regulatory updates
Washington Biometric Privacy Law: Two Statutes, Two Jobs
Washington has two biometric laws, and most explainers blur them. What RCW 19.375 requires, what My Health My Data adds, and who can sue.
Key Takeaways
- •Washington runs two biometric statutes: RCW 19.375 for commercial enrollment, and the My Health My Data Act, which treats biometric data as consumer health data with opt-in consent.
- •RCW 19.375 has no fixed destruction deadline and no private right of action. Only the Attorney General enforces it, through the Consumer Protection Act, at up to $7,500 per violation.
- •The Attorney General's first Data Privacy Report, released August 14, 2026, asks the Legislature for consent rules and retention limits for biometric data. RCW 19.375 has neither.
Washington has two biometric privacy laws, and they do different jobs. RCW 19.375 (2017) covers commercial enrollment, and only the Attorney General can enforce it. My Health My Data (2023) lets consumers sue.
Page one of search blurs the two, which is how health data rules end up in fingerprint time clock policies. Here are the two laws kept apart, with the statute text where it matters.
This is an explainer, not legal advice. Have Washington counsel verify anything you build on it.
Washington's two biometric laws, and which one applies to you
RCW 19.375 is the biometric identifiers law, passed as H.B. 1493 and signed May 16, 2017. It governs enrolling biometric identifiers in a database for a commercial purpose.
The My Health My Data Act, chapter 19.373 RCW, was signed April 27, 2023 (both dates per the Attorney General's 2026 Data Privacy Report). Most of its duties apply beginning March 31, 2024, and June 30, 2024, for small businesses (RCW 19.373.020 through .070). It regulates consumer health data, and its list of what counts includes "biometric data" by name.
| RCW 19.375 (2017) | My Health My Data (RCW 19.373) | |
|---|---|---|
| Covers | Biometric identifiers enrolled for a commercial purpose | Consumer health data, including biometric data |
| Photos and video | Excluded from the definition | Face and iris imagery included, when a template can be extracted |
| Employees | Not excluded | Excluded ("employment context") |
| Consent model | Notice, consent, or an opt-out mechanism | Opt-in consent before collection |
| Retention | "Reasonably necessary," no deadline | No schedule; delete on request within 45 days, extendable once |
| Who enforces | Attorney General only | Attorney General, and consumers through CPA suits |
The photos row is the one that surprises people. The 2017 law draws its line in the definition itself:
"Biometric identifier" does not include a physical or digital photograph, video or audio recording or data generated therefrom, or information collected, used, or stored for health care treatment, payment, or operations under the federal health insurance portability and accountability act of 1996.
My Health My Data goes the other way. Its biometric data definition covers "Imagery of the iris, retina, fingerprint, face, hand, palm, vein patterns, and voice recordings, from which an identifier template can be extracted" (RCW 19.373.010(4)). The same camera above your register can sit outside the 2017 law and inside the 2023 one.
What RCW 19.375 actually covers
The statute regulates one event: enrollment. To enroll means to capture an identifier, convert it into a reference template that "cannot be reconstructed into the original output image," and store it in a database matched to a specific person (RCW 19.375.010(5)). A fingerprint time clock enrolls. A security camera that never builds a template does not.
The trigger is "commercial purpose," and the definition is narrower than the plain words:
"Commercial purpose" means a purpose in furtherance of the sale or disclosure to a third party of a biometric identifier for the purpose of marketing of goods or services when such goods or services are unrelated to the initial transaction in which a person first gains possession of an individual's biometric identifier. "Commercial purpose" does not include a security or law enforcement purpose.
Read it as a test. Is the identifier headed to a third party, for marketing, of something unrelated to why you took it? An attendance time clock meets almost none of that. Neither does a gym's fingerprint door.
Then subsection (7) of the operative section closes the door further: "Nothing in this section requires an entity to provide notice and obtain consent to collect, capture, or enroll a biometric identifier and store it in a biometric system, or otherwise, in furtherance of a security purpose." Security purpose is defined broadly, down to "protecting the security or integrity of software, accounts, applications, online services, or any person" (RCW 19.375.010(8)). A face-recognition login or a badge door reader can plausibly claim it.
The chapter also excludes, in RCW 19.375.040, financial institutions and affiliates subject to Title V of the Gramm-Leach-Bliley Act, and activities subject to HIPAA's privacy rules. Government agencies fall outside the definition of "person."
