Washington
Washington Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 14 primary sources cited on this page. How we verify our legal content

Washington regulates biometric data under two overlapping statutes. RCW 19.375 requires businesses to provide notice and obtain consent before enrolling biometric identifiers for a commercial purpose, with the Attorney General enforcing penalties up to $7,500 per violation. The My Health My Data Act (RCW 19.373) adds separate consent and deletion rights for biometric data.
Washington is one of a small number of states with a dedicated biometric privacy statute. House Bill 1493, signed into law in 2017 and codified as RCW Chapter 19.375, regulates how private businesses collect, store, and use biometric identifiers for commercial purposes. Unlike Illinois BIPA, Washington's law does not include a private right of action, placing enforcement solely in the hands of the state Attorney General.
Washington also regulates government use of biometric data through a separate statute (RCW 40.26) and restricts government facial recognition technology under RCW 43.386. The My Health My Data Act adds another layer by treating biometric data as consumer health data with its own consent and deletion requirements.
For an overview of Washington's broader privacy framework, see the parent guide to Washington Data Privacy Laws.
What RCW 19.375 Covers: Definitions and Scope

The biometric identifiers statute defines key terms under RCW 19.375.010. Understanding these definitions is essential because they determine what activities trigger the law's requirements.
A biometric identifier means data generated by automatic measurements of an individual's biological characteristics that is used to identify a specific individual. The statute lists fingerprints, voiceprints, eye retinas, irises, and other unique biological patterns as examples. Photographs, video recordings, audio recordings, and health care data are excluded from the definition.
The term enroll has a specific technical meaning. It refers to the process of capturing a biometric identifier, converting it into a reference template that cannot be reconstructed into the original output image, and storing it in a database that matches the identifier to a specific individual. Simply capturing biometric data without storing it in a matched database does not constitute enrollment.
A commercial purpose means advancing the sale or disclosure of a biometric identifier to a third party for marketing goods or services unrelated to the initial transaction where the identifier was collected. This definition is narrower than what you might expect. It does not cover all business uses of biometric data, only those tied to third-party commercial exploitation.
The law defines person to include individuals, partnerships, corporations, LLCs, and other legal entities. Government agencies are explicitly excluded from the definition, meaning RCW 19.375 applies only to private-sector entities. Government biometric use falls under a separate statute.
Notice and Consent Requirements
Under RCW 19.375.020, a person may not enroll a biometric identifier in a database for a commercial purpose without first providing notice, obtaining consent, or providing a mechanism to prevent the subsequent use of that identifier for a commercial purpose.
The notice standard requires organizations to disclose their intentions through a procedure reasonably designed to be readily available to affected individuals. However, the statute specifies that making this disclosure available does not, by itself, constitute affirmative consent. Businesses must take the additional step of actually obtaining consent or offering an opt-out mechanism.
Once a business has collected biometric data with proper notice and consent, it cannot later change how that data is used. The statute prohibits using or disclosing a biometric identifier in a manner that is materially inconsistent with the terms under which it was originally provided, unless the business obtains fresh consent for the new purpose.
Restrictions on Disclosure to Third Parties
Businesses cannot sell, lease, or otherwise disclose biometric identifiers to third parties except in limited circumstances. Permitted disclosures include situations where the disclosure aligns with the original notice and consent, where it fulfills a product or service the individual requested, where it completes an authorized financial transaction, where it is required by law, where the recipient contractually promises not to further disclose the data, or where the disclosure is necessary for litigation.
These restrictions create a meaningful limit on the commercial exploitation of biometric data even for businesses that properly obtain initial consent.
Security and Retention Obligations
Organizations possessing biometric identifiers must take reasonable care to guard against unauthorized access to and acquisition of the data. The statute does not define "reasonable care" with specifics, leaving room for interpretation based on industry standards and the sensitivity of the data.
For retention, businesses may keep biometric identifiers only as long as necessary for one of three purposes: complying with a court order or other legal obligation, preventing fraud, or providing the services for which the individual enrolled. When none of these purposes applies, the data should be deleted.
The Security Purpose Exception

One of the most significant features of Washington's biometric law is the security purpose exception. Entities that collect, capture, enroll, or store a biometric identifier for a security purpose are not required to provide notice or obtain consent.
The statute defines a security purpose as preventing shoplifting, fraud, misappropriation, or theft, as well as protecting software, accounts, applications, online services, or the safety of individuals.
