All articles

The face scan inside your ID check: what biometric privacy law actually requires from a verification vendor

9 min read

You added an identity or age check because the law and your payment processor both expect one, picked a vendor whose product page uses words like facial matching or liveness detection, and moved on. From the outside it looks like the digital version of a bouncer glancing at a driver's license: a photo goes in, a yes or no comes out. What that description leaves out is what actually happens in between, because comparing a selfie to an ID photo usually means the software extracts a mathematical description of the person's face first, and several U.S. states have decided that specific output is not an ordinary photo at all. It is a separate, more tightly regulated category of data, with its own consent paperwork and its own damages formula, running in parallel to everything you already know about age checks and data retention.

None of this shows up on the vendor's pricing page, and almost nobody reads the underlying statute before signing the contract, which is exactly how operators end up finding out about it from a lawsuit instead. The rules below were not written with adult classifieds in mind, and most of the money changing hands so far has come from social platforms and gig-economy apps rather than directories. That is not a reason to relax: the technology triggering the exposure is the same facial-matching software, sold by many of the same vendors, plugged into the same kind of registration flow this industry already runs on.

What actually counts as biometric data

Illinois, which has the sharpest version of this law, defines a biometric identifier narrowly: a retina or iris scan, a fingerprint, a voiceprint, or a scan of hand or face geometry. Texas's parallel statute covers the same short list. Both laws go out of their way to say what does not count: a photograph on its own is excluded, along with a handwriting sample or a signature. Read quickly, that sounds reassuring for a directory that is mostly handling photographs of driver's licenses and selfies.

The exclusion does not survive contact with how the matching software actually works. Federal courts in Illinois have already ruled that a facial geometry template extracted from an otherwise-exempt photograph is still a covered biometric identifier, because the law regulates what the software derives from the image, not the image file sitting in a folder. A selfie that a human reviewer glances at and discards is very different, legally, from the same selfie run through a matching engine that turns it into a set of measurements used to compare it against an ID photo.

The practical consequence is that the label on your vendor's feature does most of the work of telling you which rules apply, and it is worth asking the direct, unglamorous question rather than trusting the marketing copy: does this specific check produce and retain a facial geometry template, or does it only compare two images without generating that intermediate data? Vendors selling into this space usually know the answer immediately, because it is the same answer their own legal team asked them for years ago.

The consent your vendor's checkbox doesn't cover

Illinois requires, in writing and before any scan happens, that the person be told the specific purpose of the collection and the exact length of time the data will be kept, followed by a written release, which an August 2024 amendment now allows to take the form of an electronic signature. A general terms-of-service acceptance almost never satisfies this, not because it lacks a checkbox, but because it was not written for this purpose: it rarely states a retention period at all, and it is bundled with dozens of unrelated clauses instead of standing on its own as the specific notice the statute describes.

Texas's version imposes a parallel structure: notice and consent before the scan is captured, a ban on selling or leasing the resulting data to anyone else, and a hard destruction deadline of no more than one year after the purpose that justified collecting it in the first place has been satisfied. What happens to the underlying photo and ID file after that point is its own separate problem, one this blog has covered in detail elsewhere, but the biometric template created during the match is subject to a stricter, statute-driven clock that runs independently of whatever retention schedule you set for the document itself.

Neither law lets an operator point at the vendor's own privacy policy and call the notice requirement satisfied. The duty falls on whichever business is actually collecting from the person, which is a question about the design of your registration flow, not about which brand name happened to appear on the popup the advertiser clicked through. If your flow routes the selfie and ID photo through your own domain before handing them to the vendor, you are the one making the collection happen from the advertiser's point of view, whatever the vendor's contract with you says about who is technically responsible.

What a violation actually costs

Illinois sets statutory damages at $1,000 or actual damages, whichever is greater, for a negligent violation, and $5,000 or actual damages for an intentional or reckless one. The state's supreme court settled years ago that a plaintiff does not need to show any harm beyond the paperwork failure itself to collect: a missing notice or a missing written release is enough on its own, regardless of whether the biometric data was ever misused.

