Hawaii
Hawaii Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Hawaii has no dedicated biometric privacy law, and its current data breach notification statute, HRS Chapter 487N, does not include biometric data such as fingerprints, voice prints, or iris images in its definition of protected personal information. A 2026 bill, SB 3016, would have added biometric data to that definition, but it died in committee and never became law. No consent requirement exists for collecting biometric data, and residents have no private right of action for unauthorized collection.
Hawaii does not have a standalone biometric privacy law like the Illinois Biometric Information Privacy Act (BIPA) or the Texas Capture or Use of Biometric Identifier Act. Instead, the state protects biometric information through its data breach notification statute, its constitutional right to privacy, and its consumer protection framework.
If you collect fingerprints, facial scans, or other biometric identifiers from Hawaii residents, you need to understand how these overlapping protections apply to your organization. This guide breaks down every relevant Hawaii law, recent legislative changes, and what businesses and individuals should expect going forward.
For the full picture of Hawaii's broader privacy framework, see our parent guide on Hawaii Data Privacy Laws.
How HRS Chapter 487N Treats Biometric Data
Hawaii's closest thing to a biometric protection is the Security Breach of Personal Information Act (HRS Chapter 487N), but its current definition of personal information does not include biometric data. It does not regulate how businesses collect or use biometric data, and it does not currently require notification when biometric data alone is compromised in a security breach.
What Biometric Data Is Covered
Under HRS 487N-1, Hawaii's current definition of "personal information" covers only an individual's name combined with a Social Security number, driver's license or state ID number, or financial account number with an access code or password. It does not include biometric data, and the statute does not currently define a "specified data element" category at all.
A 2026 bill, SB 3016, would have added biometric data, including fingerprints, voice prints, retina or iris images, and other physical or digital biometric identifiers, as a new "specified data element" category. That bill died in committee and never became law, so businesses whose only compromised data is biometric, without an accompanying Social Security number, driver's license number, or financial account number, are not currently required to notify Hawaii residents under HRS Chapter 487N.
When Breach Notification Is Required
A business must notify affected Hawaii residents when there has been unauthorized access to and acquisition of unencrypted records containing personal information, and that access creates a risk of harm. Under the current statute, "personal information" means an individual's name combined with a Social Security number, driver's license or state ID number, or financial account number with an access code or password; biometric data alone is not included.
Notification must happen "without unreasonable delay." Hawaii does not set a specific day count, unlike states such as Florida (30 days) or Texas (60 days). This flexibility standard means businesses should act promptly once they understand the scope of the breach.
Who Must Comply
Three categories of entities fall under the law:
- Any business that owns or licenses personal information of Hawaii residents
- Any business conducting business in Hawaii that owns or licenses personal information in any form
- Any government agency that collects personal information
There is no minimum company size or revenue threshold. A small employer with a single Hawaii-based employee whose Social Security number, driver's license number, or financial account data is breached must comply, though a breach of fingerprint data alone would not currently trigger this obligation.

Hawaii's Constitutional Privacy Protections
Hawaii offers something most states do not: an explicit constitutional right to privacy that can strengthen biometric privacy claims.
Article I, Section 6
Article I, Section 6 of the Hawaii State Constitution states:
"The right of the people to privacy is recognized and shall not be infringed without the showing of a compelling state interest. The legislature shall take affirmative steps to implement this right."
Added by voters in 1978, this provision applies the highest standard of judicial review (compelling state interest) to government intrusions on privacy. It also places an affirmative duty on the legislature to pass laws protecting privacy.
How This Affects Biometric Data
The constitutional right to privacy primarily restricts government action. A state agency that collects employee fingerprints or uses facial recognition technology in public spaces must demonstrate a compelling interest to justify that collection.
For private businesses, the constitutional provision has indirect effects. Courts may interpret statutes more broadly in favor of privacy protections, and the legislature's constitutional duty to protect privacy drives ongoing efforts to pass stronger biometric data laws.
Article I, Section 7
Section 7 provides additional protection by prohibiting unreasonable "invasions of privacy," going beyond the federal Fourth Amendment. This provision gives Hawaii courts an independent constitutional basis for challenging biometric surveillance or data collection by government agencies.