This exception has practical implications for employers. A business that uses fingerprint scanners to control building access or prevent "buddy punching" on timekeeping systems could potentially qualify for the security purpose exception, since these uses relate to fraud prevention and facility security. However, if the same employer began using that fingerprint data for commercial purposes like marketing analytics, the exception would no longer apply, and full notice and consent obligations would kick in.
Exemptions Under RCW 19.375.040
RCW 19.375.040 sets out three exclusions, and they are not scoped the same way. One removes an entity from the chapter; another removes only certain activities.
Financial institutions and their affiliates that are subject to Title V of the federal Gramm-Leach-Bliley Act of 1999 are exempt. Subsection (1) is entity-scoped: nothing in the chapter applies "in any manner to a financial institution or an affiliate of a financial institution" covered by Title V. This covers banks, credit unions, insurance companies, and securities firms that already face federal privacy obligations related to customer financial data.
HIPAA activities, rather than HIPAA entities, are carved out by subsection (2). It provides that nothing in the chapter applies "to activities subject to Title V of the federal health insurance privacy and portability act of 1996 and the rules promulgated thereunder." The legislature used entity language in subsection (1) and activity language in subsection (2), and the difference matters. Being a HIPAA covered entity does not place a hospital or health plan outside RCW 19.375 across the board. Biometric handling that is itself subject to HIPAA falls outside the chapter, but biometric activity that HIPAA does not reach, such as fingerprint timeclocks for employees or biometrics used for marketing, remains within it.
Law enforcement officers acting within the scope of their authority are excluded. This includes the authority of state law enforcement officers executing lawful searches and seizures. The statute explicitly states that nothing in the chapter expands or limits existing law enforcement authority.
Enforcement and Penalties

The legislature declared under RCW 19.375.030 that any violation of the biometric identifiers chapter is an unfair or deceptive act in trade or commerce and an unfair method of competition under the Consumer Protection Act (RCW 19.86).
The Attorney General has exclusive enforcement authority. Private individuals cannot file lawsuits for violations of RCW 19.375. This stands in sharp contrast to Illinois BIPA, which allows private lawsuits and has generated billions of dollars in settlement payouts.
Under RCW 19.86.140, the Attorney General can pursue civil penalties of up to $7,500 per violation of the Consumer Protection Act. For violations of injunctions related to biometric privacy, penalties can reach $125,000 per violation. An additional $5,000 applies to violations that target individuals based on protected characteristics including age, race, disability, or veteran status.
The AG can also seek injunctive relief, restitution, and attorneys' fees. In practice, biometric privacy enforcement actions under RCW 19.375 have been limited compared to the flood of litigation seen in Illinois. The AG-only enforcement model means that violations must rise to a level that attracts the attention and resources of the state's chief legal officer.
Government Biometric Rules: RCW 40.26
Washington addresses government use of biometric identifiers through a separate statute, RCW 40.26. This law was enacted alongside H.B. 1493 in 2017 and applies to state and local government agencies.
Notice and Consent for Government Collection
Agencies must provide clear notice of the purpose and use of biometric collection and obtain specific consent before collecting biometric data. That consent must be recorded and maintained for the entire retention period. This is a stricter consent standard than the private-sector law, which allows consent or an opt-out mechanism.
Use, Sharing, and Sale Restrictions
Government agencies are prohibited from selling biometric identifiers entirely. They may only use biometric data as specified in the consent or as otherwise authorized by law. Sharing biometric identifiers with other agencies is permitted only to carry out the original purpose or when explicitly authorized by the individual's consent.
Storage, Retention, and Data Minimization
Agencies must establish security policies ensuring the integrity and appropriate confidentiality of biometric data. The statute requires agencies to address biometrics in their privacy policies, retain data only as long as necessary for the original collection purpose, set tailored retention schedules, and design policies that minimize collection to what is strictly necessary.
Annual Review Requirement
Agencies must conduct annual reviews of their biometric policies to incorporate new technology developments and respond to complaints. This ongoing review obligation is unique among state biometric laws and reflects Washington's proactive approach to government data stewardship.
Government Exemptions
General authority law enforcement agencies are exempt from RCW 40.26. For limited authority law enforcement agencies, fingerprints and DNA are excluded from the statutory definition of biometric identifier entirely, so those two data types can be collected without notice or consent. If a limited authority agency needs to collect a biometric identifier other than a fingerprint or DNA, the notice-and-consent requirement is waived only if the agency first provides written notice to the state's chief privacy officer and the appropriate legislative committees.
