EnglishEspañol
California flag

California

California Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 15 primary sources cited on this page. How we verify our legal content

California Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does California have a biometric privacy law like Illinois BIPA?

No. California does not have a standalone biometric privacy statute. Instead, biometric data is protected as 'sensitive personal information' under the CCPA/CPRA (Cal. Civ. Code 1798.100 et seq.). This gives consumers the right to know what biometric data is collected, request deletion, limit its use, and opt out of its sale. The protections are comprehensive but embedded within the broader privacy law rather than existing as a separate biometric-specific statute.

Can I sue a company in California for collecting my fingerprints without consent?

The private right of action under Cal. Civ. Code 1798.150 is limited to data breach scenarios where a business failed to maintain reasonable security and your unencrypted biometric data was exposed. You cannot sue under the CCPA simply for collecting biometric data without adequate notice. For non-breach violations, you would need to file a complaint with the CPPA or the Attorney General, who can pursue enforcement on your behalf.

What biometric data do California employers need to protect?

Since the employee exemption expired on January 1, 2023, California employers must treat employee biometric data the same as consumer biometric data under the CCPA/CPRA. This includes fingerprints from time clocks, facial scans for access control, and voiceprints. Employers must provide notice before collection, honor deletion and access requests, and allow employees to limit the use of their biometric data. California Labor Code 1051 separately makes it a misdemeanor to condition a job on being photographed or fingerprinted by a third party that intends to furnish that data to another employer to the worker's detriment.

What are the penalties for mishandling biometric data in California?

The CPPA can impose fines of $2,663 per unintentional violation and $7,988 per intentional violation or violations involving minors (2025 amounts, adjusted annually). For data breaches involving biometric data, consumers can sue for $107 to $799 per incident per consumer under Cal. Civ. Code 1798.150. The Attorney General can also bring civil enforcement actions. Employers who condition employment on photographing or fingerprinting by a third party intending to furnish that data to another employer, in violation of Labor Code 1051, face misdemeanor charges.

Does California law cover facial recognition and AI-based biometric systems?

Yes. The CCPA covers biometric data extracted from facial recognition technology, and photographs stored for facial recognition purposes qualify as biometric information. AB 1008 (effective January 2025) clarified that biometric data collected without a consumer's knowledge cannot be classified as publicly available, closing a potential loophole for facial recognition systems. New CPPA regulations effective January 1, 2026, impose additional requirements on automated decisionmaking technology that processes biometric data for profiling or identity verification.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the breach notification timeline to distinguish the 30-day deadline that applies to businesses under Civil Code 1798.82 from the "most expedient time possible" standard that applies to government agencies under 1798.29, and added the statutory carve-out providing that fixing security after a breach does not count as a cure under 1798.150(b).

Updated the private-right-of-action statutory damages range for biometric data breaches from the pre-2025 $100-$750 to the current CPI-adjusted $107-$799 per consumer per incident, corrected a mis-cited Civil Code subsection for the personal-information definition, corrected the biometric-information statutory quote to match the exact statute text, and fixed a one-day date error on a CPPA regulation announcement.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected the Labor Code 1051 description (it is a narrow anti-blacklisting provision about third-party fingerprinting as a condition of employment, not a general ban on employers sharing internally-collected biometric data) and fixed the CCPA breach-notice bullet that presented the optional biometric cross-notification instruction (Civ. Code 1798.82(d)(3)(C)) as mandatory.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. California Consumer Privacy Act full text(leginfo.legislature.ca.gov).gov
  2. Cal. Civ. Code 1798.140 - CCPA Definitions including biometric information(leginfo.legislature.ca.gov).gov
  3. Cal. Civ. Code 1798.150 - Private right of action for data breaches(leginfo.legislature.ca.gov).gov
  4. Cal. Civ. Code 1798.82 - Breach notification requirements(leginfo.legislature.ca.gov).gov
  5. Cal. Civ. Code 1798.29 - Agency breach notification requirements(leginfo.legislature.ca.gov).gov
  6. California Labor Code Section 1051 - Employer fingerprint sharing prohibition(leginfo.legislature.ca.gov).gov
  7. SB 1223 - Neural data as sensitive personal information(leginfo.legislature.ca.gov).gov
  8. AB 1008 - AI model coverage and biometric data clarifications(leginfo.legislature.ca.gov).gov
  9. CPPA About Us - Agency authority and mission(cppa.ca.gov).gov
  10. CPPA 2025 penalty amount increases announcement(cppa.ca.gov).gov
  11. CPPA finalized ADMT, risk assessment, and cybersecurity audit regulations(cppa.ca.gov).gov
  12. CPPA Honda settlement enforcement action(cppa.ca.gov).gov
  13. CPPA Todd Snyder enforcement action(cppa.ca.gov).gov
  14. California Attorney General CCPA information(oag.ca.gov).gov
  15. OAG data breach reporting requirements(oag.ca.gov).gov
Share: