Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
When users enroll in identity-verified Services, a third-party vendor generates biometric facial data from a webcam headshot and photo ID; the notice states this biometric data is deleted upon successful verification or within 2 years at the latest. Supporting identity documents including name, address, date of birth, and photo ID are retained for up to 2 years and deleted upon request.
This analysis describes what Coursera's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that biometric facial data is generated by a third-party vendor and retained for up to 2 years in cases where verification is not successfully completed, creating compliance obligations under state biometric privacy statutes and GDPR Article 9 conditions for special category data processing.
Interpretive note: Compliance with specific state biometric privacy statutes depends on whether pre-collection written notice, consent, and retention schedule disclosures were provided to users, which the document does not fully detail.
The updated terms now explicitly disclose that Coursera processes communications through voice-enabled features that transcribe audio into text, and clarify that personal data may be shared with third parties including affiliates and business partners. The policy expands descriptions of AI-driven personalization and chatbot applications that use your learning and interaction data. The terms establish that data may be transferred to entities that become Coursera affiliates or subsidiaries during business transitions. You should review the updated guidance that cautions against including unnecessary or sensitive personal data in the platform's free-text and voice-enabled communication features.
View change record →The updated Privacy Notice removes explicit language stating that the policy does not apply to Coursera's Ollie mobile application and no longer directs users to a separate Ollie Privacy Notice for that app. Previously, users of Ollie had clear notice to consult a dedicated privacy policy; that direction is now absent from the main Privacy Notice. The updated notice also narrows the scope of covered entities by removing 'affiliates' from the definition of Coursera, stating the policy now applies to Coursera, Inc., its subsidiaries, and international branches only. Users of the Ollie App should independently verify what privacy terms currently govern that application, as the main Coursera Privacy Notice no longer explicitly addresses Ollie coverage.
View change record →This provision establishes that users who enroll in identity-verified services have biometric facial data generated by a third-party vendor, retained for up to 2 years, and that supporting identity documents are retained for up to 2 years unless a deletion request is submitted. The agreement states that explicit consent or another permitted condition under applicable law is required for biometric data processing.
Cross-platform context
See how other platforms handle Biometric Facial Data Collection and Retention and similar clauses.
Compare across platforms →Monitoring
Coursera has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Coursera's third-party identity verification vendor may use this Personal Data to generate biometric facial data, which is destroyed upon successful completion of verification and in no event after 2 years. Additionally, if you apply for financial aid in connection with these Services, you may be required to provide information regarding your income. [...] Biometric facial data generated as part of the identity verification process is deleted upon successful completion of verification and in any event, no later than 2 years after collection. Other information uploaded as part of the identity verification process, including your name, address, date of birth, and a photo identification document, is deleted upon request and in any event, no later than 2 years after collection.Excerpt from Coursera's Privacy Notice
1. REGULATORY LANDSCAPE: This provision implicates the Illinois Biometric Information Privacy Act (BIPA), Texas Capture or Use of Biometric Identifier Act (CUBI), Washington My Health MY Data Act, and GDPR Article 9 (special category data). The FTC has general enforcement authority over deceptive or unfair data practices; state attorneys general in Illinois, Texas, and Washington have enforcement authority under respective biometric statutes. The 2-year maximum retention period is consistent with BIPA's destruction schedule requirements, but compliance depends on whether written consent, retention schedule, and destruction policy disclosures were provided prior to collection. 2. GOVERNANCE EXPOSURE: High. Biometric data collection by a third-party vendor on behalf of Coursera creates principal-agent liability exposure under state biometric statutes. The notice states that explicit consent or another GDPR Article 9 condition is obtained, but does not specify the precise consent mechanism or whether written notice and a retention schedule are provided to users prior to collection as required under BIPA. 3. JURISDICTION FLAGS: Illinois (BIPA private right of action, statutory damages), Texas (CUBI attorney general enforcement), Washington (My Health MY Data Act), and EEA/UK (GDPR Article 9 explicit consent requirement) create heightened exposure. California does not currently have a standalone biometric statute but CCPA's sensitive personal information category covers biometric data. 4. CONTRACT AND VENDOR IMPLICATIONS: The provision discloses that biometric data is generated by a third-party identity verification vendor. Procurement teams should confirm that a data processing agreement with the vendor addresses biometric data destruction timelines, subprocessor obligations, and liability allocation. The notice does not name the identity verification vendor, which limits vendor-specific due diligence without further inquiry. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should audit the consent flow presented to users prior to identity verification enrollment to confirm it satisfies BIPA written consent, GDPR explicit consent, and applicable state law requirements. Data mapping should confirm the third-party vendor's biometric data destruction practices and timeline. Contractual provisions with the vendor should be reviewed to confirm they align with the 2-year maximum retention stated in the notice.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes that biometric facial data is generated by a third-party vendor and retained for up to 2 years in cases where verification is not successfully completed, creating compliance obligations under state biometric privacy statutes and GDPR Article 9 conditions for special category data processing.
This provision establishes that users who enroll in identity-verified services have biometric facial data generated by a third-party vendor, retained for up to 2 years, and that supporting identity documents are retained for up to 2 years unless a deletion request is submitted. The agreement states that explicit consent or another permitted condition under applicable law is required for biometric …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Coursera.