The biometric identifier definition under RCW 40.26 is similar but not identical to the private-sector definition. It covers retina and iris scans, fingerprints, voiceprints, DNA, and hand and face geometry. It excludes writing samples, photographs, demographic data, medical samples, organ tissues, HIPAA-covered health care information, and medical imaging used for diagnosis or treatment.
Facial Recognition Restrictions: RCW 43.386
Washington took an additional step in 2020 by enacting SB 6280, codified as RCW 43.386, which regulates government use of facial recognition technology. This law took effect July 1, 2021.
State and local agencies must file accountability reports before deploying facial recognition, including a civil rights impact assessment, false match rate data, and testing results across distinct subpopulations. Agencies must hold at least three community consultation meetings during the public review process.
Law enforcement faces specific restrictions. Officers cannot use facial recognition for ongoing surveillance, real-time identification, or persistent tracking without a warrant, exigent circumstances, or court order. Facial recognition results cannot serve as the sole basis for establishing probable cause. Agencies must disclose facial recognition use to criminal defendants in a timely manner before trial.
The My Health My Data Act and Biometric Data
The Washington My Health My Data Act (MHMDA), signed in April 2023 and effective for most businesses on March 31, 2024, creates an overlapping layer of biometric protection.
The MHMDA explicitly defines biometric data as a category of consumer health data. Its definition covers imagery of the iris, retina, fingerprint, face, hand, palm, and vein patterns, voice recordings from which identifiers can be extracted, and keystroke patterns, gait patterns, and exercise data containing identifying information. This is broader than the RCW 19.375 definition.
Under the MHMDA, businesses cannot collect consumer health data, including biometric identifiers, without obtaining consent for a specified purpose or establishing that the collection is necessary to provide a requested product or service. Sharing biometric data with third parties requires separate and distinct consent that clearly discloses the categories of data and specific intended uses.
Consumers have the right to request deletion of their biometric data. Businesses must delete the data from all parts of their network, including archived and backup systems. Processors and third parties that received the data must also honor deletion requests.
Violations of the MHMDA are treated as per se violations of the Consumer Protection Act. Unlike RCW 19.375, the MHMDA (RCW 19.373.090) does not limit enforcement to the Attorney General. Because the statute contains no AG-exclusivity clause, a consumer injured by an MHMDA violation can sue directly under the Consumer Protection Act's general private right of action, RCW 19.86.090, seeking actual damages, treble damages of up to $25,000, and attorney's fees, without waiting for the Attorney General to act. This is a materially different enforcement exposure than RCW 19.375's AG-only model.
Employer Obligations in Washington
Washington employers that collect biometric data from workers must evaluate which statutes apply to their specific use case.
The security purpose exception under RCW 19.375 may cover fingerprint-based timekeeping systems and biometric access controls if the primary purpose is fraud prevention or physical security. However, if the employer uses biometric data for any commercial purpose beyond security, full notice and consent requirements apply.
The My Health My Data Act may impose additional obligations depending on whether the biometric data qualifies as consumer health data in the employment context. The MHMDA's scope is tied to consumer relationships, and its application to employment data requires careful analysis.
Government employers face the stricter requirements of RCW 40.26, including specific consent, data minimization, retention schedules, and annual policy reviews.
Regardless of which statute applies, all Washington employers collecting biometric data should maintain written policies on collection, use, retention, and destruction. They should also ensure reasonable security measures protect stored biometric identifiers from unauthorized access.
How Washington Compares to Other State Biometric Laws
Washington's biometric privacy framework occupies a middle ground among state biometric laws.
Illinois BIPA remains the most aggressive statute, with its private right of action that has generated landmark settlements against companies like Facebook and Google. Washington chose not to follow that model, opting for AG-only enforcement.
Texas CUBI shares Washington's AG-only enforcement approach but imposes steeper maximum penalties of up to $25,000 per violation. Texas also lacks the security purpose exception that Washington provides.
What sets Washington apart is the breadth of its regulatory approach. No other state has combined a dedicated biometric statute (RCW 19.375), a government biometric law (RCW 40.26), a facial recognition accountability law (RCW 43.386), and a health data act that covers biometrics (RCW 19.373) into one interlocking framework. Businesses operating in Washington must navigate all four layers.
