Thomson Reuters · Thomson Reuters Privacy · View original document ↗

Biometric Data Collection and Destruction

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Thomson Reuters changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Thomson Reuters recorded 8 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Thomson Reuters Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy discloses that Thomson Reuters collects biometric data including fingerprints and facial geometry scans, and states that such data will be permanently destroyed within the timeframe specified by applicable law or when the collection purpose ends, whichever comes first.

This analysis describes what Thomson Reuters's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes biometric data collection and a destruction schedule tied to legal timelines or cessation of purpose, triggering obligations under the Illinois Biometric Information Privacy Act and analogous statutes in Texas, Washington, and other states that impose specific written consent, retention schedule, and destruction requirements before or at the point of collection.

Interpretive note: The statement does not specify the consent mechanism employed prior to biometric data collection, leaving open whether collection practices satisfy BIPA's written release requirement and analogous state law obligations.

Consumer impact (what this means for users)

This provision authorizes collection of fingerprints and facial geometry scans and establishes that destruction occurs when the collection purpose ends or within the legally mandated timeframe. Under this clause, individuals whose biometric data is collected should be subject to applicable state-law notice and consent requirements prior to collection, though the statement does not specify the consent mechanism used.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Submit a deletion request through the Thomson Reuters Data Subject Rights Portal, or email privacy.issues@thomsonreuters.com, or call 866-633-7656 to request deletion of biometric data.

Cross-platform context

See how other platforms handle Biometric Data Collection and Destruction and similar clauses.

Compare across platforms →

Monitoring

Thomson Reuters has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Biometric data Fingerprints, scans of face geometry, and other data generated by automatic measurements of an individual's physiological, biological, or behavioral characteristics... We take steps to permanently destroy any biometric data we maintain within the applicable timeframe specified by law or when it is no longer necessary to achieve the purpose for which it was collected or obtained, whichever occurs first.

Excerpt from Thomson Reuters's Privacy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision directly implicates the Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14), which requires written release prior to collection, a publicly available retention policy, and destruction within three years or when the purpose ends. Texas Business and Commerce Code Chapter 503 and Washington's My Health MY Data Act engage analogous requirements. GDPR Article 9 classifies biometric data as a special category requiring explicit consent or another enumerated lawful basis. The FTC has enforcement authority over deceptive or unfair data practices at the federal level. 2) GOVERNANCE EXPOSURE: High. The statement discloses biometric data collection across locations and events, including CCTV and security camera footage, without specifying the consent mechanism employed prior to collection. BIPA's private right of action, which has generated significant class action litigation, creates heightened exposure if written consent and public retention schedules are not demonstrably in place before collection occurs. 3) JURISDICTION FLAGS: Illinois creates the highest litigation exposure due to BIPA's private right of action. Texas and Washington impose regulatory enforcement obligations. EU and UK operations must treat biometric data as a special category under GDPR and UK GDPR, requiring explicit consent or another Article 9 basis. California's CPRA designates certain biometric data as sensitive personal information subject to opt-out rights. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams engaging Thomson Reuters as a vendor should confirm whether their personnel's biometric data may be collected at Thomson Reuters offices or events and whether applicable state-law disclosures and consents have been obtained. Vendor contracts should specify which entities within the Thomson Reuters group are responsible for biometric data processing and destruction obligations. 5) COMPLIANCE CONSIDERATIONS: Legal teams should request documentation of the consent mechanisms and retention schedules Thomson Reuters maintains for biometric data collection, particularly for Illinois-based employees, contractors, and event attendees. Data mapping exercises should identify which specific products and locations collect biometric data to assess BIPA applicability. Policies governing third-party event vendors who may separately collect biometric data at Thomson Reuters events warrant review.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has jurisdiction over Thomson Reuters' compliance with the EU-U.S. Data Privacy Framework and general unfair or deceptive data practices, including biometric data handling.
    File a complaint →
  • State AG
    Illinois, Texas, Washington, and California state attorneys general have enforcement authority over biometric data collection practices under BIPA and analogous state statutes.
    File a complaint →

Provision details

Document information
Document
Thomson Reuters Privacy
Entity
Thomson Reuters
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016229
Document ID
CA-D-00720
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
a83ee18dfe057088713d3b01069b111c1d70ed7020e69dee5af3cc20ec960afb
Analysis generated
July 9, 2026 09:54 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Thomson Reuters
Document: Thomson Reuters Privacy
Record ID: CA-P-016229
Captured: 2026-07-09 09:54:14 UTC
SHA-256: a83ee18dfe057088…
URL: https://conductatlas.com/platform/thomson-reuters/thomson-reuters-privacy/provision/CA-P-016229/biometric-data-collection-and-destruction/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Thomson Reuters's Biometric Data Collection and Destruction clause do?

This provision establishes biometric data collection and a destruction schedule tied to legal timelines or cessation of purpose, triggering obligations under the Illinois Biometric Information Privacy Act and analogous statutes in Texas, Washington, and other states that impose specific written consent, retention schedule, and destruction requirements before or at the point of collection.

How does this clause affect you?

This provision authorizes collection of fingerprints and facial geometry scans and establishes that destruction occurs when the collection purpose ends or within the legally mandated timeframe. Under this clause, individuals whose biometric data is collected should be subject to applicable state-law notice and consent requirements prior to collection, though the statement does not specify the consent mechanism used.

Is ConductAtlas affiliated with Thomson Reuters?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Thomson Reuters.