Alabama
Alabama Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Alabama has no standalone biometric privacy law in effect today, and its Data Breach Notification Act (Ala. Code 8-38-1 et seq.) does not list biometric data among the categories that trigger a breach notice. That changes on May 1, 2027, when the Alabama Personal Data Protection Act (HB 351, signed into law April 2026) takes effect and classifies biometric data processed to identify a specific person as sensitive data requiring a consumer''s opt-in consent.
Alabama does not have a standalone biometric privacy law. Unlike Illinois, Texas, and Washington, the state has not enacted legislation that specifically regulates how private businesses collect, store, use, or share biometric identifiers such as fingerprints, facial geometry, or iris scans.
Alabama''s breach notification law does not include biometric data in its definition of protected sensitive personally identifying information, so a breach exposing only biometric identifiers does not, by itself, trigger a notice obligation under current law. That gap narrows in 2027, when the Alabama Personal Data Protection Act begins treating biometric data used to identify a person as sensitive data requiring opt-in consent before it can be processed.
This guide explains the current legal framework, what protections exist, where the gaps are, and what may change.
For broader context on Alabama''s overall privacy framework, see the parent guide to Alabama Data Privacy Laws.
How Alabama Defines Biometric Data
Alabama''s Data Breach Notification Act does not currently define biometric data at all. Ala. Code 8-38-2 defines "sensitive personally identifying information" as a person''s first name or initial and last name combined with categories such as a Social Security number, a driver''s license or state ID number, a financial account number with a security code, medical history or health-insurance information, or a username or email address paired with a password. Biometric identifiers such as fingerprints, voiceprints, or retina and iris images are not among the enumerated categories, so a breach that exposes only biometric data does not by itself trigger the Act''s 45-day notice requirement.
That changes on May 1, 2027, when the Alabama Personal Data Protection Act (HB 351, signed into law April 2026) takes effect. It defines biometric data as data generated by automatic measurements of an individual''s biological characteristics, such as a fingerprint, voiceprint, retina, or iris, used to identify a specific person, and classifies it as sensitive data. Covered businesses will need a consumer''s affirmative opt-in consent before processing it.
Until then, biometric data collected in Alabama can still receive indirect protection if it is combined with other information the Act does cover, such as a name plus a financial account number, but the biometric identifier itself is not the trigger.
Alabama Data Breach Notification Act of 2018 (Ala. Code 8-38-1 et seq.)
Alabama''s primary biometric protection comes from the Data Breach Notification Act of 2018, signed into law as Acts 2018-396. This law was among the last state breach notification laws enacted in the United States. Alabama and South Dakota were the final two states to adopt breach notification requirements.
What the Law Requires
Any covered entity that acquires or uses sensitive personally identifying information of Alabama residents must follow several requirements under this law.
Reasonable security measures. Covered entities must implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security (Ala. Code 8-38-3).
Good faith investigation. After discovering or being notified of a breach, a covered entity must conduct a good faith and prompt investigation to determine the likelihood that the information has been or will be misused.
Individual notification within 45 days. If a breach compromises information within the Act''s definition of sensitive personally identifying information, such as a name combined with a Social Security number, financial account number, or medical information, and is reasonably likely to cause substantial harm, the entity must notify affected Alabama residents as expeditiously as possible but no later than 45 days after the determination that a breach occurred (Ala. Code 8-38-5). Biometric data alone, without a name and one of the Act''s other enumerated categories, does not trigger this requirement under current law.
Attorney General notification. If the breach affects more than 1,000 individuals, the entity must also notify the Alabama Attorney General within 45 days.
Third-party agent notification. Third-party agents that maintain data on behalf of a covered entity must notify the covered entity within 10 days of discovering a breach.
Penalties for Non-Compliance
A covered entity that fails to comply with notification requirements faces penalties under Ala. Code 8-38-9.
Civil penalties can reach up to $5,000 per day for each consecutive day that the entity fails to take reasonable action to comply with the notification requirements. The total civil penalty is capped at $500,000 per breach.
A violation of the Act constitutes an unlawful trade practice under the Alabama Deceptive Trade Practices Act (Ala. Code 8-19-1 et seq.).
The Alabama Attorney General holds exclusive authority to bring enforcement actions for civil penalties and to pursue damages on behalf of named individuals. Recovery in such actions is limited to actual damages plus reasonable attorney fees and costs.