Sources and References
This article references Washington state statutes and official government publications. For the full text of the biometric identifiers law, visit RCW 19.375 on the Washington State Legislature website. For government biometric rules, see RCW 40.26. For the My Health My Data Act, see RCW 19.373. For information on filing a consumer protection complaint, visit the Washington Attorney General.
This article provides general legal information about Washington biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Washington government sources.
More Washington Laws
Frequently Asked Questions
Does Washington allow private lawsuits for biometric privacy violations?
No, for violations of RCW 19.375 specifically. Under RCW 19.375.030, the Washington Attorney General has exclusive enforcement authority for violations of the biometric identifiers statute, and private individuals cannot file lawsuits under this law. Washington's other biometric-related statute is different: the My Health My Data Act (RCW 19.373) has no AG-exclusivity clause, so a violation involving biometric data classified as consumer health data can be pursued through a private lawsuit under the Consumer Protection Act (RCW 19.86.090). Consumers who believe their RCW 19.375 rights specifically have been violated should file a complaint with the Washington Attorney General through the Consumer Protection Division.
Can my employer collect my fingerprints for timekeeping without my consent in Washington?
It depends on the purpose. RCW 19.375 includes a security purpose exception that covers activities like fraud prevention. Fingerprint timekeeping systems designed to prevent buddy punching may qualify as a security purpose, which would not require notice and consent. However, if the employer uses that fingerprint data for any commercial purpose beyond security, the full notice and consent requirements apply. Employers should document why their biometric collection qualifies as a security purpose.
What are the penalties for violating Washington biometric privacy laws?
Violations of RCW 19.375 are treated as unfair or deceptive practices under the Consumer Protection Act (RCW 19.86). The Attorney General can pursue civil penalties of up to $7,500 per violation under RCW 19.86.140. Violations of injunctions can reach $125,000 per violation. An additional $5,000 applies when violations target individuals based on protected characteristics. The AG can also seek injunctive relief, restitution, and attorneys' fees.
How does the My Health My Data Act affect biometric data in Washington?
The My Health My Data Act (RCW 19.373), effective March 31, 2024, classifies biometric data as consumer health data with its own consent and deletion requirements. It covers a broader range of biometric identifiers than RCW 19.375, including face geometry, palm and vein patterns, keystroke rhythms, and gait patterns. Businesses collecting these types of biometric data must obtain consent for specified purposes, honor deletion requests across all systems including backups, and obtain separate consent before sharing data with third parties. Unlike RCW 19.375's AG-only enforcement, the MHMDA does not limit enforcement to the Attorney General, so consumers can sue directly under the Consumer Protection Act (RCW 19.86.090) for actual damages, treble damages up to $25,000, and attorney's fees.
Are government agencies in Washington subject to different biometric rules than private businesses?
Yes. Government agencies are excluded from RCW 19.375 entirely. Instead, they must comply with RCW 40.26, which requires clear notice of purpose, specific consent that must be recorded and maintained, data minimization, tailored retention schedules, and annual policy reviews. Government agencies are prohibited from selling biometric identifiers under any circumstances. General authority law enforcement agencies are exempt from RCW 40.26. For limited authority agencies, fingerprints and DNA are excluded from the statutory definition of biometric identifier entirely, so those two data types can be collected without notice or consent; the chief-privacy-officer notice requirement applies only when such an agency collects a biometric identifier other than a fingerprint or DNA.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Clarified that the HIPAA exclusion in RCW 19.375.040(2) applies to activities subject to HIPAA rather than exempting health care entities outright, so biometric uses a covered entity runs outside HIPAA still fall under the statute.
