Biometric and Sensitive Data Toolkit: Consent, Retention, and Litigation Exposure
By Casey Scott McKay ·
Biometric privacy is the rare area where a technical foul carries damages large enough to end a company, and the foul is usually a missing piece of paper. This toolkit runs the exposure from system inventory through remediation and defense, and routes each stage to the Marksy documents that do the work. It explains what counts as a biometric identifier and why the answer is an engineering question rather than a marketing one, the four obligations the leading statute imposes, and why the private right of action with liquidated damages has driven nearly all of the litigation. It covers who is liable - employers, vendors, platforms, staffing agencies, and acquirers - the exemptions and their limits, the accrual question that turns a workforce program into an existential number, and the comprehensive privacy statutes layered on top. It closes with the deployment decision, the defenses that work, and the reading path.
IP and Technology > Privacy Data Security | Toolkit | Published 25 January 2026 - Updated 17 May 2026 | Casey Scott McKay - marksy.us
Summary. Biometric privacy is the rare area where a technical foul carries damages large enough to end a company, and the foul is usually a missing piece of paper. This toolkit runs the exposure from system inventory through remediation and defense, and routes each stage to the Marksy documents that do the work. It explains what counts as a biometric identifier and why the answer is an engineering question rather than a marketing one, the four obligations the leading statute imposes, and why the private right of action with liquidated damages has driven nearly all of the litigation. It covers who is liable — employers, vendors, platforms, staffing agencies, and acquirers — the exemptions and their limits, the accrual question that turns a workforce program into an existential number, and the comprehensive privacy statutes layered on top. It closes with the deployment decision, the defenses that work, and the reading path.
Keywords: system inventory · template storage · coverage analysis · biometric identifier · public retention policy · pre-collection notice · written release · enrollment control · destruction mechanism · vendor possession · data processing agreement · indemnity cap · insurance exclusion · sensitive data consent · data protection assessment · deletion capability · class exposure modeling · labor preemption · acquisition diligence · deployment decision
Start Here
Thoresby Logistics has eleven facilities and a general counsel who read about a competitor's settlement over the weekend. On Monday, four questions.
Does the company collect biometric data? Nobody knows, because nobody has asked the functions that buy systems.
If it does, is there consent? Nobody knows, because nobody has looked at the paperwork.
How much is this worth? Nobody knows, because nobody has counted the enrolled population across the deployment period.
And is it insured? Nobody knows, because nobody has read the policy since the last renewal.
Four questions, all answerable in three weeks, and one uncomfortable fact behind them: the answers get worse every day the systems keep running.
This toolkit answers three questions.
- What do we collect, and is it covered? An inventory that reaches the functions who buy systems, and a technical answer about what each system stores.
- What does the law require? A public policy, a pre-collection notice, a signed release before the first scan, and destruction that actually happens.
- What is the exposure, and what reduces it? A model built from population, period, and accrual rule, and a remediation that stops the growth even where it cannot cure the past.
If you read only one thing, read Your Face as Data. It explains why this area behaves unlike every other privacy regime and why a technical foul carries ruinous damages.
Why This Area Is Different
Most privacy statutes are regulator-enforced, with penalties calibrated to the violation and time to fix problems before they become expensive.
Biometric privacy is not. One state gave individuals a private right of action with liquidated statutory damages and no requirement to prove actual harm, and that single feature produced the entire litigation landscape.
The arithmetic. A workforce of two thousand employees clocking in twice a day for four years, scanned without a signed release, produces a number that has nothing to do with any injury anyone suffered.
Three states have biometric-specific statutes. One with the private right of action; two enforced by the attorney general. Nearly all the litigation is in the first.
Layered on top, the comprehensive consumer privacy statutes enacted since 2020 classify biometric data as sensitive and require consent or a meaningful opt-out, with regulatory rather than class action enforcement.
No cure period, no materiality threshold, no harm requirement. A program that protects the data perfectly and never obtained a release is in violation.
What Counts
Covered, generally. A retina or iris scan, a fingerprint, a voiceprint, and a scan of hand or face geometry. 740 ILCS 14/10 uses that enumeration, and biometric information extends coverage to information based on an identifier used to identify a person, however captured or converted — which prevents an argument that a mathematical template derived from a face is not a face.
