top of page

Erie County’s Biometric Privacy Law: What Businesses Must Do Before July 5

  • Jul 3
  • 4 min read

Updated: Aug 3

Kenney Shelton Liptak Nowak LLP | Employment & Business Law Update


On June 5, 2026, Erie County became the first county in New York State to prohibit private businesses from collecting, storing, or selling their customers’ biometric data. The vehicle is Local Law No. 1 of 2026, the Biometrics Transparency and Privacy Act.


For most businesses, though, the more urgent date is July 5. Any commercial establishment that already held customer biometric information when the Act took effect has thirty days, until July 5, 2026, to notify the County in writing, adopt and post a data destruction policy, and begin deleting that data. The penalty for mishandling those obligations runs as high as $5,000 per day.


A First-in-the-State Law


The Act followed public reporting that a regional grocery chain had deployed facial recognition technology at select Erie County stores for loss prevention. The County Legislature passed the measure on April 30, 2026; County Executive Mark C. Poloncarz signed it on May 26; and it took effect upon filing with the New York Secretary of State on June 5.


Erie County is not writing on a blank slate. Illinois’s Biometric Information Privacy Act, which requires notice and consent before collection, has produced more than a decade of class litigation, while New York City has required on-site notice and barred the sale of biometric data since 2021. What sets the Erie County ordinance apart is its posture, an outright ban on collection rather than a notice or consent requirement, and its standing as the first county-level enactment of its kind in New York.


What the Law Prohibits, and Who It Reaches


Section 4 bars commercial establishments, with limited exceptions, from collecting, storing, procuring, using, and selling or otherwise monetizing a customer’s biometric identifier information in commercial settings. Mere collection or storage is enough to trigger it.


The reach is broad. A “commercial establishment” is any entity operating a place of business in Erie County that offers goods or services to the public, including nonprofits, so gyms, restaurants, venues, and professional offices all qualify. “Biometric identifier information” is equally expansive, covering facial features, iris and retina scans, fingerprints and handprints, voiceprints, genetic information, and characteristic movements such as gait or typing patterns, along with data derived from those measurements.


Because biometric functionality is often embedded in commonplace systems (fingerprint point-of-sale terminals, voice authentication, smart access controls), a business may be collecting biometric data without ever having decided to. The first compliance question is factual: what technology is deployed, and does any of it capture biometric identifiers?


Security Cameras Versus Biometric Databases


The Act does not outlaw surveillance. Section 7(e) exempts photographs and video that are not analyzed by identification software and are not shared with third parties. A conventional security camera that merely records footage is permitted; the same camera becomes a problem the moment its feed is run through facial recognition software to identify or profile individuals. Loss prevention programs built on facial recognition, the practice that prompted the law, fall on the prohibited side of that line.


Other exemptions cover conduct required by law, verification to access one’s own devices, social media face detection, valid warrants or subpoenas, government actors, and financial institutions.


The July 5 Obligation


Section 5 governs businesses that already held customer biometric data on June 5. By July 5, such a business must file written notice with the Director of the Erie County Division of Consumer Protection stating that it holds biometric information and summarizing the amount and type; establish a written destruction policy describing how and when the data will be deleted; and post that notice and policy conspicuously on site and make them public. The County has published the required forms at erie.gov/biometrics.


The obligation does not end there. Under Section 5(c), the business must then provide the Director an affidavit certifying permanent deletion within thirty days of filing the notice. A business that files on July 5 therefore faces a second deadline in early August to finish deletion and certify it.


Penalties and Enforcement


Enforcement rests primarily with the Director of Consumer Protection. A violation of the Section 4 collection prohibition may draw up to $1,000 per day after the cure period ends; a violation of the Section 5 notice and destruction requirements may draw up to $5,000 per day. For Section 5 violations, the Director must first issue a notice of violation and allow thirty days to cure, and may close the matter without penalty if the business complies.


The Act also preserves a private right of action: a customer may sue separately for injunctive relief and damages, and no settlement between the County and a business binds the customer. Under Illinois’s BIPA, private class actions produced substantial liability, a reminder that private enforcement can outpace regulatory action.


Two Points to Watch


First, employee biometrics appear to fall outside the current prohibition. Section 4 is framed around a “customer’s” information, and commercial settings are public-facing by definition, so an employer’s fingerprint or facial time-clock does not appear to be covered. That reading is not certain and the landscape may change, so employers should document their reasoning and monitor developments.


Second, the cure period contains a drafting tension. Section 6 establishes the notice-and-cure procedure only for violations of Section 5, yet the Section 4 penalty accrues “after the cure period has ended.” Whether a cure period attaches to a Section 4 violation is unsettled, so businesses should not rely on an informal cure.


Practical Steps Before July 5


  • Inventory every system that could capture biometric identifiers; ask vendors for written confirmation where capabilities are unclear.

  • Confirm whether the business held customer biometric data on June 5, which starts the Section 5 clock.

  • File the County notice, adopt and post a written destruction policy, and secure the data in the meantime.

  • Complete deletion and file the affidavit within thirty days of the notice.

  • Discontinue any prospective collection to avoid ongoing Section 4 exposure.

  • Preserve documentation as evidence of good-faith compliance.


Kenney Shelton Liptak Nowak LLP advises businesses, employers, and their insurers on privacy compliance and the litigation risks that accompany new regulatory regimes. For questions about whether your systems fall within the Biometrics Transparency and Privacy Act, or about meeting the July 5 deadline, contact our Employment and Business Law team. This article is provided for general informational purposes and does not constitute legal advice.

bottom of page