RatedWithAI

RatedWithAI

Accessibility scanner

Biometric PrivacyJuly 31, 2026

The Biometric Nobody Filed a Consent Form For: Keystroke Dynamics, Mouse Movement, and Gait

Behavioral biometrics is sold as the privacy-safe option. No face scan, no fingerprint, nothing that looks like the thing plaintiffs sue over. That framing works against BIPA's closed list of identifiers and stops working the moment a state defines biometric data by what it does instead of what it is.

Closed List
BIPA enumerates four identifiers — typing rhythm is not one of them
Functional Test
Newer state laws reach behavioral characteristics used to identify a person
No Consent Flow
Behavioral signals are usually collected silently, by design

What Behavioral Biometrics Actually Collects

The category covers any system that identifies or verifies a person from how they behave rather than how they look. In practice that means four product families: keystroke dynamics (dwell time per key, flight time between keys, error and correction patterns), mouse and touch telemetry (cursor acceleration curves, scroll cadence, pressure and swipe geometry on mobile), gait recognition (stride length, cadence, and body-sway signatures from video), and interaction-pattern models used for continuous authentication after login.

What makes these different from face or fingerprint systems is not sensitivity — a typing profile can be as distinctive as a fingerprint — but visibility. A face scan requires the user to look at something. Keystroke dynamics requires the user to do nothing at all. There is no natural moment in the flow where a consent screen belongs, so most implementations never built one, and the enrollment happens as an invisible side effect of normal use.

The BIPA Argument, and Where It Runs Out

BIPA's structure is unusually literal. It defines biometric identifier as a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry, and then explicitly excludes a list of things like writing samples, photographs, and physical descriptions. Typing rhythm is not enumerated. That is a real defense, and it is the reason behavioral-biometrics vendors have not been swept into the same wave of litigation as facial recognition.

Three things erode it. First, biometric information — the second defined term — covers information based on a biometric identifier used to identify an individual, and courts read the two terms together rather than treating the identifier list as the whole statute. Second, behavioral products rarely ship alone: a continuous-authentication SDK that scores typing cadence usually also brokers the device's fingerprint or face unlock, and the enrollment flow that touches the enumerated identifier is the one that needed written release. Third, gait systems ingest video of faces. Arguing that the pipeline only analyzed the legs of a frame it captured in full has not been a comfortable position in front of a jury.

Why the Newer State Laws Invert the Risk

Functional definitions reach behavior explicitly

Several comprehensive state privacy statutes define biometric data as data generated from measurements of biological or behavioral characteristics used to identify a specific individual. Behavioral is in the text. A typing profile keyed to a user account satisfies it directly.

Biometric data is sensitive data

Under those regimes biometrics are a sensitive category, which typically means opt-in consent before processing, a data protection assessment, and heightened contract terms with any processor — obligations that attach before the first profile is built.

Texas CUBI has no private right of action but real AG exposure

CUBI covers biometric identifiers captured for a commercial purpose and is enforced by the Attorney General with per-violation penalties. The absence of class-action risk changes the litigation math, not the compliance obligation.

Employee monitoring collapses two frameworks at once

Behavioral biometrics deployed on a workforce — keystroke scoring for productivity or insider-threat detection — triggers biometric consent rules and separately supplies the evidentiary record for an employment claim about how the monitoring output was used.

The Identify-vs-Detect Line Is the One That Matters

Nearly every functional biometric definition turns on use, not collection: the data becomes regulated biometric data when it is used to identify a specific individual. That gives behavioral systems a genuine design lever. A model that scores a session as anomalous relative to a population baseline, without ever building a stored per-person template, sits on a different side of the line than one that enrolls a persistent typing profile against a user ID and matches new sessions to it. The first is anomaly detection. The second is identification, and calling it fraud scoring in the product spec does not change what the database contains. If your architecture stores a per-user behavioral template, assume the regulated characterization and build the consent and retention path accordingly.

Behavioral Biometrics Compliance Checklist

1. Inventory What You Actually Store
  • Distinguish per-user behavioral templates from aggregate population baselines — only the former creates identification capability
  • Map every SDK and vendor in the authentication path, including device-level face or fingerprint brokers bundled with the behavioral signal
  • Confirm whether gait or in-session video features are derived from frames that also captured facial geometry
2. Consent and Disclosure
  • Build a real opt-in for jurisdictions using functional biometric definitions, not a privacy-policy paragraph
  • Where an enumerated identifier is touched anywhere in the flow, use a written release with the statutory purpose and retention disclosures
  • Give employees a separate notice path — workforce deployment is not covered by a consumer-facing consent screen
3. Retention and Segregation
  • Publish a retention schedule with a defined destruction trigger; indefinite retention is the most commonly pleaded violation
  • Keep behavioral templates out of the general analytics warehouse and out of default model-training pipelines
  • Restrict downstream access so fraud-prevention data cannot be repurposed for marketing or performance scoring
4. Vendor and Contract Terms
  • Require the vendor to state, in the contract, whether it stores per-user templates and where
  • Prohibit vendor use of your users' behavioral data to improve a shared cross-customer model without separate consent
  • Get indemnification that specifically names biometric privacy statutes rather than generic data-protection language

See how your product presents to users and regulators

RatedWithAI helps SaaS and platform teams surface compliance and trust gaps across their web properties — including the disclosure surfaces where silent data collection tends to go undocumented. Start with a free scan.

Scan Your Product for Free →

Frequently Asked Questions

If BIPA's list does not include typing rhythm, why build a consent flow at all?

Because the closed list is an Illinois artifact and your users are not only in Illinois. Once a functional definition applies — biological or behavioral characteristics used to identify an individual — the behavioral profile is biometric data and sits in the sensitive category, which means opt-in consent rather than notice. Building for the stricter standard is cheaper than partitioning the authentication stack by state.

Does anonymizing the behavioral template solve the problem?

Only if the template genuinely cannot be linked back to a person, which defeats the point of authentication. A template that must be matched against a returning user is by construction linked to that user; the hash or embedding is the identifier. What does help is avoiding per-user templates entirely where the use case only needs population-level anomaly detection.

Are gait recognition systems treated differently from camera-based facial recognition?

Legally the analysis starts differently, since body movement is not an enumerated identifier under BIPA, but practically the two collapse. Gait systems run on video that captured faces, are usually deployed by the same security teams on the same camera infrastructure, and are covered by functional definitions that reach behavioral characteristics. Treat a gait deployment as a biometric deployment.

Does a fraud-prevention purpose exempt behavioral biometrics from consent?

Not in Illinois, which has no general security exception — the defense there is that the data is not a covered identifier. Under state privacy laws with security carve-outs, the exception typically permits the fraud-detection use while still requiring disclosure, bounded retention, and no secondary use. It is a use-limitation, not a blanket pass on the obligations.

Who is liable when the behavioral biometric is inside a third-party SDK?

Both parties can be, and biometric statutes have repeatedly been read to reach the vendor that collects and stores the data as well as the customer that deployed it. Contractual allocation matters between the companies but does not resolve a claim brought against either one, so the deploying company still needs its own consent record rather than relying on the vendor's.

Related Guides

Is your own site ADA compliant?

Run a free WCAG 2.1 AA scan on any public URL. Real axe-core checks in a real browser — instant report, no signup.

Need it watched instead of checked once? Starter is $29/mo for continuous monitoring, audit trails and PDF/CSV exports.