Georgia
Georgia Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Georgia has no biometric-specific privacy law, but its first comprehensive consumer privacy statute, the Georgia Consumer Privacy Protection Act (SB 111, Act 462), was signed by Governor Kemp on May 11, 2026, and takes effect July 1, 2026. SB 111 classifies biometric data processed to uniquely identify a person as sensitive data and requires covered businesses to obtain consent before processing it. The Personal Identity Protection Act (O.C.G.A. 10-1-910 et seq.) separately requires breach notification but excludes biometric data from its definition of personal information, leaving biometric-only breaches without a state-level notification requirement.
Georgia is one of the majority of U.S. states that has not enacted a dedicated biometric privacy law. Residents who use fingerprint scanners at work, submit to facial recognition at public venues, or provide biometric data to apps and devices have limited state-level legal protections governing how that data is collected, stored, shared, or destroyed.
This guide explains what Georgia law currently does and does not cover when it comes to biometric information, what the new Georgia Consumer Privacy Protection Act (SB 111) changed, and what federal protections fill the remaining gaps.
For broader context on Georgia's overall privacy framework, see the parent guide to Georgia Data Privacy Laws.
What Counts as Biometric Data
Biometric data includes unique physical or behavioral characteristics used to identify an individual. Common examples include fingerprints, facial geometry (used in facial recognition), iris and retina scans, voiceprints, palm prints, and gait analysis.
States with dedicated biometric privacy laws, such as Illinois (BIPA) and Texas (CUBI), define these identifiers in statute and regulate how entities handle them. Georgia has not taken this step.
Georgia's Current Legal Framework
Personal Identity Protection Act (O.C.G.A. 10-1-910 et seq.)
Georgia's primary data protection law is the Personal Identity Protection Act, enacted in 2005 and amended in 2007. This law requires businesses and data brokers to notify Georgia residents when a security breach compromises their personal information.
However, the statute defines "personal information" under O.C.G.A. 10-1-911 as an individual's name combined with one or more of the following:
- Social Security number
- Driver's license or state ID number
- Financial account, credit card, or debit card numbers (with access codes)
- Account passwords or PINs
Biometric data such as fingerprints, facial scans, and voiceprints are not included in this definition. A breach involving only biometric records would not trigger notification obligations under current Georgia law.
Fair Business Practices Act (O.C.G.A. 10-1-390 et seq.)
Georgia's Fair Business Practices Act prohibits unfair and deceptive trade practices. While the statute does not mention biometric data specifically, a business that made false promises about how it handles biometric information could theoretically face enforcement action under this law.
The Georgia Attorney General enforces the FBPA. There is no private right of action that would allow individual consumers to sue for biometric data misuse under this statute alone.
No Employer-Specific Biometric Rules

Georgia does not restrict employers from collecting fingerprints, facial scans, or other biometric data from employees. Businesses that use biometric time clocks, fingerprint-based access controls, or facial recognition for security purposes are not required by state law to:
- Obtain written consent before collecting biometric data
- Disclose how biometric data will be stored or used
- Establish retention schedules or destruction timelines
- Limit sharing of biometric data with third parties
This stands in sharp contrast to states like Illinois, where the Biometric Information Privacy Act requires informed written consent and imposes statutory damages of $1,000 to $5,000 per violation.
Georgia Consumer Privacy Protection Act (SB 111, Act 462)

The most significant change for biometric privacy in Georgia is the Georgia Consumer Privacy Protection Act (SB 111), which Governor Kemp signed into law as Act 462 on May 11, 2026, after it was introduced in the 2025-2026 legislative session.
What SB 111 Does for Biometric Data
The law classifies biometric data processed for the purpose of uniquely identifying an individual as "sensitive data." SB 111:
- Requires covered businesses to obtain explicit consumer consent before processing biometric data
- Mandates clear notices when a business sells or shares sensitive data, including biometric information
- Requires data protection assessments for activities involving sensitive data processing
- Authorizes the Georgia Attorney General to seek civil penalties of up to $7,500 per violation, with treble damages for knowing or willful violations
Current Status
SB 111 passed the Georgia Senate on March 3, 2025, by a vote of 53-2. The House withdrew and recommitted the bill in March 2025 and did not act on it before the 2025 session adjourned. The House passed a substitute version 162-1 on March 31, 2026, the Senate agreed to that substitute on April 2, 2026, and Governor Kemp signed the bill into law as Act 462 on May 11, 2026. SB 111 takes effect July 1, 2026.
