Arizona
Arizona Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Arizona has no standalone biometric privacy law. The state's Data Breach Notification Law (A.R.S. 18-551 and 18-552) protects biometric data by requiring entities to notify residents within 45 days if a breach exposes their biometric data alongside their name. No private right of action exists.
Arizona does not have a standalone biometric privacy law. Unlike Illinois, Texas, and Washington, the state has not enacted legislation that comprehensively regulates how private businesses collect, store, use, or share biometric identifiers such as fingerprints, facial geometry, or iris scans.
What Arizona does have is a breach notification law that includes biometric data in its definition of protected personal information, a student biometric data protection statute, and pending legislative proposals that could expand protections. These existing protections are limited compared to states with dedicated biometric statutes, but they create real obligations for businesses that handle biometric data in Arizona.
This guide explains the current legal framework, what protections exist, where the gaps are, and what proposed legislation could change.
For broader context on Arizona's overall privacy framework, see the parent guide to Arizona Data Privacy Laws.
How Arizona Defines Biometric Data
Arizona's Data Breach Notification Law defines biometric data under ARS 18-551 as "unique biometric data generated from a measurement or analysis of human body characteristics to authenticate an individual when the individual accesses an online account."
This definition is notably narrow. It only covers biometric data used to authenticate access to an online account. Biometric data used for physical access control (such as a fingerprint scanner at a door), timekeeping (fingerprint time clocks), or surveillance (facial recognition cameras) falls outside this statutory definition.
The law requires that the biometric data be paired with an individual's first name (or first initial) and last name to qualify as protected "personal information."

Arizona Data Breach Notification Law (ARS 18-551 and 18-552)
Arizona's primary biometric protection comes from the Data Breach Notification Law, originally enacted in 2006 and significantly amended in 2018 by HB 2154 and again in 2022 by HB 2146. The 2018 amendments added biometric data to the list of specified data elements.
What the Law Requires
Any person that owns, maintains, or licenses unencrypted and unredacted computerized data that includes personal information of Arizona residents must follow these requirements.
Investigation. After discovering a security system breach, the entity must conduct a reasonable investigation to promptly determine if there has been a breach that is reasonably likely to cause substantial harm.
Individual notification within 45 days. If a breach compromises biometric data combined with an individual's name, the entity must notify affected Arizona residents within 45 days after determining that a breach occurred (ARS 18-552).
Attorney General and credit agency notification. If the breach affects more than 1,000 individuals, the entity must notify the Arizona Attorney General and the three largest nationwide consumer reporting agencies in writing.
Department of Homeland Security notification. Under the 2022 amendments, entities must also notify the Arizona Department of Homeland Security when a reportable breach occurs.
Penalties for Non-Compliance
A knowing and willful violation of the notification law is classified as an unlawful practice under ARS 44-1522 (the Arizona Consumer Fraud Act).
The Attorney General may impose civil penalties up to $10,000 per affected individual, or the total amount of economic loss sustained by affected individuals, whichever is less. The maximum civil penalty for a single breach or series of related breaches is capped at $500,000.
The Attorney General may also recover restitution for affected individuals on top of civil penalties.
Only the Attorney General may enforce violations. The statute does not create a private right of action for individuals.
Exemptions
The law includes several important exemptions. Encrypted or redacted data is excluded from the definition of personal information. The notification requirements also do not apply to persons subject to Title V of the Gramm-Leach-Bliley Act or entities that maintain breach notification procedures under HIPAA.
Student Biometric Protections
Arizona has enacted specific protections for student biometric data. The original ARS 15-109 required schools to provide written notice at least 30 days before collecting biometric information from students and mandated written parental consent.
The statute defined "biometric information" broadly as the noninvasive electronic measurement and evaluation of any physical characteristics attributable to a single person, including fingerprint characteristics, eye characteristics, hand characteristics, vocal characteristics, facial characteristics, and any other physical characteristics used for electronic identification.
ARS 15-109 remains separate, current Arizona law; it was not consolidated into or replaced by ARS 15-1046. ARS 15-1046 is a distinct, broader student data privacy statute that separately requires operators of education technology to implement reasonable security procedures for covered student data, including biometric information, but it does not itself impose the written-parental-consent or 30-day-notice requirements found in ARS 15-109.

What Arizona Law Does Not Cover
Arizona's existing laws leave significant gaps in biometric privacy protection for adults.
No general consent requirement for adults. Outside the school context, Arizona does not require businesses or employers to obtain consent before collecting biometric data from adults. An employer can implement fingerprint time clocks or facial recognition systems without notifying employees or getting their approval.
Narrow online-only definition. The breach notification law only covers biometric data used to authenticate access to online accounts. Biometric data used for physical security, timekeeping, or surveillance falls outside the statute.
No retention or destruction timelines. The state does not mandate specific retention schedules or destruction timelines for biometric data held by private entities.
