It’s Just Math: Recent Legislative Trend Reignites Debate About the Bounds of Biometric Data
Special thanks to FPF’s Rafal Fryc (former U.S. Policy Intern), Tatiana Rice (Senior Director for U.S. Legislation), and Jim Siegl (Senior Fellow) for research support and feedback
A new exemption being proposed and considered in state legislatures across the country is resurfacing old debates around the contours of what constitutes biometric data. Biometric data has long been at the forefront of privacy debates in U.S. states. Illinois, Texas, and Washington all have standalone biometric privacy laws, and 20+ state comprehensive privacy laws also include heightened protections for biometric data as a category of sensitive data. Although this tide of legislation shows that there is growing consensus on the need to protect biometric data through privacy laws, defining “biometric data” remains a point of debate.
Beyond the threshold question of what constitutes “biometric data,” a newer and more subtle question is surfacing: whether converting biometric data into an irreversible mathematical representation—a security measure applied to otherwise in-scope data—should exempt it from biometric privacy protections altogether even if the data is still intended and able to be used for uniquely identifying an individual.
State comprehensive privacy laws typically define biometric data to mean data generated by automatic measurements of an individual’s biological characteristics that are used to identify a specific individual. A number of bills have included that definition with a novel exception for information that has been converted to a “mathematical representation” and which cannot be used to recreate the data generated by the measurement of an individual’s biological patterns or characteristics.
This new exception appears to be focused on biometric identification systems that use one-way mathematical processes to convert biometric data into a form that allegedly cannot be reversed to recreate an individual’s raw biometric data but nevertheless still allow for verification or identification. Although no state comprehensive privacy law has enacted this exemption so far, it is appearing in an increasing number of bills, including several that have come close to being enacted.
This blog post examines how this new legislative language differs from the existing biometric privacy landscape and some of the potential interpretive and policy questions it raises. Some key takeaways include:
- Novelty: While biometric data privacy debates often center on the “identifiability” of the resultant data, the proposed ‘irreversible mathematical representation’ exemptions focus on (1) whether the in-scope biometric data went through a technical process to render it a “mathematical representation,” and (2) whether that resultant mathematical representation can be reverse engineered to create the data that was initially generated by automatic measurement of an individual’s biological patterns or characteristics.
- Reversibility: The core component of the exemption—reversibility—is not defined and could arguably apply to differing degrees of biometric transformation processes with differing levels of security and assurance. While the spirit of the law may mean the exemption is less likely to apply to commonplace mathematical transformations (e.g., encryption of biometric templates), certain privacy enhancing technologies (PETs) such as cancellable biometrics could be intended to be in scope of the exemption.
- Policy: If the policy justifications of biometric privacy laws are to mitigate the security risk posed to an individual by a breach of their biometric data and minimize the surveillance risk of biometric identification (i.e., risks to an individual’s autonomy, anonymity, or freedom of movement in public), a potential middle-ground could be to include the ‘irreversible mathematical representation’ exception only for specific, low-risk uses of biometric data that do not implicate broader surveillance concerns.
State Privacy Laws Typically Protect “Biometric Data” as “Sensitive Data”
State comprehensive privacy laws typically require controllers to (1) obtain opt-in consent to process sensitive data, and (2) conduct a data protection assessment prior to processing sensitive data. “Biometric data” is a common category of sensitive data under these laws. Connecticut’s definition of “biometric data” reflects the language common to the majority of these state laws:
“Biometric data” means data generated by automatic measurements of an individual’s biological characteristics, such as a fingerprint, a voiceprint, eye retinas, irises or other unique biological patterns or characteristics that are used to identify a specific individual.
“Biometric data” does not include (A) a digital or physical photograph, (B) an audio or video recording, or (C) any data generated from a digital or physical photograph, or an audio or video recording, unless such data is generated to identify a specific individual.
