Biometric Data Checklist: Inventory, Notice, Written Consent, Retention, and Deletion

By ·

Biometric exposure enters a company through a purchase order and is discovered through a lawsuit. This checklist runs the compliance work in twelve phases: inventory the systems, establish what each actually stores, publish the retention policy, deliver pre-collection notice, obtain the written release before the first scan, build a destruction mechanism that runs, diligence and contract the vendors, satisfy the comprehensive privacy statutes, review insurance, remediate a legacy deployment, model the residual exposure, and set the annual review. Each box gives the reason, the authority, and the trap. Boxes marked as gates should clear before any enrollment. A worked remediation runs throughout.

IP and Technology > Privacy Data Security | Checklist | Published 31 December 2023 - Updated 20 January 2026 | Casey Scott McKay - marksy.us

Summary. Biometric exposure enters a company through a purchase order and is discovered through a lawsuit. This checklist runs the compliance work in twelve phases: inventory the systems, establish what each actually stores, publish the retention policy, deliver pre-collection notice, obtain the written release before the first scan, build a destruction mechanism that runs, diligence and contract the vendors, satisfy the comprehensive privacy statutes, review insurance, remediate a legacy deployment, model the residual exposure, and set the annual review. Each box gives the reason, the authority, and the trap. Boxes marked as gates should clear before any enrollment. A worked remediation runs throughout.

Keywords: biometric inventory, template storage, coverage analysis, public retention policy, pre-collection notice, written release, enrollment control, destruction job, vendor possession, data processing agreement, indemnity cap, insurance exclusion, sensitive data consent, data protection assessment, deletion capability, rights requests, acquisition diligence, legacy remediation, exposure model, annual review


How to use this checklist

| Phase | What it covers | |---|---| | 1 | Inventory the systems | | 2 | What each system stores | | 3 | The public retention policy | | 4 | The pre-collection notice | | 5 | The written release | | 6 | Destruction that runs | | 7 | Vendors | | 8 | The comprehensive privacy layer | | 9 | Insurance | | 10 | Remediating a legacy deployment | | 11 | Modeling the exposure | | 12 | Ownership and annual review |

Boxes marked [Gate] should clear before any person is enrolled.

The matter. A regional logistics company with eleven facilities discovered its exposure when a competitor was sued. The inventory found nine systems; technology knew about three.


Phase 1. Inventory


Phase 2. What each system stores


Phase 3. The public retention policy


Phase 4. The pre-collection notice


Phase 5. The written release


Phase 6. Destruction that runs


Phase 7. Vendors


Phase 8. The comprehensive privacy layer


Phase 9. Insurance


Phase 10. Remediating a legacy deployment


Phase 11. Modeling the exposure


Phase 12. Ownership and annual review

Phase 13. Deployment-pattern boxes

Six patterns account for nearly all of the litigation. Run the pattern-specific boxes for whichever apply.

Workforce timekeeping

Staffing and contractor placements

Retail loss prevention

Consumer platforms

Voice authentication

Access control and facilities


Phase 14. What clients ask, with the answers


Phase 15. The three documents, element by element

The public policy

The pre-collection notice

The release

The test that matters


Phase 16. Failure modes, collected


Phase 17. The deploy-or-not decision

Compliance is a cost. For some deployments the honest recommendation is not to proceed, and the analysis takes an hour.


Phase 18. Where this sits in the wider privacy program


Phase 19. Defending a claim, if one arrives

The defenses are narrower than defendants hope and they are mostly threshold arguments. Assemble them in this order.


Phase 20. The ninety-day plan

For a company starting from nothing, this is the sequence and the pace.

The whole program is a part-time assignment for one lawyer, one engineering change, and a vendor negotiation. Set against the modeled exposure of a six-year unconsented deployment, that ratio is the entire argument for doing it before somebody else's lawsuit prompts it.


Outcome. The inventory found nine systems where technology knew of three, and eight were in scope. Yard camera matching was suspended because the drivers were third-party contractors who could not practically sign. A public policy, per-system notices, releases, an enrollment control, and a monthly deletion job were built in eight weeks, and every current employee re-consented before the next scan. The general liability policy was found to contain a biometric exclusion added at the prior renewal; a cyber endorsement was obtained. Six years of prior collection at two facilities remained exposed, but accrual had stopped and the remediation record existed.


Key Authorities at a Glance

| Authority | Proposition | Phase | |---|---|---| | 740 ILCS 14/10 | Definitions; identifiers and exclusions | 2 | | 740 ILCS 14/15 | Policy, notice, release, disclosure, care | 3, 4, 5 | | 740 ILCS 14/20 | Right of action; damages; fees | 11 | | Tex. Bus. & Com. Code § 503.001 | Informed consent; destruction | 8 | | Wash. Rev. Code § 19.375.020 | Enrollment; notice and consent | 8 | | Cal. Civ. Code § 1798.100 | Notice at collection | 8 | | Cal. Civ. Code § 1798.105 | Deletion | 7, 8 | | Cal. Civ. Code § 1798.121 | Limit use of sensitive data | 8 | | Cal. Civ. Code § 1798.140 | Sensitive personal information | 8 | | Cal. Civ. Code § 1798.150 | Private right of action for breaches | 9 | | Va. Code § 59.1-575 | Sensitive data | 8 | | Va. Code § 59.1-578 | Consent and assessment | 8 | | Colo. Rev. Stat. § 6-1-1303 | Definitions | 8 | | Colo. Rev. Stat. § 6-1-1308 | Consent and assessments | 8 | | 15 U.S.C. § 45 | FTC unfair or deceptive practices | 8 | | 15 U.S.C. § 6801 | Financial privacy; exemption basis | 10 | | 29 U.S.C. § 185 | Labor preemption defense | 10 | | 18 U.S.C. § 2511 | Interception; voice capture | 2 | | Fed. R. Civ. P. 23 | Class certification | 10, 11 | | Fed. R. Civ. P. 12 | Motions to dismiss | 10 | | Fed. R. Evid. 702 | Technical testimony on what is stored | 2 |


The five things people get wrong

One: they inventory by asking IT. The timeclock came from human resources, the door readers from facilities, and the cameras from security. An inventory that does not reach the functions who buy systems finds a third of them.

Two: they assess coverage from a datasheet. Whether a template capable of identifying a person is created and retained is an engineering question, and the answer decides everything downstream. 740 ILCS 14/10.

Three: they treat a handbook paragraph as a release. The statute requires a written release executed before collection. Continued employment is not execution and a policy acknowledgment is not a release. 740 ILCS 14/15.

Four: they write the destruction policy and never build the job. It is the most documented and least executed obligation in the program, and a policy nobody runs is worse than none because it establishes the obligation.

Five: they check the insurance at tender. Many carriers added express biometric exclusions after the first coverage cases, and the time to discover that is at renewal rather than after a complaint. See Building a Biometric Compliance Program.


Related Documents

Articles

Guides

Checklists

Toolkits

Templates & Forms


This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Biometric compliance turns on specific systems, records, and state statutes. Marksy is not a law firm.

Read this article on Marksy