No restrictions on biometric data sales. Arizona does not prohibit or restrict the sale or sharing of biometric data with third parties under existing law.
No private right of action. There is no state law allowing individuals to sue because a company collected their biometric data without consent or failed to protect it.
Employer Use of Biometric Data in Arizona
Arizona has no state law that restricts employers from collecting biometric data from employees. Companies operating in Arizona that use fingerprint scanners for timekeeping, facial recognition for building access, or other biometric systems are not required by state law to:
- Provide written notice before collecting biometric data
- Obtain employee consent
- Establish data retention or destruction policies
- Limit sharing of employee biometric data with vendors or third parties

This stands in sharp contrast to Illinois, where employers face statutory damages of $1,000 to $5,000 per violation of the Biometric Information Privacy Act.
Employers should still implement reasonable security measures. If a breach occurs that exposes employee biometric data used for online account authentication alongside names, the employer must comply with the 45-day notification requirement or face penalties up to $500,000.
Pending Legislation
Arizona has seen several legislative attempts to expand biometric privacy protections.
SB 1238 (56th Legislature, 1st Regular Session). This bill proposes a comprehensive biometric identifiers law modeled in part on Illinois BIPA. Key provisions would require private entities to develop written retention and destruction policies, obtain written consent before collecting biometric identifiers, prohibit selling or profiting from biometric data, and mandate destruction of data within three years of an individual's last interaction or when the original purpose is fulfilled. As of March 2026, SB 1238 has been introduced but has not been enacted.
HB 2478 (54th Legislature). This earlier bill also proposed regulating biometric identifiers but did not advance into law.
If SB 1238 passes, it would bring Arizona significantly closer to the protections available in Illinois, creating consent requirements, retention limits, and restrictions on commercial use of biometric data.
Federal Protections That Apply in Arizona
Because Arizona lacks a comprehensive biometric privacy law, federal statutes provide additional protections for residents.
Section 5 of the FTC Act allows the Federal Trade Commission to take enforcement action against companies engaged in unfair or deceptive practices involving biometric data.
HIPAA protects biometric data collected or used by covered healthcare entities and their business associates under the Privacy Rule.
COPPA requires parental consent before collecting biometric data from children under 13, enforced by the FTC.
How Arizona Compares to Other States
Arizona falls into a lower tier of states for biometric privacy protection. While the inclusion of biometric data in the breach notification law is meaningful, the narrow online-account-only definition and lack of collection-level protections place it behind more protective states.
- Illinois has the strongest biometric law in the nation (BIPA), with a private right of action and statutory damages of $1,000 to $5,000 per violation
- Texas and Washington have biometric-specific statutes enforced by their attorneys general
- States with comprehensive privacy laws (Colorado, Connecticut, Virginia) classify biometric data as sensitive and require opt-in consent
- Arizona protects biometric data only through a narrowly defined breach notification law and student data privacy standards
This article provides general legal information about Arizona biometric privacy laws. It is not legal advice. Laws and regulations change frequently, and this content may not reflect the most recent developments. Consult a qualified attorney licensed in Arizona for advice about your specific situation.
- Arizona AI Meeting Recording Laws
- Arizona Alimony Laws
- Arizona At-Will Employment Laws
- Arizona Car Accident Laws
- Arizona Car Seat Laws
- Arizona Child Custody Laws
- Arizona Child Support Laws
- Arizona Common Law Marriage Laws
- Arizona Dashcam Laws
- Arizona Deepfake Laws
- Arizona Divorce Laws
- Arizona Dog Bite Laws
- Arizona Drone Laws
- Arizona Emancipation Laws
- Arizona Employee Monitoring Laws
- Arizona Expungement Laws
More Arizona Data Privacy and Recording Laws
Frequently Asked Questions
Does Arizona have a biometric privacy law?
Arizona does not have a standalone biometric privacy statute like Illinois BIPA. However, the state protects biometric data through its Data Breach Notification Law (ARS 18-551 and 18-552), which requires entities to notify Arizona residents within 45 days if a breach exposes their biometric data alongside their name. Arizona also has student biometric data protections under ARS 15-1046. A proposed bill, SB 1238, would create broader biometric privacy protections if enacted.
Can my employer collect my fingerprints without consent in Arizona?
Yes. Arizona has no law requiring employers to obtain consent before collecting biometric data such as fingerprints or facial scans from employees. Employers can implement fingerprint time clocks, facial recognition access systems, or other biometric tools without providing written notice or obtaining approval. If SB 1238 passes, this could change by requiring written consent before biometric data collection.
What are the penalties for a biometric data breach in Arizona?
A knowing and willful violation of Arizona's breach notification law can result in civil penalties of up to $10,000 per affected individual, capped at a maximum of $500,000 per breach or series of related breaches. Violations are classified as unlawful practices under the Arizona Consumer Fraud Act. The Attorney General may also recover restitution for affected individuals.
