Biometric Data Collection at Work in Texas: Your Rights
Last reviewed: July 2026
Quick Answer
Texas does not have a specific biometric privacy law, but employers can collect biometric data subject to federal privacy laws and data security requirements. Under the Texas Identity Theft Enforcement and Protection Act (Texas Business & Commerce Code § 521.053), employers must protect biometric data and notify employees within 30 days of a breach. Federal law, including the Americans with Disabilities Act and FCRA, may restrict how employers use biometric data, particularly for hiring decisions or in regulated industries like financial services.
Key Facts
- •Texas does not have a comprehensive state biometric privacy law comparable to Illinois or California.
- •Employers may collect biometric data but must comply with federal privacy laws and the Texas Identity Theft Enforcement and Protection Act.
- •No explicit written consent requirement exists under Texas law for biometric collection.
- •Employers must safeguard biometric data and notify employees of any breaches within 30 days under Texas law.
Federal Law: The Baseline
Federal law does not provide comprehensive biometric privacy protection across all employers. However, several federal statutes restrict biometric data collection and use. The Americans with Disabilities Act (42 U.S.C. § 12112) prohibits employers from collecting genetic information, medical information, or protected health information through biometric means without a legitimate business reason related to the job. The Fair Credit Reporting Act (15 U.S.C. § 1681) applies when biometric data is used for employment decisions through third parties; employers must comply with disclosure, consent, and adverse action notice requirements.
The Gramm-Leach-Bliley Act (15 U.S.C. § 6801) applies to financial institutions and requires safeguards for sensitive personal information, including biometric identifiers. The Health Insurance Portability and Accountability Act (HIPAA) restricts healthcare employers from using biometric data for genetic information purposes. The Federal Trade Commission enforces standards requiring biometric data collection to be reasonable, proportional, and secure. Enforcement occurs through the EEOC (for discrimination claims), the FTC (for unfair or deceptive practices), and the Department of Labor (for specific regulated industries). Employees can bring private lawsuits under some federal statutes for violations, though remedies vary by statute.
Texas Law: What's Different
Texas does not have a dedicated biometric privacy statute comparable to the Illinois Biometric Information Privacy Act (740 ILCS 14/1) or the California Consumer Privacy Act (CCPA). This creates a significant gap in state-level protection for Texas employees. However, Texas law does restrict biometric collection in specific contexts and requires data security compliance.
Under Texas Labor Code § 52.006, employers are prohibited from requiring employees to submit to polygraph tests (a form of biometric collection) except in limited circumstances. This statute reflects early Texas policy against involuntary biometric screening. Additionally, Texas Business & Commerce Code § 521.053 requires any person or business, including employers, that collects personal information to implement and maintain reasonable security measures. Biometric identifiers—defined as fingerprints, voiceprints, iris recognition, or other unique biological or behavioral characteristics—are explicitly mentioned as personal information triggering breach notification duties.
Texas law does not explicitly require written consent before employers collect biometric data, unlike Illinois's Biometric Information Privacy Act, which mandates written notice and affirmative consent. However, employers are bound by federal privacy laws, particularly the ADA's restrictions on genetic and medical information collection. Texas employers must also comply with the Fair Credit Reporting Act when using third parties to collect biometric data for employment decisions; this requires pre-collection disclosure and consent. Breach notification is mandatory within 30 days, and employers must inform affected employees of the scope of the breach, the types of information affected, and recommended protective steps. Failure to notify breaches can result in civil liability and regulatory enforcement by the Texas Attorney General.
Key Numbers & Thresholds
Breach notification deadline: 30 days from discovery of unauthorized access (Texas Business & Commerce Code § 521.053). No employee size threshold for Texas biometric data security requirements—applies to all employers. No statutory cap on damages for failure to notify biaches; courts may award actual damages, court costs, and attorney's fees. Statute of limitations for identity theft and breach claims: up to 4 years from discovery (Texas Business & Commerce Code § 521.0001).
Exceptions & Special Cases
Texas law does not provide a blanket exception for employers to collect biometric data without restriction, but several important limitations and defenses apply. The Texas Labor Code § 52.006 exception to polygraph prohibition includes limited situations: employers may require testing in narrow contexts such as investigations into economic loss, where the employee had access to the item or information involved, and the employer has reasonable suspicion. This reflects the state's historical resistance to biometric screening.
Federal ADA defenses apply in Texas: employers may collect biometric data if it is job-related and consistent with business necessity. Routine security clearance biometrics for building access or time-clock fingerprints may qualify if applied uniformly. However, this defense is not unlimited; employers cannot use biometric data as a proxy for disability screening or genetic information gathering.