There is some variation between states’ definitions of biometric data. For example, states are split on whether biometric data should include data generated from a physical or digital photograph or a video or audio recording. There is also a growing divide between states that limit the definition to data that is used or intended to be used to identify a specific individual, on the one hand, and data that can be used for identification or that allows for identification, on the other hand. As detailed in a 2022 blog post, When Is a Biometric No Longer a Biometric?, these definitional differences raise threshold questions around whether privacy restrictions and protections should apply not just tools designed to identify or verify individuals’ identities but also emerging technologies that rely on data derived from humans, even if not used for identification, such as detection and characterization tools. In 2026, this carries even greater implications for emerging technologies like multimodal AI models, spatial intelligence models, accessibility features, face-blurring features, deepfake detection, and transcription tools.
Although divergent approaches to defining biometric “identification” are a significant policy issue, the proposed ‘irreversible mathematical representation’ exception appearing in a growing number of state privacy bills raises a distinct question, i.e., whether biometric data that is used or intended to be used to identify a specific individual should be exempt if certain technical and security processes occur as to render the data in a format such that it cannot be used to recreate the biologically-derived data.
The Proposed ‘Irreversible Mathematical Representation’ Exception
Multiple bills in recent years have proposed narrower definitions of biometric data that are similar to the definition from Connecticut above but which exclude information that has been captured and converted to a mathematical representation and that cannot be used to recreate data generated by automatic measurement of an individual’s biological characteristics. Looking at a comprehensive consumer privacy bill from the 2026 legislative session, for example, Mississippi HB 1051 included the following definition:
“Biometric data” means data generated by automatic measurement of an individual’s biological characteristics, such as fingerprints, voiceprints, eye retinas or irises, or other unique biological patterns or characteristics that are used to identify a specific individual. This term does not include: . . . (ii) Information captured and converted to a mathematical representation, including a numeric string or similar configuration, that cannot be used to recreate data generated by automatic measurement of an individual’s biological patterns or characteristics used to identify the specific individual.
Note that this is framed as an exception to information that would otherwise be “biometric data,” meaning it is information generated by measuring an individual’s biological characteristics and which is used or intended to be used for identification. If the information cannot be used for identifying an individual, then it is already out of the scope.
Versions of this ‘irreversible mathematical representation’ exception have appeared in numerous bills in recent years, including comprehensive privacy bills in Pennsylvania (HB 78, SB 112, & HB 1201) and Georgia (SB 111), as well as proposed amendments to Illinois’s BIPA (SB 3122, HB 2838, HB 3667, HB 5635, HB 2335, SB 1506, HB 2252, and HB 559).
The proposed exception is broader in some bills. Pennsylvania HB 78, for example, would include the ‘irreversible mathematical representation’ exception in its definition of “biometric data.” But that bill would also define “personal data” to not include “biometric data captured and converted to a mathematical representation,” without the additional criterion that such a representation cannot be used to recreate the original data. That is a much broader exception, and it highlights that the ‘irreversible mathematical representation’ exception, as it is commonly articulated, includes two distinct conditions:
- The information must be converted to a “mathematical representation,” (i.e., there must be some mathematical process applied to the data generated).
- One must be unable to recreate the underlying data from the mathematical representation (i.e., the process must be irreversible or one-way).
The condition that such information be converted to a “mathematical representation” means little if interpreted literally. All digital information is a mathematical representation—binary code. A digital scan of an analogue photograph, for example, is information that has been captured and converted to a mathematical representation. Under that interpretation, Pennsylvania HB 78 appears to be saying that biometric data is never personal data under the bill.
Setting aside the trivial interpretation that would cover all digital information, the “mathematical representation” language still likely captures all biometric data. To conduct biometric identification, there has to be an initial capture of a raw biometric input by a sensor (e.g., data collected by a scanner or microphone). That raw input data must then be processed, standardized, and have relevant features extracted to create a reference template (e.g., deriving a unique iris code from an iris scan) against which a future biometric input can be processed and compared. That process is itself a capture of information (raw input data) and conversion to a mathematical representation (the template or feature representation). The more stringent condition, therefore, is that the resultant mathematical representation “cannot” be used to “recreate” data generated by automatic measurement of an individual’s biological patterns or characteristics.
This ‘irreversible mathematical representation’ exception poses a number of questions about its scope, the technological processes to which it would apply, and the policy rationales that support it. Given its repeat appearances in proposed privacy legislation, it is worth exploring these questions, which reignite a debate as old as biometric privacy law itself: When is a biometric no longer a biometric?