The ACLU of Georgia has criticized the law for high applicability thresholds. It applies only to entities that exceed $25 million in annual revenue and process personal information of at least 175,000 Georgia residents, or 25,000 residents if the entity derives more than 50% of revenue from selling personal data.
The law also does not create a private right of action. Only the Attorney General can bring enforcement actions.
Federal Protections That Apply in Georgia
Georgia's SB 111 requires consent before covered businesses process biometric data as sensitive data, but it exempts employee data and applies only to larger businesses, so federal statutes remain the primary legal guardrails for biometric data that falls outside SB 111's scope.
Section 5 of the FTC Act allows the Federal Trade Commission to bring enforcement actions against companies engaged in unfair or deceptive practices involving biometric data. The FTC has taken action against companies for deceptive facial recognition practices and inadequate data security.
HIPAA protects biometric data when it is collected or used by covered healthcare entities and their business associates. Fingerprint or facial recognition data used in a healthcare setting falls under HIPAA's Privacy Rule.
FERPA restricts how educational institutions handle student biometric data. Schools that use fingerprint-based lunch payment systems or facial recognition must comply with FERPA's privacy requirements.
COPPA imposes strict requirements on the collection of biometric data from children under 13, including parental consent requirements enforced by the FTC.
How Georgia Compares to Other States
Georgia falls into the least protective tier of states for biometric privacy. For comparison:
- Illinois has the strongest biometric law in the country (BIPA), with a private right of action and statutory damages of $1,000 to $5,000 per violation
- Texas and Washington have biometric-specific statutes enforced by their attorneys general
- States with comprehensive privacy laws (like Colorado, Connecticut, and Virginia) classify biometric data as sensitive and require consent for processing
- Georgia has no biometric-specific statute, but its new comprehensive privacy law, SB 111 (Act 462), effective July 1, 2026, classifies biometric data as sensitive and requires consent from covered businesses, with no private right of action
This article provides general legal information about Georgia biometric privacy laws. It is not legal advice. Laws and regulations change frequently, and this content may not reflect the most recent developments. Consult a qualified attorney licensed in Georgia for advice about your specific situation.
More Georgia Laws
Frequently Asked Questions
Does Georgia have a biometric privacy law?
Not a dedicated one. Georgia has no biometric-specific statute like Illinois' BIPA. However, the Georgia Consumer Privacy Protection Act (SB 111, Act 462), signed by Governor Kemp on May 11, 2026, and effective July 1, 2026, classifies biometric data processed to uniquely identify a person as sensitive data and requires covered businesses to get consent before processing it, subject to the law's revenue and data-volume thresholds.
Can my employer require fingerprint scans in Georgia?
Yes. Georgia law does not restrict employers from collecting biometric data such as fingerprints or facial scans. Employers are not required to obtain written consent, disclose how biometric data will be used, or establish retention and destruction schedules. The Georgia Consumer Privacy Protection Act (SB 111), effective July 1, 2026, does not change this because it exempts employee and contractor data processed in a human resources context. This differs significantly from states like Illinois, where employers must obtain informed written consent before collecting any biometric information.
What happens if my biometric data is breached in Georgia?
Georgia's Personal Identity Protection Act (O.C.G.A. 10-1-912) requires breach notification, but only when the breach involves personal information as defined by the statute, which includes Social Security numbers, driver's license numbers, and financial account numbers. Biometric data is not included in this definition, so a breach involving only biometric records would not trigger notification requirements under current state law.
Can I sue a company in Georgia for misusing my biometric data?
Georgia does not provide a private right of action for biometric data misuse. Unlike Illinois, where individuals can sue under BIPA and recover statutory damages, Georgia residents must rely on common-law tort theories such as invasion of privacy or negligence, federal protections like the FTC Act, or a complaint to the Georgia Attorney General. The Georgia Consumer Privacy Protection Act (SB 111), now in effect, gives the Attorney General exclusive enforcement authority over its biometric consent requirements but still does not create a private right of action.
Has Georgia passed a biometric privacy law?