No Private Right of Action
Alabama''s breach notification law does not create a private cause of action. Individuals cannot sue a covered entity directly under this statute for failing to provide timely notification. Only the Attorney General can bring enforcement actions.
This is a significant distinction from states like Illinois, where BIPA grants individuals the right to sue and recover statutory damages of $1,000 to $5,000 per violation.
Exemptions
The law includes several exemptions. Information that has been encrypted, secured, or modified by any method or technology that removes personally identifying elements or renders the information unusable is excluded from the definition of sensitive personally identifying information.
Financial institutions that comply with the Gramm-Leach-Bliley Act and entities that comply with HIPAA are deemed in compliance with Alabama''s security requirements.
What Alabama Law Does Not Cover
Alabama''s existing laws leave significant gaps in biometric privacy protection.
No general consent requirement. Alabama does not require businesses or employers to obtain consent before collecting biometric data from adults. An employer can implement fingerprint time clocks or facial recognition systems without notifying employees or getting their approval.
No retention or destruction timelines. The state does not mandate specific retention schedules or destruction timelines for biometric data held by private entities.
No restrictions on biometric data sales. Alabama does not prohibit or restrict the sale or sharing of biometric data with third parties.
No private right of action for collection practices. There is no state law allowing individuals to sue because a company collected their fingerprints or facial scans without consent.
No law enforcement restrictions. Alabama has not enacted limits on government or law enforcement use of facial recognition or other biometric surveillance technologies.
Employer Use of Biometric Data in Alabama
Alabama has no state law that restricts employers from collecting biometric data from employees. Companies operating in Alabama that use fingerprint scanners for timekeeping, facial recognition for building access, or other biometric systems are not required by state law to:
- Provide written notice before collecting biometric data
- Obtain employee consent
- Establish data retention or destruction policies
- Limit sharing of employee biometric data with vendors or third parties
This stands in sharp contrast to Illinois, where employers face statutory damages of $1,000 to $5,000 per violation of the Biometric Information Privacy Act.
That said, employers should still implement reasonable security measures for biometric data as a matter of practice. Under current Alabama law, a breach that exposes only employee biometric data does not by itself trigger the Data Breach Notification Act''s 45-day notice requirement, since biometric data is not among the Act''s enumerated categories; the duty applies only if the biometric data is exposed together with a name and one of the Act''s other covered categories, such as a Social Security or financial account number.
Alabama's New Comprehensive Privacy Law: What Changes for Biometric Data in 2027
Alabama enacted its first comprehensive consumer privacy law in 2026, and it directly addresses biometric data in a way the 2018 breach notification law does not.
HB 351, the Alabama Personal Data Protection Act (APDPA). The Alabama Legislature passed HB 351 in April 2026, and the governor signed it into law that same month. The Act takes effect May 1, 2027, and applies to businesses that control or process the personal data of more than 25,000 Alabama residents, or that derive more than 25 percent of gross revenue from selling personal data. The APDPA classifies genetic or biometric data processed to uniquely identify a person as sensitive data, and it prohibits a covered controller from processing sensitive data without first obtaining the consumer''s affirmative opt-in consent.
Two earlier bills did not become this law. SB272 (2026 Regular Session), introduced by Senator Orr, proposed narrower amendments to Alabama''s data protection framework and did not advance. HB283 (2025 Regular Session) proposed an earlier version of a comprehensive privacy framework and also did not pass. HB 351 is the bill that succeeded.
Once the APDPA takes effect, Alabama''s biometric data protection will move closer to the opt-in consent model used by states like Colorado, Connecticut, and Virginia, though Alabama''s law will only apply to businesses that meet its size or revenue thresholds.
Federal Protections That Apply in Alabama
Because Alabama lacks a comprehensive biometric privacy law, federal statutes provide additional protections for residents.
Section 5 of the FTC Act allows the Federal Trade Commission to take enforcement action against companies engaged in unfair or deceptive practices involving biometric data, including failures to secure biometric information.
HIPAA protects biometric data collected or used by covered healthcare entities and their business associates under the Privacy Rule.
COPPA requires parental consent before collecting biometric data from children under 13, enforced by the FTC.
How Alabama Compares to Other States
Alabama falls into a lower tier of states for biometric privacy protection today, though that will change in 2027. Because Alabama''s breach notification law does not separately cover biometric data, and because the state''s new comprehensive privacy law will not take effect until May 2027, Alabama currently lacks both breach-notification coverage and the collection-level protections found in more protective states.
