. Code 1798.150 is limited to data breach scenarios where a business failed to maintain reasonable security and your unencrypted biometric data was exposed. You cannot sue under the CCPA simply for collecting biometric data without adequate notice. For non-breach violations, you would need to file a complaint with the CPPA or the Attorney General, who can pursue enforcement on your behalf.
What biometric data do California employers need to protect?
Since the employee exemption expired on January 1, 2023, California employers must treat employee biometric data the same as consumer biometric data under the CCPA/CPRA. This includes fingerprints from time clocks, facial scans for access control, and voiceprints. Employers must provide notice before collection, honor deletion and access requests, and allow employees to limit the use of their biometric data. California Labor Code 1051 separately makes it a misdemeanor to condition a job on being photographed or fingerprinted by a third party that intends to furnish that data to another employer to the worker's detriment.
What are the penalties for mishandling biometric data in California?
The CPPA can impose fines of $2,663 per unintentional violation and $7,988 per intentional violation or violations involving minors (2025 amounts, adjusted annually). For data breaches involving biometric data, consumers can sue for $107 to $799 per incident per consumer under Cal. Civ. Code 1798.150. The Attorney General can also bring civil enforcement actions. Employers who condition employment on photographing or fingerprinting by a third party intending to furnish that data to another employer, in violation of Labor Code 1051, face misdemeanor charges.
Does California law cover facial recognition and AI-based biometric systems?
Yes. The CCPA covers biometric data extracted from facial recognition technology, and photographs stored for facial recognition purposes qualify as biometric information. AB 1008 (effective January 2025) clarified that biometric data collected without a consumer's knowledge cannot be classified as publicly available, closing a potential loophole for facial recognition systems. New CPPA regulations effective January 1, 2026, impose additional requirements on automated decisionmaking technology that processes biometric data for profiling or identity verification.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the breach notification timeline to distinguish the 30-day deadline that applies to businesses under Civil Code 1798.82 from the "most expedient time possible" standard that applies to government agencies under 1798.29, and added the statutory carve-out providing that fixing security after a breach does not count as a cure under 1798.150(b).
Updated the private-right-of-action statutory damages range for biometric data breaches from the pre-2025 $100-$750 to the current CPI-adjusted $107-$799 per consumer per incident, corrected a mis-cited Civil Code subsection for the personal-information definition, corrected the biometric-information statutory quote to match the exact statute text, and fixed a one-day date error on a CPPA regulation announcement.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the Labor Code 1051 description (it is a narrow anti-blacklisting provision about third-party fingerprinting as a condition of employment, not a general ban on employers sharing internally-collected biometric data) and fixed the CCPA breach-notice bullet that presented the optional biometric cross-notification instruction (Civ. Code 1798.82(d)(3)(C)) as mandatory.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
California Civil Code
§ 1798.100In forcecited in 11 of our articles
General Duties of Businesses that Collect Personal Information (a) A business that controls the collection of a consumer’s personal information shall, at or before the point of collection, inform consumers of the following: (1) The categories of personal information to be collected and the purposes for which the categories of personal information are collected or used and whether that information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section. (2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared.
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 36 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Untitled California Attorney General Opinion (California Attorney General Reports 2022)“…ROUND The California Consumer Privacy Act of 2018 (Civil Code, §§ 1798.100 et seq.) is the first law of its kind i…”
- Troester v. Starbucks Corporation (California Supreme Court 2018, 235 Cal. Rptr. 3d 820)“…he consumer law context. (See Consumer Privacy Act of 2018, Civ. Code, § 1798.100 et seq. (added by Stats. 2018, ch. 55,…”
- Hajny v. Volkswagen Group of America CA1/1 (California Court of Appeal 2024)“…ions of the California Consumer Privacy Act of 2018 (CCPA), Civil Code section 1798.100 et seq. Shortly after Wynne filed…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: California Sues 23andMe's Successor Over Genetic Data Breach (2026), Employee Data Privacy: Employer Obligations by State (2026), Privacy Policy Requirements: What You Must Include (2026)
§ 1798.140In forcecited in 3 of our articles
Definitions For purposes of this title: (a) “Advertising and marketing” means a communication by a business or a person acting on the business’ behalf in any medium intended to induce a consumer to obtain goods, services, or employment. (b) “Aggregate consumer information” means information that relates to a group or category of consumers, from which individual consumer identities have been removed, that is not linked or reasonably linkable to any consumer or household, including via a device. “Aggregate consumer information” does not mean one or more individual consumer records that have been deidentified. (c) “Biometric information” means an individual’s physiological, biological, or behavioral characteristics, including information pertaining to an individual’s deoxyribonucleic acid (DNA), that is used or is intended to be used singly or in combination with each other or with other identifying data, to establish individual identity.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 12 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Untitled California Attorney General Opinion (California Attorney General Reports 2022)“…e business uses and shares that information. 26 21 Civ. Code, § 1798.140, subd. (c)(1)(A)-(C). 22 Civ. Code…”
- Netchoice, LLC v. Bonta (Court of Appeals for the Ninth Circuit 2026)“…cisionmaking, or choice, as further defined by regulation.” Cal. Civ. Code § 1798.140(l); id. § 1798.99.30(a). 40…”
- Keown v. International Association of Sheet Metal Air Rail Transportation Workers (District Court, District of Columbia 2024)“…or financial benefit of its shareholders or other owners.” Cal. Civ. Code § 1798.140(d)(1). As for the UCL, both state and f…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Biometric Privacy Laws by State (2026): BIPA, CUBI & Consent, California Data Privacy Laws: CCPA, CPRA & Consumer Rights (2026)
§ 1798.150In forcecited in 5 of our articles
Personal Information Security Breaches (a) (1) Any consumer whose nonencrypted and nonredacted personal information, as defined in subparagraph (A) of paragraph (1) of subdivision (d) of Section 1798.81.5, or whose email address in combination with a password or security question and answer that would permit access to the account is subject to an unauthorized access and exfiltration, theft, or disclosure as a result of the business’ violation of the duty to implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information may institute a civil action for any of the following: (A) To recover damages in an amount not less than one hundred dollars ($100) and not greater than seven hundred and fifty ($750) per consumer per incident or actual damages, whichever is greater. The amounts in this subdivision shall be adjusted pursuant to subdivision (d) of Section 1798.199.95. (B) Injunctive or declaratory relief. (C) Any other relief the court deems proper.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 41 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Jarman v. HCR ManorCare, Inc. (California Supreme Court 2020, 267 Cal. Rptr. 3d 696)“…of the harm, as it has done in other contexts. (See, e.g., Civ. Code, § 1798.150, subd. (a)(2).) These deficiencie…”
- Untitled California Attorney General Opinion (California Attorney General Reports 2022)“…ubd. (c). 48 Civ. Code, § 1798.155, subd. (b). 49 Civ. Code, § 1798.150. 50 Initiative Measure (Prop. 24)…”
- Hajny v. Volkswagen Group of America CA1/1 (California Court of Appeal 2024)“…750 without having to prove causation and actual damages. (Civ. Code, § 1798.150, subd. (a)(1)(A).) No other state provi…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: California Data Breach Notification Laws: Reporting Rules & Timelines (2026), What Is CCPA? California Consumer Privacy Act Explained (2026), GDPR vs CCPA: Key Differences Explained (2026)
§ 1798.82In forcecited in 3 of our articles
(a) (1) An individual or business that conducts business in California, and that owns or licenses computerized data that includes personal information, shall disclose a breach of the security of the system following discovery or notification of the breach in the security of the data to a resident of California whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, or whose encrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the encryption key or security credential was, or is reasonably believed to have been, acquired by an unauthorized person, and the person or business that owns or licenses the encrypted information has a reasonable belief that the encryption key or security credential could render that personal information readable or usable. (2) (A) Subject to subparagraph (B), the disclosure required by this subdivision shall be made within 30 calendar days of discovery or notification of the data breach.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 39 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):The breach notice duty is enforced through unfair competition suits. In People v. Experian Data Corp. (2024), a case of first impression, the Court of Appeal held the San Diego City Attorney may invoke the discovery rule to delay accrual of a claim whose predicate violation was Experian failing to give notice under Section 1798.82(a).
Opinions citing this section in our collection:
- People v. Experian Data Corp. (California Court of Appeal 2024)✓The San Diego City Attorney sued Experian under the unfair competition law for failing to promptly notify consumers of a data breach as Section 1798.82 requires; the court held the discovery rule can delay accrual of that non-fraud enforcement action and reversed.
- Bank of America Corp. v. Superior Court (California Court of Appeal 2011, 198 Cal. App. 4th 862)“…ssue notice of default) (6th cause of action); violation of Civil Code section 1798.82 (requiring disclosure to consumer of da…”
- Eisenhower Medical Center v. Superior Court (California Court of Appeal 2014, 226 Cal. App. 4th 430)“…of action for violation of the Customer Records Act (CRA) (Civ.Code, § 1798.82), which requires notification to consum…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 1798.29In forcecited in 2 of our articles
(a) Any agency that owns or licenses computerized data that includes personal information shall disclose any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of California (1) whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, or, (2) whose encrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the encryption key or security credential was, or is reasonably believed to have been, acquired by an unauthorized person and the agency that owns or licenses the encrypted information has a reasonable belief that the encryption key or security credential could render that personal information readable or usable. The disclosure shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subdivision (c), or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 4 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- Beeman v. Anthem Prescription Management, LLC (California Supreme Court 2013, 58 Cal. 4th 329)“…usiness maintaining computerized personal information data (Civ. Code, §§ 1798.29, 1798.82), or the nature and investment…”
- Sifuentes v. X Corp. (District Court, N.D. California 2024)“…4 (9) Violations of California Civil Code sections 1798.29 and 1798.82, (id. at ¶¶ 90-97), 5…”
- Damner v. Facebook Incorporated (District Court, N.D. California 2020)“…enant of good faith and 8 fair dealing; (7) violation of Cal. Civ. Code § 1798.29; and (8) fraudulent and negligent 9…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
California Labor Code
§ 1051In force
Except as provided in Section 1057, any person or agent or officer thereof, who requires, as a condition precedent to securing or retaining employment, that an employee or applicant for employment be photographed or fingerprinted by any person who desires his or her photograph or fingerprints for the purpose of furnishing the same or information concerning the same or concerning the employee or applicant for employment to any other employer or third person, and these photographs and fingerprints could be used to the detriment of the employee or applicant for employment is guilty of a misdemeanor.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2014
Opinions citing this section in our collection:
- Gunawan v. Howroyd-Wright Employment Agency (District Court, C.D. California 2014, 997 F. Supp. 2d 1058)“…mployee or applicant” engaged in protected activity) and Cal. Labor Code § 1051 (providing protection for the fingerpr…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- California Consumer Privacy Act full text(leginfo.legislature.ca.gov).gov
- Cal. Civ. Code 1798.140 - CCPA Definitions including biometric information(leginfo.legislature.ca.gov).gov
- Cal. Civ. Code 1798.150 - Private right of action for data breaches(leginfo.legislature.ca.gov).gov
- Cal. Civ. Code 1798.82 - Breach notification requirements(leginfo.legislature.ca.gov).gov
- Cal. Civ. Code 1798.29 - Agency breach notification requirements(leginfo.legislature.ca.gov).gov
- California Labor Code Section 1051 - Employer fingerprint sharing prohibition(leginfo.legislature.ca.gov).gov
- SB 1223 - Neural data as sensitive personal information(leginfo.legislature.ca.gov).gov
- AB 1008 - AI model coverage and biometric data clarifications(leginfo.legislature.ca.gov).gov
- CPPA About Us - Agency authority and mission(cppa.ca.gov).gov
- CPPA 2025 penalty amount increases announcement(cppa.ca.gov).gov
- CPPA finalized ADMT, risk assessment, and cybersecurity audit regulations(cppa.ca.gov).gov
- CPPA Honda settlement enforcement action(cppa.ca.gov).gov
- CPPA Todd Snyder enforcement action(cppa.ca.gov).gov
- California Attorney General CCPA information(oag.ca.gov).gov
- OAG data breach reporting requirements(oag.ca.gov).gov