Michigan
Michigan Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Michigan has no dedicated biometric privacy law. The Identity Theft Protection Act (MCL 445.63) classifies biometric data as personal identifying information, but that classification alone does not trigger breach notification: the Act's notification duty under MCL 445.72 is tied to a narrower, separately defined term, personal information, that currently covers only a name paired with a Social Security number, driver's license or state ID number, or financial account number. There is no private right of action. Two pending bills, SB 359 and SB 360, could add consent requirements and, in SB 360's case, add biometrics to the breach notification definition for the first time.
Michigan takes a different approach to biometric privacy than states like Illinois and Texas. Rather than enacting a dedicated biometric information privacy act, Michigan protects biometric data through its existing Identity Theft Protection Act and Consumer Protection Act. For residents wondering whether their fingerprints, facial scans, or voiceprints have legal protection, the answer is yes, but with important limitations.
This guide breaks down how Michigan law currently treats biometric data, what businesses must do when biometric information is compromised, and how pending legislation could bring Michigan closer to the comprehensive biometric protections found in other states.
For broader context on Michigan privacy protections, see the parent guide to Michigan Data Privacy Laws.
What Counts as Biometric Data Under Michigan Law
Michigan law references biometric data in two key statutes, each with a slightly different scope.
Identity Theft Protection Act (MCL 445.63)
The Identity Theft Protection Act, enacted as Act 452 of 2004, defines "personal identifying information" as a name, number, or other information used to identify a specific person or provide access to financial accounts. The statute explicitly lists biometrics as a category of personal identifying information alongside driver's license numbers, Social Security numbers, and financial account credentials.
This classification does not by itself extend Michigan's breach notification framework to biometric data. The Identity Theft Protection Act's notification duty under MCL 445.72 is triggered only by exposure of personal information, a separately defined and narrower term limited to a name paired with a Social Security number, driver's license or state ID number, or financial account number. Biometric data on its own does not currently trigger notification obligations unless it happens to be exposed alongside one of those elements.
Michigan Consumer Protection Act (MCL 445.903)
The Michigan Consumer Protection Act (MCPA), Act 331 of 1976, does not specifically define biometric data. However, the MCPA prohibits unfair, unconscionable, or deceptive trade practices. The Michigan Attorney General has the authority to pursue enforcement actions under the MCPA against businesses that collect or handle biometric data in ways that mislead consumers or violate reasonable privacy expectations.
Types of Biometric Identifiers
Under current Michigan law and pending legislation, biometric data includes:
- Fingerprints and palm prints
- Voiceprints
- Retina and iris scans
- Facial geometry measurements
- Other unique biological patterns used for identification
Photographs, video recordings, and audio recordings are generally excluded from the biometric data definition unless they are specifically processed to extract biometric identifiers for identification purposes.
Breach Notification Requirements for Biometric Data
Biometrics fall within Michigan's broader definition of personal identifying information, but the breach notification rules in MCL 445.72 are keyed to a narrower, separately defined term, personal information, limited to a name paired with a Social Security number, driver's license or state ID number, or financial account number. Biometric data by itself is not currently part of that triggering definition, a gap SB 360 would close.
Who Must Comply
Any person or agency that owns or licenses data containing personal information of Michigan residents must comply. This includes private businesses, government agencies, nonprofits, and any entity that maintains a database with biometric records.
When Notification Is Required
An entity must notify affected Michigan residents after discovering a security breach that results in the unauthorized access and acquisition of unencrypted and unredacted personal information, meaning a name paired with a Social Security number, driver's license or state ID number, or financial account number. Biometric data alone is not currently included in that definition. Notification is not required if the entity determines that the breach is unlikely to cause substantial loss, injury, or identity theft.
Notification Timeline
Under current law, notification must be provided "without unreasonable delay." Delays are permitted only when necessary to determine the scope of the breach or when law enforcement requests a postponement for an ongoing criminal investigation.
How to Notify
Michigan law allows several notification methods depending on the number of affected individuals and the cost of notification:
- Written notice sent by postal mail
- Electronic notice if the affected individual previously consented to electronic communications
- Telephone notice through a live representative, with written follow-up
- Substitute notice for breaches affecting more than 500,000 residents or costing more than $250,000, which includes email notification, conspicuous website posting, and notification to major statewide media
Third-Party Obligations
Entities that maintain personal information on behalf of another organization must notify the data owner of any breach. The data owner then bears the responsibility for notifying affected individuals.
Penalties for Biometric Data Violations
Michigan enforces biometric data protections primarily through its breach notification penalty framework and the Consumer Protection Act.
Breach Notification Penalties
Under MCL 445.72, knowingly failing to provide required breach notification carries civil fines of up to $250 per failure to notify. The total liability for a single breach event is capped at $750,000.
Filing a false breach notification with intent to defraud is a misdemeanor. First offenses carry up to 93 days of imprisonment or a $250 fine. Penalties increase for repeat violations, reaching up to $750 for a third offense.
Consumer Protection Act Enforcement
The Michigan Attorney General can bring enforcement actions under the Consumer Protection Act against entities that engage in unfair or deceptive practices involving biometric data. Remedies can include injunctive relief, restitution, and civil penalties.
No Private Right of Action for Data Breaches
Unlike Illinois, where individuals can sue companies directly for biometric privacy violations under BIPA, Michigan does not currently provide a private right of action specifically for biometric data breaches. Enforcement authority rests with the Michigan Attorney General and county prosecuting attorneys.
How Michigan Compares to Other States
Michigan's biometric protections are moderate compared to other states. Understanding the differences helps businesses operating across state lines assess their compliance obligations.
Illinois has the strongest biometric privacy law in the country through the Biometric Information Privacy Act (BIPA), which requires written consent before collection, mandates retention and destruction policies, and provides a private right of action with statutory damages of $1,000 to $5,000 per violation.
Texas requires consent before capturing biometric identifiers under the Capture or Use of Biometric Identifier Act (CUBI), but only the Texas Attorney General can enforce it.
Michigan currently has no standalone consent requirement for biometric collection. Protection is limited to general consumer protection enforcement, since biometric data alone does not currently trigger the state's breach notification law. If SB 359 or SB 360 passes, Michigan would gain affirmative opt-in consent requirements and would extend breach notification duties to cover biometric identifiers directly.

Employer Use of Biometric Data in Michigan
Michigan does not have a specific statute governing employer collection of biometric data for purposes like time clocks, building access, or identity verification. However, several legal frameworks apply.
Background Check Fingerprinting
The Public Employee Fingerprint-Based Criminal History Check Act (Act 427 of 2018) requires fingerprint-based background checks for public employees who will have access to federal information databases. The Michigan State Police Biometrics and Identification Division processes these fingerprint submissions through the state's Automated Fingerprint Identification System (AFIS).
Certain regulated industries, including security businesses under MCL 338.1068, must submit employee fingerprints to the Michigan State Police before the employee begins work.
Best Practices for Employers
Even without a dedicated biometric consent law, Michigan employers collecting biometric data should:
- Provide written notice explaining what biometric data is collected, how it will be used, and how long it will be stored
- Obtain written consent before collecting fingerprints, facial scans, or other biometric identifiers
- Establish a retention and destruction policy that permanently destroys biometric data when the employment relationship ends or the data is no longer needed
- Limit access to biometric data to authorized personnel only
- Use encryption for stored and transmitted biometric information
These practices align with the requirements proposed in SB 359 and help employers prepare for potential future legislation.

Pending Legislation: What Could Change
Two significant bills passed the Michigan Senate in 2025 and are pending in the House as of March 2026. If enacted, they would substantially strengthen biometric privacy protections.