Clarified that Washington's My Health My Data Act, unlike the state's biometric identifiers statute, carries no exclusive Attorney General enforcement clause, so consumers can sue directly under the Consumer Protection Act for damages when biometric data covered by that Act is mishandled.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected which biometric data types trigger the RCW 40.26 chief-privacy-officer notice requirement for limited authority law enforcement agencies: fingerprints and DNA are excluded from the statute's notice/consent requirements entirely, while the written-notice obligation applies only to OTHER biometric identifiers those agencies collect.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Revised Code of Washington
§ 19.375.020Enrollment, disclosure, and retention of biometric identifiers.In forcecited in 9 of our articles
(1) A person may not enroll a biometric identifier in a database for a commercial purpose, without first providing notice, obtaining consent, or providing a mechanism to prevent the subsequent use of a biometric identifier for a commercial purpose. (2) Notice is a disclosure, that is not considered affirmative consent, that is given through a procedure reasonably designed to be readily available to affected individuals. The exact notice and type of consent required to achieve compliance with subsection (1) of this section is context-dependent.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at app.leg.wa.gov
Also relied on in: Washington Smart Glasses Recording Laws (2026), Washington Data Privacy Laws: My Health My Data Act & More (2026), Washington Employee Monitoring Laws: Biometric Privacy, Social Media, and Surveillance (2026)
§ 19.375.010Definitions.In forcecited in 4 of our articles
The definitions in this section apply throughout this chapter , unless the context clearly requires otherwise. (1) "Biometric identifier" means data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that is used to identify a specific individual. "Biometric identifier" does not include a physical or digital photograph, video or audio recording or data generated therefrom, or information collected, used, or stored for health care treatment, payment, or operations under the federal health insurance portability and accountability act of 1996. (2) "Biometric system" means an automated identification system capable of capturing, processing, and storing a biometric identifier, comparing the biometric identifier to one or more references, and matching the biometric identifier to a specific individual. (3) "Capture" means the process of collecting a biometric identifier from an individual.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
§ 19.375.030Application of consumer protection act.In forcecited in 3 of our articles
(1) The legislature finds that the practices covered by this chapter are matters vitally affecting the public interest for the purpose of applying the consumer protection act, chapter 19.86 RCW. A violation of this chapter is not reasonable in relation to the development and preservation of business and is an unfair or deceptive act in trade or commerce and an unfair method of competition for the purpose of applying the consumer protection act, chapter 19.86 RCW. (2) This chapter may be enforced solely by the attorney general under the consumer protection act, chapter 19.86 RCW.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
Also relied on in: Washington Security Camera Laws: Rules for Home and Business Surveillance (2026)
§ 19.375.040Exclusions.In forcecited in 2 of our articles
(1) Nothing in this chapter applies in any manner to a financial institution or an affiliate of a financial institution that is subject to Title V of the federal Gramm-Leach-Bliley act of 1999 and the rules promulgated thereunder. (2) Nothing in this chapter applies to activities subject to Title V of the federal health insurance privacy and portability act of 1996 and the rules promulgated thereunder. (3) Nothing in this chapter expands or limits the authority of a law enforcement officer acting within the scope of his or her authority including, but not limited to, the authority of a state law enforcement officer in executing lawful searches and seizures.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
§ 40.26.020Biometric identifiers—Notice and consent—Agencies—Use, storage, retention—Review—Definitions—Exceptions.In force
(1) Unless authorized by law, an agency may not collect, capture, purchase, or otherwise obtain a biometric identifier without first providing notice and obtaining the individual's consent, as follows: (a) The notice provided must clearly specify the purpose and use of the biometric identifier; and (b) The consent obtained must be specific to the terms of the notice, and must be recorded and maintained by the agency for the duration of the retention of the biometric identifier. (2) Any biometric identifier obtained by an agency: (a) May not be sold; (b) May only be used consistent with the terms of the notice and consent obtained under subsection (1) of this section, or as authorized by law; and (c) May be shared, including with other state agencies or local governments, only: (i) As needed to execute the purposes of the collection, consistent with the notice and consent obtained under subsection (1) of this section, or as authorized by law; or (ii) If such sharing is specified within the original consent.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