Is a “Biometric” No Longer “Biometric” If It’s Irreversible?
The ‘irreversible mathematical representation’ exception raises a unique definitional question regarding the bounds of biometric data. Focusing only on the subset of technologies used for individual identification, the question raised by these bills is whether data should be exempted from heightened protections for biometric data if the information has been converted to a format such that it “cannot” be used to “recreate data generated by automatic measurement of an individual’s biological patterns or characteristics.”
What Constitutes Reversibility? Three Potential Applications
It is unclear how this exception would apply in practice. Namely, the ‘irreversible mathematical representation’ exception does not clarify what it means to “recreate” data generated by automatic measurement of an individual’s biological patterns or characteristics. This section will consider “reversibility” in three contexts: inverting a biometric template, encrypted biometric data, and one-way data distortions such as cancelable biometrics. Whether the exception would apply in each of those contexts helps clarify the purpose behind the exception.
1. Inverting a Biometric Template
At a high level, biometric identification typically involves an initial capture of raw biometric input data by a sensor (e.g., a scan of a fingerprint, palm, iris, or face). That data then undergoes pre-processing and feature extraction to generate a biometric template which is retained in a database for future use. In subsequent interactions, the individual’s biometric characteristic is again measured, processed, and then compared against the database of biometric templates to identify the individual in question.
Under a broad interpretation, one could argue that this process is within scope of the exception because it involves a capture of information about an individual’s biological characteristics and a process that subsequently converts that raw input data into a mathematical representation (the template). That is likely not the intended scope of the exception, for multiple reasons. As a matter of policy, that interpretation would broadly exempt almost all uses of biometric data for identification, causing the exception to swallow the rule. There is also a technical issue with that interpretation—irreversibility. If one has access to an unprotected biometric template, a raw mathematical map of biological features that has not undergone a non-invertible transformation, it is increasingly possible to reverse-engineer a synthetic sample of the individual’s biometric data through an inversion attack. For example, reverse-engineering iris images from iris codes was shown to be possible in 2012. Given the known risk of inversion, the ‘irreversible mathematical representation’ exception is unlikely to apply to unprotected biometric templates, although the actual risk of inversion may vary depending on the modality and other factors.
If the exception requires some additional process that is applied to reduce the risk of reversing a template to extract the original biometric data—or if the exception requires a mathematical transformation of the template itself, not merely the biological input data—then there are two likely other cases to consider: encryption or other forms of privacy enhancing technologies (PETs) (e.g, cancelable biometrics).
2. Encrypted Biometric Data
Encryption is the use of a mathematical process to convert data from an intelligible format to an unintelligible format for unauthorized persons. Merely encrypting biometric data is unlikely to be within the scope of the exception because it is a reversible process, provided the actor is in possession of the relevant key. However, the ‘irreversible mathematical representation’ exception does not specify from whose perspective it should be applied. A controller who encrypts its biometric data would likely argue that the exception should apply to them because a third party (without access to the key) would be unlikely to recreate the original data generated were they to access any encrypted templates or samples. Encrypted biometric templates are often considered “near-impossible to reverse engineer into usable data,” although “harvest now, decrypt later” attacks remain a risk. Whether this argument is persuasive would likely depend on the specific language used in the exception and the business’s security safeguards. It may matter, for example, if the exception says that the mathematical representation “cannot be used” to recreate the original data or if it “cannot reasonably be used” to do so. Given that some providers of biometric identification systems describe an encrypted biometric template as “a mathematical representation” that “cannot be reverse-engineered,” it is possible that companies would try to avail themselves of this exception merely by encrypting templates.
3. Cancelable Biometrics
If encryption is not a sufficient process to trigger this proposed exception, then that leaves more novel forms of biometric template protection, such as cancelable biometrics, biometric cryptosystems, or encrypted-domain biometrics. To focus on one example, cancelable biometrics describes the use of one-way data transformations to create a protected output. This differs from standard encryption in that there is no decryption step necessary to conduct the comparison—the comparison occurs in the transformed domain. Cancelable biometrics can utilize a data transformation either at the signal level (i.e., changes are made to the raw biometric data input prior to the creation of a template) or at the feature level (e.g., locality-sensitive hashing performed on feature vectors) to create a protected output. Biometrics vendors may use terms such as “biometric tokenization” to describe cancelable biometrics or other forms of biometric template protection.
