Nexa Sight guide

Is face recognition access control legal?

Usually yes, and rarely without conditions. Face recognition creates biometric data, which sits in a stricter category than ordinary CCTV in most jurisdictions, and the conditions attached are about consent, retention and disclosure rather than about the technology. This is an orientation to what the rules ask for, not legal advice: the specifics depend on where you operate and who is in frame, and both need your own counsel.

Why is this different from ordinary CCTV?

Because a camera recording a corridor captures an image, while face recognition creates a biometric identifier, a mathematical template unique to a person. Most privacy regimes treat that template as a special category of data requiring a stronger legal basis than general video surveillance.

The practical consequence is that the compliance work sits around the system rather than inside it. Notice, consent, how long templates are kept, who can access them, and what happens when someone asks for theirs to be deleted. None of that is a technical capability question, which is why buyers who evaluate only on accuracy tend to stall late.

It also means the answer varies more by geography than most software decisions. The same deployment can be straightforward in one jurisdiction and require written consent per person in another.

What do the main regimes require?

Broad strokes, and the detail matters more than the summary.

WhereWhat it turns onPractical effect
Illinois (BIPA)Written consent before collection, plus a published retention schedulePrivate right of action with statutory damages, 1,000 USD for negligent and 5,000 USD for reckless or intentional violations. Since the 2024 amendment, repeated collection of the same identifier from the same person by the same method counts once rather than per scan.
Texas (CUBI), WashingtonConsent and retention limits, enforced by the stateNo private lawsuits, but state enforcement carries the largest numbers in US biometric law: the Texas Attorney General settled with Meta for 1.4 billion USD in July 2024 and with Google for 1.375 billion USD in May 2025.
Other US statesVaries; several have biometric provisions inside broader privacy lawsAssume nothing transfers from one state to another.
EU and UK (GDPR)Biometrics for identification are special category dataNeeds an Article 9 condition, usually explicit consent, plus a data protection impact assessment.
EU AI ActWhether the system verifies a claimed identity 1:1 or identifies people 1:N against an enrolled databaseVerification whose sole purpose is confirming someone is who they claim to be, which Recital 17 and Annex III point 1(a) illustrate with security access to premises, is outside the high-risk category. Identification against a database is high-risk, and some remote uses in public spaces are prohibited outright. The Annex III obligations were deferred from 2 August 2026 to 2 December 2027 by Regulation (EU) 2026/1744, the Digital Omnibus on AI.

Does employee consent count?

It is the sharpest question in workplace deployments, and the honest answer is that consent from an employee is weaker than consent from a member of the public. Regulators in the EU and UK have repeatedly held that an employment relationship is imbalanced enough that consent may not be freely given, so relying on it alone is fragile.

That does not make workplace face recognition impossible. It usually means the deployment needs to rest on something other than consent, with a genuine alternative for anyone who declines, a documented assessment of why a less intrusive method would not achieve the same purpose, and access limited to people who need it.

The pattern that survives scrutiny is offering a real alternative. If someone can badge in instead and nothing about their employment changes as a result, the argument is far stronger than if declining means they cannot work.

What does a compliant deployment look like in practice?

Notice before the camera, not after. Signage at every entrance to a monitored area, plainly stating that face recognition is in use, what it is for and who to contact. This is the cheapest control available and its absence is the first thing an investigation finds.

A retention schedule you actually enforce. Templates and event logs need a defined lifetime and automated deletion. Keeping everything indefinitely is the default behaviour of most systems and the most common finding against them.

Access control on the system itself. Who can see the log, who can enrol a person, who can export. An audit trail of those actions matters as much as the recognition log, because the question after an incident is who looked, not only who was seen.

And a route for individuals: how someone asks what is held about them, and how it is deleted. If that process does not exist before launch it gets invented under time pressure during a complaint.

Does it help if video never leaves the site?

Substantially, and it is the single most useful architectural decision available. An on-premise deployment where footage and templates stay inside the local network removes the international transfer question, narrows the number of parties involved, and makes the answer to "who else can see this" a short one.

It does not remove the consent, notice or retention obligations. Those attach to the processing, not the location, and a common misreading is that keeping data on site means the rest does not apply.

Where it changes the conversation most is procurement. A buyer whose own contracts forbid sub-processors, which is normal in defence, critical infrastructure and parts of the public sector, can often only proceed with an on-premise deployment, and asking early avoids discovering that after a pilot.

What should you ask before deploying?

Which jurisdictions are the people in frame in, since that determines the regime rather than where your company is registered. Whether the purpose could be achieved by something less intrusive, because that assessment will be requested and it is better to have done it. Where templates are stored, for how long, and who can access them. What the alternative is for someone who declines. And who owns the process when an individual asks for their data.

Then put those answers to counsel in the relevant jurisdiction rather than to a vendor. Any supplier telling you a deployment is definitely compliant, without knowing where your staff are or what your purpose is, is not in a position to say so, and that includes us.

Common questions

Is face recognition legal for workplace access control?
In most jurisdictions yes, subject to conditions on notice, consent and retention, because biometric templates are treated as a stricter category of data than ordinary CCTV. The conditions vary considerably by location, and Illinois in particular carries a private right of action with statutory damages attached. This is orientation rather than legal advice; the specifics need counsel in the jurisdictions your staff are in.
Do we need employee consent for face recognition at work?
Consent is usually necessary but is treated as weaker in an employment context, because regulators have held that the imbalance in the relationship means it may not be freely given. Deployments that survive scrutiny normally offer a genuine alternative such as badge entry, with no consequence for choosing it, alongside a documented assessment of why a less intrusive method would not serve the same purpose.
How long can biometric templates be kept?
Only as long as the stated purpose requires, with the retention period published and enforced automatically rather than by policy alone. Indefinite retention is the default behaviour of most systems and the most common finding against them. Illinois requires a published retention schedule and destruction guidelines specifically.
Does keeping video on site make it compliant?
It helps considerably and does not make it compliant by itself. An on-premise deployment removes international transfer questions and reduces the number of parties with access, which matters for buyers whose own contracts forbid sub-processors. Consent, notice and retention obligations attach to the processing rather than to the location, so they still apply.
What is BIPA and why does it matter?
The Illinois Biometric Information Privacy Act, which requires written consent before collecting biometric identifiers and a published retention schedule. It matters disproportionately because it grants individuals a private right of action, with statutory damages of 1,000 USD for negligent violations and 5,000 USD for reckless or intentional ones, which is why most US biometric class actions are filed there. The largest payouts are not Illinois ones, though: the biggest BIPA settlement is the 650 million USD Facebook class action approved in February 2021, while Texas obtained 1.4 billion USD from Meta in July 2024 and 1.375 billion USD from Google in May 2025 through Attorney General actions under CUBI. An amendment in August 2024 limited the arithmetic considerably: repeated collection of the same identifier from the same person by the same method now counts as one violation rather than one per scan, and the Seventh Circuit has held that change applies to cases already pending. Illinois remains the most litigated jurisdiction to deploy in.

Let’s create something out of this world together.

Have a project in mind? Contact us for expert design and development solutions. Let’s discuss how we can help grow your business.

Azaadi Offer

Claim a free security assessment

Until 31 August we're covering the cost of a full vulnerability assessment and penetration test. Mention it in your message and we'll scope it with you.

  • Web application testing, authenticated and unauthenticated
  • Mobile application testing across iOS and Android
  • External network and infrastructure assessment
  • Manual exploitation by engineers, not scanner output

Testing and the report are free. Fixing what we find is quoted separately, with no obligation to accept.

Read the full offer

Tell us what you are trying to build and we will tell you plainly whether we are the right people for it. Book a call with an expert to work through the detail, or ask for a fixed quote if the scope is already clear. No obligation either way.

Four fields is all we need to get started.

Fastnexa Logo

© 2026 fastnexa. All rights reserved.