Establishes the biometric identifier privacy act, requiring private entities to develop policies for retaining and destroying biometric data.
The Biometric Identifier Privacy Act mandates that private entities in possession of biometric identifiers or biometric information must create a written policy outlining a retention schedule and guidelines for destroying such data. This destruction must occur when the initial purpose for collecting or obtaining the data has been fulfilled or within three years of the individual's last interaction with the entity, whichever is sooner.
Included in complete analysis
- Overview
- Core Provisions
- Implementation
- Impact
- Legal Framework
- Critical Issues
See what it does, who it affects, and the critical issues in plain language. Free, 30 seconds.