RatedWithAI

RatedWithAI

Accessibility scanner

Biometric PrivacySeptember 22, 2026

The Photo Is Excluded. What You Computed From It Is Not.

Forty-odd industry guides tell you what BIPA requires once it applies. The argument that decides most disputes happens one step earlier, in a definitions section that excludes photographs and covers face geometry in the same breath.

The shortest version: the statute names the template, not the picture. Ask what your pipeline computes rather than what it stores, and the definitional question usually answers itself.

How the Definition Is Shaped

The definition is a closed list, then an excluded list

A biometric identifier is a retina or iris scan, a fingerprint, a voiceprint, or a scan of hand or face geometry. The section then excludes a series of things explicitly — among them writing samples, written signatures, photographs, human biological samples used for valid scientific testing or screening, demographic data, physical descriptions such as height, weight, hair colour or eye colour, and tattoo descriptions. Everything turns on which list a given artefact lands in.

Photographs are excluded and face geometry is included, in the same section

Both sentences are in the statute, which means the exclusion cannot be read to swallow the face-geometry clause or the clause would never apply to anything. The widely followed reading is that the excluded item is the picture itself, while a measurement of facial geometry computed from it is the covered identifier. The image is the input; the template is the thing the statute names.

Biometric information is a second, wider category

The Act separately defines biometric information as any information, regardless of how it is captured, converted, stored or shared, based on an individual's biometric identifier and used to identify that individual. That clause is drafted to follow the data through transformation — which is why converting a template into a hash, a vector or a proprietary format does not obviously leave the statute.

The excluded items are narrower than their everyday meaning

A written signature is excluded; a dynamic capture of how a signature was produced is a different artefact. A physical description is excluded; an estimate of age or gender inferred from a face scan is not plainly a description of the kind listed. Read each exclusion as the specific thing named rather than as a category you can argue your feature into.

The consequence attaches at collection, not at use

If what you computed is an identifier, the notice, purpose, retention-schedule and written-release duties attach when you collected or captured it — before any matching happens, and regardless of whether the match succeeded. A pipeline that generates embeddings for every uploaded image and matches none of them has still done the collecting.

Five Artefacts and Where They Land

The question is never about the feature's name. It is about the thing the pipeline produced and whether it is used to recognise a person.

A face embedding from a user-uploaded photo

The photo is on the excluded list. The 128- or 512-dimension vector your model produced from it is a measurement of facial geometry by another name, and it is retained, indexed and compared precisely because it identifies the person. Build on the assumption that the vector is the identifier and the JPEG is merely where it came from.

A hash or 'irreversible' template

Teams reach for hashing as an anonymisation story, but the biometric-information definition follows data converted from an identifier and used to identify someone. A value that is still matched against future captures to recognise a person is, by construction, still identifying them. Irreversibility is a good security property and a weak legal argument.

Age or liveness estimation from a selfie

A feature framed as estimating whether a user is old enough, or whether a live human is present, may still compute facial geometry to do it. The framing the product uses is not the test; the operation performed on the face is. Ask the vendor what is computed and what is retained, and get the answer in the contract rather than the datasheet.

Voice embeddings from recorded calls

A voiceprint is named in the identifier list. A speaker-recognition or speaker-diarisation embedding derived from a call recording sits in the same position as a face template — the recording may be governed by other laws, and the embedding is the thing this statute names.

Third-party enrichment you did not compute

Receiving templates, match scores or identity signals derived from biometrics puts you in possession of biometric information you never captured. The duties that attach to possession — a published retention and destruction schedule, the disclosure limits — do not require that you were the one who ran the model.

Four Arguments That Do Less Work Than Expected

'We delete the photo immediately'

Deleting the input while retaining the derived template keeps the covered artefact and discards the evidence of where it came from. It is a reasonable data-minimisation step and it does not answer the question the statute asks, which is about what you are holding now.

'The vendor does the processing'

A processor's involvement does not remove the duties from the party that collected, and it puts the processor itself in possession. Both ends of that relationship end up inside the Act, which is why vendor contracts in this space need a subprocessor list, a retention schedule and a deletion commitment rather than a generic data-processing addendum.

'It is excluded because it is health data'

The exclusions and the health-care carve-outs in the Act are specific and narrow, and they are drafted around particular contexts such as information collected and used under federal health-privacy rules, or biological samples used for valid scientific testing or screening. They are not a general exemption for a product used in a clinical setting. Check whether the specific words describe your specific flow.

'No one was actually identified'

The obligations attach to collection and possession, not to a successful match, and the private right of action has been held not to require harm beyond the violation itself. A system that enrols thousands and matches nobody has the same intake obligations as one that matches everybody.

