Colorado's Biometric Consent Law for AI and Employers 2026: What HB 24-1130 Requires
Illinois gets the headlines because it has a private right of action. Colorado is the one that quietly reaches more companies: its biometric obligations attach to any controller collecting biometric identifiers, with no revenue floor and no consumer count to clear, and they apply to your employees by name.
Why This One Reaches Companies the CPA Doesn't
The Colorado Privacy Act's main obligations are threshold-gated — you need to be processing personal data about a substantial number of Colorado consumers before the general duties apply. HB 24-1130 detached the biometric provisions from that gate. If you collect biometric identifiers from Colorado residents, the biometric rules apply, full stop.
The second departure is scope of person. Most US privacy statutes exclude data processed in an employment context. Colorado's biometric provisions run the other direction and address employers explicitly, which makes this one of the few US laws that genuinely governs workplace biometric AI rather than gesturing at it.
The Line Between a Photo and a Biometric Identifier
A biometric identifier is data generated by technological processing of a biological, physical or behavioral characteristic that can identify a specific individual. The raw media usually is not the identifier; the template generated from it is. Where AI features cross the line:
The recurring failure is procedural, not conceptual: nobody classified the feature. A transcription tool adds speaker recognition in a routine release, and a product that was outside the statute on Monday is inside it on Tuesday with no consent flow, no policy update and no retention schedule.
What Consent Has to Look Like
Consent must be obtained before collection, and it must be consent in the CPA's sense — a clear, affirmative act, freely given, specific, informed, and unambiguous. Three consequences worth stating plainly:
- Bundled acceptance does not work. Burying the permission in a handbook acknowledgement or a terms-of-service checkbox that also covers ten other things is not specific consent.
- Silence and pre-ticked boxes do not work. The affirmative act has to be affirmative.
- The disclosure is part of the consent. Informed means the individual was told the purpose, the retention schedule, and whether the identifier is disclosed to anyone else — before, not after.
The four employment carve-outs. An employer may condition employment on biometric consent only for: access to secure physical or digital locations; recording the start and end of a full work shift; workplace safety; and public safety during an emergency. Note the shift language — it authorises clocking in and out, not continuous scanning through the day. A vendor that markets face-recognition break tracking or productivity monitoring is selling a use that sits outside the carve-outs, and consent for it must be genuinely refusable.
Retention, Deletion, and the Annual Review Nobody Diarises
You need a written policy with a retention schedule and a deletion protocol. Deletion is required at the earliest of three triggers:
- The purpose for collecting the identifier has been satisfied.
- Twenty-four months after the individual's last interaction with the controller.
- Forty-five days after determining that storage is no longer necessary, adequate or relevant to the purpose.
The schedule must be reviewed at least annually. In practice, trigger two is the one that produces findings: former employees and lapsed users whose templates are still sitting in a vendor system because the offboarding checklist deletes the account and not the biometric artefact. Ask your vendor where templates live, whether deletion in your admin console propagates to their store, and whether they will confirm it in writing.
Colorado Versus Illinois: What Actually Transfers
- Enforcement. BIPA's private right of action drives class litigation. Colorado is enforced by the Attorney General and district attorneys, with violations treated as deceptive trade practices — a different risk shape, and one that rewards being demonstrably organised rather than merely lucky.
- Employees. Colorado addresses employment directly and limits what can be made a condition of employment. BIPA has no equivalent enumerated list.
- Thresholds. Neither statute lets small companies out, which surprises teams who assumed their CPA analysis covered this.
- Documents. A BIPA-grade written policy, consent record and retention schedule is most of what Colorado wants. Add the annual review and the employment-purpose analysis and you are close to done.
A One-Page Compliance Pass
- Inventory the templates. List every system — yours and your vendors' — that generates an identifying template from a face, voice, eye, fingerprint or behavioral signal. Include features shipped since your last review.
- Classify each use against the carve-outs. Access, shift start and end, workplace safety, emergency public safety. Anything else needs refusable consent and an alternative for people who refuse.
- Fix the consent moment. Standalone, pre-collection, specific to biometrics, with the purpose and retention stated. Keep the record.
- Publish the policy. Retention schedule and deletion protocol, public where you collect from consumers, and reachable internally for employees.
- Wire deletion to offboarding. Account deactivation and template deletion are different operations in almost every product.
- Diarise the annual review. A dated calendar entry with an owner. The review is a requirement, and it is the cheapest evidence of good faith you will ever produce.
Frequently Asked Questions
We have no office in Colorado but some remote employees live there. Are we covered?
Almost certainly, if you collect biometric identifiers from them. Colorado's regime keys on the residency of the individuals whose data you process rather than on where your company sits — the same logic that makes state privacy laws apply to out-of-state SaaS companies. A distributed workforce means you are exposed to the biometric rules of every state your employees live in, which is why the practical answer for most companies is to build one process to the strictest standard rather than a per-state matrix.
Our vendor collects the biometric data, not us. Whose obligation is it?
Yours as controller, with the vendor as processor acting on your instructions. Determining the purposes and means of processing is what makes you the controller, and choosing to deploy a face-scan time clock is exactly that determination. The vendor's compliance materials are useful evidence but they do not transfer the duty. What you need contractually is that the processor only acts on your instructions, deletes on your instruction within your schedule, and will confirm deletion — the third one is routinely missing.
Does an employee's consent stay valid after they leave?
Consent to collection does not extend retention. The twenty-four month trigger runs from the individual's last interaction with the controller, and for a departed employee that clock is already running. Separately, the purpose-satisfied trigger usually bites earlier: once someone no longer needs building access or shift recording, the purpose for holding their template is spent. Treat termination as a deletion event rather than a retention countdown and you satisfy both.
We use facial recognition for security cameras in a retail location. Which carve-out applies?
None of them automatically, because the carve-outs are about what an employer may require of employees — they do not authorise collection from customers. Collecting biometric identifiers from members of the public requires consent obtained before collection, which is difficult to construct honestly for a camera in a doorway. Loss-prevention face matching is the single hardest use case to run compliantly in any biometric-consent state, and the realistic options are usually to not build the template, or to restrict the system to detection that never identifies.
Is a signed handbook acknowledgement enough for employee consent?
No. Consent must be specific and unambiguous, and an acknowledgement covering the whole handbook is neither. Use a standalone biometric consent that names the identifier being collected, the purpose, the retention schedule, and any disclosure to vendors, signed before the first scan. Keep the executed record — in an enforcement posture, an undated policy plus an undocumented rollout is functionally the same as no consent at all.
Start With the Feature Inventory
Nearly every biometric compliance failure starts as a classification failure: a feature shipped, a vendor swapped, a model upgraded, and the thing that used to detect people now recognises them. No policy catches that unless someone is looking.
Inventory the systems that generate templates, map each to a permitted purpose, and put the annual review on a calendar with a name against it. That sequence is most of Colorado compliance, and it is the same sequence that satisfies Illinois, Texas and Washington with local adjustments.