Can I sue a company in Arizona for collecting my biometric data without permission?
No. Arizona does not provide a private right of action for the unauthorized collection of biometric data. Only the Attorney General can bring enforcement actions under the breach notification law. This differs from Illinois, where individuals can recover $1,000 to $5,000 per violation of the Biometric Information Privacy Act.
Does Arizona's breach notification law cover all biometric data?
No. Arizona's definition of biometric data in the breach notification law is narrow. It only covers unique biometric data generated from measurement or analysis of human body characteristics used to authenticate an individual when accessing an online account. Biometric data used for physical access control, timekeeping, or surveillance is not covered by this specific statute.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the claim that ARS 15-109's biometric-consent protections were 'updated and consolidated' into ARS 15-1046; the two statutes are separate and both remain current Arizona law.
Corrected a KeyTakeaways bullet that still attributed the collection-time parental-consent and notice requirements for student biometric data to ARS 15-1046; those requirements come from ARS 15-109, which remains separate, current law.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 3 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Arizona Revised Statutes, Title 15 (Education), Chapter 9 (SCHOOL DISTRICT BUDGETING AND FINANCIAL ASSISTANCE), Article 8 (Student Accountability Information System)
§ 15-1046Student data privacy; definitionsIn forcecited in 2 of our articles
A. An operator may not knowingly do any of the following: 1. Engage in targeted advertising on the operator's site, service or application or on any other site, service or application if the targeting of the advertising is based on any information, including covered information and persistent unique identifiers, that the operator has acquired because of the use of that operator's site, service or application for school purposes. 2. Use information, including persistent unique identifiers, created or gathered by the operator's site, service or application to amass a profile about a student except in furtherance of school purposes. This paragraph does not apply to the collection and retention of account information that remains under the control of the student, the student's parent or guardian or the public school. 3. Sell or rent a student's information, including covered information.
Official text (excerpt) · as of 2026-08-04 · Read the full section at azleg.gov
Also relied on in: Arizona Data Privacy Laws: Breach Rules & Consumer Rights (2026)
Arizona Revised Statutes, Title 18 (Information Technology), Chapter 5 (NETWORK SECURITY), Article 4 (Data Security Breaches)
§ 18-551DefinitionsIn forcecited in 3 of our articles
In this article, unless the context otherwise requires: 1. "Breach" or "security system breach": (a) Means an unauthorized acquisition of and unauthorized access that materially compromises the security or confidentiality of unencrypted and unredacted computerized personal information maintained as part of a database of personal information regarding multiple individuals. (b) Does not include a good faith acquisition of personal information by a person's employee or agent for the purposes of the person if the personal information is not used for a purpose unrelated to the person and is not subject to further unauthorized disclosure. 2. "Court" means the supreme court, the court of appeals, the superior court, a court that is inferior to the superior court and a justice court. 3. "Encrypt" means to use a process to transform data into a form that renders the data unreadable or unusable without using a confidential process or key. 4. "Individual" means a resident of this state who has a principal mailing address in this state as reflected in the records of the person conducting business in this state at the time of the breach. 5.
Official text (excerpt) · as of 2026-08-04 · Read the full section at azleg.gov
Also relied on in: Arizona Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 18-552Notification of security system breaches; requirements; enforcement; confidentiality; civil penalty; preemption; exceptionsIn forcecited in 3 of our articles
A. If a person that conducts business in this state and that owns, maintains or licenses unencrypted and unredacted computerized personal information becomes aware of a security incident, the person shall conduct an investigation to promptly determine whether there has been a security system breach. B. If the investigation results in a determination that there has been a security system breach, the person that owns or licenses the computerized data, within forty-five days after the determination, shall: 1. Notify the individuals affected pursuant to subsection E of this section and subject to the needs of law enforcement as provided in subsection D of this section. 2. If the breach requires notification of more than one thousand individuals, notify both: (a) The three largest nationwide consumer reporting agencies.
Official text (excerpt) · as of 2026-08-04 · Read the full section at azleg.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- ARS 18-551 definitions including biometric data(azleg.gov).gov
- ARS 18-552 breach notification requirements, enforcement, and civil penalties(azleg.gov).gov
- Arizona Attorney General data breach notification FAQ(azag.gov).gov
- Arizona AG data breach notification form(azag.gov).gov
- HB 2154 (2018) expanding breach notification definitions(azleg.gov).gov
- HB 2146 (2022) amending breach notification requirements(azleg.gov).gov
- ARS 15-1046 student data privacy protections(azleg.gov).gov
- SB 1238 proposed biometric identifiers privacy act(azleg.gov).gov
- FTC Act Section 5 enforcement authority(ftc.gov).gov
- HIPAA Privacy Rule(hhs.gov).gov
- COPPA rule on children online privacy(ftc.gov).gov