Expressly excluded. Writing samples, written signatures, photographs, demographic data, tattoo descriptions, physical descriptions, donated tissue, materials under federal genetic privacy law, information captured in a health care setting or under federal health privacy law, and X-rays and similar imaging.
The photograph problem. Photographs are excluded and a face template extracted from a photograph is not. The prevailing reading is that the exclusion covers the image, not the derived data.
Usually not covered. Detection without identification — determining a face is present, counting people, or producing blurred or aggregated analytics. The line is identification: a template capable of identifying a particular individual is what the statutes regulate.
Voice. Enumerated, which brings call center analytics, voice authentication, and some assistant products into scope. A recording is not a voiceprint; a template derived from it to identify the speaker is.
How to answer the question. Engineering documentation, not a datasheet. Does the system create a template capable of identifying a specific person, is it retained after the match, and where does it live. Fed. R. Evid. 702 — a technical witness will have to support the answer.
The Four Obligations
A public written policy establishing a retention schedule and destruction guidelines, made available to the public. Destruction when the initial purpose has been satisfied or within three years of the individual's last interaction, whichever comes first. 740 ILCS 14/15.
Written notice before collection, informing the person that a biometric identifier is being collected or stored and stating the specific purpose and the length of term.
A written release, executed before collection. In employment it may be executed as a condition of employment, which makes the requirement easy to satisfy and its omission harder to explain. This is the provision that generates the litigation.
No sale, lease, trade, or profit from a person's biometric identifier or information, separate from disclosure, which is permitted with consent, to complete a requested transaction, where required by law, or under a warrant.
Plus a duty of care in storage, using the reasonable standard within the industry and in a manner at least as protective as the entity uses for other confidential and sensitive information.
The other two statutes. Tex. Bus. & Com. Code § 503.001 prohibits capture for a commercial purpose without informed consent, restricts disclosure, requires reasonable care, and requires destruction within a reasonable time. Wash. Rev. Code § 19.375.020 prohibits enrolling an identifier in a database for a commercial purpose without notice, consent, or a mechanism to prevent subsequent commercial use, and its definition excludes photographs, video, and audio recordings.
Who Is Liable
Employers. The largest category. Fingerprint and hand-geometry timeclocks were adopted widely and the vendors selling them did not supply consent paperwork, because consent was the customer's problem and nobody said so.
Vendors. A company supplying the hardware, the software, or the cloud service may itself possess identifiers. Vendor liability has been litigated extensively, and the safer assumption is that a vendor storing templates is subject to the statute independently of its customer.
Platforms and retailers. Face recognition applied to uploaded photographs, security camera footage, or customers entering a store. Signage at the door is not a written release, and this pattern has no clean compliance answer in the private-right-of-action states.
Staffing agencies and their clients. A worker placed by an agency and scanned at the client's site raises the question of who collected. Both, prudently, with the release obtained by whoever runs the enrollment and an indemnity allocating between them.
Acquirers. Exposure is inherited. Diligence should ask what biometric systems the target operates, since when, and whether releases exist for every enrolled person — and it usually does not.
Exemptions and Their Limits
Financial institutions subject to federal financial privacy law are excluded, and the scope is contested at the edges for affiliates and service providers. 15 U.S.C. § 6801.
Health care. Information collected in a health care setting and information subject to federal health privacy law is excluded. A hospital's patient identification system is treated differently from the same hospital's employee timeclock, which surprises people.
Government contractors are outside the private entity definition, with limits.
Union-represented employees. Claims may be preempted where resolution requires interpreting a collective bargaining agreement, on the reasoning that the union may bargain over the subject. 29 U.S.C. § 185. This has become one of the more effective employment-case defenses and it turns on the management rights clause.
No exemption for good intentions. No cure period, no materiality threshold, no harm requirement.
The Damages Arithmetic
Liquidated damages per violation for negligent conduct and a higher figure for intentional or reckless conduct, or actual damages if greater, plus attorney fees and injunctive relief. 740 ILCS 14/20.
The accrual question. Whether a violation occurs once at first collection or on each scan was litigated intensively, and the answer that emerged — a separate claim with each scan — is what turns a workforce program into an existential number. Legislative amendments limiting per-scan accrual have followed, applying prospectively, which means exposure for prior conduct persists.
The limitations period. A single five-year period governs all claims under the statute, resolving an earlier split.
No harm required. Decided early, and it is the foundation of everything.
