Biometric Data Retention Is a Liability: The 2026 Case for Minimisation
Biometric data retention is the practice of storing facial templates, fingerprints or other physical identifiers after the verification that produced them has completed. Through 2026 the legal cost of that practice became considerably easier to quantify, and considerably harder to justify.
In late August, a federal judge certified a class of approximately 22,402 drivers in a biometric privacy action against a major transport operator. In a separate matter, a wrongfully arrested driver sought disclosure of 168 other individuals flagged by a venue's facial recognition system. In a third, an appellate court declined to certify a class over facial-analysis cameras, a reminder that outcomes vary while exposure does not.
The pattern across all three is the same. The liability attaches to holding the data, and it survives the business purpose that justified collecting it.
Key takeaways
- Statutory biometric privacy regimes assess damages per person, per violation, which makes class size the dominant variable.
- A certified class of 22,402 turns a compliance question into an existential one.
- Deployments produce disclosable operational records: a system that flagged 168 people created 168 discoverable events.
- Retention liability persists after the operational purpose ends and is not reduced by good security.
- The only control that reliably reduces exposure is not holding the data.
Why per-person statutory damages change the arithmetic
Most data protection regimes assess penalties against an organisation's turnover or the severity of a breach. Statutory biometric privacy regimes work differently: they assign a fixed sum per affected individual per violation, and in several cases they do not require proof of concrete harm.
The consequences are structural.
| Factor | Effect on exposure |
|---|---|
| Number of individuals enrolled | Directly multiplies liability |
| Number of separate violations per person | Multiplies again |
| Whether a breach occurred | Frequently irrelevant |
| Quality of the organisation's security | Frequently irrelevant |
That last row is the one most often misunderstood. An organisation that collected biometrics without the required notice and consent is exposed whether or not the data was ever at risk. Excellent encryption does not cure a consent defect. The violation is in the collection and retention, not in the outcome.
Class certification is therefore the decisive event. Before it, an organisation faces individual claims. After it, it faces the entire enrolled population as a single number.
The discovery surface nobody budgets for
The facial recognition disclosure dispute illustrates a second category of exposure that rarely appears in a deployment business case.
A recognition system generates records: every match, every alert, every action taken on the basis of one. When a single decision is challenged, those records become discoverable. A claimant seeking disclosure of the other individuals a system flagged is asking the operator to produce the full operational history of its deployment.
That history was never designed to be read by an adversarial party. It contains the false positive rate in practice rather than in the vendor datasheet, the pattern of who the system flagged, and the actions taken without independent verification.
Deploying biometric matching therefore creates two liabilities: the data, and the record of what was done with it.
Why "secure it better" is the wrong response
The instinctive response to biometric risk is stronger protection: encryption at rest, template hashing, access controls, shorter retention windows. All are worth doing. None addresses the underlying property.
A biometric cannot be reissued. When a password database is compromised, users rotate credentials and the exposure ends. When a biometric template database is compromised, the affected individuals carry that exposure permanently. There is no rotation.
This asymmetry means the risk-reduction curve for biometric retention flattens quickly. You can reduce breach probability substantially. You cannot reduce breach consequence at all, because the consequence is permanent by construction.
Which leaves one control with a genuinely different shape: hold less.
What minimisation looks like architecturally
Minimisation is often read as shorter retention. That helps, but it does not change the model. The structural version separates two things organisations habitually conflate.
Where verification happens. A qualified issuer performs the biometric verification once, under controlled conditions, with liveness and attack detection applied properly, and under an audit regime appropriate to holding that data.
What relying parties receive. Every subsequent party receives a cryptographic assertion about the verification, not the biometric. A zero-knowledge proof confirms the specific fact required, that a unique person is behind the account, that they are over a threshold age, that they passed verification at a stated assurance level, without transmitting the underlying data.
The exposure profile changes completely:
| Retention model | Credential model | |
|---|---|---|
| Parties holding biometrics | Every relying party | One qualified issuer |
| Class size if compromised | Full enrolled population, per party | Limited to the issuer |
| Statutory exposure for relying parties | Per person, per violation | Minimal, no biometric held |
| Discovery surface | Full operational history at each party | Verification records at the issuer |
A relying party cannot be sued for retaining data it never retained, and cannot leak what it never held.
AIR Identity is built on this separation. Verification is performed once by a qualified partner; relying partners confirm assertions through zero-knowledge proofs and never receive raw biometric or personal data. For organisations in fintech, travel and loyalty and gaming, where verified identity is operationally necessary but biometric custody is pure downside, that separation removes a liability without removing the capability.
Frequently asked questions
What is biometric data retention?
Biometric data retention is the storage of facial templates, fingerprints, iris scans, voiceprints or similar identifiers after the process that collected them has completed. Retention is the point at which most statutory biometric privacy obligations attach, covering notice, consent, disclosure limits and defined destruction schedules.
Why are biometric privacy class actions so expensive?
Because damages are assessed per person per violation and frequently do not require proof of harm. Once a class is certified, exposure scales directly with the number of people enrolled, so an organisation with tens of thousands of enrolled individuals faces a figure driven by class size rather than by any actual loss.
Does encrypting biometric data reduce legal liability?
It reduces breach probability, not statutory liability. Most biometric privacy claims turn on whether required notice and consent were obtained and whether retention and destruction rules were followed. An organisation that failed those requirements is exposed regardless of how well the data was protected.
How can a business verify identity without storing biometrics?
By separating verification from reliance. A qualified issuer performs the biometric verification once and issues a credential. Relying parties then confirm the assertion cryptographically, using a zero-knowledge proof, without receiving the biometric. The relying party gets the assurance and holds no biometric data.
What is a zero-knowledge proof in identity verification?
A zero-knowledge proof is a cryptographic method that lets one party prove a statement is true without revealing the information that makes it true. In identity, it allows a service to confirm that a user is over eighteen, is a unique person, or passed verification at a given assurance level, while learning nothing else about them.
Related reading
- Why biometrics alone are no longer enough
- Reusable KYC in emerging markets
- Proof of human: bot detection at the login layer
More from AIR: AIR Identity, travel and loyalty, or browse the full AIR blog.
Holding biometric data you do not need to hold? See how AIR Identity delivers verified assurance without transferring raw personal data, or read the developer documentation.




.png)