SB 3016: Failed Attempt to Add Biometric Data to the Breach Law (2026)
The Hawaii Legislature considered SB 3016 in 2026, which would have strengthened biometric data protections within the breach notification framework. The bill passed the Senate 25-0, but it stalled in the House Judiciary and Hawaiian Affairs Committee and died when the legislature adjourned sine die on May 8, 2026, without being enacted.
What SB 3016 Would Have Changed
Had it passed, SB 3016 would have updated the definition of "personal information" under HRS Chapter 487N and formally codified "specified data element" as a category, with biometric data listed explicitly among nine types of specified data elements. None of this took effect:
- Social Security numbers (including last four or more digits)
- Driver's license or state ID numbers
- Taxpayer identification numbers
- Military identification numbers
- Passport numbers
- Financial account numbers
- Security codes, PINs, or passwords for financial accounts
- Biometric data (fingerprints, voice prints, iris images)
- Health insurance identification numbers
- Private authentication keys
The bill would also have introduced a new "identifier" definition that broadens what counts as identifying information, including names, usernames, phone numbers, and email addresses. None of this is in effect because the bill died in committee.
Current Status: Bill Died
SB 3016 did not pass. It stalled in the House Judiciary and Hawaiian Affairs Committee and died when the Hawaii Legislature adjourned sine die on May 8, 2026. HRS Chapter 487N remains unchanged, and businesses have no expanded biometric notification obligations under this bill.

Failed Biometric Privacy Legislation: SB 1085
Hawaii lawmakers have attempted to pass a dedicated biometric privacy statute. SB 1085, modeled after Illinois BIPA, was introduced in the 2023 legislative session. The bill would have required:
- Written consent before collecting biometric identifiers
- Published retention and destruction policies
- A prohibition on selling or profiting from biometric data
- A three-year maximum retention period after an individual's last interaction with the collecting entity
- A private right of action allowing individuals to sue for violations
The Senate Committee on Labor and Technology deferred SB 1085 in February 2023, and the bill died without advancing. It was reintroduced in the 2024 session but again did not advance.
This means Hawaii still lacks the consent, purpose limitation, and private right of action provisions found in states like Illinois and Washington. Without SB 1085 or similar legislation, businesses in Hawaii are not required to obtain consent before collecting biometric data from residents.
Consumer Protection as a Biometric Safeguard
Hawaii's Unfair and Deceptive Acts or Practices (UDAP) law (HRS Section 480-2) provides a secondary layer of protection for biometric data. If a business makes promises in its privacy policy about how it handles biometric information and then breaks those promises, it could face enforcement action under this statute.
The Office of Consumer Protection and the Attorney General can bring actions under Hawaii's unfair-practices statutes. Penalties under those statutes range from $500 to $10,000 per violation, which is significantly higher than the $2,500 per violation ceiling under the breach notification law.
This matters for employers and businesses that publish privacy policies covering biometric data. If your policy states you will not share fingerprint data with third parties, violating that promise could trigger UDAP liability.

Employer Use of Biometric Data in Hawaii
Hawaii does not have a law specifically governing employer use of biometric data for time tracking, building access, or identity verification. No state statute requires employers to obtain consent before scanning an employee's fingerprint for a biometric time clock.
However, employers should consider these factors:
Breach notification obligations. Current HRS Chapter 487N does not require notification for a breach of fingerprint or facial scan data alone. That obligation only applies if the breach also involves a Social Security number, driver's license number, or financial account number; a 2026 bill that would have added biometric data on its own died in committee.
Constitutional privacy (government employers). State and county government employers in Hawaii must consider Article I, Sections 6 and 7 before implementing biometric collection programs. A government agency that requires employee fingerprint scans may need to demonstrate a compelling interest.
UDAP exposure. Employers that describe biometric data handling practices in employee handbooks or privacy notices create enforceable expectations. Failing to follow through could constitute a deceptive practice.
Federal considerations. Employers subject to federal regulations, such as those in financial services or healthcare, may have additional obligations under HIPAA, GLBA, or other federal frameworks.
Penalties and Enforcement
Breach Notification Violations
Under HRS Chapter 487N, any business that violates the breach notification requirements faces penalties of up to $2,500 per violation. The Attorney General or the executive director of the Office of Consumer Protection may bring enforcement actions.
Individual Hawaii residents who are adversely affected by a breach may also bring a civil action seeking actual damages and attorney fees.
