California’s biometric privacy law is not a standalone statute. Fingerprints, face and hand geometry, iris scans, voiceprints, DNA, and behavioral identifiers like keystroke and gait patterns are regulated under the California Consumer Privacy Act (CCPA), as strengthened by the California Privacy Rights Act (CPRA), where they qualify as “sensitive personal information.” That classification triggers pre-collection notice duties, consumer rights to limit and delete, and reasonable security obligations. Violations can draw administrative fines of up to $7,988 per intentional violation, and consumers can sue when a breach exposes their biometric data because a business failed to secure it.
What Counts as Biometric Information
The CCPA defines biometric information broadly. It covers any physiological, biological, or behavioral characteristic that can establish someone’s identity, either alone or combined with other data. The statute specifically includes iris and retina imagery, fingerprints, face and hand geometry, palm and vein patterns, voice recordings, DNA, keystroke rhythms, and gait patterns. Sleep, health, and exercise data also qualify when they contain identifying information.1California Privacy Protection Agency. California Consumer Privacy Act of 2018
That reach is wider than most people picture. A fitness app logging your gait, a workplace system tracking keystroke rhythm, or a wearable capturing vein patterns all fall within the definition when the data can be used to identify you.
Which Businesses Are Covered
The CCPA applies to for-profit businesses that collect personal information from California residents and meet at least one of three size thresholds: annual gross revenue above $26,625,000 (adjusted annually for inflation), buying or selling the personal information of 100,000 or more consumers or households per year, or deriving 50 percent or more of annual revenue from selling or sharing personal information.2California Privacy Protection Agency. Updated Monetary Thresholds in CCPA A business does not need to be physically located in California; if it collects data from California residents and meets any threshold, the law applies.3State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)
Government agencies, law enforcement bodies, and nonprofits are not covered by the CCPA’s biometric obligations, though other California privacy statutes may reach them. Within the private sector, even a mid-size company can trigger coverage if it processes enough consumer data.
Employee Biometric Data
The CCPA originally exempted employee and job-applicant data from most of its requirements. That exemption expired on January 1, 2023, and the legislature did not extend it. Workplace biometric systems, fingerprint time clocks, facial recognition for facility access, and similar tools are now fully covered.
Employers must give employees the same pre-collection notice required for consumers, honor requests to limit the use of that data, and respond to deletion requests within the statutory timeframe. Biometric data collected from employees is sensitive personal information, giving workers the right to limit how their employer uses it beyond what the employment relationship requires.1California Privacy Protection Agency. California Consumer Privacy Act of 2018
Notice, Purpose Limits, and Security
Before collecting biometric data, a business must inform the person at or before the point of collection. The notice must disclose the categories of sensitive personal information being collected, the specific purposes, and whether the data will be sold or shared. The business must also state how long it intends to retain each category, or explain the criteria it uses to determine that period.4California Legislative Information. California Civil Code CIV 1798.100
A business cannot later expand collection beyond what was originally disclosed without fresh notice. If you were told your fingerprint would be used for building access, the company cannot start feeding that data into marketing analytics without telling you first and giving you a chance to exercise your rights.
Businesses must also implement reasonable security procedures appropriate to the sensitivity of the data they hold. The statute does not specify technical standards, so “reasonableness” is judged in context, including the nature and volume of the biometric data at issue.1California Privacy Protection Agency. California Consumer Privacy Act of 2018 There is no checklist, and whether security measures were reasonable often becomes the central question in breach litigation.
Consumer Rights Over Biometric Data
Because biometric information is sensitive personal information, consumers get an extra layer of control beyond ordinary personal data.
Right To Limit Use
California residents can direct a covered business to limit its use and disclosure of their sensitive personal information to what is necessary to provide the requested goods or services. Businesses that use biometric data for purposes beyond service delivery must post a conspicuous link, typically labeled “Limit the Use of My Sensitive Personal Information,” so consumers can submit that request.1California Privacy Protection Agency. California Consumer Privacy Act of 2018 Once the request is made, the business can still use the data for security, fraud prevention, and system functionality, but not for secondary commercial purposes like profiling or advertising.5California Privacy Protection Agency. LOCKED Series: Right to Limit and Opt-Out
Right To Delete
Consumers can request that a business delete personal information it has collected, including biometric data. On a verifiable request, the business must delete the data from its own records and direct its service providers, contractors, and any third parties to which it sold or shared the data to do the same.6California Legislative Information. California Civil Code CIV 1798.105 Businesses generally have 45 days to respond, with an optional 45-day extension if the consumer is notified.
