Is Facial Recognition Legal? Your Biometric Privacy Rights Explained
Facial recognition law is a patchwork of state statutes, GDPR, and pending federal bills. Learn what the law says, your biometric privacy rights, and how to find and delete your face data.
Facial recognition law in the United States is a patchwork: there is no comprehensive federal biometric privacy statute, but strong state laws (led by Illinois's BIPA), the EU's GDPR and AI Act, and active proposals in the U.S. Senate govern how face data can be collected and used. If you want to protect your own biometric privacy, the practical move is to first find where your face already appears online with a reverse face search, then exercise your deletion rights.
This guide explains what the current facial-recognition legal landscape actually says, what rights you have today, and how to act on them.
What laws govern facial recognition? (overview)
Facial recognition is regulated through a mix of state statutes, international regulations, and pending federal bills:
Illinois BIPA — the state gold standard
The Illinois Biometric Information Privacy Act (BIPA) is the strongest biometric law in the U.S. It requires written consent before a private entity collects biometric identifiers and provides a private right of action. In *Cothron v. White Castle* (2023), the Illinois Supreme Court held each unauthorized scan is a separate violation. Texas (CUBI) and Washington (RCW 19.375) have their own biometric statutes.
The EU GDPR and AI Act
Under GDPR Article 9, biometric data used to identify a person is a special category requiring explicit consent or another lawful basis, and Article 17 grants a right to erasure. The EU AI Act, in force since 2024, classifies real-time biometric identification in public spaces as "unacceptable risk" and bans it with narrow law-enforcement exceptions.
U.S. federal proposals
There is no comprehensive federal biometric law yet. Bills like the American Data Privacy and Protection Act (ADPPA) have proposed nationwide standards, and the U.S. Government Accountability Office (GAO) has reported that numerous federal agencies use facial recognition without adequate privacy policies. The National Conference of State Legislatures (NCSL) tracks the 15+ states with biometric or privacy bills.
Surveillance vs. self-search — the key distinction
Most regulatory concern centers on mass surveillance: agencies or corporations scanning crowds or social media without consent. That is fundamentally different from an individual searching for *their own* face to protect their privacy.
"The difference between surveillance technology and privacy technology lies in who controls the search and what they can do with the results." — Electronic Frontier Foundation (EFF)
Reverse Face sits in the privacy-protection category: it's built for individuals searching for their own face, not for building biometric databases or conducting surveillance.
How to protect your biometric privacy — step by step
Step 1: Find where your face appears online
You can't control exposure you can't see. Run a reverse face search on yourself with Reverse Face to map where your face currently appears across the public web.
Step 2: Exercise your existing rights
- GDPR (EU) — request deletion of biometric data under Article 17.
- CCPA (California) — request disclosure and deletion of personal information.
- BIPA (Illinois) — companies must have your written consent before collecting biometric data.
- Other states — check the NCSL database for your state's law.
Step 3: Set up continuous monitoring
Continuous monitoring scans the web on a schedule and alerts you when your face appears on a new site.
Step 4: Support privacy legislation
Contact your representatives. The Electronic Privacy Information Center (EPIC) maintains a tracker of pending federal privacy legislation.
Frequently asked questions
Is facial recognition legal in the United States? There's no comprehensive federal ban or authorization. It's governed by a patchwork of state laws — Illinois BIPA, Texas CUBI, Washington RCW 19.375 — plus GDPR for anyone processing EU residents' data. Rules vary by state and by use.
Can I request that my face data be deleted? Yes, depending on jurisdiction. GDPR Article 17 (EU) and the CCPA (California) grant deletion rights, and BIPA (Illinois) requires consent before collection. Start by finding where your face appears, then submit deletion requests.
What's the difference between facial recognition surveillance and reverse face search? Surveillance scans many people without consent, controlled by an agency or company. A reverse face search is controlled by you, searching for your own face to audit and protect your privacy.
The bottom line
The regulatory landscape for facial recognition is shifting — but you don't have to wait for legislation to protect yourself. Find where your face appears with a reverse face search, exercise your GDPR, CCPA, and BIPA rights, and set up monitoring so you stay in control regardless of what happens on Capitol Hill.