DraftKings authorizes vendors Onfido and Socure to collect and process facial scan data from users' government ID photos and selfie photos or videos for identity verification, with retention scheduled for up to three years following a user's last interaction with the verification provider. Users may revoke consent by emailing privacy@draftkings.com, though doing so may limit their ability to complete verification required to access services.
This analysis describes what DraftKings's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes collection and retention of biometric identifiers by named third-party processors under a consent framework, with a stated retention period of up to three years post-last interaction. This schedule and the consent mechanism require evaluation under state biometric privacy statutes including Illinois BIPA, Texas CUBI, and Washington MHMDA, which impose specific written consent, publicly available retention schedule, and destruction obligation requirements that may differ from the terms stated in this notice.
Interpretive note: Compliance with applicable state biometric statutes depends on whether the consent mechanism and retention schedule stated in the notice satisfy jurisdiction-specific written consent and destruction requirements, which vary by state and are not fully resolved by the document language alone.
This provision establishes that facial scan data extracted from government-issued ID documents and user-submitted selfies is collected and stored by Onfido or Socure for up to three years following the user's last interaction with the provider. Under this clause, users who decline or revoke consent may find their ability to complete account verification and access certain services limited.
Cross-platform context
See how other platforms handle Biometric Facial Scan Collection and Retention and similar clauses.
Compare across platforms →"With your consent, we may use facial image scan services provided by our vendors (including, for example, Onfido and Socure) to help verify your identity. These biometric identity verification providers and their contractors compare facial scan data extracted from your photo in your ID (e.g., driver's license) to the facial scan data extracted from the selfie photo or video you upload, and then report back to us whether or not there is a match. These scans and associated results may constitute biometric information or biometric identifiers under certain laws. Any biometric identifier/information or representation of it will be processed based on your consent and collected, stored, and managed by Onfido, Socure, or the applicable biometric identity verification provider. Biometric data collected and processed for our verification purposes is scheduled to be retained until the earlier of when verification is complete or for up to three (3) years following your last interaction with the biometric identity verification provider, unless otherwise set forth at the time you provide consent or unless otherwise required by law or legal process.Excerpt from DraftKings's Privacy Policy
1) REGULATORY LANDSCAPE: This provision implicates Illinois BIPA (740 ILCS 14), Texas Capture or Use of Biometric Identifier Act (CUBI), Washington My Health MY Data Act, and potentially New York and other state biometric statutes.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision authorizes collection and retention of biometric identifiers by named third-party processors under a consent framework, with a stated retention period of up to three years post-last interaction. This schedule and the consent mechanism require evaluation under state biometric privacy statutes including Illinois BIPA, Texas CUBI, and Washington MHMDA, which impose specific written consent, publicly available retention schedule, and …
This provision establishes that facial scan data extracted from government-issued ID documents and user-submitted selfies is collected and stored by Onfido or Socure for up to three years following the user's last interaction with the provider. Under this clause, users who decline or revoke consent may find their ability to complete account verification and access certain services limited.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by DraftKings.