Face recognition in the United States
The United States has no federal face recognition statute. A deployment is governed by state biometric privacy law, and the strictest is Illinois' Biometric Information Privacy Act, which requires written notice, a written release and a published retention schedule, and gives individuals a private right of action.
Which US laws govern face recognition?
No single one. Congress has passed no general biometric privacy statute, so the obligations come from the states, and they differ in both what they require and who can enforce them.
| Law | Requires | Enforced by |
|---|---|---|
| Illinois BIPA (740 ILCS 14) | Written notice, written release, published retention and destruction schedule | Private right of action by the individual |
| Texas CUBI (Bus. & Com. Code 503.001) | Notice and consent before capture; destruction within a set period | State Attorney General |
| Washington (RCW 19.375) | Notice and consent before enrolling a biometric identifier for a commercial purpose | State Attorney General |
| California CCPA as amended by CPRA | Biometric data treated as sensitive personal information, with a right to limit its use | California Privacy Protection Agency and the Attorney General |
Several other states have since enacted comprehensive privacy laws that classify biometric data as sensitive and require consent before processing it. The practical consequence for a multi-state operator is that the strictest applicable state usually sets the design, because building one system per state is not realistic.
What does Illinois BIPA actually require?
- Publish a written policy with a retention schedule and guidelines for permanent destruction, made available to the public.
- Inform the person in writing that a biometric identifier is being collected, and of the specific purpose and length of term.
- Obtain a written release from that person before collection.
- Do not sell, lease or otherwise profit from the biometric identifier.
- Store it using the reasonable standard of care for the industry, and at least as protectively as other confidential information.
BIPA attaches to the biometric identifier and the information derived from it, which includes a face template extracted from a photograph. Deleting the photograph does not, on its own, discharge the obligation to the template.
What is the role of NIST evaluation in US procurement?
The National Institute of Standards and Technology runs the reference evaluations of face recognition algorithms, and United States procurement frequently asks whether a supplier's algorithm has been submitted to them. The evaluations are independent: NIST tests submitted algorithms on its own sequestered datasets and publishes the results.
Ayonix states that its technology has been evaluated by NIST, and links to the published evaluation material rather than restating a figure. It does not claim NIST certification, approval or endorsement, because NIST issues none of those: it is a measurement body, and a report of a measurement is not an accreditation. NIST does not certify, approve or endorse vendors.
A supplier claiming to be 'NIST certified' is describing something that does not exist. The question worth asking is narrower and answerable: which evaluation, which track, which report, and on what date.
Where does the data sit, and why does it matter here?
There is no United States data localisation requirement for commercial biometric data. What matters instead is control, because BIPA and the state statutes impose duties that an operator can only discharge if it can actually reach the data: a published destruction schedule is not meaningful if the templates live in a vendor's cloud under the vendor's lifecycle.
- On-premise or air-gapped deployment keeps templates inside the operator's own estate, where its retention schedule is enforceable.
- Edge processing means the face never leaves the device that saw it, and only the result is transmitted.
- Where a cloud deployment is chosen, the destruction schedule has to be a contractual term, not an assumption.
- Federal sector work brings its own requirements, including FISMA and the relevant NIST Special Publications, which are controls frameworks rather than face recognition law.
This page describes what the named laws require, with each instrument cited so it can be checked. It is not legal advice, and it is not a statement that any particular deployment complies: that assessment belongs to your own counsel and your data protection authority.
Frequently asked questions
- Is there a federal face recognition law in the United States?
- No. Congress has not enacted a general biometric privacy statute. Obligations come from state law, principally Illinois' BIPA, Texas' CUBI, Washington's RCW 19.375 and the comprehensive state privacy laws that classify biometric data as sensitive.
- Why does Illinois BIPA matter so much outside Illinois?
- Because it is the statute with a private right of action. An individual can sue directly rather than waiting for a regulator, which has produced large class settlements and made Illinois the design constraint for operators who run in more than one state.
- Is Ayonix NIST certified?
- No, and no face recognition product is. NIST runs evaluations and publishes measurements; it does not certify, approve or endorse products. Ayonix technology has been evaluated by NIST, which is a different and checkable statement.
- Does US biometric data have to stay in the United States?
- There is no general commercial localisation requirement. The operative question is control rather than geography: state statutes require published retention and destruction schedules, which an operator can only enforce if it can reach the templates. On-premise deployment makes that straightforward.
- Can face recognition be used in US retail stores?
- It depends on the state. In Illinois it requires written notice and a written release before collection. In states with no biometric statute, the general consumer protection and privacy framework applies. Several cities have additionally restricted or required disclosure of retail use.
- Does Ayonix have a US presence?
- Ayonix publishes a United States office contact number alongside its Tokyo headquarters. The company was founded in Japan in 2007 and its engineering base is there; deployments in the United States run on the customer's own infrastructure rather than on an Ayonix-operated service.