Notice and consent: what the statute actually says
Here is the core obligation, verbatim, because paraphrases keep making it stricter:
A person may not enroll a biometric identifier in a database for a commercial purpose, without first providing notice, obtaining consent, or providing a mechanism to prevent the subsequent use of a biometric identifier for a commercial purpose.
Read the "or" twice. Illinois demands written notice and a signed release, both, before collection. Washington offers three alternatives, and any one of them can satisfy the section. Then the statute makes the vagueness official:
The exact notice and type of consent required to achieve compliance with subsection (1) of this section is context-dependent.
Notice does not even count as affirmative consent; it only has to be "readily available to affected individuals." What does that mean for your enrollment flow? On September 25, 2026, I searched CourtListener's case-law archive for "RCW 19.375" and for each section number, 19.375.010 through .040. The only result was an unrelated 1992 Rhode Island decision. No published opinion tells you what "context-dependent" means.
One more rule binds you after enrollment: a new use "materially inconsistent" with the original terms needs fresh consent (RCW 19.375.020(5)).
My operational advice is to build to the stricter reading anyway: written notice and recorded affirmative consent, before enrollment. RCW 19.375 leaves that open. My Health My Data requires consent before collecting biometric data unless the collection is necessary for a service the consumer asked for (RCW 19.373.030), and its bar is explicit: consent is "a clear affirmative act that signifies a consumer's freely given, specific, informed, opt-in, voluntary, and unambiguous agreement" (RCW 19.373.010(6)). Meeting the higher bar once beats arguing later about which statute applied.
Selling and disclosure
After enrollment, RCW 19.375.020(3) bars selling, leasing, or otherwise disclosing the identifier for a commercial purpose without consent, unless the disclosure is:
- Necessary for a product or service the person subscribed to, requested, or authorized
- Necessary to complete a financial transaction the person requested or authorized
- Required or expressly authorized by a federal or state statute, or court order
- Made to a third party that contractually promises not to disclose it further
- Made to prepare for litigation or to respond to judicial process
The vendor trap from Illinois applies here unchanged. Your timekeeping provider, payroll processor, and cloud host all touch enrolled templates, and each disclosure has to sit inside consent or one of those exceptions. The fourth exception only works if the contract actually contains the promise, so read that clause before you sign.
Retention and destruction: there is no schedule
Illinois gives you a calendar: destroy when the purpose is satisfied, or three years after the last interaction, whichever comes first. Colorado sets a 24-month outer limit.
Washington gives you a sentence. A person holding an identifier enrolled for a commercial purpose must guard it with reasonable care, and:
May retain the biometric identifier no longer than is reasonably necessary to: (i) Comply with a court order, statute, or public records retention schedule specified under federal, state, or local law; (ii) Protect against or prevent actual or potential fraud, criminal activity, claims, security threats, or liability; and (iii) Provide the services for which the biometric identifier was enrolled.
No number of years. No named trigger. Note what clause (ii) allows: "claims" and "liability" are on the list, so a holder can argue a template stays necessary while a claim about it is still possible. That argument only holds if you can name the claim and the date it expires.
The practical answer is to write the schedule the statute declined to write. For every system holding a template, record the purpose it serves and the event that ends it: termination for attendance, account closure for login. A former customer's template still in a vendor's database two years after the account closed is the fact a regulator would ask you to explain.
This section may not stay vague. On August 14, 2026, the Attorney General released the office's first Data Privacy Report. Its call to action on biometric and location data asks the Legislature to:
Require clear, informed consent before companies collect biometric or precise geolocation data. Limit or prohibit the sale and unnecessary commercial use of biometric and precise geolocation data. Establish clear limits on how long biometric and precise geolocation data may be retained.
When the office with sole enforcement power over RCW 19.375 lists the rules it wants, read the list as a preview.
Who enforces it, and what an AG action costs
RCW 19.375.030 makes a violation an unfair or deceptive act under the Consumer Protection Act, then limits who can use that hook: "This chapter may be enforced solely by the attorney general under the consumer protection act, chapter 19.86 RCW." An employee enrolled without notice cannot sue under this chapter.
