EnglishEspañol
District of Columbia flag

District of Columbia

District of Columbia Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 9 primary sources cited on this page. How we verify our legal content

District of Columbia Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does DC require consent before collecting fingerprints or facial recognition data?

No. The District of Columbia does not have a law requiring consent before collecting biometric data. DC law protects biometric information only through its breach notification statute (DC Code 28-3851 et seq.), which imposes obligations after a data breach occurs, not at the point of collection.

What happens if a company loses my biometric data in a breach?

The company must notify you without unreasonable delay, describing what information was compromised and providing contact information for the company, consumer reporting agencies, the FTC, and the DC Attorney General. If the breach affects 50 or more DC residents, the company must also report it to the Attorney General. You can sue for actual damages under DC Code 28-3905(k)(2)(A)(ii), not the treble damages or $1,500 per violation available for other DC consumer protection claims; that heavier remedy does not apply to breach-notification violations.

Can my employer require me to use a fingerprint scanner for timekeeping in DC?

Yes. DC has no law that prevents employers from requiring biometric data collection for timekeeping, building access, or other workplace purposes. Employers must maintain reasonable security safeguards for that data, and a breach would trigger notification obligations, but there is no consent requirement for initial collection.

How does DC compare to Illinois for biometric privacy protection?

DC offers significantly less protection. Illinois BIPA requires informed written consent before collecting biometric data, mandates written retention and destruction policies, prohibits the sale of biometric data, and provides a private right of action for any violation. DC law only addresses biometric data in the breach notification context, with no consent, retention, or purpose limitation requirements.

Can I sue a company in DC for collecting my biometric data without permission?

No. DC law does not provide a cause of action for collecting biometric data without consent. Legal remedies are available only when a company fails to notify you after a breach involving your biometric data, or when it fails to maintain reasonable security safeguards. A violation of these requirements is treated as an unfair or deceptive trade practice.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the remedies described for a DC breach-notification violation: DC Code 28-3853(b) and 28-3905(k)(2)(A)(ii) limit consumers to actual damages, not treble damages or $1,500 per violation as this page previously stated in three places. Also fixed the consumer-reporting-agency notice threshold to 'more than 1,000' individuals and added the Attorney General's $5,000/$10,000 per-violation civil penalty authority under DC Code 28-3909(b).

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. DC Code 28-3851 - Definitions (biometric data definition)(code.dccouncil.gov).gov
  2. DC Code 28-3852 - Notification of security breach(code.dccouncil.gov).gov
  3. DC Code 28-3852.01 - Security requirements(code.dccouncil.gov).gov
  4. DC Code 28-3852.02 - Remedies(code.dccouncil.gov).gov
  5. DC Code 28-3853 - Enforcement(code.dccouncil.gov).gov
  6. DC Code 28-3904 - Unfair or deceptive trade practices(code.dccouncil.gov).gov
  7. Security Breach Protection Amendment Act of 2020 (D.C. Law 23-98)(code.dccouncil.gov).gov
  8. DC Attorney General - Consumer Alert: Online Privacy(oag.dc.gov).gov
  9. AG Schwalb secures over $350,000 from Blackbaud for data breach(oag.dc.gov).gov
  10. Personal Health Data Security Amendment Act of 2025 (B26-0525)(legiscan.com)
Share: