Control
Face or voice biometric template computed without prior notice and consent
Before a face-recognition or voice model turns a person's image or voice into an identifying template or match, the person is told what is collected and why and gives the consent the governing law requires.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
Law in force in European Union (EU), Illinois (US-IL), Texas (US-TX), Washington (US-WA).
The guard to add
Check a recorded, purpose-specific biometric notice and consent before any code computes, enrolls, or matches a face or voice template.
A consent gate placed immediately before the call that turns an image, video frame, or voice sample into a template or identity match (face_encodings, DeepFace.represent, rekognition.index_faces, voice embedding). The gate reads a stored consent record for this person and purpose (what is collected, why, and how long it is kept), refuses to compute the template without it, and the template is stored with a reference to that record. The notice copy shown at enrollment lives in the capture UI.
Where it goes: 1 application source code, 2 data models, 6 API calls and integrations, 14 user-facing text.
What reviewers look for: on every path from an uploaded selfie, camera frame, or voice clip to a template or match call, a check of a stored consent or release record (not just a checkbox that is never read); the template row references the consent; templates are not built from scraped or public images without the person's consent.
Example (Python face_recognition), before:
def enroll(user_id, image):
encoding = face_recognition.face_encodings(image)[0]
db.templates.insert(user_id=user_id, encoding=encoding)After:
def enroll(user_id, image):
consent = db.biometric_consents.get(user_id=user_id, purpose='face_login')
if consent is None or consent.withdrawn_at:
raise ConsentRequired('biometric notice and consent needed before enrollment')
encoding = face_recognition.face_encodings(image)[0]
db.templates.insert(user_id=user_id, encoding=encoding, consent_id=consent.id)Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
Binding law — in force (4)
- European Union (EU)
- Face or voice recognition that identifies people needs explicit consent or another Art. 9(2) basis (GDPR Art. 9) GDPR Article 9(1) · AI-adjacent law
- Illinois (US-IL)
- Inform in writing and obtain a written release before collecting face or voice biometrics (Illinois BIPA) 740 ILCS 14/15(b) · AI-adjacent law
- Texas (US-TX)
- Inform and obtain consent before capturing face or voice biometrics for a commercial purpose (Texas) Tex. Bus. & Com. Code 503.001(b) · AI-adjacent law
- Washington (US-WA)
- Obtain consent before collecting biometric data from face or voice features (Washington My Health My Data Act) RCW 19.373.030(1)(a) · AI-adjacent law