No biometric identifier as defined by BIPA, CUBI, GDPR, or CCPA is collected, stored, or transmitted
When no biometric data is collected, consent and notice requirements under biometric privacy statutes do not apply
No biometric data retained means no retention schedule, no destruction policy, no compliance calendar
Regulatory Compliance: BIPA, CUBI, GDPR, CCPA
Biometric privacy laws regulate the collection, storage, and use of biometric data. Safience does not collect, store, or use biometric data. The compliance analysis is straightforward: the statutes do not apply because the regulated activity does not occur.
Statute-by-Statute Analysis
The following analysis maps Safience's architecture against the key requirements of each major biometric privacy regulation. In each case, the analysis turns on a single architectural fact: Safience does not create, store, or retain biometric templates, biometric identifiers, or biometric information as those terms are defined in each statute.
BIPA: Illinois Biometric Information Privacy Act (740 ILCS 14)
BIPA regulates the collection, storage, and use of "biometric identifiers" (retina scans, fingerprints, voiceprints, hand scans, face geometry) and "biometric information" (information derived from biometric identifiers). Requires written consent before collection, a publicly available retention and destruction policy, and prohibits sale or disclosure. Private right of action with statutory damages: $1,000 per negligent violation, $5,000 per intentional or reckless violation.
RTIS does not create or store face geometry templates. A single still image is captured, compared, and (for non-matches) immediately destroyed. No "biometric identifier" as defined in Section 10 is collected or stored. No "biometric information" derived from a biometric identifier is retained. No consent mechanism is required for data that is not collected. No retention or destruction policy is required for data that does not exist. BIPA Section 15(b) notice and consent obligations are not triggered.
CUBI: State Biometric Privacy Laws (Texas CIPA, Washington WBPA, others)
Multiple states have enacted or are considering biometric privacy statutes modeled on or adjacent to BIPA. Texas CIPA (Tex. Bus. & Com. Code 503.001) prohibits capture of biometric identifiers for commercial purposes without consent. Washington WBPA (RCW 19.375) requires notice and consent for enrollment in a biometric system. Additional states (New York, Maryland, Colorado, others) have biometric provisions within broader privacy or consumer protection laws.
No biometric identifier is "captured" for storage or commercial use. The image is processed and destroyed. No "enrollment" in a biometric system occurs. Safience does not build an enrollment database of venue attendees. The same architectural analysis applies across all CUBI variants: no collection, no storage, no retention.
GDPR: General Data Protection Regulation (EU/EEA)
GDPR classifies biometric data as "special category" personal data (Article 9). Processing requires one of several lawful bases, typically explicit consent for biometric data. Requires a Data Protection Impact Assessment (DPIA) for large-scale processing of special-category data. Data subjects have rights to access, erasure, and portability.
No biometric data (as defined in GDPR Article 4(14): "personal data resulting from specific technical processing relating to physical, physiological or behavioural characteristics") is retained. A single image compared and immediately destroyed does not constitute "processing" of biometric data in the Article 9 sense where no template or biometric dataset is created or stored. DPIA obligations are significantly reduced when no special-category data is retained. Data subject access and erasure requests have a straightforward response: no biometric data exists to produce or delete.
CCPA/CPRA: California Consumer Privacy Act / California Privacy Rights Act
CCPA/CPRA classifies biometric information as "sensitive personal information" requiring additional protections. Consumers have the right to opt out of the sale or sharing of personal information and the right to limit the use of sensitive personal information.
No biometric information is collected or stored, so no "sensitive personal information" exists to regulate. No opt-out mechanism is required for data that is not collected. No right-to-delete request can apply to data that does not exist.
Request Compliance Documentation
We provide compliance support documentation including architecture summaries, data flow diagrams, and regulatory position papers for your legal team's review. Available under NDA.