Insurance. Coverage disputes over whether general liability policies reach these claims have gone both ways, turning on personal and advertising injury coverage and on exclusions for violations of statutes governing communications. Many carriers now exclude biometric claims expressly, which makes the policy review a real exercise rather than a formality.
Settlement values. Class settlements have run into eight and nine figures for large workforces and platform-scale collections, which is why the compliance investment is trivial by comparison.
The Comprehensive Privacy Layer
Biometric data is sensitive under nearly every comprehensive state statute. Cal. Civ. Code § 1798.140; Va. Code § 59.1-575; Colo. Rev. Stat. § 6-1-1303.
What that triggers. Affirmative consent before processing in some states, a right to limit use in others. Va. Code § 59.1-578; Cal. Civ. Code § 1798.121. Plus a data protection assessment, purpose limitation, and specific notice disclosures. Colo. Rev. Stat. § 6-1-1308; Cal. Civ. Code § 1798.100.
Consumer rights apply, including deletion, which means the program must locate and delete a named individual's templates on request — a capability many biometric systems do not support natively. Cal. Civ. Code § 1798.105.
Processor contracts with specified terms, plus diligence.
Enforcement is regulatory, by attorneys general, with cure periods being phased out. A different exposure profile with different economics, and the private right of action for security breaches under Cal. Civ. Code § 1798.150 reaches biometric data held insecurely.
The practical consequence. A national program needs the biometric paperwork plus the comprehensive-law apparatus. Building for the strictest biometric statute gets most of the way to both.
Building the Program
The inventory, first. Ask human resources, facilities, security, store operations, and the contact center — not only technology. Timeclocks, access control, camera analytics, voice authentication, kiosks, vehicle and server room entry. Record vendor, deployment date, locations, enrolled population, purpose, and any consent obtained. Include remote employees resident in private-right-of-action states.
The technical answer per system, in writing, from engineering documentation.
The public policy, published, with the retention schedule in statutory terms and the systems named.
The pre-collection notice, a separate document, naming the specific identifier, the specific purpose, the term, and who holds the data, versioned so the company can produce what a person was told on a given date.
The written release, signed before the first scan, referencing the notice version, retained with the enrollment record.
The enrollment control. The system should not create a template for a person without a release on file. Process without a technical control fails across four years and two thousand hires.
The destruction job, built rather than written, covering device, appliance, vendor cloud, and backups, triggered on departure as well as at the three-year limit, logged, and tested annually.
Vendor terms. Who possesses what, the vendor's own compliance, no secondary use including model training, deletion on termination and on individual request, and an indemnity whose cap is not tied to fees paid.
Insurance reviewed now, not at tender.
Acquisition diligence naming biometric systems specifically rather than relying on a general compliance representation.
Remediating and Defending
Stop the accrual first. Obtain releases prospectively or suspend the system. Every day of continued operation adds exposure.
Do not backdate anything. Remediation documents suggesting earlier consent convert a paperwork case into a fraud case.
Suspend where the population cannot sign. Retail loss prevention and third-party drivers are the recurring examples, and turning the system off is frequently the honest recommendation.
Document the remediation, because it bears on the negligent-versus-reckless distinction and the statutory figures differ substantially.
Model the exposure honestly. Distinct individuals enrolled rather than current headcount; the state footprint including remote workers; the period per individual; the accrual rule in force during each part of it; the five-year limitation; the negligent-versus-reckless split; the class certification discount where enrollment practices varied; and a settlement benchmark adjusted for population.
The defenses that work. Coverage, argued from engineering documentation. Exemption, each narrower than it sounds. Labor preemption for union-represented employees. Extraterritoriality, because the statute reaches conduct occurring primarily and substantially within the state. Consent in fact, where a signed acknowledgment exists. And class certification, where enrollment practices varied by location, by year, or by supervisor — the defense with the largest practical effect on exposure. Fed. R. Civ. P. 23; Fed. R. Civ. P. 12.
What does not work. That nobody was harmed, that the data was well protected, that the vendor should have said something, or that the company fixed it on learning.
The Deployment Decision
Some deployments should not proceed, and saying so is the advice.
What does the biometric buy over the alternative? A hand-geometry clock prevents buddy punching; so does a photo badge and a supervisor. The marginal benefit is frequently smaller than the exposure.
Can the population sign? Employees can. Contractors can with coordination. Retail customers, visitors, and third-party drivers generally cannot, and in the private-right-of-action states that is close to dispositive.
