Is Facial Recognition Legal in California? Police and Businesses

Facial recognition is legal in California. No state law bans the technology outright, either for businesses or for police. What California does have is a strong consumer privacy framework that treats your faceprint as sensitive personal information when a company uses it to identify you, plus a patchwork of city ordinances that restrict government use in a handful of places. For everyone else in the state, the technology operates in an open field, subject to general privacy and constitutional rules rather than a dedicated statute.

What the Law Says About Businesses Using Your Face

The California Consumer Privacy Act took effect in January 2020 and classifies biometric information as personal information. In November 2020, voters passed Proposition 24, which created the California Privacy Rights Act and amended the CCPA with stronger protections that became operative on January 1, 2023.1Office of the Attorney General. California Consumer Privacy Act (CCPA)

The CPRA added a category called “sensitive personal information” that covers biometric data processed to identify a consumer. Photographs fall inside that category when a business stores or uses them for facial recognition.1Office of the Attorney General. California Consumer Privacy Act (CCPA) The distinction is practical. A company keeping your headshot on an employee badge is in one bucket. A retailer running your image through a facial-matching system is in a much more regulated one.

These rules only reach companies that meet the CCPA’s size thresholds: annual gross revenue above $25 million, buying or selling the personal information of 100,000 or more consumers or households, or drawing 50 percent or more of annual revenue from selling or sharing personal information.1Office of the Attorney General. California Consumer Privacy Act (CCPA) Smaller operators fall outside the CCPA even if their conduct would otherwise qualify.

One boundary worth naming: California’s framework does not set hard deadlines for destroying biometric records the way Illinois, Texas, and Colorado do. Those states require written retention schedules. California relies on general data-minimization principles and the consumer’s right to demand deletion.

Your Rights When a Company Collects Your Faceprint

If a covered business is scanning your face, California law gives you five concrete rights:

  • The right to know what categories of personal information it is gathering and what it plans to do with them, disclosed before or at the point of collection.
  • The right to have that biometric information deleted, with limited exceptions.
  • The right to opt out of the sale or sharing of your personal information, including through a browser-based global privacy control signal.
  • The right to limit use of your sensitive personal information to what is needed to provide the service you actually asked for.
  • The right to correct inaccurate personal information the business holds about you.

Businesses must respond to a verified request within 45 days.

Can Police in California Use Facial Recognition?

Yes. This is where public perception and current law diverge most sharply, so it’s worth being direct: as of 2026, no statewide California statute specifically bars law enforcement from using facial recognition technology.

The Body-Camera Ban Expired

In 2019, California enacted Assembly Bill 1215, prohibiting law enforcement agencies from using facial recognition or other biometric surveillance in connection with officer body cameras. The law was codified at Penal Code Section 832.19, and it reflected concerns about accuracy, particularly higher error rates when identifying people of color.2California Legislative Information. AB 1215 Law Enforcement Facial Recognition and Biometric Surveillance

The ban was temporary by design. Its sunset clause caused it to repeal automatically on January 1, 2023.3California Legislative Information. California Penal Code 832.19 The legislature did not renew it or pass a permanent replacement.

A Few Cities Have Their Own Bans

San Francisco was the first major American city to prohibit facial recognition use by city agencies, with its Board of Supervisors voting 8-to-1 for the Acquisition of Surveillance Technology Ordinance in 2019.4San Francisco Police Department. 19B Surveillance Technology Policies Oakland and Berkeley followed with their own bans on government use later that year. Those ordinances remain in force but only inside city limits.

Outside those cities, no state or local law specifically stops a police department from deploying facial recognition. Agencies remain subject to general constitutional constraints on searches and surveillance, and some have adopted voluntary internal policies, but there is no statutory backstop at the state level.

What Happens When a Business Breaks the Rules

Companies that mishandle facial recognition data face two kinds of financial exposure: administrative fines and civil enforcement actions.

The base statutory penalties under the CCPA are $2,500 per violation and $7,500 per intentional violation, adjusted periodically for inflation. Following the most recent adjustment announced in late 2024, those figures rose to $2,663 per violation and $7,988 per intentional violation or any violation involving a minor’s data.5California Privacy Protection Agency. California Privacy Protection Agency Announces 2025 Increases for CCPA Fines and Penalties Multiplied across thousands of consumer records, the numbers move fast.

The California Privacy Protection Agency, created by the CPRA and now the primary rulemaker for the CCPA/CPRA regulations it finalized in March 2023,6California Privacy Protection Agency. California Consumer Privacy Act Regulations can investigate complaints, conduct audits, and impose administrative fines. The Attorney General, along with district attorneys and city attorneys in California’s largest cities, can also bring civil actions. Courts may weigh a company’s good-faith cooperation when setting penalty amounts.

Suing After a Breach of Your Biometric Data

California law also gives you a personal right to sue, but only in a narrow situation: your biometric data is exposed in a data breach caused by a business’s failure to maintain reasonable security. Under Civil Code Section 1798.150, you can recover statutory damages between $100 and $750 per consumer per incident, your actual damages if higher, and injunctive relief.

Before filing for statutory damages, you must give the business 30 days’ written notice identifying the violation. If the business cures the problem within that window and provides a written statement confirming no further violations will occur, statutory damages are off the table for that breach. The notice requirement does not apply if you are suing only for actual financial losses.

This private right of action covers breaches, not every CCPA violation. If a business is scanning your face without proper disclosure and no breach has occurred, your remedy runs through the Privacy Protection Agency or the Attorney General, not the courts.

How to Use Your Rights

If you suspect a business is collecting your facial recognition data, submit a request to know what information the company holds about you. Once the business confirms, you can follow up with a deletion request or an instruction to stop selling or sharing that information. If the company ignores you or retaliates for the request, file a complaint with the California Privacy Protection Agency or the Attorney General’s office.

If your biometric data is caught up in a breach, talk to an attorney about Section 1798.150 before the 30-day notice period slips by. And because there is no statewide restriction on police use, your city’s rules do most of the work on the government side. If your city has not adopted a surveillance technology ordinance, that’s a live question worth taking to your council.