Erie County, New York โ population roughly 950,000, containing Buffalo โ enacted Local Law No. 1-2026, the Biometrics Transparency and Privacy Act, and it took effect on 5 June 2026.
It prohibits commercial establishments in the county from collecting, storing, retaining, procuring, using, selling or otherwise monetizing a customerโs biometric identifier information in commercial settings. Civil penalties run from $1,000 to $5,000 per day for each day a violation continues.
It is the first county-level ban of its kind in New York State, and it received modest coverage outside western New York when it was signed. Most national compliance programmes do not track county legislatures.
That is the reason to write about it โ not because Erie County is large, but because the mechanism it demonstrates is one that privacy programmes are structurally bad at detecting.
What the law does
The prohibition is broader than the consent-based model most practitioners have internalised from Illinois.
BIPA โ the Illinois Biometric Information Privacy Act, and the template for most biometric litigation in the United States โ is a consent statute. It permits collection of biometric identifiers where the private entity provides written notice of the specific purpose and retention period and obtains a written release. Compliance is achievable through process.
Erie Countyโs law is closer to a prohibition. It bars commercial establishments from collecting, storing, retaining, using, selling or monetizing customer biometric identifier information in commercial settings. The compliance answer for a covered use is generally not a better consent flow. It is not doing it.
That distinction is the single most important thing to take from this law, and it is the thing a programme built around BIPA-style consent will get wrong.
The transition duty that has already passed
The Act contained a one-time obligation with a short fuse.
Every commercial establishment in possession of biometric identifier information at the time of enactment was required to provide written notice to the Erie County Director of Consumer Protection within 30 days of the effective date. That notice had to include:
- a summary of the amount and type of biometric information held, and
- a Destruction Policy detailing the method and timing for permanent deletion or destruction of all biometric information in its possession.
Thirty days from 5 June 2026 expired in early July 2026. An organisation discovering this obligation now is discovering a deadline it has already missed.
The correct response to a missed notice deadline is not to skip it. It is to file, late, with an accurate account and a destruction policy, and to document when and how the obligation was identified. Regulators distinguish between an entity that self-reported late and one that never filed, and the daily-penalty structure means the cost of continuing non-compliance accrues while the question is being considered.
Penalties
$1,000 to $5,000 per day, per continuing violation.
The per-day structure is the material feature. A single unremediated biometric system does not produce a fixed exposure that can be provisioned for โ it produces a running total. At the top of the range, a violation continuing for a year is in the low millions of dollars for one establishment.
Reporting available at the time of writing does not clearly establish whether the law creates a private right of action. This matters enormously for exposure modelling โ BIPAโs private right of action, with statutory damages per violation, is what produced the Illinois class action wave rather than a regulatory enforcement programme. Organisations with Erie County operations should obtain the full text of Local Law No. 1-2026 and take local advice on this point specifically rather than relying on secondary summaries, this one included.
Who is caught
The likely in-scope uses cluster in retail and hospitality, and several are deployed by teams that would not describe them as biometric systems:
- Facial recognition for loss prevention in retail stores โ the use case that motivated the law
- Facial recognition or face-matching for age estimation at point of sale
- Fingerprint or palm-vein payment systems
- Voiceprint analysis in customer service telephony
- Biometric access for customers, as distinct from employees, in gyms, clubs and venues
- Analytics platforms performing face-matching for repeat-visitor detection, even where the vendor characterises the output as anonymous
That last category is where most organisations will find unexpected exposure. A retail analytics vendor that generates a face template to recognise a returning shopper is processing biometric identifier information regardless of whether the resulting dashboard shows a number rather than a name.
Note the customer/employee distinction. The Erie County law is framed around customers in commercial settings. Employee biometric timekeeping โ the single largest source of BIPA litigation in Illinois โ is not obviously the target of this law. That does not make employee biometrics safe in New York; it makes them a different analysis, governed by New York Labor Law ยง 201-a, which prohibits employers from requiring fingerprinting as a condition of employment.
The structural problem this exposes
Erie County is one county. The reason it is worth a compliance teamโs attention is what it says about the regulatory surface.
Privacy programmes are built to track federal and state law. There are fifty states and a manageable set of federal regulators, and the tracking services the industry buys cover them. Sub-state regulation is not covered, and there are more than 3,000 counties and roughly 19,000 municipalities in the United States.
New York City has been demonstrating this for years โ Local Law 144 on automated employment decision tools, and the NYC biometric identifier information law requiring notice from commercial establishments and prohibiting sale of biometric data. Portland, Oregon banned private-sector facial recognition in places of public accommodation. Baltimore restricted it. Several California cities have their own ordinances.
The pattern is now clear enough to plan for: where state legislatures stall on biometrics, local governments act, and they act with prohibition-shaped rules rather than consent-shaped ones, because a county legislature is not trying to build a workable national compliance regime. New York State has considered comprehensive biometric legislation repeatedly without enacting it. Erie County did not wait.
Meanwhile the state-level picture is also moving in ways that catch physical premises. Connecticut added facial-recognition signage and policy duties for covered on-premises security uses from 1 October 2026 โ an obligation that lands on the same estate teams and is equally easy to miss.
What to do
Run a location-based biometric inventory, not a system-based one. The standard AI or privacy inventory lists systems and their owners. That structure cannot answer โdo we operate a biometric system in Erie Countyโ, because the system is national and the law is local. Add deployment location to your biometric inventory as a first-class field, at the granularity of individual sites. This is the single highest-value change, and it is what makes every future local ordinance a query instead of a project.
Ask the loss prevention and store operations teams directly. Retail facial recognition is frequently procured by loss prevention, deployed through a security integrator, and never registered with privacy or IT. The inventory will not find it. A direct question will.
Interrogate your analytics vendors on face-matching. Ask specifically whether the platform generates or compares facial templates, biometric embeddings or face signatures, regardless of what the output looks like. Vendor marketing consistently describes this as anonymous analytics.
If you have Erie County operations with customer biometrics: stop, destroy, and file. Cease collection, execute a destruction policy, and submit the late notice to the Director of Consumer Protection. The daily penalty accrues while the matter is under consideration.
Add sub-state monitoring for your physical footprint. You cannot monitor 19,000 municipalities, and you do not need to. You need to monitor the ones where you operate premises that interact with the public. That is a tractable list for almost every organisation, and it is derivable from your own property or store register.
Default to prohibition-shaped compliance for customer biometrics. Given the direction of local regulation, the strategically sound posture for customer-facing biometrics in the United States is to treat them as a capability requiring affirmative justification per jurisdiction, rather than a default capability requiring a consent flow. The consent model works in Illinois. It does not work in Erie County, and Erie County is the pattern that is spreading.
The lesson
A county of under a million people passed a law in the spring that made a common retail technology unlawful within its borders, imposed a 30-day filing duty that has already expired, and attached a penalty that accrues daily.
Almost no national compliance programme detected it, because almost no national compliance programme is built to look below the state line.
The systems are national. The rules increasingly are not.
This article is provided for informational purposes only and does not constitute legal advice.