- Illinois has the strongest biometric law in the nation (BIPA), with a private right of action and statutory damages of $1,000 to $5,000 per violation
- Texas and Washington have biometric-specific statutes enforced by their attorneys general
- States with comprehensive privacy laws (Colorado, Connecticut, Virginia) classify biometric data as sensitive and require opt-in consent
- Alabama currently has no biometric-specific protection; a breach exposing only biometric data does not trigger its 2018 breach notification law. Starting May 1, 2027, the Alabama Personal Data Protection Act will require opt-in consent for biometric data processed by covered businesses
This article provides general legal information about Alabama biometric privacy laws. It is not legal advice. Laws and regulations change frequently, and this content may not reflect the most recent developments. Consult a qualified attorney licensed in Alabama for advice about your specific situation.
More Alabama Laws
Frequently Asked Questions
Does Alabama have a biometric privacy law?
Not yet in a comprehensive way. Alabama does not have a standalone biometric privacy statute like Illinois BIPA, and its Data Breach Notification Act of 2018 (Ala. Code 8-38-1 et seq.) does not include biometric data among the categories that trigger a breach notice. That changes on May 1, 2027, when the Alabama Personal Data Protection Act (HB 351, enacted 2026) takes effect and requires covered businesses to obtain opt-in consent before processing biometric data used to identify a person.
Can my employer collect my fingerprints without consent in Alabama?
Yes, under current law. Alabama has no statute requiring employers to obtain consent before collecting biometric data such as fingerprints or facial scans from employees, and employers can implement fingerprint time clocks, facial recognition access systems, or other biometric tools without providing written notice or obtaining approval. A breach that exposes only biometric data does not by itself trigger a notification duty under Alabama''s current breach notification law. Starting May 1, 2027, larger employers covered by the Alabama Personal Data Protection Act will need opt-in consent before processing biometric data to identify an employee.
What are the penalties for a biometric data breach in Alabama?
Alabama''s Data Breach Notification Act does not treat a breach of biometric data alone as a reportable breach, so its penalties apply only if the biometric data was exposed together with a name and another covered category, such as a Social Security or financial account number. In that scenario, a covered entity that fails to comply with the notification requirements faces civil penalties of up to $5,000 per day for each consecutive day of non-compliance, with a maximum cap of $500,000 per breach, and the Attorney General has exclusive enforcement authority. Starting May 1, 2027, the Alabama Personal Data Protection Act adds separate consent obligations for biometric data, also enforced by the Attorney General.
Can I sue a company in Alabama for collecting my biometric data without permission?
No. Alabama does not provide a private right of action for the unauthorized collection of biometric data. The state''s breach notification law also does not allow individuals to sue directly. Only the Alabama Attorney General can bring enforcement actions. This differs from Illinois, where individuals can recover $1,000 to $5,000 per violation of the Biometric Information Privacy Act.
Does Alabama require businesses to delete biometric data?
No. Alabama does not have a law that requires businesses to delete biometric data after a specific period or upon request. The state has no retention schedule or destruction mandate for biometric information held by private entities. The only data-related destruction requirement exists within the breach notification framework, which focuses on notification obligations rather than data lifecycle management.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the page's central premise: Alabama's Data Breach Notification Act (Ala. Code 8-38-2) does not define or cover biometric data, so a biometric-only breach does not trigger the 45-day notice. Added the real, newly enacted protection: the Alabama Personal Data Protection Act (HB 351, signed April 2026, effective May 1, 2027) classifies biometric data as sensitive data requiring opt-in consent. Also swapped two competitor-domain (Justia) citations for official Alabama Legislature sources.
Governing law re-checked for recent changes
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 6 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Code of Alabama 1975, Title 8: Commercial Law and Consumer Protection.
§ 8-19-1Short Title.In forcecited in 2 of our articles
This chapter shall be known and may be cited as the “Deceptive Trade Practices Act.”