Can the system be configured outside coverage? Detection without identification, matching without retention, or on-device processing with nothing transmitted. Several vendors support these modes and do not advertise them.
Model the rollout, not the pilot. Fifty people at one site is manageable; the same system at eleven sites over six years is not, and the decision is usually made at the pilot.
Consider a state-limited deployment, which several national retailers have concluded the arithmetic supports.
Will the vendor stand behind it? A vendor that will not answer the technical questions in writing, cannot delete on request, and will not move the indemnity cap is telling you how much risk you are absorbing.
Write the decision down either way.
Thoresby's Ninety Days
The same four questions, answered.
Week one, the inventory. Nine systems, not the three technology knew about. Hand-geometry timeclocks at all eleven facilities, deployed over six years by human resources. Fingerprint readers on two server rooms, installed by facilities. Face recognition on the yard cameras at three sites, bought by security to identify drivers. Voice authentication in the customer service line, procured by the contact center. Two facilities in a private-right-of-action state, plus fourteen remote employees resident there.
Week two, the technical answers. The timeclock vendor stores a proprietary template on a local appliance and syncs to its cloud. The server room readers store templates on the device only. The yard cameras run detection and matching against a driver roster, retaining templates. The voice system builds and stores voiceprints. Eight of the nine are in scope; one camera system does occupancy counting only and is not.
Week three, the paperwork audit. No public policy. No pre-collection notice. A handbook paragraph mentioning "biometric timekeeping" with no signature. No destruction has ever occurred, and templates for employees who left in the first year are still present.
Week four, the decisions. Suspend the yard camera matching, because the drivers are third-party contractors who cannot practically be asked to sign and badge scanning serves the purpose. Keep the other systems and remediate.
Weeks five to eight, the build. Public policy published. A notice per system, versioned. A release form referencing the notice version. An enrollment control in the timekeeping system preventing a template without a release flag. A monthly deletion job with logging, covering appliance, cloud, and backup.
Weeks nine and ten, re-consent. Every current employee receives the notice and signs before the next scan. Three refusals across eleven facilities move to badge-and-PIN.
Weeks eleven and twelve, contracts and insurance. The timeclock vendor's agreement amended for possession, deletion on request, and prohibited secondary use, with a higher indemnity cap. The general liability policy found to contain a biometric exclusion added at the prior renewal; a cyber endorsement obtained.
What remains. Six years of collection at two facilities without a release, plus the remote employees. Modeled honestly, a large number. The remediation did not eliminate it and it did three things: stopped accrual, produced a documented good-faith record relevant to the negligent-versus-reckless question, and meant that if a claim arrives the company defends a historical period rather than an ongoing violation.
What it cost. Twelve weeks of one lawyer's part-time attention, a modest vendor negotiation, and an engineering change. Against the modeled exposure, the ratio is the entire argument for doing this before someone else's lawsuit prompts it.
What Clients Ask
"We turned the system off. Are we fine?" No. The claims accrued while it ran and the limitations period runs from accrual. Turning it off stops the bleeding and does not close the wound.
"Our vendor said it was compliant." Vendors say this. It usually means the template is encrypted, not that anyone obtained a written release from your employees. The obligation is yours and it is not delegable, though an indemnity is negotiable.
"Nobody complained." Irrelevant. No harm is required, and the claim is brought as a class action by counsel who located the deployment rather than by an aggrieved employee.
"It's in the handbook." A handbook provision is not a written release executed before collection, and continued employment is not execution.
"Can we get consent now?" Yes, prospectively, and it does not cure the prior period.
"Is this covered by insurance?" Check the policy now rather than at tender. Many carriers added express biometric exclusions after the first wave of coverage litigation, and the ones that did not have contested coverage on the personal and advertising injury provisions.
"What about the company we bought last year?" Inherited. Ask what systems the target ran, since when, and whether releases exist for everyone enrolled.
"What should we do first?" The inventory. Every conclusion depends on it, and most companies discover at least one system they did not know about.
Deployment Patterns and Their Failure Modes
Six patterns account for nearly all of the litigation and each fails characteristically.
The workforce timeclock. A finger or hand scanner installed to prevent buddy punching. The vendor sold hardware and software and supplied no consent paperwork. The employer enrolled two thousand people over four years with no public policy, no pre-collection notice, and no signed release. Entirely a paperwork failure, and the archetypal case.
