Anthropic · Anthropic Privacy Policy (Superseded Capture) · View original document ↗

Biometric Data Collection via Identity Verification

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Anthropic changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Anthropic recorded 3 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Anthropic Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy discloses that identity or age verification processes may collect government-issued identity document images, photographic or video images of the user, and facial geometry templates, and acknowledges that facial geometry templates may qualify as biometric data under applicable law in certain jurisdictions.

This analysis describes what Anthropic's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that facial geometry template collection is within scope of Anthropic's data collection practices, and the policy's acknowledgment that such data may be classified as biometric data in some jurisdictions triggers compliance review obligations under state biometric privacy statutes that impose specific consent, retention, and destruction requirements.

Interpretive note: The policy does not specify in which circumstances verification is required, which third-party vendors process biometric data, or what the specific retention and destruction timeline for verification data is, leaving material compliance details unresolved.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, users who complete identity or age verification may have facial geometry templates collected and processed; the agreement acknowledges these may constitute biometric data in some jurisdictions, though the specific retention period and destruction timeline for verification data are not detailed in the main policy text.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Submit a deletion request for verification data, including any biometric data collected, by emailing privacy@anthropic.com with sufficient information to verify your identity.

Cross-platform context

See how other platforms handle Biometric Data Collection via Identity Verification and similar clauses.

Compare across platforms →

Monitoring

Anthropic has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Verification Data: In certain circumstances, we may ask you to verify your age or identity. If you choose to do so, data we will collect includes, depending on the method: an image of your government-issued identity document and the information appearing on it (such as your ID number and date of birth); your image in photo or video form, facial geometry templates (which may be considered 'biometric data' in some jurisdictions); and the result of the verification (for example, whether your age meets the applicable threshold).

Excerpt from Anthropic's Privacy Policy (Superseded Capture)

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: This provision directly implicates Illinois BIPA (740 ILCS 14), which requires written consent prior to biometric data collection, a publicly available retention and destruction policy, and prohibition on sale of biometric identifiers. Texas CUBI and Washington's biometric laws impose similar requirements. GDPR Article 9 classifies biometric data processed for identification purposes as a special category requiring explicit consent. The FTC and State Attorneys General are primary US enforcement authorities. GOVERNANCE EXPOSURE: High. BIPA carries a private right of action with statutory damages of $1,000 to $5,000 per violation, and Illinois courts have interpreted the statute broadly. The policy does not provide a standalone biometric data retention schedule or destruction policy as required by BIPA, which represents a potential compliance gap if users subject to Illinois jurisdiction complete verification. JURISDICTION FLAGS: Illinois (BIPA private right of action), Texas (CUBI enforcement by Texas AG), Washington (My Health MY Data Act and biometric law), EU and EEA (GDPR Article 9 special category data requiring explicit consent), UK (UK GDPR equivalent requirements). The policy's acknowledgment that facial geometry may be biometric data in some jurisdictions does not itself satisfy consent or disclosure requirements in those jurisdictions. CONTRACT AND VENDOR IMPLICATIONS: If biometric verification is performed by a third-party vendor (which the policy does not specify), BIPA and similar statutes impose obligations on the data controller regarding vendor contracts, including prohibitions on disclosure to third parties without consent. Procurement teams should confirm whether any verification vendor contracts include required BIPA-compliant data handling provisions. COMPLIANCE CONSIDERATIONS: Legal teams should audit whether the verification workflow includes a BIPA-compliant written consent mechanism prior to collection, a publicly accessible retention and destruction schedule, and assurance that biometric data is not sold or transferred to third parties. GDPR compliance review should confirm explicit consent is obtained for special category data processing before verification is initiated.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • State AG
    State Attorneys General in Illinois, Texas, and Washington have enforcement authority over biometric privacy statutes including BIPA, CUBI, and state biometric laws that may apply to facial geometry template collection.
    File a complaint →

Provision details

Document information
Document
Anthropic Privacy Policy (Superseded Capture)
Entity
Anthropic
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016552
Document ID
CA-D-00012
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
e91b78d120f18b8a635385fb036a9ad6b0135fe530a2e4aadcc4d575da32fca0
Analysis generated
July 9, 2026 17:12 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Anthropic
Document: Anthropic Privacy Policy (Superseded Capture)
Record ID: CA-P-016552
Captured: 2026-07-09 17:12:50 UTC
SHA-256: e91b78d120f18b8a…
URL: https://conductatlas.com/platform/anthropic/anthropic-privacy-policy-superseded-capture/provision/CA-P-016552/biometric-data-collection-via-identity-verification/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Anthropic's Biometric Data Collection via Identity Verification clause do?

This provision establishes that facial geometry template collection is within scope of Anthropic's data collection practices, and the policy's acknowledgment that such data may be classified as biometric data in some jurisdictions triggers compliance review obligations under state biometric privacy statutes that impose specific consent, retention, and destruction requirements.

How does this clause affect you?

Under this clause, users who complete identity or age verification may have facial geometry templates collected and processed; the agreement acknowledges these may constitute biometric data in some jurisdictions, though the specific retention period and destruction timeline for verification data are not detailed in the main policy text.

Is ConductAtlas affiliated with Anthropic?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Anthropic.