Georgia has not enacted a dedicated biometric privacy statute, but the Georgia Consumer Privacy Protection Act (SB 111, Act 462) now covers biometric data as one category of sensitive data. Governor Kemp signed it on May 11, 2026, and it takes effect July 1, 2026. It requires consent from covered businesses before processing biometric data and authorizes Attorney General enforcement with penalties up to $7,500 per violation. The law has faced criticism for high applicability thresholds and the lack of a private right of action.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
Corrected the article: Georgia’s SB 111 (the Georgia Consumer Privacy Protection Act) was not left stalled in the legislature as previously stated — Governor Kemp signed it into law as Act 462 on May 11, 2026 (effective July 1, 2026), and it now requires consent before covered businesses process biometric data as sensitive data. Updated the intro, KeyTakeaways, legislation section, comparison table, and FAQs to reflect enactment, and relabeled the stale bill-page citation.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 4 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Official Code of Georgia Annotated
§ 10-1-390Short title.In forcecited in 2 of our articles
This part shall be known and may be cited as the "Fair Business Practices Act of 1975." (Ga. L. 1975, p. 376, § 1; Ga. L. 2015, p. 1088, § 2/SB 148.)
Official text (excerpt) · as of 2021-08-17 · Read the full section at archive.org
Cited in 171 court opinionsMost recently applied by a court: 2026
Leading cases: Larson v. TANDY CORPORATION (Court of Appeals of Georgia 1988, 187 Ga. App. 893) · Robin v. Bellsouth Advertising & Publishing Co. (Court of Appeals of Georgia 1996, 221 Ga. App. 360) · ANTOINETTE MARQUES v. JP MORGAN CHASE BANK, N.A. (Court of Appeals of Georgia 2023)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Georgia Lemon Law (2026): How to Qualify & Get a Refund
§ 10-1-910Legislative findings.In force
The General Assembly finds and declares as follows: (1) The privacy and financial security of individuals is increasingly at risk due to the ever more widespread collection of personal information by both the private and public sectors; (2) Credit card transactions, magazine subscriptions, real es
Official text (excerpt) · as of 2026-08-04 · Read the full section at legis.ga.gov
Cited in 16 court opinionsMost recently applied by a court: 2022
Leading cases: McCONNELL Et Al. v. DEPARTMENT OF LABOR (Court of Appeals of Georgia 2016, 337 Ga. App. 457) · Dep't of Labor v. Mcconnell (Supreme Court of Georgia 2019, 305 Ga. 812) · COLLINS v. ATHENS ORTHOPEDIC CLINIC, P.A (Supreme Court of Georgia 2019, 307 Ga. 555)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 10-1-911Definitions.In forcecited in 3 of our articles
As used in this article, the term: (1) "Breach of the security of the system" means unauthorized acquisition of an individual's electronic data that compromises the security, confidentiality, or integrity of personal information of such individual maintained by an information broker or data collect
Official text (excerpt) · as of 2026-08-04 · Read the full section at legis.ga.gov
Cited in 2 court opinionsMost recently applied by a court: 2018
Leading cases: McCONNELL Et Al. v. DEPARTMENT OF LABOR (Court of Appeals of Georgia 2016, 337 Ga. App. 457)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Georgia Data Privacy Laws: Breach Notification & Consumer Rights (2026), Georgia Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 10-1-912Notification required upon breach of security regarding personal information.In forcecited in 3 of our articles
(a) Any information broker or data collector that maintains computerized data that includes personal information of individuals shall give notice of any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of this state…
Official text (excerpt) · as of 2021-08-17 · Read the full section at archive.org
Cited in 3 court opinionsMost recently applied by a court: 2019
Leading cases: McCONNELL Et Al. v. DEPARTMENT OF LABOR (Court of Appeals of Georgia 2016, 337 Ga. App. 457) · In re Equifax, Inc. (District Court, N.D. Georgia 2019, 362 F. Supp. 3d 1295)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Georgia Personal Identity Protection Act breach notification requirements(law.justia.com)
- O.C.G.A. 10-1-911 definitions of personal information(law.justia.com)
- Georgia Fair Business Practices Act(law.justia.com)
- Georgia General Assembly: SB 111, Georgia Consumer Privacy Protection Act (Act 462), signed May 11, 2026(legis.ga.gov).gov
- SB 111 full bill text(legis.ga.gov).gov
- ACLU of Georgia report on SB 111(acluga.org)
- FTC Act Section 5 enforcement authority(ftc.gov).gov
- HIPAA Privacy Rule(hhs.gov).gov
- FERPA privacy requirements(www2.ed.gov).gov
- COPPA rule on children online privacy(ftc.gov).gov
- Illinois Biometric Information Privacy Act(ilga.gov).gov