Six Things to Put in Place

Write down what is computed, not what is stored

For each feature touching a face, a voice, a hand or an eye, record the operation performed and the artefact produced — image, vector, score, hash — and its lifetime. The definitional question is almost always answerable from that table alone, and most teams have never written it down.

Classify each artefact against the two definitions

Identifier or information, or neither, with a one-line reason. Doing this in writing before a dispute means the reasoning exists in a document you authored rather than in a deposition, and it surfaces the features where the answer is genuinely uncertain.

Stop relying on the input being excluded

If the only argument is that the source was a photograph, the position is weak. Either the derived artefact is covered and the intake duties apply, or the feature can be redesigned so no geometry is computed — an image classifier that never produces a comparable template is a different product from a recogniser.

Publish the retention and destruction schedule

The Act requires a written policy, made available to the public, with a retention schedule and destruction guidelines, and it is the cheapest of the obligations to satisfy. Its absence is also checkable from outside the company, which makes it a common first exhibit.

Fix the consent to match the artefact

Notice of the fact of collection, the specific purpose, the retention period, and a written release, obtained before the first capture. If your release describes photo uploads and your system builds face templates, the document is describing a different operation from the one occurring.

Ask the vendor the definitional question directly

Does the product compute a scan of face or hand geometry, or a voiceprint; is a template retained; for how long; where; and who else receives it. A vendor unable to answer those five questions in writing is a vendor whose compliance story you will be reconstructing yourself later.

Questions Product and Legal Teams Ask

Photographs are excluded from the definition. Why does face recognition still get sued?

Because the same section that excludes photographs also names a scan of face geometry as a covered identifier, and both sentences have to mean something. Reading the exclusion broadly enough to cover anything derived from an image would leave the face-geometry clause with almost nothing to operate on, since facial measurements are ordinarily computed from images. The reading that has generally prevailed separates the artefacts: the picture is the excluded item, and the geometric template computed from it is the covered identifier. For a product team this is a useful clarification rather than a technicality, because it tells you where to look — not at the upload, but at what your model produces from the upload and retains afterwards.

We only store an irreversible hash. Does that take us outside the Act?

Probably not on its own, because the Act's second definition is drafted to follow the data. Biometric information means information based on a biometric identifier and used to identify an individual, regardless of how it is captured, converted, stored or shared. A hash that is compared against future captures in order to recognise the same person is information converted from an identifier and used to identify — which is the clause read literally. Irreversibility is genuinely valuable: it limits what a breach exposes and it is the right engineering decision. It is a security property rather than a definitional escape, and presenting it as the latter in a privacy policy creates a statement the other side will quote back. If the goal is to leave the statute, the question is whether the system can work without a comparable template at all.

Our feature estimates age from a selfie and stores nothing. Is that covered?

It depends on what is computed, not on what is kept, because the intake duties attach at collection or capture. If the estimator derives facial geometry in order to produce its output, the collection happened even if the artefact lived for a hundred milliseconds in memory. If it produces a classification from image features without computing anything comparable to a face template, the position is materially better. Most teams cannot answer this about their own product, because the model came from a vendor and the datasheet describes the outcome rather than the operation. That is the question to put in writing to the vendor: does the pipeline compute a scan of face geometry, is any template materialised, and is anything retained. The answer determines whether you need notice and a written release before the first use.

Does a written signature or a physical description count?

The statute excludes writing samples, written signatures, demographic data, physical descriptions such as height, weight, hair colour and eye colour, and descriptions of tattoos, among others. Read those as the specific artefacts named. A static image of a signature is on the excluded list; a dynamic capture that records the pressure, timing and stroke order of how the signature was produced is a different artefact, and arguing it into the exclusion is not a comfortable position. Similarly, an eye colour recorded from a form is excluded demographic data, while an iris scan is expressly an identifier. The pattern across the exclusions is that they cover the ordinary descriptive datum and not a biometric measurement that happens to concern the same body part.

We receive match scores from a partner and never touch biometrics. Are we exposed?

Possibly, because several of the Act's duties attach to an entity in possession of biometric identifiers or biometric information rather than to the entity that collected them. Information based on someone's biometric identifier and used to identify them is within the second definition regardless of who computed it, so receiving templates, embeddings or identity signals derived from a face or a voice can put you in possession. The practical consequences are the published retention and destruction schedule, the limits on onward disclosure, and the need to know what your partner told the individuals when it collected. A contract that positions you as a downstream recipient allocates risk between the two companies; it does not answer a duty owed to the people the data describes.

The Comparable-Template Test

For each feature that touches a face or a voice, ask one question: does it produce a value that can be compared against a future capture to decide whether it is the same person?

If it does, the exclusion for the input is not the argument — the value is, and the duties attached to it started at the first capture rather than at the first match.

Related Reading