Illinois tried to soften the worst version of that math in August 2024, changing how violations are counted from once per scan to once per person, which is the difference between one claim and dozens for the same advertiser who verifies repeatedly over time. Whether that change reached cases that were already pending stayed an open question in the courts until this spring, when a federal appeals court ruled that it does apply to pending cases as well, so the gentler per-person count is now the rule actually being enforced rather than a future promise.

Texas and Washington built the same underlying idea around a different lever: no individual advertiser can sue your directory directly under either state's biometric statute, only the state Attorney General can bring a case. Texas set its ceiling at $25,000 per violation with no overall cap, and that single number is what its Attorney General used to extract $1.4 billion from Meta and $1.375 billion from Google over facial-recognition data practices unrelated to age or identity verification. A private lawsuit and a state enforcement action are different shapes of the same underlying exposure, and which one you are looking at depends entirely on where your advertisers live, not on where your company is registered.

The broader privacy landscape adds a third layer that is easy to miss: most of the twenty-plus U.S. states that now have a comprehensive consumer privacy law classify biometric data as a separate category of sensitive information, on top of whatever a dedicated biometric statute already requires. Some of those laws demand opt-in consent before that data can be processed at all, others give the person a right to object after the fact, and the broader age verification requirements now on the books already assume some form of identity or age checking is happening, without settling the separate question of what a facial-matching step inside that check has to do to stay lawful.

The vendor doesn't automatically stand between you and the claim

The clearest example of how this plays out for an identity-verification vendor specifically, rather than a social platform tagging photos, is Sosa v. Onfido. Onfido is a UK-based company with no Illinois office, providing exactly the kind of facial-matching identity check a marketplace uses to confirm a new user's ID is genuine. An Illinois resident whose face had been scanned through that process sued directly, and Onfido argued its servers and its entire business sat outside Illinois, so the state's law could not reach it. The federal appeals court disagreed: what matters is where the person's face was captured and used, not where the company's infrastructure or headquarters happen to be. Onfido settled for roughly $28.5 million.

That outcome is not automatic just because a plaintiff happens to live in Illinois. A different court threw out a similar claim against a Canadian app maker because Illinois app downloads alone, without more, were not enough to tie the company's own conduct to the state. Being based outside Illinois sometimes works as a defense and sometimes does not, and the difference usually turns on details the operator controls directly: how the verification flow is built, how many of the affected people are actually in that state, and how tightly the company's own systems reach into it, rather than on where the business happens to be incorporated.

A more recent ruling matters even more for an operator who never personally handles the scan. In January 2026, an Illinois appeals court held that a business which simply integrates a vendor's biometric system, without itself acquiring or controlling the resulting biometric data, is not a collector under the statute at all, rejecting the idea that everyone whose product touches the process shares equal exposure. Read plainly, that means the line separating an operator with real exposure from one without it is not whether a face got scanned somewhere along the way. It is whether the operator itself ever receives, stores, or controls the resulting geometric template, as opposed to only ever seeing a pass-or-fail result the vendor sends back.

What to check before the next contract renewal

Start by asking the vendor the plain, unglamorous question directly: does this specific check produce and retain a facial geometry template, or does it stop at comparing two images without generating that intermediate data? Get the answer in writing rather than inferring it from the feature's marketing name, since facial matching and liveness detection describe very different technical processes depending on which vendor is selling them.

Then confirm, and check technically rather than take on faith, that the integration never routes the raw biometric template back into your own systems, and that only a verification result crosses that line. Courts are increasingly using exactly that distinction to decide which party in the chain counts as the one with real legal exposure, which makes it worth more than a paragraph in a vendor contract that nobody rereads after signing.

Ask for the vendor's public biometric retention and destruction schedule, since Illinois and Texas both require one to exist and be published, and a vendor that cannot produce one on request has already told you something useful about how carefully the rest of its process was built. Where the vendor's own policy is vague or missing, assume the gap is yours to close, not theirs to explain away later.

Finally, add a standalone consent step ahead of the scan itself, separate from the general terms of service, that states the specific purpose and the exact retention period in plain language, and check where your advertiser base actually lives before assuming a law written for one state has nothing to do with a company registered in another. The statute that reaches you is decided by your advertisers' addresses, not by your own.

Try the DEMO

Escort directory software, ready to go