SB 359: Personal Privacy Data Act
Senate Bill 359, introduced by Senator Rosemary Bayer on June 5, 2025, would create Michigan's first comprehensive consumer data privacy law. The bill was reported favorably by the Senate Finance, Insurance, and Consumer Protection Committee and referred to the Committee of the Whole.
Key biometric provisions in SB 359 include:
- Biometric data as sensitive data. The bill classifies biometric data as a category of sensitive data alongside precise geolocation, data about known children, and certain health information.
- Opt-in consent required. Controllers must obtain a consumer's affirmative consent before processing any sensitive data, including biometric identifiers.
- Data minimization. Collection and processing of biometric data must be limited to what is strictly necessary to provide or maintain the specific product or service requested by the consumer.
- Consumer rights. Michigan residents would gain the right to access, correct, delete, and port their personal data, plus the right to opt out of data sales and targeted advertising.
- Attorney General enforcement. SB 359 would be enforced exclusively by the Michigan Attorney General, with no private right of action.
The bill would apply to entities doing business in Michigan that process data on at least 100,000 consumers per year, or at least 25,000 consumers if they derive any revenue from selling personal data.
SB 360: Identity Theft Protection Act Amendments
Senate Bill 360, part of a five-bill package (SB 360-364), passed the Michigan Senate on August 26, 2025, and has been referred to the House Committee on Government Operations.
Key changes proposed by SB 360 include:
- Expanded personal information definition. The bill would explicitly add "any genetic information or biometric information that is used to authenticate or ascertain the individual's identity, such as a fingerprint, voice print, retina, or iris image" to the definition of personal information in the breach notification statute.
- 45-day notification deadline. Entities must notify affected individuals and the Attorney General within 45 days of determining a breach occurred, replacing the current "without unreasonable delay" standard.
- Attorney General notification. Breaches affecting 100 or more Michigan residents would require notification to the Attorney General.
- Mandatory security programs. Entities must implement reasonable security procedures, designate a security coordinator, and follow the NIST Cybersecurity Framework 2.0 or an equivalent industry standard.
- Enhanced enforcement. The Attorney General would gain expanded powers to issue written demands, accept assurances of discontinuance, and pursue civil fines of up to $2,000 per security procedure violation or investigation failure.

Michigan State Police and Biometric Data
The Michigan State Police (MSP) operates one of the largest biometric databases in the state through its Biometrics and Identification Division. Two systems are particularly relevant to biometric privacy.
Automated Fingerprint Identification System (AFIS)
The MSP's Automated Print Identification Section maintains fingerprint records for criminal justice purposes. Fingerprints collected during arrests, background checks, and licensing processes are stored in AFIS and can be searched against state and FBI databases.
Statewide Network of Agency Photos (SNAP)
The SNAP system allows law enforcement to conduct facial recognition searches against a database of booking photos. The MSP's SNAP Acceptable Use Policy restricts facial recognition searches to five purposes: consent of the individual, probable cause to arrest, a court order or search warrant, identification of a vulnerable or impaired person, or identification of a deceased individual.
The MSP does not use real-time facial recognition surveillance. The department has stated publicly that it does not own the technology to scan crowds or identify people from live video feeds.
This article provides general legal information about Michigan biometric privacy laws. It is not legal advice. Biometric privacy law is evolving rapidly in Michigan, and the pending legislation discussed here may change before enactment. Consult a qualified Michigan attorney for guidance on your specific situation.
More Michigan Laws
Frequently Asked Questions
Does Michigan have a biometric privacy law like Illinois BIPA?
No. Michigan does not have a standalone biometric privacy statute. The Identity Theft Protection Act (MCL 445.61 et seq.) classifies biometrics as personal identifying information, but that term is broader than the personal information definition that actually triggers the Act's breach notification duty, so biometric data exposure alone does not currently require notice. Violations of biometric data handling can also be pursued under the Michigan Consumer Protection Act as unfair trade practices. However, Michigan does not currently require prior consent for biometric data collection or provide individuals with a private right of action for biometric privacy violations.