This method adds additional layers of security because a template can be “canceled” if compromised and a new template can be created by adjusting the transformation applied. These outputs are also considered by many computationally infeasible to reverse, although such claims about irreversibility can be challenged. Data transformations such as cancelable biometrics are likely the use cases intended to be covered by the exception—they are forms of identification that use mathematical representations of data that are derived from measuring an individual’s biological characteristics but from which one (likely) cannot recreate the data originally measured.
Were it to be enacted in any jurisdiction, the full impact of this ‘irreversible mathematical representation’ exception would likely turn on a number of fact-specific questions, including nuanced technical and administrative details about an entity’s use of encryption or one-way data transformations. Setting those questions aside, it is sufficient to say at this stage that this exemption could affect a broad range of entities and technologies, given the prevalence of these kinds of technical safeguards and the exceptions’ lack of specificity.
Whether to Exempt this Kind of Data Depends on Why Biometric Data is Considered Sensitive
To recap, state privacy laws commonly include “biometric data” as a category of sensitive data, and these laws typically scope “biometric data” to mean information generated by automatic measurement of an individual’s biological characteristics that are used to identify a specific individual. A growing number of proposed bills include this definition with an added exception, providing that “biometric data” would not include information captured and converted to a mathematical representation that cannot be used to recreate data generated by automatic measurement of an individual’s biological patterns or characteristics used to identify the specific individual. Applying the exception in practice may prove difficult, as it does not adequately define when a mathematical transformation sufficiently guards against the risk of recreating the originally captured information.
For the remainder of this blog post, assume that the ‘irreversible mathematical representation’ exception is scoped to cover at least one-way data transformations incorporated into the biometric identification process, such as cancelable biometrics. Evaluating whether this new exception furthers responsible data use requires unpacking the rationale for subjecting biometric data to heightened protections. There are two highly relevant policy justifications here: (1) the security risk posed to an individual by a breach of their biometric data; and (2) the surveillance risk of biometric identification (i.e., risks to an individual’s autonomy, anonymity, or freedom of movement in public).
1. The Security Rationale
One reason as to why biometric data is inherently sensitive is the long-term security risks posed by a data breach or inadvertent disclosure of biometric data. Biometrics are a double-edged sword when used for authentication and security purposes. Because of the unique nature of one’s biological characteristics, and the difficulty of changing those characteristics, they are uniquely suited to identifying an individual. Biometric verification also requires less effort from the individual as compared to remembering a password or maintaining alternative, layered forms of identification. Yet the permanence and uniqueness of biometrics make exposure extremely risky: it is easy to change a password, but it isn’t feasible to change your iris. This is stated in the legislative findings for Illinois’ BIPA, for example:
Biometrics are unlike other unique identifiers that are used to access finances or other sensitive information. For example, social security numbers, when compromised, can be changed. Biometrics, however, are biologically unique to the individual; therefore, once compromised, the individual has no recourse, is at heightened risk for identity theft, and is likely to withdraw from biometric-facilitated transactions.
It follows therefore that if a policymaker is concerned about the security risk posed to an individual by the risk of biometric data becoming permanently compromised, then it is good policy to incentivize companies to apply security measures and PETs in a manner that eliminates or greatly reduces the risk of a bad actor being able to access data from which they could create a synthetic sample of an individual’s biometrics.
If this is the policy rationale behind the ‘irreversible mathematical representation’ exception—incentivizing companies to adopt state of the art technical safeguards—then it is important to recognize that broadly carving out such data is not the only potential means of encouraging this behavior. Privacy laws regularly impose data security obligations that require reasonable practices to protect the confidentiality, integrity, and availability of personal data. Policymakers can consider other paths to encourage PETs adoption as potential alternatives to taking the resulting data outside of the scope of heightened protections for biometric data.