§ 19.373.090Application of consumer protection act.In forcecited in 4 of our articles
The legislature finds that the practices covered by this chapter are matters vitally affecting the public interest for the purpose of applying the consumer protection act, chapter 19.86 RCW. A violation of this chapter is not reasonable in relation to the development and preservation of business, and is an unfair or deceptive act in trade or commerce and an unfair method of competition for the purpose of applying the consumer protection act, chapter 19.86 RCW.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
Also relied on in: MHMDA Business Compliance (Washington), MHMDA Consumer Rights (Washington), What Is MHMDA? WA My Health My Data Act
§ 19.86.140Civil penalties.In force
Every person who shall violate the terms of any injunction issued as in this chapter provided, shall forfeit and pay a civil penalty of not more than $125,000. Every person who violates RCW 19.86.030 or 19.86.040 shall pay a civil penalty of up to three times the unlawful gains or loss avoided as a result of each violation. Every person who violates RCW 19.86.020 shall forfeit and pay a civil penalty of not more than $7,500 for each violation: PROVIDED, That nothing in this paragraph shall apply to any radio or television broadcasting station which broadcasts, or to any publisher, printer or distributor of any newspaper, magazine, billboard or other advertising medium who publishes, prints or distributes, advertising in good faith without knowledge of its false, deceptive or misleading character.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
Cited in 30 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- State v. Ralph Williams' North West Chrysler Plymouth, Inc. (Washington Supreme Court 1976, 87 Wash. 2d 298)“…The reference in paragraph F to RCW 19.86.130, instead of RCW 19.86.140, the civil penalty section, represents…”
- State Of Washington, Resp/x-app v. The Mandatory Poster Agency Inc, Apps/x-resps (Court of Appeals of Washington 2017, 199 Wash. App. 506)“…reasonable attorney's fees. In addition, pursuant to RCW 19.86.140[J violations of the injunctive provisio…”
- Stigall v. Courtesy-Chevrolet-Pontiac, Inc. (Court of Appeals of Washington 1976, 15 Wash. App. 739)“…t erroneously refused to instruct the jury that pursuant to RCW 19.86.140 2 plaintiffs were entitled…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 19.86.090Civil action for damages—Treble damages authorized—Action by governmental entities.In forcecited in 5 of our articles
Any person who is injured in his or her business or property by a violation of RCW 19.86.020, 19.86.030, 19.86.040, 19.86.050, or 19.86.060, or any person so injured because he or she refuses to accede to a proposal for an arrangement which, if consummated, would be in violation of RCW 19.86.030, 19.86.040, 19.86.050, or 19.86.060, may bring a civil action in superior court to enjoin further violations, to recover the actual damages sustained by him or her, or both, together with the costs of the suit, including a reasonable attorney's fee. In addition, the court may, in its discretion, increase the award of damages up to an amount not to exceed three times the actual damages sustained: PROVIDED, That such increased damage award for violation of RCW 19.86.020 may not exceed twenty-five thousand dollars: PROVIDED FURTHER, That such person may bring a civil action in the district court to recover his or her actual damages, except for damages which exceed the amount specified in RCW 3.66.020, and the costs of the suit, including reasonable attorney's fees.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
Cited in 529 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Hangman Ridge Training Stables, Inc. v. Safeco Title Insurance (Washington Supreme Court 1986, 105 Wash. 2d 778)“…izens would be encouraged to bring suit to enforce the CPA. RCW 19.86.090, as amended, first in 1971 and again in…”
- Washington State Physicians Insurance Exchange & Ass'n v. Fisons Corp. (Washington Supreme Court 1993, 122 Wash. 2d 299)“…any trade or commerce are hereby declared unlawful. *312 RCW 19.86.090 creates a private right of action by pr…”
- Bowers v. Transamerica Title Insurance (Washington Supreme Court 1983, 100 Wash. 2d 581)“…d its discretion in awarding attorney fees of $42,805 under RCW 19.86.090. We hold that: 1. An escrow agent i…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Washington Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- RCW 19.375 - Biometric Identifiers Chapter(app.leg.wa.gov).gov
- RCW 19.375.010 - Biometric Identifier Definitions(app.leg.wa.gov).gov
- RCW 19.375.020 - Enrollment, Disclosure, and Retention(app.leg.wa.gov).gov
- RCW 19.375.030 - Consumer Protection Act Application(app.leg.wa.gov).gov
- RCW 19.375.040 - Exclusions(app.leg.wa.gov).gov
- RCW 40.26 - Government Biometric Identifiers(app.leg.wa.gov).gov
- RCW 40.26.020 - Agency Notice, Consent, Storage, Retention(app.leg.wa.gov).gov
- RCW 43.386 - Facial Recognition (SB 6280)(app.leg.wa.gov).gov
- RCW 19.373 - Washington My Health My Data Act(app.leg.wa.gov).gov
- RCW 19.86 - Consumer Protection Act(app.leg.wa.gov).gov
- RCW 19.86.140 - Civil Penalties(app.leg.wa.gov).gov
- Washington AG - Consumer Protection Division(atg.wa.gov).gov
- SB 6280 - Facial Recognition Bill Summary(app.leg.wa.gov).gov
- HB 1493 House Bill Report(lawfilesext.leg.wa.gov).gov