What happens if a company fails to notify Michigan residents after a biometric data breach?
Under MCL 445.72, knowingly failing to provide required breach notification carries civil fines of up to $250 per failure to notify, with total liability capped at $750,000 per breach event. The Michigan Attorney General and county prosecuting attorneys can bring enforcement actions. Filing a false breach notification is a misdemeanor punishable by up to 93 days imprisonment or fines ranging from $250 to $750 depending on the number of prior offenses.
Can Michigan employers require fingerprint scans for time clocks or building access?
Yes, under current Michigan law. There is no state statute that prohibits employers from collecting fingerprints or other biometric data for workplace purposes like time tracking or access control. However, if SB 359 passes, employers processing biometric data of Michigan consumers would need to obtain opt-in consent and follow data minimization requirements. Employers should adopt written consent and retention policies now to prepare for potential legislative changes.
Will Michigan pass a comprehensive biometric privacy law?
It is possible. SB 359, the Personal Privacy Data Act, was introduced in June 2025 and classifies biometric data as sensitive data requiring opt-in consent before processing. The bill passed the Senate Finance Committee favorably and is progressing through the legislature. SB 360, which would expand breach notification to explicitly cover biometric identifiers and impose a 45-day notification deadline, passed the full Senate in August 2025. Both bills are pending in the Michigan House as of March 2026.
Does Michigan use facial recognition technology, and are there privacy protections?
The Michigan State Police operates the Statewide Network of Agency Photos (SNAP) system for facial recognition searches against booking photos. Use is restricted to five authorized purposes under the SNAP Acceptable Use Policy: individual consent, probable cause to arrest, court order or search warrant, identification of vulnerable or impaired persons, and identification of deceased individuals. The MSP does not conduct real-time surveillance or scan crowds using facial recognition. All SNAP data is classified as highly restricted personal information under state and federal CJIS policies.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected a sitewide claim that biometric data exposure triggers Michigan's breach notification law: MCL 445.72's notice duty is tied to the narrower "personal information" definition (SSN/driver's license/financial account), not the broader "personal identifying information" definition that includes biometrics, so biometric exposure alone does not currently require notice.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 5 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Michigan Compiled Laws
§ 338.1068Employment of unqualified employees; fingerprints; fee; background check of prospective employee; employment application; refusal to surrender identificationIn forcecited in 2 of our articles
(1) A licensee shall not knowingly employ any person who fails to meet the requirements of section 17. (2) The licensee shall cause fingerprints to be taken of all prospective employees who are direct providers of the security business, which fingerprints shall be submitted to the department of state police and the federal bureau of investigation for a state and national criminal history background check. The fingerprints shall be accompanied by a fingerprint processing fee in the amount prescribed by section 3 of 1935 PA 120, MCL 28.273, as well as any fees imposed by the federal bureau of investigation. The results of the national criminal history background check as returned by the federal bureau of investigation to the department of state police shall be used by the department to make a fitness determination. A licensee shall not employ a person who is a direct provider of the security business before submitting fingerprints to the department of state police. (3) The fingerprints required to be taken under subsection (2) may be taken by a law enforcement agency or any other person determined by the department of state police to be qualified to take fingerprints.
Official text (excerpt) · as of 2026-07-30 · Read the full section at legislature.mi.gov
§ 445.61Short titleIn forcecited in 6 of our articles
This act shall be known and may be cited as the "identity theft protection act".
