Skip to content

Washington state enacts biometric privacy law requiring employee notice and written consent

US United States — US-WA Labour Code / Employment Law

Washington has enacted biometric privacy requirements that mandate employers provide notice before collecting biometric data (fingerprints, facial geometry, voiceprints, etc.) and obtain written consent from employees. The law also requires employers to restrict data use and disclosure, maintain confidentiality, and ensure proper data disposal. Employers must audit internal systems for biometric data collection (timekeeping, facial recognition, surveillance), implement compliant notice and consent procedures, and ensure third-party vendor compliance.

Washington state has enacted a biometric privacy law that mandates employers provide advance notice and obtain written consent before collecting biometric data from employees. The law also requires employers to restrict how biometric data is used and disclosed, maintain strict confidentiality, and ensure proper data disposal. The effective date has not yet been publicly specified; employers should monitor the Washington state legislature for the official implementation timeline.

Who is affected

All employers operating in Washington state that collect, store, or process biometric data from employees are subject to these requirements. This includes organizations of all sizes that use biometric systems for timekeeping, access control, surveillance, or identity verification purposes. Employers with remote or multi-state workforces must determine whether employees are located in Washington and apply the law accordingly.

What's changing

Employers must now implement the following practices before collecting any biometric data:

Requirement Details
Notice Employers must inform employees in advance that biometric data will be collected and explain the purpose of collection.
Written consent Employers must obtain signed, written consent from each employee before collecting biometric data.
Data restriction Biometric data may only be used for the stated purpose and cannot be disclosed to third parties without additional authorization.
Confidentiality Employers must implement safeguards to protect biometric data from unauthorized access or misuse.
Proper disposal Employers must establish procedures to securely delete or destroy biometric data when it is no longer needed.

Biometric data covered by the law includes fingerprints, retina scans, iris scans, voiceprints, hand scans, facial geometry, vein patterns, and other unique biological characteristics used for identification.

What NEO partners and clients should do

  • Audit all systems that collect biometric data, including fingerprint timekeeping systems, facial recognition software, voice authentication tools, video surveillance, and dash-camera footage.
  • Draft and implement compliant notice and consent procedures that clearly explain what biometric data will be collected, how it will be used, and how long it will be retained.
  • Review all third-party vendor agreements to ensure vendors collecting, storing, or processing employee biometric data comply with Washington's requirements.
  • Establish data disposal protocols to ensure biometric data is securely deleted or destroyed when no longer needed for the stated purpose.

NEO
Powered by NEO AI - Intelligent Matching Technology