Deletion is not absolute. A business can refuse when the data is needed to complete a transaction, detect security incidents, comply with a legal obligation, or fulfill certain other specified purposes. Employers sometimes invoke these exceptions to retain biometric time-clock data during active employment or pending litigation.
Penalties and Enforcement
California enforces biometric violations on two tracks: administrative fines brought by the state, and private lawsuits filed by consumers after a breach. They differ in who can bring them, what triggers them, and how much money is at stake.
Administrative Fines
The California Privacy Protection Agency (CPPA) can impose administrative fines of up to $2,663 per violation, or up to $7,988 per intentional violation or per violation involving data of a consumer the business knew was under 16.7California Privacy Protection Agency. 2025 Increases for CCPA Monetary Thresholds The base statutory amounts are $2,500 and $7,500, adjusted upward annually for inflation.8California Legislative Information. California Civil Code CIV 1798.155 Fines can be calculated per affected consumer, so a single biometric violation affecting thousands of people can produce enormous exposure. The CPPA does not need to wait for a consumer complaint or a breach to open an investigation.
Private Lawsuits After a Breach
Consumers can sue, but only in narrow circumstances. The private right of action requires that nonencrypted and nonredacted personal information was accessed, stolen, or disclosed without authorization because the business failed to maintain reasonable security. The consumer must show the breach resulted from the business’s security failures, not just that a breach occurred.9California Legislative Information. California Civil Code CIV 1798.150
Statutory damages range from $100 to $750 per consumer per incident, or actual damages, whichever is greater.9California Legislative Information. California Civil Code CIV 1798.150 Courts weigh the seriousness of the misconduct, the number of violations, how long it persisted, and the defendant’s financial position when setting the amount. Per-consumer figures may sound modest individually, but class actions can aggregate them into eight- or nine-figure exposure.
Before filing for statutory damages, a consumer must give the business 30 days’ written notice identifying the specific violations. If the business cures the problem within that window and provides a written statement that no further violations will occur, the suit for statutory damages is blocked. The cure provision does not apply to lawsuits seeking only actual damages, and plugging a security hole after a breach has already happened does not count as a cure for that breach.9California Legislative Information. California Civil Code CIV 1798.150
Key Exemptions
Several categories of data fall outside the CCPA’s reach, though the exemptions are narrower than many businesses assume.
HIPAA and California Medical Confidentiality
Protected health information collected by a HIPAA-covered entity or business associate is exempt from the CCPA, as is medical information governed by California’s Confidentiality of Medical Information Act.10California Legislative Information. California Civil Code CIV 1798.145 The exemption protects the data, not the entity across the board. A HIPAA-covered hospital that collects biometric data from website visitors for non-medical purposes cannot shield that data under the health-care carve-out. Fitness apps, wearable device makers, and direct-to-consumer genetic testing services get no benefit from this exemption regardless of how health-adjacent their products feel.
Gramm-Leach-Bliley Financial Data
Personal information collected, processed, sold, or disclosed under the federal Gramm-Leach-Bliley Act (GLBA) and its implementing regulations is exempt from the CCPA. But the statute expressly provides that this exemption does not apply to the private right of action for data breaches under Section 1798.150.10California Legislative Information. California Civil Code CIV 1798.145 A bank that suffers a biometric data breach because of inadequate security can still be sued by consumers regardless of GLBA compliance.
Law Enforcement Cooperation
The CCPA does not prevent a business from complying with law enforcement. Businesses can cooperate with investigations, respond to subpoenas and court orders, and honor directives to preserve consumer data for up to 90 days, with extensions available for good cause, while officers obtain a warrant or subpoena.10California Legislative Information. California Civil Code CIV 1798.145 A business that retains biometric data it would otherwise delete is protected when acting on a valid law enforcement directive.
How California Differs From Illinois BIPA
Companies operating in multiple states often compare California’s approach to the Illinois Biometric Information Privacy Act. Illinois requires specific written consent before collecting biometrics and provides a private right of action for any statutory violation, not just data breaches. Illinois courts have awarded statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation. California’s private lawsuit option is narrower, available only when a breach results from inadequate security, with per-incident statutory damages of $100 to $750.9California Legislative Information. California Civil Code CIV 1798.150
Where California hits harder is on the regulatory side. The CPPA can impose fines per violation per affected consumer without waiting for a breach, and the CCPA covers far more data types and business activities than BIPA. A company collecting biometric data in both states must satisfy both frameworks; compliance with one does not guarantee compliance with the other.