UDAP Violations
Violations of Hawaii's unfair-practices statutes carry fines between $500 and $10,000 per violation. Both government enforcement and private lawsuits are available.
No Private Right of Action for Biometric Collection
Because Hawaii does not have a dedicated biometric privacy statute, there is no private right of action for unauthorized biometric data collection itself. Residents cannot sue a business simply for collecting their fingerprints without consent, as they can in Illinois. Legal recourse is limited to breach notification failures and deceptive practices claims.
What to Watch: Future Biometric Legislation
Hawaii's legislative trend suggests stronger biometric protections are coming. Key developments to monitor:
A revived SB 3016. The 2026 bill died in committee, but similar legislation could be reintroduced in a future session to add biometric data to the breach notification law.
Dedicated biometric privacy bills. The repeated introduction of SB 1085 signals ongoing legislative interest in an Illinois-style biometric consent law. Future sessions may see a version that advances further.
Comprehensive privacy law. Hawaii has introduced consumer data protection acts in 2024 and 2025 sessions. If a comprehensive privacy law passes, it would likely include biometric data provisions alongside broader consumer rights.
Geolocation and surveillance data. SB 1163 (2026), which restricts the sale of geolocation and browser data, signals expanding legislative attention to all forms of personal data, including biometrics.
This article is for informational purposes only and does not constitute legal advice. Biometric privacy laws change frequently, and enforcement interpretations evolve over time. Consult a licensed attorney in Hawaii for advice about your specific situation. Last reviewed: March 2026.
More Hawaii Laws
Frequently Asked Questions
Does Hawaii require consent before collecting biometric data?
No. Hawaii does not currently have a law requiring businesses to obtain consent before collecting fingerprints, facial scans, or other biometric identifiers. Hawaii's breach notification law (HRS Chapter 487N) does not currently include biometric data in its definition of personal information, so it offers no biometric-specific protection; Hawaii's unfair-practices law (HRS Section 480-2) may apply only if a business breaks its own stated privacy promises. A dedicated consent law (SB 1085) was proposed in 2023 and 2024 but did not pass, and a 2026 bill to add biometric data to the breach law (SB 3016) also died in committee.
What happens if my fingerprint data is exposed in a data breach in Hawaii?
Under current Hawaii law, a breach of fingerprint data alone does not trigger notification under HRS Chapter 487N, because biometric data is not part of the statute's definition of personal information. Notification is required only if the breach also involves your name combined with a Social Security number, driver's license number, or financial account number. A 2026 bill, SB 3016, would have added biometric data to that definition, but it died in committee and never took effect.
Can my employer require me to use a fingerprint scanner for time tracking in Hawaii?
Yes. Hawaii has no law prohibiting employers from requiring biometric time clocks or mandating employee fingerprint scans. Current HRS Chapter 487N would not require notification if only that fingerprint data were breached, because biometric data is not part of the statute's definition of personal information. Government employers face additional constraints under Hawaii's constitutional right to privacy.
How does Hawaii compare to Illinois for biometric privacy protections?
Hawaii's protections are significantly weaker than Illinois. The Illinois Biometric Information Privacy Act requires written consent before collection, mandates published retention policies, and provides a private right of action with statutory damages of $1,000 to $5,000 per violation. Hawaii does not regulate biometric data collection at all, and its breach notification law does not currently cover biometric data either. Hawaii has no private right of action for unauthorized biometric data collection.
Does Hawaii's SB 3016 (2026) create new biometric consent requirements?
