Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that identity or age verification processes may collect government-issued identity document images, photographic or video images of the user, and facial geometry templates, and acknowledges that facial geometry templates may qualify as biometric data under applicable law in certain jurisdictions.
This analysis describes what Anthropic's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that facial geometry template collection is within scope of Anthropic's data collection practices, and the policy's acknowledgment that such data may be classified as biometric data in some jurisdictions triggers compliance review obligations under state biometric privacy statutes that impose specific consent, retention, and destruction requirements.
Interpretive note: The policy does not specify in which circumstances verification is required, which third-party vendors process biometric data, or what the specific retention and destruction timeline for verification data is, leaving material compliance details unresolved.
Under this clause, users who complete identity or age verification may have facial geometry templates collected and processed; the agreement acknowledges these may constitute biometric data in some jurisdictions, though the specific retention period and destruction timeline for verification data are not detailed in the main policy text.
Cross-platform context
See how other platforms handle Biometric Data Collection via Identity Verification and similar clauses.
Compare across platforms →Monitoring
Anthropic has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Verification Data: In certain circumstances, we may ask you to verify your age or identity. If you choose to do so, data we will collect includes, depending on the method: an image of your government-issued identity document and the information appearing on it (such as your ID number and date of birth); your image in photo or video form, facial geometry templates (which may be considered 'biometric data' in some jurisdictions); and the result of the verification (for example, whether your age meets the applicable threshold).Excerpt from Anthropic's Privacy Policy (Superseded Capture)
REGULATORY LANDSCAPE: This provision directly implicates Illinois BIPA (740 ILCS 14), which requires written consent prior to biometric data collection, a publicly available retention and destruction policy, and prohibition on sale of biometric identifiers. Texas CUBI and Washington's biometric laws impose similar requirements. GDPR Article 9 classifies biometric data processed for identification purposes as a special category requiring explicit consent. The FTC and State Attorneys General are primary US enforcement authorities. GOVERNANCE EXPOSURE: High. BIPA carries a private right of action with statutory damages of $1,000 to $5,000 per violation, and Illinois courts have interpreted the statute broadly. The policy does not provide a standalone biometric data retention schedule or destruction policy as required by BIPA, which represents a potential compliance gap if users subject to Illinois jurisdiction complete verification. JURISDICTION FLAGS: Illinois (BIPA private right of action), Texas (CUBI enforcement by Texas AG), Washington (My Health MY Data Act and biometric law), EU and EEA (GDPR Article 9 special category data requiring explicit consent), UK (UK GDPR equivalent requirements). The policy's acknowledgment that facial geometry may be biometric data in some jurisdictions does not itself satisfy consent or disclosure requirements in those jurisdictions. CONTRACT AND VENDOR IMPLICATIONS: If biometric verification is performed by a third-party vendor (which the policy does not specify), BIPA and similar statutes impose obligations on the data controller regarding vendor contracts, including prohibitions on disclosure to third parties without consent. Procurement teams should confirm whether any verification vendor contracts include required BIPA-compliant data handling provisions. COMPLIANCE CONSIDERATIONS: Legal teams should audit whether the verification workflow includes a BIPA-compliant written consent mechanism prior to collection, a publicly accessible retention and destruction schedule, and assurance that biometric data is not sold or transferred to third parties. GDPR compliance review should confirm explicit consent is obtained for special category data processing before verification is initiated.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that facial geometry template collection is within scope of Anthropic's data collection practices, and the policy's acknowledgment that such data may be classified as biometric data in some jurisdictions triggers compliance review obligations under state biometric privacy statutes that impose specific consent, retention, and destruction requirements.
Under this clause, users who complete identity or age verification may have facial geometry templates collected and processed; the agreement acknowledges these may constitute biometric data in some jurisdictions, though the specific retention period and destruction timeline for verification data are not detailed in the main policy text.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Anthropic.