us

216.73.217.32

Back
Blogs

Facial Recognition Laws Global: a country-by-country Compliance Guide

Facial Recognition Laws Global: a country-by-country Compliance Guide
Huma ZahraHuma Zahra JULY 1, 2026 16 minutes read

TL;DR

 

  • No country bans facial recognition outright, so the real question is which mode you run.
  • EU prohibitions applied from 2 February 2025; the penalties backing them, up to €35m or 7% of global turnover, applied from 2 August 2025.
  • High-risk EU duties slipped to 2 December 2027 under the Digital Omnibus on AI.
  • China’s dedicated facial recognition rules took effect on 1 June 2025.
  • Every regime now expects accuracy evidence across demographic groups, not just consent.

On 2 February 2025, the European Union’s prohibited-practices rules started to become more restrictive. On 1 June 2025, China’s dedicated facial recognition regulation came into force. The United States, meanwhile, still has no federal facial recognition statute, and by the end of 2024 only fifteen states had passed laws limiting police use of the technology.

This three-way split has become the reason why a singular global biometric policy no longer holds. A regulated business verifying customers across Europe, the United States, and East Asia is answering to three legal architectures at once, and the bans that make the headlines are rarely the provisions that trip it. The provision that trips it is quieter, because every serious regime has converged on one demand that most compliance files cannot satisfy.

Which facial recognition laws actually apply to your business?

Almost none of the headline prohibitions reach a commercial identity-verification flow. The laws that reach it are the general data protection statutes underneath, and they attach to how your face verification works rather than to what you call it.

What is the difference between 1:1 and 1:N face matching?

Facial recognition covers two different checks, and regulators treat them very differently.

A 1:1 check, also called verification, compares one live face against one stored photo. The person has already said who they are, by showing a passport or by logging in, and the system only confirms it. That is what happens at an e-passport gate and in most onboarding flows.

A 1:N check, which is also called identification, takes one face and searches it against a database of many photos to work out who the person is. Nobody has given a name first. That is what happens in surveillance, and it carries the strongest legal limits.

The difference decides which rules you read. Call your onboarding selfie check “facial recognition” in a data protection impact assessment, and you invite the regulator to test it against 1:N rules it never triggers. Run a real 1:N search across your customer database and record it as verification, and the mistake costs far more. Write the mode down before anything else, because biometric identification and facial recognition technology work very differently once a database is involved.

The four elements every Facial Recognition Regulation has in common 

Read eleven statutes side by side and the same four demands surface, in different order and with different teeth:

  1. Lawful basis and consent: Whether you need explicit opt-in, a documented legitimate interest, or a statutory exemption before the first capture.
  2. Mode and purpose limits: Whether 1:N search, emotion inference, facial age estimation, or trait categorisation is restricted or barred outright, and for whom.
  3. Residency and retention:  Where the template may be stored, how long you may keep it, and what must be deleted when the purpose ends.
  4. Demonstrable accuracy and explainability: Whether you can evidence that the system performs consistently across demographic groups, and explain any individual decision it produced.

Levers one to three are well understood, and most compliance teams already hold paperwork for them. Lever four is the gap, because it is newer, harder to fake, and now often the first question a regulator raises once the consent record has cleared.

What do EU facial recognition laws require in 2026?

The EU AI ACT facial recognition splits the work across two instruments. The AI Act decides whether a given facial recognition deployment is permitted at all, and the General Data Protection Regulation governs how the underlying biometric data may be processed once it is.

What Article 5 actually prohibits, and who it binds?

Article 5 of the AI Act has applied since 2 February 2025, and the widely repeated summary of it is wrong in a way that matters commercially.

The prohibition on real-time remote biometric identification in publicly accessible spaces is scoped to law enforcement purposes, with narrow exceptions. It is not a blanket ban on commercial facial recognition, and reading it as one leads teams to over-restrict a compliant onboarding flow while missing the provisions that do bind them.

Three Article 5 prohibitions apply to private deployers directly. Untargeted scraping of facial images from the internet or CCTV to build or expand a facial recognition database is barred. Emotion recognition in workplaces and educational institutions is barred. Biometric categorisation that infers sensitive characteristics such as race, political opinion, or sexual orientation is barred. 

Penalties under Article 99(3) reach €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher, and those penalties became enforceable from 2 August 2025. That ceiling sits above the GDPR maximum, which means an AI Act breach is now the more expensive of the two exposures for a large group.

Where facial recognition sits in the high-risk tier

Annex III of the EU AI Act places biometric systems among the categories that can be considered high-risk, but it does not treat every biometric use the same way. A standard identity verification check, where the system only confirms that a person is the same person they claim to be, is specifically excluded from the high-risk category. 

This is a 1:1 biometric match, such as comparing a selfie with a biometric ID document during onboarding. However, the rules change if the system does more than verify identity, such as identifying people from a database, estimating age, detecting emotions, or categorising people based on sensitive traits. These additional functions can move the system into a high-risk category or, in some cases, make it prohibited under Article 5. The key point is that the AI Act looks at the actual purpose and function of the system, not the name given to it. A product called “identity verification” may still face stricter rules if it performs tasks beyond confirming a claimed identity. 

GDPR Article 9, the layer that never moved

Article 9 of the GDPR classifies biometric data processed for the purpose of uniquely identifying a person as a special category, and prohibits processing unless a specific condition applies. In practice, that means explicit consent, a documented lawful basis, and a data protection impact assessment completed before deployment rather than after it. None of that timing was touched by the Omnibus, so the GDPR layer is live now regardless of what happens to the AI Act calendar.

How do US facial recognition laws differ from the EU model?

The United States regulates facial recognition from the bottom up, through state biometric statutes and consumer privacy acts rather than a single federal framework. Congress has passed no facial recognition legislation, and the Facial Recognition and Biometric Technology Moratorium Act of 2023 died in committee. Twenty-three states have now passed or expanded laws restricting the mass scraping of biometric data, which produces a patchwork where your exposure depends on where your users sit rather than where you are incorporated.

Statute Who enforces it Consent standard Exposure
Illinois BIPA Private right of action Written release before collection $1,000 negligent, $5,000 reckless or intentional, per violation
Texas CUBI Attorney General only Notice and consent before capture, unless an exception applies Civil penalties up to $25,000 per violation
Washington My Health My Data Act Attorney General and private action in limited circumstances Consent Requirement for regulated health data processing Consumer Protection Act penalties
Colorado Privacy Act Attorney General and district attorneys Opt-in for biometric identifiers as sensitive data CPA enforcement, cure period rules apply
Oregon Consumer Privacy Act Attorney General Opt-in for biometric data as sensitive data OCPA enforcement
No federal statute Sectoral regulators and the FTC Varies by sector Unfair or deceptive practice theories

Illinois BIPA after SB 2979

Illinois remains the most litigated biometric jurisdiction in the world because it is the only major statute granting individuals a private right of action, and class actions follow that right.

The arithmetic changed on 2 August 2024. Governor Pritzker signed SB 2979, the first amendment to Illinois BIPA in the statute’s sixteen-year history, and it provides that where a private entity collects the same biometric identifier from the same person using the same method of collection, the claimant is entitled to a single recovery, not one per scan. Before the amendment, a fingerprint clock used twice daily for two years could theoretically be pleaded as more than a thousand violations. The Seventh Circuit held in April 2026 that the amendment applies retroactively to cases pending when it took effect, per reporting in ABA Business Law Today. The per-scan multiplier that drove nine-figure settlement demands is therefore gone, though the underlying duty to obtain a written release before the first capture is untouched.

Texas CUBI and the Attorney General model

Texas takes the opposite enforcement route. Only the Attorney General may bring an action under the Capture or Use of Biometric Identifier Act, and civil penalties reach up to $25,000 per violation, per the Texas Attorney General’s own guidance. No private plaintiffs means no class action volume, but a single state-initiated action can be larger than an Illinois settlement, and the Texas AG has built a dedicated privacy enforcement unit around these statutes.

What are the facial recognition privacy laws in Asia Pacific?

Asia Pacific has moved from general data protection to purpose-built biometric rules faster than any other region, and China is now the only major economy with a dedicated facial recognition instrument.

China’s Security Management Measures

The Cyberspace Administration of China and the Ministry of Public Security issued the Security Management Measures for the Application of Facial Recognition Technology on 21 March 2025, and they took effect on 1 June 2025. It is the first dedicated legislation anywhere governing the commercial use of facial data, and its logic is necessity rather than consent alone.

Operators must justify why facial recognition is necessary for the stated purpose, and individuals must not be compelled to verify by face where another method would work. Facial recognition is restricted in sensitive locations such as hotel rooms and changing rooms. Encryption, access control, authorisation management, and intrusion detection are mandated as baseline technical measures. Any organisation storing facial data on more than 100,000 individuals must file with its provincial cyberspace administration within 30 working days of crossing that threshold, according to the translation published by Georgetown’s Center for Security and Emerging Technology. That filing threshold is the provision most foreign operators discover late, because it converts a scale milestone into a registration deadline.

India’s DPDP Act and the 2025 Rules

India notified the Digital Personal Data Protection Rules on 14 November 2025, which set the operational detail the 2023 Act left open. The Ministry of Electronics and Information Technology staged commencement across three dates, with the Data Protection Board framework live immediately, consent-manager registration at twelve months, and full functional compliance on consent, notice, data principal rights, and grievance redressal by 13 May 2027, per the MeitY notification. Indian onboarding programmes now work to a fixed deadline rather than an open horizon, so 13 May 2027 is the date your consent architecture has to clear.

Australia, where a retailer set the bar

Australia has no dedicated facial recognition statute, and it produced one of the clearest enforcement signals anywhere without one. The Privacy Act 1988 treats facial images and other biometric information as sensitive information, which generally requires consent for collection. In a determination the Office of the Australian Information Commissioner published in November 2024, the Privacy Commissioner found that Bunnings had interfered with the privacy of hundreds of thousands of customers through facial recognition across 62 stores, having failed to obtain consent, failed to notify adequately, and failed to implement compliant practices and procedures. The Administrative Review Tribunal affirmed aspects of that determination in February 2026, and the Commissioner’s stated position is that the bar for deploying facial recognition in Australia is high. A general privacy statute, applied firmly, delivered a stricter practical outcome than several dedicated laws have.

What do laws on facial recognition require in the UK, Canada, Brazil?

Three more markets matter to most global onboarding programmes, and each regulates facial recognition through an instrument that never mentions it by name.

UK’s Lack of Dedicated Facial Recognition Statute

The United Kingdom has no dedicated facial recognition statute. Deployments are governed by UK GDPR, the Data Protection Act 2018, human rights and equality legislation, and common law police powers, which the Home Office itself has described as a patchwork. A government consultation on a new legal framework closed in February 2026, so the position is likely to change. Michael Murray, Head of Regulatory Strategy at the Information Commissioner’s Office, has made the practical consequence explicit, noting that “it’s conceivable one organisation could be non-compliant across both pieces of legislation” where two regulators cover the same service. Overlapping regimes mean a single deployment can fail two audits, which is why the assessment work has to be done once against both.

Quebec’s 60-day notification requirement

Canada regulates federally through PIPEDA, and Quebec adds an obligation teams routinely miss. Under the province’s private-sector privacy regime, an organisation that intends to use a biometric process to verify or confirm identity must declare it to the Commission d’accès à l’information at least 60 days before the system is brought into service. A launch date set without that notification is a launch date that has to move.

Brazil, LGPD Article 11 and stadium enforcement

Article 11 of Brazil’s LGPD classifies biometric data linked to a natural person as sensitive personal data, processable only with consent or where indispensable for a defined set of purposes. Enforcement has arrived through ticketing rather than banking. The Brazilian data protection authority opened action against a set of football clubs over facial recognition used for stadium entry and ticket sales, citing transparency and children’s-data failures, and ordered the clubs to publish adequate biometric-processing information on their ticketing platforms. Sports venues, not fintechs, are drawing the regulator’s first line.

A compliance checklist for facial recognition laws by country

Six controls satisfy the four levers across every regime covered above, and each one maps to a lever rather than to a country.

  1. Document the mode in writing: Record whether each deployment is 1:1 verification or 1:N identification, and keep that classification consistent across your DPIA, your vendor contract, and your privacy notice. Lever two.
  2. Name the lawful basis per jurisdiction: The applicable lawful basis or processing condition varies by jurisdiction, including explicit consent where required, a written release for Illinois, notice and consent for Texas, and necessity plus non-compulsion for China. One global consent notice will not carry all four. Lever one. 
  3. File what has to be filed: Quebec requires a CAI declaration 60 days before launch, and China requires a provincial filing within 30 working days of holding facial data on 100,000 people. Both are calendar items, not policy items. Levers one and three.
  4. Fix residency before you scale: Decide where templates are stored per market, and check whether your deployment model can actually honour that. Cloud, regional cloud, and on-premises options exist precisely because some regulators will not accept a single global instance. Lever three.
  5. Set and enforce a retention clock: Delete templates when the stated purpose ends, and make deletion evidenceable rather than assumed. Lever three.
  6. Produce accuracy evidence across demographic groups: Hold documentation showing how the system performs for different populations, and retain a per-decision explanation for any individual outcome. Lever four, and the one most files are missing.

What counts as proof that a face-matching system is fair? 

The reason why the last element keeps appearing is that the documented failures of early facial recognition were accuracy failures, not consent failures, and they fell unevenly. Misidentifications concentrated among darker-skinned individuals, traced to demographic imbalance in training data. Every regime written since has absorbed that history, which is why the AI Act asks for explainability, the GDPR asks for a DPIA that assesses risk to individuals, and the Australian Commissioner asks whether the deployment was proportionate in the first place.

Tom Gadsden, VP of Product at Shufti, has been blunt about where the industry starts from. “A lot of AI algorithms are, on the surface, somewhat sexist and racist,” he has said, adding that he was “really pleased that Shufti’s algorithms are commendably flat across racial groups.” 

The reassurance is not what really is the pivot here, but the point is that flatness across groups is a measurable property, and a vendor who has never measured it cannot hand you the evidence when a regulator asks.

Independent benchmarking is what turns that claim into a document you can file. 

In the US Department of Homeland Security’s 2025 Remote Identity Validation Rally, Shufti recorded zero selfie extraction failures and zero document extraction failures across all tested smartphones and issuing-state combinations, with a worst-case false non-match rate below 0.68%, and was among the 31% of tested systems that met every performance goal in the Selfie Match to Document track, per Shufti’s published summary of the results. A government-run evaluation across diverse populations is the kind of artefact that answers lever four in a single line, where a vendor datasheet does not.

How does Shufti help compliance teams evidence facial recognition decisions?

Most teams reach an audit that is able to produce a consent record and unable to produce a fairness record. The consent trail is easy, because a lawyer designed it. The accuracy and explainability trail was usually never designed at all, and regulators have started to ask for exactly that.

Shufti face verification software layer returns a per-decision explanation rather than a bare score. Every flagged image, including a deepfake detection alert,  carries a colour-coded attention map marking natural, moderate, and high-anomaly zones, so a fraud or compliance analyst can show where risk was identified and why, which is exactly the artefact an explainability requirement asks for. Because the models are Shufti’s own, that reasoning is not mediated through a third-party licence. The independent anchor is public: Shufti met 100% of the biometric accuracy goals in the DHS 2025 Remote Identity Validation Rally, tested across diverse populations.

See how Shufti evidences a facial recognition decision on your own onboarding data, then book a 20-minute demo.

Frequently Asked Questions

What penalties apply for violating facial recognition laws?

Penalties vary by regime. EU AI Act breaches of the Article 5 prohibitions reach €35 million or 7% of worldwide annual turnover, whichever is higher. Illinois BIPA awards $1,000 for negligent and $5,000 for reckless violations. Texas CUBI reaches $25,000 per violation.

Do facial recognition laws require user consent?

Usually, but not always in the same form. The EU and Brazil may require explicit consent for biometric data, Illinois requires a written release before collection, and Texas requires notice and consent. China goes further by requiring necessity, so consent alone does not make a deployment lawful there.

What privacy laws cover facial recognition data?

Most facial recognition is regulated by general privacy statutes rather than dedicated ones. GDPR Article 9, UK GDPR, LGPD Article 11, Australia's Privacy Act 1988, India's DPDP Act, and PIPEDA all treat biometric data as sensitive. China's 2025 Measures are the main dedicated exception.

Is facial recognition legal for customer onboarding?

Yes, in every jurisdiction covered here. Onboarding checks are 1:1 verification, which no major law prohibits. The obligations attach to consent, purpose limitation, residency, retention, and your ability to evidence accuracy and explain decisions.

Does a country without a facial recognition law mean no legal risk?

No. Australia has no dedicated statute and produced one of the strictest enforcement outcomes on record under its general privacy law. Data protection statutes, constitutional privacy rights, and cross-border transfer rules all reach biometric data regardless.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.