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
Also relied on in: Alabama Data Privacy Laws: Breach Notification & Consumer Rights (2026)
§ 8-38-1Short Title.In forcecited in 3 of our articles
This chapter may be cited and shall be known as the Alabama Data Breach Notification Act of 2018.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
Also relied on in: Alabama Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 8-38-2Definitions.In forcecited in 3 of our articles
For the purposes of this chapter, the following terms have the following meanings: (1) BREACH OF SECURITY or BREACH. The unauthorized acquisition of data in electronic form containing sensitive personally identifying information. Acquisition occurring over a period of time committed by the same entity constitutes one breach. The term does not include any of the following: a. Good faith acquisition of sensitive personally identifying information by an employee or agent of a covered entity, unless the information is used for a purpose unrelated to the business or subject to further unauthorized use. b. The release of a public record not otherwise subject to confidentiality or nondisclosure requirements. c. Any lawful investigative, protective, or intelligence activity of a law enforcement or intelligence agency of the state, or a political subdivision of the state. (2) COVERED ENTITY. A person, sole proprietorship, partnership, government entity, corporation, nonprofit, trust, estate, cooperative association, or other business entity that acquires or uses sensitive personally identifying information. (3) DATA IN ELECTRONIC FORM.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
§ 8-38-3Reasonable Security Measures; Assessment.In forcecited in 2 of our articles
(a) Each covered entity and third-party agent shall implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security. (b) Reasonable security measures means security measures practicable for the covered entity subject to subsection (c), to implement and maintain, including consideration of all of the following: (1) Designation of an employee or employees to coordinate the covered entity’s security measures to protect against a breach of security. An owner or manager may designate himself or herself. (2) Identification of internal and external risks of a breach of security. (3) Adoption of appropriate information safeguards to address identified risks of a breach of security and assess the effectiveness of such safeguards. (4) Retention of service providers, if any, that are contractually required to maintain appropriate safeguards for sensitive personally identifying information. (5) Evaluation and adjustment of security measures to account for changes in circumstances affecting the security of sensitive personally identifying information.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
§ 8-38-5Notice of Security Breach - Individuals Affected.In forcecited in 3 of our articles
(a) A covered entity that is not a third-party agent that determines under Section 8-38-4 that, as a result of a breach of security, sensitive personally identifying information has been acquired or is reasonably believed to have been acquired by an unauthorized person, and is reasonably likely to cause substantial harm to the individuals to whom the information relates, shall give notice of the breach to each individual. (b) Notice to individuals under subsection (a) shall be made as expeditiously as possible and without unreasonable delay, taking into account the time necessary to allow the covered entity to conduct an investigation in accordance with Section 8-38-4. Except as provided in subsection (c), the covered entity shall provide notice within 45 days of the covered entity’s receipt of notice from a third-party agent that a breach has occurred or upon the covered entity’s determination that a breach has occurred and is reasonably likely to cause substantial harm to the individuals to whom the information relates.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
§ 8-38-9Violations of Notification Requirements.In forcecited in 2 of our articles
(a) A violation of the notification provisions of this chapter is an unlawful trade practice under the Alabama Deceptive Trade Practices Act, Chapter 19 of this title, but does not constitute a criminal offense under Section 8-19-12. The Attorney General shall have the exclusive authority to bring an action for civil penalties under this chapter. (1) A violation of this chapter does not establish a private cause of action under Section 8-19-10. Nothing in this chapter may otherwise be construed to affect any right a person may have at common law, by statute, or otherwise. (2) Any covered entity or third-party agent who is knowingly engaging in or has knowingly engaged in a violation of the notification provisions of this chapter is subject to the penalty provisions set out in Section 8-19-11. For the purposes of this chapter, knowingly shall mean willfully or with reckless disregard in failing to comply with the notice requirements of Sections 8-38-5 and 8-38-6. Civil penalties assessed under Section 8-19-11, shall not exceed five hundred thousand dollars ($500,000) per breach.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Alabama Code 8-38-2, definitions of sensitive personally identifying information (does not include biometric data)(alisondb.legislature.state.al.us).gov
- Alabama Data Breach Notification Act of 2018 (Acts 2018-396)(alabamaag.gov).gov
- Ala. Code 8-38-5 individual breach notification requirements(alisondb.legislature.state.al.us).gov
- Ala. Code 8-38-9 violation penalties up to $500,000 per breach(alisondb.legislature.state.al.us).gov
- Alabama Attorney General data breach notification page(alabamaag.gov).gov
- Alabama SB272 (2026 Regular Session)(alison.legislature.state.al.us).gov
- Alabama HB283 Personal Data Protection Act (2025)(alison.legislature.state.al.us).gov
- FTC Act Section 5 enforcement authority(ftc.gov).gov
- HIPAA Privacy Rule(hhs.gov).gov
- COPPA rule on children online privacy(ftc.gov).gov
- Alabama HB 351 (2026), Alabama Personal Data Protection Act, enrolled bill (signed April 2026, effective May 1, 2027)(alison.legislature.state.al.us)