2. The Privacy/Surveillance Rationale
Another reason for treating biometric data as sensitive is the risk of surveillance. The aforementioned difficulty in changing one’s biological characteristics also makes biometric identification a powerful tool for persistent monitoring. Depending on how these systems are deployed, they can pose a significant risk to not just our privacy but our collective autonomy. If policymakers think that the processing of biometric data should be subject to heightened protections such as opt-in consent for that reason, then the ‘irreversible mathematical representation’ exception could exacerbate that risk because it removes the heightened notice and consent requirements for such uses even though the data can still be used to uniquely identify an individual. This risk speaks to a broader debate about how to adequately protect sensitive data: if “data is what data does,” and there is an agreed-upon privacy risk from biometric identification that warrants heightened obligations to collect and use that data, then merely transforming the data into a distinct format may be an insufficient protection if the underlying risky purpose for processing that data remains viable.
Some cases under existing biometric privacy laws illustrate this paramount focus on identifiability over the technical form of the data. For example, in denying a motion to dismiss in Rivera v. Google, the Northern District of Illinois held that, regardless of whether an entity converts “a person’s biometric identifier into some other piece of information, like a mathematical representation . . . the resulting information is still covered by the Privacy Act if that information can be used to identify the person.” In another BIPA case, Zellmer v. Meta, this line of reasoning arguably fared better for defendants. In Zellmer, the Ninth Circuit considered whether Facebook’s “face signatures”—created as part of the tag suggestions process and which converted face scans to “an abstract, numerical representation” that cannot be reverse engineered—are biometric identifiers. The Ninth Circuit found that, with respect to non-users of Facebook who do not have a corresponding face template to be matched, Facebook lacked the ability to identify such non-users and thus no biometric identifier was created. Again, this decision emphasizes identifiability. This debate is also ongoing outside of the US. For example, a 2025 decision by the Bavarian State Office for Privacy Supervision (“BayLDA”) rejected an argument that iris codes were not personal data because they could not be reverse engineered to reconstruct individual irises. Per the BayLDA decision, “[t]he reversibility of the algorithm under which an identifier was created” is not necessary under the GDPR’s definitions of “personal data” or “biometric data.” (¶ 325.) However, the finality of this decision is being appealed by defendant Worldcoin Foundation, which asserts that the Bavarian DPA’s holding runs contrary to the Court of Justice of the European Union’s more recent decision in EDPS v SRB (Case C-413/23 P).
None of these cases involved the specific language of the ‘irreversible mathematical exception’ that has been proposed in state privacy legislation. However, they do speak to the importance of an entity’s capability to identify an individual rather than the nature of the data itself.
An important nuance in this debate is that different uses of biometrics (both in terms of the modality and the use-case) raise different degrees of risk. Take, for example, a ticketless entry system for a sporting event. Given how people interface with these systems, a thumbprint scanner poses less of a surveillance risk than a facial recognition system because once someone’s face is enrolled in a facial recognition system, that tool can more easily be used for secondary, surreptitious purposes beyond the initial entry, such as security and public safety (including partnering with law enforcement) or profiling.
There are ways the ‘irreversible mathematical representation’ exception could be refined to still be responsive to individuals’ concerns over privacy and surveillance. For example, the exception could be paired with strong disclosure, purpose specification, and secondary use provisions. However, imposing such requirements would raise the question as to why this data was exempted from heightened consent requirements in the first place. Another potential middle-ground could be to include the exception but only for specific, low-risk uses of biometric data that do not implicate broader surveillance concerns, such as biometric locks which use 1:1 verification to grant access to a device or space and which are utilized for security purposes or limited 1:few identification systems.
Conclusion
Given the recurring appearance of this ‘irreversible mathematical representation’ exception in state privacy legislation, it is important to explore how this exception would apply and whether it can be scoped to support individuals’ privacy and security. Regardless of whether policymakers accept or reject this exception, they should clearly identify their priorities with respect to biometric identification and what specific harms they are responding to in regulating private entities’ collection and use of this data. This exception could enable positive uses of biometric technology that would otherwise be de facto prohibited under strict consent regimes. However, it would be important to ensure that the exception be paired with other measures that would prevent it from being overinclusive. Incentivizing responsible uses of biometric data, including adequate data security practices, does not need to come at the expense of vital protections for individuals’ privacy such as obtaining freely given, specific, informed, and unambiguous consent for processing biometric data used for identification.