Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that Thomson Reuters collects biometric data including fingerprints and facial geometry scans, and states that such data will be permanently destroyed within the timeframe specified by applicable law or when the collection purpose ends, whichever comes first.
This analysis describes what Thomson Reuters's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes biometric data collection and a destruction schedule tied to legal timelines or cessation of purpose, triggering obligations under the Illinois Biometric Information Privacy Act and analogous statutes in Texas, Washington, and other states that impose specific written consent, retention schedule, and destruction requirements before or at the point of collection.
Interpretive note: The statement does not specify the consent mechanism employed prior to biometric data collection, leaving open whether collection practices satisfy BIPA's written release requirement and analogous state law obligations.
This provision authorizes collection of fingerprints and facial geometry scans and establishes that destruction occurs when the collection purpose ends or within the legally mandated timeframe. Under this clause, individuals whose biometric data is collected should be subject to applicable state-law notice and consent requirements prior to collection, though the statement does not specify the consent mechanism used.
Cross-platform context
See how other platforms handle Biometric Data Collection and Destruction and similar clauses.
Compare across platforms →Monitoring
Thomson Reuters has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Biometric data Fingerprints, scans of face geometry, and other data generated by automatic measurements of an individual's physiological, biological, or behavioral characteristics... We take steps to permanently destroy any biometric data we maintain within the applicable timeframe specified by law or when it is no longer necessary to achieve the purpose for which it was collected or obtained, whichever occurs first.Excerpt from Thomson Reuters's Privacy
1) REGULATORY LANDSCAPE: This provision directly implicates the Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14), which requires written release prior to collection, a publicly available retention policy, and destruction within three years or when the purpose ends. Texas Business and Commerce Code Chapter 503 and Washington's My Health MY Data Act engage analogous requirements. GDPR Article 9 classifies biometric data as a special category requiring explicit consent or another enumerated lawful basis. The FTC has enforcement authority over deceptive or unfair data practices at the federal level. 2) GOVERNANCE EXPOSURE: High. The statement discloses biometric data collection across locations and events, including CCTV and security camera footage, without specifying the consent mechanism employed prior to collection. BIPA's private right of action, which has generated significant class action litigation, creates heightened exposure if written consent and public retention schedules are not demonstrably in place before collection occurs. 3) JURISDICTION FLAGS: Illinois creates the highest litigation exposure due to BIPA's private right of action. Texas and Washington impose regulatory enforcement obligations. EU and UK operations must treat biometric data as a special category under GDPR and UK GDPR, requiring explicit consent or another Article 9 basis. California's CPRA designates certain biometric data as sensitive personal information subject to opt-out rights. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams engaging Thomson Reuters as a vendor should confirm whether their personnel's biometric data may be collected at Thomson Reuters offices or events and whether applicable state-law disclosures and consents have been obtained. Vendor contracts should specify which entities within the Thomson Reuters group are responsible for biometric data processing and destruction obligations. 5) COMPLIANCE CONSIDERATIONS: Legal teams should request documentation of the consent mechanisms and retention schedules Thomson Reuters maintains for biometric data collection, particularly for Illinois-based employees, contractors, and event attendees. Data mapping exercises should identify which specific products and locations collect biometric data to assess BIPA applicability. Policies governing third-party event vendors who may separately collect biometric data at Thomson Reuters events warrant review.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes biometric data collection and a destruction schedule tied to legal timelines or cessation of purpose, triggering obligations under the Illinois Biometric Information Privacy Act and analogous statutes in Texas, Washington, and other states that impose specific written consent, retention schedule, and destruction requirements before or at the point of collection.
This provision authorizes collection of fingerprints and facial geometry scans and establishes that destruction occurs when the collection purpose ends or within the legally mandated timeframe. Under this clause, individuals whose biometric data is collected should be subject to applicable state-law notice and consent requirements prior to collection, though the statement does not specify the consent mechanism used.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Thomson Reuters.