The staffing arrangement. A placed worker scans in at the client's site. Both entities may have collected, neither obtained a release, and each points at the other. The fix is a release obtained by whoever runs the enrollment and an indemnity between them.
Retail loss prevention. Cameras matching faces against a watchlist. Signage is not a release, the shoppers matched cannot be asked to sign, and the health care and financial exemptions do not apply. This pattern has no clean compliance answer in the private-right-of-action states, which is why several retailers have simply turned the systems off there.
The consumer platform. Face templates generated from uploaded photographs for tagging, search, or organization. The photograph exclusion does not cover the derived template, the class is enormous, and the settlements have been correspondingly large.
Voice authentication. Call centers building voiceprints to authenticate callers. A recording is not a voiceprint; a template used to identify the caller is. Two-party consent recording statutes apply separately, and 18 U.S.C. § 2511 supplies a federal baseline that state law frequently exceeds.
Access control and building security. Fingerprint or face entry for doors, server rooms, and vehicles. Small deployments, the same paperwork failure, and frequently missed in inventories because facilities bought the system rather than technology.
The common thread. In none of these did anyone decide to skip the consent. Somebody bought a system, deployed it, and nobody asked whether the law required a signature before the first scan. That is why the inventory — reaching the functions that buy systems — is the entire preventive program.
Who Owns This
Programs fail on ownership more often than on analysis.
One accountable owner, usually privacy counsel or the compliance function. Not "legal" collectively, and not the technology organization, which does not buy most of the systems.
A control, not just a policy. The enrollment gate in the timekeeping system is worth more than any memorandum, because it does not depend on anyone remembering.
One question in the purchasing workflow. Does this system identify people from a physical or behavioral characteristic. Routed to legal when the answer is yes, it catches nearly everything before deployment and it costs one line in a form.
An annual briefing for human resources, facilities, security, and store operations. These four functions buy the systems that create the exposure and none of them reads privacy guidance.
Funded engineering. Deletion jobs and enrollment gates require developer time, and an unfunded technical control is a policy binder.
Board reporting where the exposure is material. The modeled range, the remediation status, and the residual. Directors who learn of this from a complaint ask why they did not learn of it earlier.
And one page, kept current. Systems in scope, releases on file, destruction job status, state footprint, insurance position, and the modeled residual. It is what a board, a regulator, or successor counsel reads first.
Vendor Diligence: Eight Questions
Most exposure enters a company through a purchase order, and eight questions asked before signing prevent nearly all of it.
Does the system create a template capable of identifying a specific person? If not, coverage may not attach at all, and the answer should come from engineering documentation rather than a datasheet.
What is stored, where, and in what form? Raw image, hash, proprietary template, or nothing after the match. In writing.
Who possesses the data — you, us, or both? This determines who owes the statutory obligations, and "both" is a common and uncomfortable answer.
Do you supply consent and notice materials? Most vendors do not, and those that do usually supply a template nobody has reviewed.
Can you delete a named individual's data on request, and how quickly? Required by the comprehensive statutes and frequently unsupported by the product. Test it rather than accepting the answer. Cal. Civ. Code § 1798.105.
Can you enforce a retention schedule automatically? If deletion is manual, it will not happen.
Will you indemnify for claims arising from your possession, and at what cap? A cap tied to fees paid is an order of magnitude below realistic exposure.
Where are your other customers deployed? A vendor with customers in private-right-of-action states has been asked these questions before and has better answers.
Where This Is Heading
More private rights of action. Several states have considered biometric statutes modeled on the one that produced this landscape, and the pattern would repeat: a statute sits largely unused until a few decisions resolve the threshold questions, and then a decade of accumulated non-compliance becomes visible at once.
Narrowing accrual. Legislative amendments limiting per-scan accrual have followed the litigation, applying prospectively. The prospective relief does not help anyone with historical exposure, which is most defendants.
Expanding sensitive-data treatment. Every new comprehensive state privacy statute has classified biometric data as sensitive, and the consent and assessment obligations are converging.
Insurance hardening. Express biometric exclusions are now common at renewal, which shifts the exposure entirely onto the insured and turns the policy review from a formality into a genuine annual exercise with a real finding attached to it.