The Fair Credit Reporting Act creates an exception for employers using third-party biometric vendors, provided the employer complies with pre-collection disclosure and dispute procedures. If biometric data is collected by a third party on behalf of the employer, the employer is entitled to rely on the vendor's representations that they obtained proper consent, though the employer remains liable for violations.
Industry-specific exemptions exist for federally regulated employers in financial services (GLBA) and healthcare (HIPAA), where biometric collection is more tightly controlled. At-will employment status does not create an exception to biometric data security laws; even at-will employees retain privacy and data security rights. Union-represented employees may have additional protections through collective bargaining agreements that impose consent requirements beyond state law.
What to Do If Your Rights Are Violated
Step 1: Document the biometric data collection and use. Keep records of: (1) what biometric data was collected (fingerprints, iris scan, voice recognition, facial recognition), (2) when it was collected and by whom, (3) how it was stored and who had access, (4) whether the employer provided notice of collection, (5) any written consent forms or policies, and (6) the stated business purpose. Photograph or screenshot screens showing how the data is stored, accessed, or shared. Retain copies of employee handbooks, privacy policies, or consent documents provided (or not provided). Save emails or communications from HR about the collection purpose.
Step 2: Request an internal review and file a formal written complaint. Send a written complaint to your employer's Human Resources or Compliance department documenting: (1) the date(s) biometric data was collected, (2) your lack of prior written notice or consent (if applicable), (3) how the collection violated company policy or your understanding, and (4) any concerns about data security or unauthorized access. Request a written response within 14 days. If there has been a breach, ask the employer to confirm whether your biometric data was affected and demand written proof of notification compliance. Do not agree to informal resolution yet; preserve all written responses.
Step 3: Determine which agency to file with based on the violation type. If the issue is a data breach or security failure, file a complaint with the Texas Attorney General's Consumer Protection Division (website: texasattorneygeneral.gov; phone: 1-800-621-0508). If the employer violated ADA protections by collecting genetic or medical information through biometrics, file an EEOC charge within 180 days (federal filing deadline in Texas, which is a non-deferral state). Visit www.eeoc.gov, call 1-800-669-4000, or file in-person at the EEOC Houston District Office. If a third-party vendor collected the data and the employer failed to comply with Fair Credit Reporting Act requirements (pre-collection disclosure, dispute procedures), file a complaint with the Federal Trade Commission at reportidentitytheft.ftc.gov or call 1-877-438-4338.
Step 4: Understand the investigation process and timeline. For Texas Attorney General breach complaints, investigators will contact the employer to request documentation of their security practices, breach notification timeline, and data retention policies. This investigation typically takes 60–90 days. The AG may negotiate a settlement or refer the matter to civil enforcement. EEOC investigations take 6–18 months; investigators will interview you and the employer, request documents about collection practices, and determine whether a violation of the ADA or other federal law occurred. FTC investigations of FCRA violations are conducted by the agency's attorneys; resolution may result in civil settlement or referral to the Department of Justice. Do not expect a quick resolution; federal investigations move slowly but are thorough.
Step 5: Consult an employment attorney immediately if: (1) the employer has not responded to your internal complaint within 30 days, (2) you discover your biometric data was shared with third parties without consent, (3) a breach occurred and the employer did not notify you within 30 days, (4) the employer retaliated against you for raising biometric privacy concerns, or (5) you want to pursue a private lawsuit for damages. Contact an attorney licensed in Texas who specializes in employment law and privacy disputes. Many employment attorneys offer free initial consultations. If you cannot afford one, contact the State Bar of Texas Lawyer Referral Service (1-800-252-9690) or the Texas RioGrande Legal Aid office (1-888-529-5277) for low-cost representation. An attorney can help you evaluate whether you have claims under federal law (ADA, FCRA) or state law (breach notification statute), estimate potential damages, and negotiate a settlement.
Relevant Agency
Texas Attorney General - Consumer Protection Division
https://www.texasattorneygeneral.gov/consumer-protection1-800-621-0508
If you believe your employer violated your biometric privacy rights, consider consulting an employment attorney licensed in Texas to evaluate your claim and protect your interests.
Get notified when employment law changes
Laws change every year. We'll email you when something changes that affects this topic.
Frequently Asked Questions
Does my employer need my written consent before collecting my biometric data in Texas?
