Faceprints and voiceprints: consent rules under BIPA and the GDPR

September 27, 2026

Illinois and the EU both treat your faceprint and voiceprint as specially protected, and both usually require consent before a company captures them.

BiometricsConsentIdentityCreatorsDevelopersPlatformsBrands

The short version

  • Illinois' Biometric Information Privacy Act (BIPA) bars private companies from collecting your faceprint, voiceprint, fingerprint or iris scan unless they first tell you in writing and get a written release.
  • The EU's GDPR generally prohibits processing biometric data to uniquely identify someone unless an exception applies, most commonly explicit consent.
  • BIPA lets individuals sue. The GDPR is enforced mainly by data protection authorities, with fines of up to €20 million or 4% of global annual turnover.

What the law does

Illinois BIPA (740 ILCS 14). "Biometric identifiers" include a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. Photographs themselves are excluded, but a face-geometry scan made from a photo is the kind of data the law addresses. Before collecting or obtaining your biometric identifier or information, a private company must:

  • Tell you in writing that it is being collected or stored.
  • Tell you in writing the specific purpose and how long it will be collected, stored and used.
  • Receive a written release from you, which since 2024 can be an electronic signature.

Companies must also publish a retention and destruction policy (destroying data once the purpose is met or within three years of your last interaction, whichever comes first), protect the data, get consent before disclosing it, and never sell or otherwise profit from it.

Anyone "aggrieved" can sue for $1,000 per negligent violation or $5,000 per intentional or reckless violation, or actual damages if higher, plus attorney's fees. In Rosenbach v. Six Flags (2019), the Illinois Supreme Court held that you don't need to show separate harm beyond the violation. A 2024 amendment (Public Act 103-0769) says that repeatedly collecting the same biometric from the same person by the same method is a single violation, with at most one recovery.

EU GDPR (Regulation 2016/679). Article 4(14) defines biometric data as data from specific technical processing of physical or behavioral characteristics that allows or confirms unique identification, such as facial images or fingerprint data. Article 9 lists biometric data processed "for the purpose of uniquely identifying a natural person" as a special category, and processing is prohibited unless an exception applies. The main exception for commercial uses is explicit consent under Article 9(2)(a), which you can withdraw at any time under Article 7(3).

Who it protects

BIPA: Individuals whose biometrics are collected by private companies. Courts generally apply it where the collection is connected to Illinois. Government agencies are not covered.

GDPR: People whose data is processed by organizations established in the EU, or by organizations elsewhere that offer goods or services to, or monitor, people in the EU.

What it means for you

Creators and performers: Voice-cloning and face-scanning services that build a model of you may be capturing a voiceprint or face geometry. Under BIPA and the GDPR, that usually requires clear notice and your consent.

Developers and platforms: Map where you create face or voice templates. Get written or explicit consent first, set retention limits, and don't sell the data.

Brands and agencies: Check that vendors running face or voice capture at events or in apps have consent flows that meet these rules.

What it doesn't do

  • BIPA doesn't apply to state or local government, and it excludes certain health care data and photographs as such.
  • The GDPR's biometric rule applies when data is processed to uniquely identify someone. Ordinary photos and recordings aren't automatically special-category data.
  • Neither law, on its own, stops someone from making a deepfake of you from public media. For that, look to likeness and deepfake laws.

Status and key dates

  • October 3, 2008: BIPA in effect.
  • May 25, 2018: GDPR applies across the EU.
  • August 2, 2024: BIPA amendment (Public Act 103-0769) in effect, limiting per-scan damages and allowing electronic signatures.

Frequently asked questions

Is a voiceprint protected under BIPA? Yes. "Voiceprint" is listed as a biometric identifier, so collecting one generally requires written notice and a written release.

Does GDPR require consent for facial recognition? Processing biometric data to uniquely identify someone is prohibited unless an Article 9 exception applies. For most commercial services, that means explicit consent.

How much can I recover under BIPA? $1,000 per negligent violation or $5,000 per intentional or reckless violation, or actual damages if higher, plus fees. Repeated scans by the same method count as one violation.

Can I withdraw biometric consent under GDPR? Yes. Article 7(3) lets you withdraw consent at any time. You can also ask for erasure under Article 17.

What you can do

  • Read the consent screen before any app scans your face or records your voice to build a model.
  • Ask companies for their biometric retention policy, and request deletion when you stop using a service.
  • In the EU, you can make a data subject request or complain to your national data protection authority.

Royall helps you keep a record of what you have and haven't consented to.

Sources

Last verified: 2026-09-27

This is general information, not legal advice.

onwards,
The Royall team