Technology moving faster than the statutes. Gait recognition, keystroke dynamics, typing cadence, and other behavioral biometrics sit at the edge of definitions written for fingerprints and iris scans, and the coverage questions are genuinely open. A conservative program treats anything that identifies a person from how they move, type, or speak as in scope until told otherwise.
What is stable. Notice before collection, a signed release obtained before the first scan, a published retention policy, destruction that actually happens, and a duty of care in storage. A company that does those five things is compliant under the statutes that exist today and well positioned for the ones that arrive, and it will not be the company that discovers a nine-figure exposure because a system nobody in the legal department had heard of was collecting fingerprints twice a day for six years.
A Suggested Reading Path
If you are starting from nothing:
For the wider privacy program:
- The Data Behind the Marketing
- Building a Privacy Compliance Program for a Consumer Brand
- Marketing Privacy Compliance Checklist
For the vendor relationship and the breach case:
Primary Authorities
| Authority | Proposition | |---|---| | 740 ILCS 14/10 | Definitions; identifiers and exclusions | | 740 ILCS 14/15 | Policy, notice, release, disclosure, care | | 740 ILCS 14/20 | Right of action; liquidated damages; fees | | Tex. Bus. & Com. Code § 503.001 | Informed consent; destruction; AG enforcement | | Wash. Rev. Code § 19.375.020 | Enrollment; notice and consent | | Cal. Civ. Code § 1798.100 | Notice at collection | | Cal. Civ. Code § 1798.105 | Deletion rights | | Cal. Civ. Code § 1798.121 | Limiting sensitive data use | | Cal. Civ. Code § 1798.140 | Sensitive personal information | | Cal. Civ. Code § 1798.150 | Private right of action for breaches | | Va. Code § 59.1-575 | Sensitive data definition | | Va. Code § 59.1-578 | Consent and assessment | | Colo. Rev. Stat. § 6-1-1303 | Definitions | | Colo. Rev. Stat. § 6-1-1308 | Consent and assessments | | 15 U.S.C. § 45 | Unfair or deceptive practices | | 15 U.S.C. § 6801 | Financial privacy; exemption basis | | 29 U.S.C. § 185 | Labor preemption defense | | 18 U.S.C. § 2511 | Interception; voice capture consent | | Fed. R. Civ. P. 23 | Class certification | | Fed. R. Civ. P. 12 | Motions to dismiss | | Fed. R. Evid. 702 | Technical testimony on what is stored |
Forms and Templates
The License Agreement Template is the starting point for the vendor relationship that creates most of this exposure, and the provisions that matter are the ones a standard software agreement does not address: who possesses the templates, whether the vendor may use them for its own purposes including model training, whether it can delete a named individual's data within the customer's statutory response window, and whether the indemnity cap bears any relationship to the realistic exposure. The Portfolio Inventory Template doubles as the system register — vendor, deployment date, locations, enrolled population, purpose, consent status, and the technical answer about what is stored — which is the document that answers every question in this toolkit and that no company has until someone builds it. The Assignment Agreement Template sits in the employment packet where the release and notice belong, so that the paperwork governing an employee's biometric enrollment travels with the rest of their onboarding documents rather than living in a separate system nobody maintains.
Related Toolkits and Checklists
For the breach response where biometric data is exposed, the Incident Response and Breach Notification Toolkit covers the notification analysis and the private right of action that attaches to security failures. For the wider consumer privacy program these obligations sit inside, the Privacy and Marketing Data Toolkit. For the vendor agreements that determine who bears the risk, the Technology Contracts Toolkit. And where the collection involves face or voice used to create a synthetic likeness rather than to identify, the Digital Replica and Synthetic Media Toolkit governs a different consent regime with overlapping facts.
Related Documents
Articles
- Your Face as Data
- The First Seventy-Two Hours
- The Data Behind the Marketing
- Who Owns the Data
- Synthetic You
Guides
- Building a Biometric Compliance Program
- Running a Data Breach Response
- Building a Privacy Compliance Program for a Consumer Brand
- Negotiating a Technology Agreement
Checklists
- Biometric Data Checklist
- Incident Response Checklist
- Marketing Privacy Compliance Checklist
- Technology Agreement Checklist
Toolkits
- Incident Response and Breach Notification Toolkit
- Privacy and Marketing Data Toolkit
- Technology Contracts Toolkit
- Digital Replica and Synthetic Media Toolkit
Templates & Forms
This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Biometric compliance turns on specific systems, records, and state statutes. Marksy is not a law firm.