Before any lawsuit, the Attorney General's tool is a civil investigative demand (RCW 19.86.110). Each demand must describe "the class or classes of documentary material to be produced" and set a return date. Read against RCW 19.375, the classes follow from the statute: the notice, the consent or opt-out mechanism, the disclosure contracts, and the reason each template is still held.
The Consumer Protection Act supplies the price. The Attorney General can seek an injunction, restitution, and, if the state prevails, its costs and a reasonable attorney's fee (RCW 19.86.080). On top of that comes a civil penalty of "not more than $7,500 for each violation" (RCW 19.86.140). Per violation, across every enrolled person, adds up.
AG-only enforcement can still carry large stakes. Texas has the same structure under CUBI, and on July 30, 2024 its Attorney General announced a $1.4 billion settlement with Meta, "the largest ever obtained from an action brought by a single State" (Texas Attorney General press release).
Do you have to consent to biometrics in Washington?
For workers, the honest answer is uncomfortable. RCW 19.375 gives you no lawsuit if consent was skipped, and it may not require your consent at all for attendance or security uses. My Health My Data excludes "an individual acting in an employment context" from its definition of consumer (RCW 19.373.010(7)). Neither statute, read plainly, gives an employee a right to refuse a time clock; ask counsel about your facts.
For customers, the answer changes. My Health My Data routes violations through the same Consumer Protection Act, with no solely-the-AG clause:
A violation of this chapter is not reasonable in relation to the development and preservation of business, and is an unfair or deceptive act in trade or commerce and an unfair method of competition for the purpose of applying the consumer protection act, chapter 19.86 RCW.
That opens the Consumer Protection Act's private suit: a person injured in business or property can recover actual damages, costs, and a reasonable attorney's fee, with any increased award capped at $25,000 (RCW 19.86.090). Plaintiffs have used it. Maxwell v. Amazon.com, Inc., No. 2:25-cv-00261 (W.D. Wash.), filed February 10, 2025, pleaded an MHMD count; the plaintiff voluntarily dismissed it on May 29, 2025, before any ruling.
So your fingerprint time clock probably lives under the quiet statute. A face-scanning kiosk or voice analytics aimed at the public can live under the one with a plaintiff attached.
How Washington compares to Illinois, Texas, and Colorado
| State | Consent required | Retention rule | Who can sue |
|---|---|---|---|
| Illinois, BIPA (740 ILCS 14) | Written notice and signed release, before collection | Purpose satisfied or 3 years after last interaction | The person: private right of action |
| Texas, CUBI (Tex. Bus. & Com. Code 503.001) | Notice and consent before capture | Destroy by the first anniversary of the purpose expiring | Attorney General only, up to $25,000 per violation |
| Washington (RCW 19.375) | Notice, consent, or opt-out mechanism | "Reasonably necessary," no deadline | Attorney General only |
| Washington (RCW 19.373) | Opt-in consent for consumer health data | Delete on request within 45 days | Attorney General and consumers |
| Colorado (C.R.S. 6-1-1314) | Notice of purpose and retention, then consent | Earliest of purpose met, 24 months after last interaction, or 45 days after a review finds it unneeded | Attorney General and district attorneys |
If you run Illinois too, start from the BIPA breakdown linked above; its duties are the strictest in the table.
What you would produce
Run the Washington test on your own operation. Pick one person enrolled in any of your biometric systems and ask: could you produce, in writing, by Friday, the notice they received, the consent or opt-out mechanism you relied on under RCW 19.375.020(1), and the reason their template is still reasonably necessary today?
That last item is the Washington-specific record. Illinois asks for a schedule; Washington asks for a reason, per template, that stays true over time. Here is an illustrative version of that retention rationale; the rows are examples, not any company's real systems:
| System | Who holds the template | Purpose at enrollment | End event | Deletion evidence |
|---|---|---|---|---|
| Time clock | Timekeeping vendor | Attendance for active employees | Termination date | Vendor deletion confirmation, dated |
| Door reader | Facilities system | Site access for badged staff | Badge deactivation | Access-system purge log |
| Voice login | Auth provider | Account authentication | Account closure | Provider deletion confirmation |
Fill it in for your own systems this week, one row per place a template lives. Once it exists, the statute's vaguest sentence has a dated answer, under either of Washington's two laws and under whatever the Attorney General's report turns into next.
Related Resources