No. SB 3016 would have expanded the definition of personal information under Hawaii's breach notification law to explicitly include biometric data as a 'specified data element,' but the bill died in committee in 2026 and never became law. Even if it had passed, it would not have required consent for biometric data collection, established retention limits, or created a private right of action for unauthorized collection.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected two blocking errors: (1) the page presented the failed 2026 bill SB 3016 as enacted law with a July 1, 2026 effective date; it actually died in committee on May 8, 2026 and never took effect, so every section describing it (KeyTakeaways, 'What Biometric Data Is Covered', the dedicated SB 3016 section, FAQ) now says so. (2) The page fabricated a 'specified data element' biometric category as part of HRS 487N-1's current definition; current law covers only SSN, driver's license/state ID, and financial account number. Also corrected the $500-$10,000 UDAP penalty, which the page attributed to HRS 480-2 twice; that section contains no penalty language, so the figure is now attributed to Hawaii's unfair-practices statutes generically.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 3 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Hawaii Revised Statutes, Chapter 480: MONOPOLIES; RESTRAINT OF TRADE
§ 480-2Unfair competition, practices, declared unlawfulIn forcecited in 2 of our articles
(a) Unfair methods of competition and unfair or deceptive acts or practices in the conduct of any trade or commerce are unlawful. (b) In construing this section, the courts and the office of consumer protection shall give due consideration to the rules, regulations, and decisions of the Federal Trade Commission and the federal courts interpreting section 5(a)(1) of the Federal Trade Commission Act (15 U.S.C. 45(a)(1)), as from time to time amended. (c) No showing that the proceeding or suit would be in the public interest (as these terms are interpreted under section 5(b) of the Federal Trade Commission Act) is necessary in any action brought under this section. (d) No person other than a consumer, the attorney general or the director of the office of consumer protection may bring an action based upon unfair or deceptive acts or practices declared unlawful by this section. (e) Any person may bring an action based on unfair methods of competition declared unlawful by this section. [L 1965, c 129, pt of §1; Supp, §205A-1.1; HRS §480-2; am L 1987, c 274, §2; am L 1988, c 51, §1; am L 2002, c 229, §2]
Official text (excerpt) · as of 2026-07-30 · Read the full section at capitol.hawaii.gov
Also relied on in: Hawaii Data Privacy Laws: Constitutional Privacy & Consumer Rights (2026)
Hawaii Revised Statutes, Chapter 487N: [SECURITY BREACH OF PERSONAL INFORMATION]
§ 487N-1DefinitionsIn forcecited in 2 of our articles
. As used in this chapter, unless the context otherwise requires: "Business" means a sole proprietorship, partnership, corporation, association, or other group, however organized, and whether or not organized to operate at a profit. The term includes a financial institution organized, chartered, or holding a license or authorization certificate under the laws of the State, any other state, the United States, or any other country, or the parent or the subsidiary of any such financial institution. The term also includes an entity whose business is records destruction. "Council" means the information privacy and security council established under section 487N-5. "Encryption" or "encrypted" means the use of an algorithmic process to transform data into a form in which the data is rendered unreadable or unusable without the use of a confidential process or key. "Government agency" means any department, division, board, commission, public corporation, or other agency or instrumentality of the State or of any county.
Official text (excerpt) · as of 2026-07-30 · Read the full section at capitol.hawaii.gov
Also relied on in: Hawaii Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 487N-2Notice of security breachIn forcecited in 2 of our articles
(a) Any business that owns or licenses personal information of residents of Hawaii, any business that conducts business in Hawaii that owns or licenses personal information in any form (whether computerized, paper, or otherwise), or any government agency that collects personal information for specific government purposes shall provide notice to the affected person that there has been a security breach following discovery or notification of the breach. The disclosure notification shall be made without unreasonable delay, consistent with the legitimate needs of law enforcement as provided in subsection (c) of this section, and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach, and restore the reasonable integrity, security, and confidentiality of the data system.
Official text (excerpt) · as of 2026-07-30 · Read the full section at capitol.hawaii.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- HRS Chapter 487N - Security Breach of Personal Information(capitol.hawaii.gov).gov
- HRS 487N-1 - Definitions(capitol.hawaii.gov).gov
- HRS 487N-2 - Notice of Security Breach(capitol.hawaii.gov).gov
- Hawaii Constitution Article I Section 6 - Right to Privacy(capitol.hawaii.gov).gov
- Hawaii Constitution Article I Section 7(capitol.hawaii.gov).gov
- SB 3016 (2026) - Breach Notification Expansion (died May 8, 2026)(data.capitol.hawaii.gov).gov
- SB 1085 (2023) - Biometric Information Privacy Act(capitol.hawaii.gov).gov
- SB 1038 (2025) - Breach Notification Updates(capitol.hawaii.gov).gov
- HRS Section 480-2 - UDAP(capitol.hawaii.gov).gov
- Hawaii Office of Consumer Protection - Breach Notices(cca.hawaii.gov).gov
- SB 1163 (2026) - Geolocation and Browser Data Privacy(data.capitol.hawaii.gov).gov