Official text (excerpt) · as of 2026-07-30 · Read the full section at legislature.mi.gov
Also relied on in: Michigan Data Privacy Laws: Consumer Rights & Protections (2026), Michigan Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 445.63DefinitionsIn forcecited in 6 of our articles
As used in this act: (a) "Agency" means a department, board, commission, office, agency, authority, or other unit of state government of this state. The term includes an institution of higher education of this state. The term does not include a circuit, probate, district, or municipal court. (b) "Breach of the security of a database" or "security breach" means the unauthorized access and acquisition of data that compromises the security or confidentiality of personal information maintained by a person or agency as part of a database of personal information regarding multiple individuals. These terms do not include unauthorized access to data by an employee or other individual if the access meets all of the following: (i) The employee or other individual acted in good faith in accessing the data. (ii) The access was related to the activities of the agency or person. (iii) The employee or other individual did not misuse any personal information or disclose any personal information to an unauthorized person. (c) "Child or spousal support" means support for a child or spouse, paid or provided pursuant to state or federal law under a court order or judgment.
Official text (excerpt) · as of 2026-07-30 · Read the full section at legislature.mi.gov
§ 445.72Notice of security breach; requirementsIn forcecited in 6 of our articles
(1) Unless the person or agency determines that the security breach has not or is not likely to cause substantial loss or injury to, or result in identity theft with respect to, 1 or more residents of this state, a person or agency that owns or licenses data that are included in a database that discovers a security breach, or receives notice of a security breach under subsection (2), shall provide a notice of the security breach to each resident of this state who meets 1 or more of the following: (a) That resident's unencrypted and unredacted personal information was accessed and acquired by an unauthorized person. (b) That resident's personal information was accessed and acquired in encrypted form by a person with unauthorized access to the encryption key.
Official text (excerpt) · as of 2026-07-30 · Read the full section at legislature.mi.gov
§ 445.903Unfair, unconscionable, or deceptive methods, acts, or practices in conduct of trade or commerce; rules; applicability of subsection (1)(hh)In forcecited in 6 of our articles
(1) Unfair, unconscionable, or deceptive methods, acts, or practices in the conduct of trade or commerce are unlawful and are defined as follows: (a) Causing a probability of confusion or misunderstanding as to the source, sponsorship, approval, or certification of goods or services. (b) Using deceptive representations or deceptive designations of geographic origin in connection with goods or services. (c) Representing that goods or services have sponsorship, approval, characteristics, ingredients, uses, benefits, or quantities that they do not have or that a person has sponsorship, approval, status, affiliation, or connection that he or she does not have. (d) Representing that goods are new if they are deteriorated, altered, reconditioned, used, or secondhand. (e) Representing that goods or services are of a particular standard, quality, or grade, or that goods are of a particular style or model, if they are of another. (f) Disparaging the goods, services, business, or reputation of another by false or misleading representation of fact. (g) Advertising or representing goods or services with intent not to dispose of those goods or services as advertised or represented.
Official text (excerpt) · as of 2026-07-30 · Read the full section at legislature.mi.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Identity Theft Protection Act (Act 452 of 2004)(legislature.mi.gov).gov
- MCL 445.63 - Personal Identifying Information Definitions(legislature.mi.gov).gov
- MCL 445.72 - Breach Notification Requirements(legislature.mi.gov).gov
- Michigan Consumer Protection Act (MCL 445.903)(legislature.mi.gov).gov
- SB 359 - Personal Privacy Data Act (2025)(legislature.mi.gov).gov
- SB 360 - Identity Theft Protection Act Amendments (2025)(legislature.mi.gov).gov
- SB 360 As Passed Senate(legislature.mi.gov).gov
- Public Employee Fingerprint-Based Criminal History Check Act (Act 427 of 2018)(legislature.mi.gov).gov
- Michigan State Police Biometrics and Identification Division(michigan.gov).gov
- MSP Facial Recognition FAQ(michigan.gov).gov
- MSP Automated Print Identification Section(michigan.gov).gov
- Michigan Attorney General(michigan.gov).gov
- NIST Cybersecurity Framework 2.0(nist.gov).gov
- Illinois Biometric Information Privacy Act (BIPA)(ilga.gov).gov
- Texas Capture or Use of Biometric Identifier Act (CUBI)(statutes.capitol.texas.gov).gov