Texas does not have a specific biometric consent law like Illinois does. There is no explicit state requirement for written consent before employers collect fingerprints, iris scans, voiceprints, or facial recognition data. However, federal law may apply. Under the Americans with Disabilities Act, employers cannot collect genetic information or medical information through biometric means without a legitimate business reason. Additionally, if your employer uses a third-party vendor to collect biometric data for employment decisions, the Fair Credit Reporting Act requires pre-collection disclosure and your consent. Your employer's own policies may also require consent; review your employee handbook or privacy policy. If you were not given notice of biometric collection at hire or before collection occurred, consult an attorney to assess whether federal law was violated.
What happens if my employer suffers a data breach involving my biometric information?
Under Texas Business & Commerce Code § 521.053, your employer must notify you within 30 days of discovering a breach affecting your biometric data. The notification must include: (1) the type of biometric information affected, (2) what happened and when, (3) steps you should take to protect yourself, and (4) contact information for the employer and credit monitoring services if applicable. If the employer fails to notify you within 30 days, you may have a claim for actual damages under Texas law, including costs of identity monitoring, fraudulent charges, or attorney's fees. You can file a complaint with the Texas Attorney General's Consumer Protection Division (1-800-621-0508) or pursue a private lawsuit. If the breach was caused by inadequate security measures, you may argue the employer failed to maintain reasonable security as required by law.
Can my employer use facial recognition or fingerprint scanning to monitor me throughout the workday in Texas?
Texas does not prohibit employers from using facial recognition, fingerprint scanning, or other biometric monitoring methods during work hours. However, use is limited by federal law and reasonableness. Under the ADA, employers cannot use biometric monitoring to collect genetic information or to screen for disability-related conditions. Employers can use fingerprint or iris scanning for time and attendance tracking, building access control, or security purposes if the practice is applied uniformly to all employees and is job-related and consistent with business necessity. However, excessive monitoring—such as real-time facial recognition to track employee movements outside security areas—may expose the employer to privacy tort liability. Courts may recognize a tort claim for invasion of privacy if monitoring is highly intrusive and not justified by a legitimate employer interest. If you believe the monitoring exceeds reasonable workplace needs, consult an employment attorney about potential claims under Texas common law.
What should I do if my employer collects biometric data but I refuse to participate?
Your rights depend on the context and employer's policy. If biometric collection is mandatory for your job—such as fingerprint scanning for access to secure areas—refusal may be grounds for discipline or termination under Texas at-will employment doctrine. However, exceptions apply if the collection violates the ADA (e.g., collecting genetic information), discriminates based on a protected characteristic, or is used in a manner that violates federal law. If your employer's policy requires written consent and you were not provided one, refusing to participate protects your rights and may prevent liability for the employer's later misuse of your data. Document your refusal in writing to HR and retain a copy. If the employer disciplines you for refusing biometric collection after you invoked a legal protection, you may have a retaliation claim. Consult an employment attorney to evaluate your specific situation before resisting collection, as the outcome depends heavily on the employer's stated purpose and your rights under federal law.
Can my employer share my biometric data with third parties, such as a background check company or law enforcement?
Texas law does not prohibit employers from sharing biometric data with third parties, but federal law and data security duties apply. If your employer shares biometric data with a vendor for employment decisions (such as a background check company or identity verification service), the Fair Credit Reporting Act requires the employer to: (1) disclose this to you before the disclosure occurs, (2) obtain your written authorization, and (3) provide you with dispute rights if the vendor's report causes an adverse employment decision. The employer remains liable for the vendor's compliance with FCRA standards. Sharing with law enforcement requires a valid legal process (subpoena, warrant, or court order); absent that, the employer may violate privacy rights. Employers must also ensure any third-party vendor maintains reasonable security measures under Texas Business & Commerce Code § 521.053. Unauthorized sharing, or sharing without proper disclosure and consent, may expose the employer to civil liability. If your employer shared your biometric data without your knowledge or consent, file a complaint with the Federal Trade Commission (reportidentitytheft.ftc.gov) and consult an employment attorney about potential violations of your privacy rights.
Related Topics in Texas
Sources & References
- Texas Business & Commerce Code § 521.053 — Requires notification of security breaches affecting personal information including biometric identifiers
- Texas Labor Code § 52.006 — Prohibits employers from requiring lie detector tests; limits use of biometric screening
- Americans with Disabilities Act (42 U.S.C. § 12112) — Restricts collection of genetic information and medical information through biometric collection
- Gramm-Leach-Bliley Act (15 U.S.C. § 6801) — Applies to financial institutions collecting biometric data; requires safeguards and privacy notices
Informational only. Not legal advice. Laws change — always verify with a licensed attorney.
Editorial standards: This guide is reviewed against primary government sources and cites 4 statutes. Last reviewed July 2026. Scheduled for re-verification by July 2027.
See our editorial policy for how content is created and verified, or report an inaccuracy.