Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Biometrics Privacy Law Takes Effect in NYC

By Elizabeth Smith on July 13, 2021
Email this postTweet this postLike this postShare this post on LinkedIn

Last week a new privacy law limiting what businesses can do with biometric data (for example, facial recognition information and fingerprints) took effect in New York City. The new ordinance requires commercial establishments that collect biometric information to post notices to customers explaining how their data will be used. The law applies to a wide range of businesses, including stores, restaurants, and theaters. The ordinance defines “biometric identifier information” as any “physiological or biological characteristic that is used by or on behalf of a commercial establishment, singly or in combination, to identify, or assist in identifying, an individual, including, but not limited to: (i) a retina or iris scan, (ii) a fingerprint or voiceprint, (iii) a scan of hand or face geometry, or any other identifying characteristic.” The law does, however, permit the collection, use, and retention of biometric identifying data if a notice to customers in “plain, simple language” is clearly displayed. The NYC Commissioner of Consumer and Worker Protection is expected to issue further guidance detailing the exact requirements that businesses must follow to comply with the law.

The law does not apply to biometric data collected from employees of these businesses. In enacting this law, New York follows in the footsteps of Portland, Oregon, which enacted a facial recognition ordinance last year. With the rapidly increasing use of facial recognition and similar technologies, similar laws are expected to continue cropping up in cities and states around the country. The definition of “biometric information” varies from state to state and is constantly evolving as new technologies emerge. Companies that collect and/or use any information about their customers or employees are advised to monitor developments in their city and state to ensure compliance with the ever-changing landscape of data protection laws.

A more fulsome analysis by Perkins Coie attorneys Sunita Bali, Debra R. Bernard, Samantha V. Ettari, Susan Fahringer, Nicola Menaldo, Adam H. Schuman, and Ryan Spear is available here.

  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Perkins on Privacy
  • Organization:
    Perkins Coie LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo