Skip to content

Privacy, de-identification and sensitive data

Biometric data in AI training datasets: BIPA, Texas CUBI and Washington rules for buyers

Quick answer

A face or voice dataset becomes a biometric dataset when someone extracts, or can be said to have extracted, face geometry or a voiceprint from it. Illinois BIPA reaches anyone who obtains that data, requires a prior written release and carries a private right of action. Texas CUBI and Washington's RCW 19.375 are enforced by the attorney general and have narrower scopes: Texas now exempts most AI training, and Washington excludes photos and recordings. Buyers should confirm which identifiers exist, where subjects live, and what consent evidence the supplier holds.

By SourceX Editorial · Updated

This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.

When images, video and audio count as biometric identifiers

Raw media is usually not the trigger; the measurement taken from it is. BIPA Section 10 defines a biometric identifier as a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry, and expressly excludes photographs, while "biometric information" covers anything based on an identifier that is used to identify a person [1]. Texas uses nearly the same list, describing a "record of hand or face geometry" [3].

Washington's definition is narrower. RCW 19.375.010 defines a biometric identifier as data generated by automatic measurements of biological characteristics used to identify a specific individual, and states that the term does not include a physical or digital photograph, video or audio recording, or data generated from them [10]. Photo, video and audio datasets may therefore fall outside RCW 19.375 entirely, but they may still be biometric data under Washington's My Health My Data Act [4].

In Illinois and Texas, plaintiffs argue that a face-detection, face-embedding or speaker-verification pass over a dataset is the scan. The risk question is not "does the dataset have faces" but "has anyone in the chain run, or will we run, a model that computes face landmarks, ArcFace-style embeddings, x-vectors or speaker embeddings tied to individuals." Your own training pipeline can create the biometric data even if the supplier never did.

Signals that a dataset already contains biometric data:

  • Columns or sidecar files named face_embedding, landmarks_68, speaker_id with enrollment vectors, voiceprint_hash, or iris/fingerprint templates.
  • Annotation exports (COCO keypoints, dlib landmarks, diarization RTTM with persistent cross-file speaker IDs) that link geometry or voice features to a named or persistent person.
  • Collection apps that performed face matching, liveness checks or voice login at capture time.

How BIPA, Texas CUBI and Washington RCW 19.375 differ for a dataset buyer

The three statutes share a definition core but differ sharply on scope, who can sue and what consent looks like. BIPA drives litigation because Section 20 gives a private right of action with liquidated damages of $1,000 per negligent and $5,000 per intentional or reckless violation [1].

Question a buyer asksIllinois BIPA (740 ILCS 14)Texas CUBI (Bus. & Com. Code 503.001)Washington (RCW 19.375)
Photos, video, audioPhotographs excluded; geometry or voiceprints derived from them can be covered [1]Records of face geometry and voiceprints covered [3]Photos, video and audio recordings and data generated from them excluded; may instead be MHMDA biometric data [10][4]
Covered actCollect, capture, purchase, receive through trade or otherwise obtain [1]Capture for a commercial purpose [3]Enroll in a database for a commercial purpose [10]
AI trainingNo AI-specific exemption [1]Exempt for developing, training or evaluating AI unless the system is used to uniquely identify individuals [3][11]No AI-specific provision [10]
Consent formInformed written release after written notice of purpose and term; electronic signature accepted after the 2024 amendment [1][2]Inform before capture and receive consent; public online images alone are not consent [3][11]Notice plus consent, or a mechanism to prevent later commercial use [10]
Sale or profitNo sale, lease, trade or other profit from the data [1]Sale, lease and disclosure limited to listed exceptions [3]Sale, lease or disclosure for a commercial purpose limited without consent [10]
RetentionPublic written retention schedule; destroy when the purpose is met or within 3 years of last interaction, whichever is first [1]Destroy within a reasonable time, no later than one year after the purpose expires [3]Keep no longer than reasonably necessary [10]
Who enforcesPrivate plaintiffs, often class actions [1]Texas attorney general; civil penalty up to $25,000 per violation [3]Attorney general under the Consumer Protection Act; no private right of action [10]
Damages countingRepeated collection from the same person by the same method is one violation [2]Per violation [3]Consumer Protection Act remedies [10]

Two points matter as of October 2026. The Texas text effective January 1, 2026, as amended by HB 149, says a person is not informed and has not consented merely because an image or other media containing the identifier is publicly available online, unless the individual made it public; it also says Section 503.001 does not apply to training, processing or storing biometric identifiers to develop, train, evaluate or offer AI models or systems, unless the system is used to uniquely identify a specific individual [3][11]. If identifiers captured for training are later used for another commercial purpose, the possession and destruction duties and penalties apply again [11].

In Washington, biometric data is also "consumer health data" under the My Health My Data Act, which has its own consent and privacy-policy duties and is enforced through the Consumer Protection Act, including by private suits [4]. Because RCW 19.375 excludes recordings [10], the MHMDA, not RCW 19.375, is usually the Washington statute to analyze for face and voice media.

Why dataset users, not only collectors, end up as defendants

BIPA's verbs include "purchase" and "otherwise obtain," so a downstream licensee is a natural defendant. The IBM Diversity in Faces litigation, brought over a face dataset assembled for AI fairness research from public photos, was narrowed but allowed to proceed in part [6]. Google settled a separate BIPA suit over a facial recognition dataset [7]. Where servers and subjects sit outside Illinois, extraterritoriality is a contested defense, not a safe harbor.

The exposure is now moving to audio. In May 2026, journalists, podcasters and voice actors filed suits in the Northern District of Illinois alleging their voices were used to train AI models without consent [8]. Law-firm commentary reads these filings as a signal that biometric privacy claims will follow training pipelines, not just consumer-facing face recognition [9]. None of these voice claims had been decided on the merits as of October 2026, and this page does not predict outcomes. For speech-specific analysis, see voiceprint risk in licensed voice datasets.

Evidence to request before licensing face or voice data

Ask for documents that prove each statutory element, not a representation that the data is "compliant." A supplier warranty helps allocate risk, but it does not stop a class action from being filed against the licensee. The checklist below maps each request to the rule it answers.

Illustrative example: invented to show structure; it does not describe an available dataset.

Biometric screening checklist (buyer due diligence)

#RequestAnswersRed flag
1Data map: which files contain faces, voices, hands, gait; which fields hold embeddings or templatesIs there a biometric identifier at all [1][3][10]Supplier cannot say whether embeddings were generated
2Subject residency breakdown (IL, TX, WA, other) and how it was determinedWhich statute applies"Global crowd" with no location field
3Signed release template plus a sample of executed releases with timestampsBIPA written release; CUBI consent [1][2][3]Clickwrap terms that never mention biometric data or AI training
4Release text naming purpose (model training), recipients (licensees) and termBIPA notice of purpose and length of term [1]Purpose limited to "service improvement" or the original app
5Public retention and destruction schedule and destruction logsBIPA Sec. 15(a); CUBI destruction; RCW 19.375 retention for any enrolled templates [1][3][10]No schedule, or a schedule that ends before your license term
6Consent to disclosure to third parties, and the supplier's theory for why a license fee is not "profit"BIPA Sec. 15(c)-(d) [1]Silence on the profit prohibition
7Proof that no biometric extraction occurred, if that is the claim (pipeline config, absence of embedding fields)Whether any identifier was ever createdFace detection run "only for blurring" with stored landmarks
8Withdrawal and deletion mechanism that reaches licensees; MHMDA consent for Washington subjectsRCW 19.375 consent or opt-out mechanism; MHMDA consent [10][4]No way to propagate a deletion request
9Any health context (clinical audio, patient video) and its HIPAA statusSafe Harbor and limited data set exclusions cover biometric identifiers [5]Health recordings labeled "de-identified" with voices intact
10Written statement of the model's purpose for Texas subjects: will it identify, verify or match individuals, and will captured identifiers be reused commerciallyTexas AI exemption applies only if the system is not used to uniquely identify individuals [3][11]Recognition or speaker-verification use relying on the training exemption; consent inferred from public web images

Use the general de-identification evidence package checklist for method documentation, and the face data consent and anonymization guide for release wording on image and video projects. If you would rather describe the face or voice data you need to SourceX, include the subject residency and model purpose from rows 2 and 10.

Removing faces and voices when identity is not the training signal

If the model does not need to recognize or verify individuals, the cleanest control is to remove the biometric surface before delivery. For video, that means face and body blurring or replacement, masking reflections and screens, and stripping audio or converting it to text; the video anonymization guide covers bystanders and on-screen text. For speech, voice conversion or re-synthesis can remove the speaker's voiceprint while keeping lexical content, at a measurable cost to acoustic fidelity.

Anonymization has its own failure modes that a buyer should test on a sample:

  • Detector misses: profile faces, small faces, occluded faces and dark-skin false negatives leave unblurred frames; ask for recall measured on a labeled hold-out.
  • Residual voice: pitch shifting alone often preserves speaker identity; ask for a speaker-verification equal error rate before and after conversion.
  • Sidecar leakage: landmarks or embeddings computed to guide blurring may persist in metadata or intermediate buckets.
  • Cross-modal linkage: a blurred face plus an unaltered voice and a name tag still identifies the person; see multimodal de-identification.

When identity is the signal (face recognition, speaker verification, liveness), anonymization is not available, and Texas's AI training exemption does not apply to a system used to uniquely identify individuals [11]. The route is purpose-specific written consent from each subject that satisfies BIPA's written-release rule and CUBI's pre-capture notice [1][3]. For Washington subjects, check MHMDA consent for biometric data, and RCW 19.375 enrollment consent if templates are created by means other than photos or recordings [4][10].

License terms that allocate biometric risk

The license should restate the consent scope and bind the buyer's own pipeline. Useful clauses include a representation that releases cover training by the named licensee, a prohibition on deriving face or voice templates unless the release covers it, a retention end date no later than the supplier's published schedule, deletion propagation within a defined window, and an indemnity sized to statutory damages exposure rather than the license fee. Pair these with a re-identification prohibition clause so downstream teams do not reverse anonymization.

For the Illinois statute's supplier-side mechanics, SourceX's Illinois BIPA overview summarizes the law; the privacy and de-identification hub collects related buyer guides.

Sourcing face, voice or video data for AI training

SourceX sources operational datasets from US companies on request, including new recordings of hands-on work, and does not source scraped web content or generic CCTV or photos. Every dataset is rights-reviewed for ownership and consents, personal details are removed or replaced before delivery with the method recorded, and nothing is contracted until the supplying company agrees. Describe the modalities and whether identity matters to the model, and start a buyer request at SourceX; a request does not guarantee a match.

Sources

  1. Illinois General Assembly, "Biometric Information Privacy Act (740 ILCS 14/)". https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004
  2. Illinois General Assembly, "SB 2979 (103rd General Assembly), BIPA amendment, engrossed text" (2024). https://www.ilga.gov/documents/legislation/103/SB/PDF/10300SB2979eng.pdf
  3. Texas Legislature, "Texas Business and Commerce Code Chapter 503, Section 503.001 - Capture or Use of Biometric Identifier" (2026). https://statutes.capitol.texas.gov/Docs/BC/htm/BC.503.htm
  4. Washington State Legislature, "Chapter 19.373 RCW - Washington My Health My Data Act". https://app.leg.wa.gov/RCW/default.aspx?cite=19.373&full=true
  5. eCFR, Office of the Federal Register / HHS, "45 CFR 164.514 - Other requirements relating to uses and disclosures of protected health information" (2026). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514
  6. Bloomberg Law, "IBM Trims Privacy Lawsuit Over Its Diversity in Faces Dataset". https://news.bloomberglaw.com/ip-law/ibm-trims-privacy-lawsuit-over-its-diversity-in-faces-dataset
  7. CADE Project, "Google settles biometric privacy lawsuit over facial recognition dataset". https://cadeproject.org/?p=152064
  8. Chicago Sun-Times, "Tech giants sued over 'stealing' voices of well-known journalists, voice actors to train AI" (2026). https://chicago.suntimes.com/technology/2026/05/19/tech-giants-sued-over-stealing-voices-of-well-known-journalists-voice-actors-to-train-ai
  9. Perkins Coie, "New Biometrics Lawsuits Signal Potential Legal Risks for AI". https://perkinscoie.com/insights/update/new-biometrics-lawsuits-signal-potential-legal-risks-ai
  10. Washington State Legislature, "Chapter 19.375 RCW - Biometric identifiers". https://lawfilesext.leg.wa.gov/Law/RCW/RCW%20%2019%20%20TITLE/RCW%20%2019%20.375%20%20CHAPTER/RCW%20%2019%20.375%20%20CHAPTER.htm
  11. Texas Legislature, "H.B. No. 149 (89th Legislature), Texas Responsible Artificial Intelligence Governance Act, enrolled text" (2025). https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.htm

Tell us what your models need

Share scope, volume, language, format, timing and licensing requirements.

Request data