Provision record
Coursera · Coursera Privacy Notice · View original document ↗

Biometric Facial Data Collection and Retention

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Coursera changes these terms. Follow Coursera →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Coursera recorded 2 documented changes in the last 30 days.
Follow Coursera →
Monitor governance changes for Coursera Monitor emails you the same day this changes. The archive stays free.
Follow Coursera →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

When users enroll in identity-verified Services, a third-party vendor generates biometric facial data from a webcam headshot and photo ID; the notice states this biometric data is deleted upon successful verification or within 2 years at the latest. Supporting identity documents including name, address, date of birth, and photo ID are retained for up to 2 years and deleted upon request.

This analysis describes what Coursera's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that biometric facial data is generated by a third-party vendor and retained for up to 2 years in cases where verification is not successfully completed, creating compliance obligations under state biometric privacy statutes and GDPR Article 9 conditions for special category data processing.

Interpretive note: Compliance with specific state biometric privacy statutes depends on whether pre-collection written notice, consent, and retention schedule disclosures were provided to users, which the document does not fully detail.

Recent Activity

This document changed recently

Medium May 11, 2026

The updated terms now explicitly disclose that Coursera processes communications through voice-enabled features that transcribe audio into text, and clarify that personal data may be shared with third parties including affiliates and business partners. The policy expands descriptions of AI-driven personalization and chatbot applications that use your learning and interaction data. The terms establish that data may be transferred to entities that become Coursera affiliates or subsidiaries during business transitions. You should review the updated guidance that cautions against including unnecessary or sensitive personal data in the platform's free-text and voice-enabled communication features.

View change record →
Medium Apr 18, 2026

The updated Privacy Notice removes explicit language stating that the policy does not apply to Coursera's Ollie mobile application and no longer directs users to a separate Ollie Privacy Notice for that app. Previously, users of Ollie had clear notice to consult a dedicated privacy policy; that direction is now absent from the main Privacy Notice. The updated notice also narrows the scope of covered entities by removing 'affiliates' from the definition of Coursera, stating the policy now applies to Coursera, Inc., its subsidiaries, and international branches only. Users of the Ollie App should independently verify what privacy terms currently govern that application, as the main Coursera Privacy Notice no longer explicitly addresses Ollie coverage.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

This provision establishes that users who enroll in identity-verified services have biometric facial data generated by a third-party vendor, retained for up to 2 years, and that supporting identity documents are retained for up to 2 years unless a deletion request is submitted. The agreement states that explicit consent or another permitted condition under applicable law is required for biometric data processing.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Send an email to privacy@coursera.org requesting deletion of identity verification data including your name, address, date of birth, and photo identification document. Note that biometric facial data is stated to be deleted automatically upon successful verification.

Cross-platform context

See how other platforms handle Biometric Facial Data Collection and Retention and similar clauses.

Compare across platforms →

Monitoring

Coursera has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Coursera → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Coursera's third-party identity verification vendor may use this Personal Data to generate biometric facial data, which is destroyed upon successful completion of verification and in no event after 2 years. Additionally, if you apply for financial aid in connection with these Services, you may be required to provide information regarding your income. [...] Biometric facial data generated as part of the identity verification process is deleted upon successful completion of verification and in any event, no later than 2 years after collection. Other information uploaded as part of the identity verification process, including your name, address, date of birth, and a photo identification document, is deleted upon request and in any event, no later than 2 years after collection.

Excerpt from Coursera's Privacy Notice

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision implicates the Illinois Biometric Information Privacy Act (BIPA), Texas Capture or Use of Biometric Identifier Act (CUBI), Washington My Health MY Data Act, and GDPR Article 9 (special category data). The FTC has general enforcement authority over deceptive or unfair data practices; state attorneys general in Illinois, Texas, and Washington have enforcement authority under respective biometric statutes. The 2-year maximum retention period is consistent with BIPA's destruction schedule requirements, but compliance depends on whether written consent, retention schedule, and destruction policy disclosures were provided prior to collection. 2. GOVERNANCE EXPOSURE: High. Biometric data collection by a third-party vendor on behalf of Coursera creates principal-agent liability exposure under state biometric statutes. The notice states that explicit consent or another GDPR Article 9 condition is obtained, but does not specify the precise consent mechanism or whether written notice and a retention schedule are provided to users prior to collection as required under BIPA. 3. JURISDICTION FLAGS: Illinois (BIPA private right of action, statutory damages), Texas (CUBI attorney general enforcement), Washington (My Health MY Data Act), and EEA/UK (GDPR Article 9 explicit consent requirement) create heightened exposure. California does not currently have a standalone biometric statute but CCPA's sensitive personal information category covers biometric data. 4. CONTRACT AND VENDOR IMPLICATIONS: The provision discloses that biometric data is generated by a third-party identity verification vendor. Procurement teams should confirm that a data processing agreement with the vendor addresses biometric data destruction timelines, subprocessor obligations, and liability allocation. The notice does not name the identity verification vendor, which limits vendor-specific due diligence without further inquiry. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should audit the consent flow presented to users prior to identity verification enrollment to confirm it satisfies BIPA written consent, GDPR explicit consent, and applicable state law requirements. Data mapping should confirm the third-party vendor's biometric data destruction practices and timeline. Contractual provisions with the vendor should be reviewed to confirm they align with the 2-year maximum retention stated in the notice.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has enforcement authority over unfair or deceptive data practices, including third-party biometric data collection and retention disclosures.
    File a complaint →
  • State AG
    State attorneys general in Illinois, Texas, and Washington have enforcement authority under biometric privacy statutes implicated by this provision.
    File a complaint →

Provision details

Document information
Document
Coursera Privacy Notice
Entity
Coursera
Document last updated
May 5, 2026
Tracking information
First tracked
May 21, 2026
Last verified
July 9, 2026
Record ID
CA-P-016024
Document ID
CA-D-00158
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
3c5d29b9e68e11ce59e899d357a4125c9cdd43a884fc699ab73522c51379edab
Analysis generated
May 21, 2026 05:07 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Coursera
Document: Coursera Privacy Notice
Record ID: CA-P-016024
Captured: 2026-05-21 05:07:28 UTC
SHA-256: 3c5d29b9e68e11ce…
URL: https://conductatlas.com/platform/coursera/coursera-privacy-notice/provision/CA-P-016024/biometric-facial-data-collection-and-retention/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Coursera's Biometric Facial Data Collection and Retention clause do?

This provision establishes that biometric facial data is generated by a third-party vendor and retained for up to 2 years in cases where verification is not successfully completed, creating compliance obligations under state biometric privacy statutes and GDPR Article 9 conditions for special category data processing.

How does this clause affect you?

This provision establishes that users who enroll in identity-verified services have biometric facial data generated by a third-party vendor, retained for up to 2 years, and that supporting identity documents are retained for up to 2 years unless a deletion request is submitted. The agreement states that explicit consent or another permitted condition under applicable law is required for biometric …

Is ConductAtlas affiliated with Coursera?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Coursera.