Minnesota
Minnesota Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Minnesota has no standalone biometric privacy statute. The Minnesota Consumer Data Privacy Act (MCDPA), Minn. Stat. Chapter 325M, effective July 31, 2025, classifies biometric data as sensitive personal data and requires opt-in consent before businesses can collect or process it. The Attorney General enforces the law; consumers have no private right of action.
Minnesota does not have a standalone biometric privacy statute like Illinois's BIPA or Texas's CUBI. Instead, the state protects biometric data through the Minnesota Consumer Data Privacy Act (MCDPA), a comprehensive consumer privacy law that classifies biometric identifiers as sensitive data requiring affirmative consent before collection or processing.
Governor Tim Walz signed HF 4757 into law on May 19, 2024. The MCDPA took effect on July 31, 2025, making Minnesota one of a growing number of states with comprehensive privacy legislation that covers biometric data.
For an overview of Minnesota's broader privacy framework, see the parent guide to Minnesota Data Privacy Laws.
How the MCDPA Defines Biometric Data
The MCDPA defines biometric data under Minn. Stat. 325M.11(d) as data generated by automatic measurements of an individual's biological characteristics that are used to identify a specific individual. The statute lists these examples:
- Fingerprints
- Voiceprints
- Eye retinas
- Irises
- Other unique biological patterns or characteristics
The law draws a clear line around what does not qualify. A physical or digital photograph, a video or audio recording, or data generated from those recordings is not biometric data unless that data is specifically generated to identify a specific individual.

This definition follows the same approach used in several other state comprehensive privacy statutes, including Connecticut and Kentucky. It is narrower than the definition used in Illinois's BIPA, which covers a broader set of biometric identifiers without the same exclusions.
Sensitive Data Classification and Consent
Under the MCDPA, biometric data processed for the purpose of uniquely identifying an individual qualifies as "sensitive data" per Minn. Stat. 325M.11(v). This is the highest protection category in the law.
Other categories of sensitive data under the MCDPA include:
- Data revealing racial or ethnic origin
- Religious beliefs
- Mental or physical health condition or diagnosis
- Sexual orientation
- Citizenship or immigration status
- Genetic data processed for identification
- Specific geolocation data
- Personal data of a known child under 13
Consent requirement. Under Minn. Stat. 325M.16(2)(d), controllers cannot process sensitive data, including biometric data, without first obtaining consumer consent. This means a business cannot collect your fingerprint, faceprint, or iris scan for identification purposes without your affirmative agreement.

Revocation right. Under Minn. Stat. 325M.16(2)(e), consumers can revoke consent at any time. Controllers must provide a revocation mechanism that is at least as easy to use as the original consent process. Once a consumer revokes consent, the controller must stop processing their biometric data within 15 days.
Who Must Comply
The MCDPA applies to entities that conduct business in Minnesota or produce products or services targeted to Minnesota residents and meet one of these thresholds under Minn. Stat. 325M.12:
- Process personal data of 100,000 or more consumers during a calendar year, excluding data processed solely for completing payment transactions, or
- Process personal data of 25,000 or more consumers and derive over 25% of gross revenue from the sale of personal data
Small businesses as defined by the U.S. Small Business Administration receive limited exemptions but must still obtain consent before selling sensitive data, including biometric data.
Key Exemptions
The MCDPA exempts several categories of entities and data from coverage:
Entity exemptions:
- HIPAA-covered entities and their business associates
- Financial institutions subject to the Gramm-Leach-Bliley Act (GLBA)
- Nonprofit organizations
- Government agencies
- Postsecondary institutions regulated by the Office of Higher Education (exempt until July 31, 2029)
Data exemptions:
- Data regulated under HIPAA
- Data governed by the Fair Credit Reporting Act (FCRA)
- Data covered by the Family Educational Rights and Privacy Act (FERPA)
- Data under the Driver's Privacy Protection Act (DPPA)
Employee data exemption. The MCDPA does not apply to personal data collected about job applicants, employees, or individuals acting as business representatives when that data is processed in the context of the employment relationship. If your employer collects your fingerprints for a timekeeping system or uses facial recognition for building access, the MCDPA does not regulate that collection. Minnesota does not have a separate law governing employer use of biometric data.
Consumer Rights Over Biometric Data
Because biometric data is sensitive personal data under the MCDPA, Minnesota consumers have these rights under Minn. Stat. 325M.14:
Right to confirm and access. You can ask any covered business whether it is processing your biometric data and request access to that data. However, controllers are not required to disclose biometric data itself in response to access requests. Instead, they must inform you that they have collected such information.
Right to correct. If a business holds inaccurate biometric data about you, you can request a correction.
Right to delete. You can request that a business delete the biometric data it holds about you.
Right to data portability. You can obtain a copy of your personal data in a portable and readily usable format.
Right to opt out. You can opt out of the processing of your personal data for targeted advertising, the sale of personal data, or profiling that produces legal or similarly significant effects.
Right to non-discrimination. Businesses cannot penalize you for exercising any of these rights by denying goods or services, charging different prices, or providing a different quality of service.
Businesses must respond to consumer rights requests within 45 days. They can extend this period by an additional 45 days when reasonably necessary, but must notify the consumer of the extension and the reason for it.
Data Protection Assessments for Biometric Data
Controllers that process sensitive data, including biometric data, must conduct data protection assessments under Minn. Stat. 325M.18. These assessments must weigh the benefits of processing against potential risks to consumers, including:
- Unfair or deceptive treatment or unlawful disparate impact
- Financial, physical, or reputational injury
- Intrusion upon solitude or seclusion
- Other substantial injury
Controllers must also establish and maintain reasonable administrative, technical, and physical data security practices proportional to the volume and nature of the biometric data they process. The Minnesota Attorney General can request these assessments during an investigation.
Breach Notification and Biometric Data
Minnesota's separate breach notification law at Minn. Stat. 325E.61 requires businesses to notify affected individuals when a security breach compromises unencrypted personal information. However, the statute's definition of personal information is limited to Social Security numbers, driver's license or ID numbers, and financial account numbers with security codes.
Biometric data is not explicitly listed as a category of personal information triggering breach notification under Minn. Stat. 325E.61. This creates a gap in Minnesota's data protection framework. A breach that exposes biometric data alone, without an accompanying Social Security or financial account number, may not trigger the breach notification requirement under the older statute.
The MCDPA's data security requirements under Minn. Stat. 325M.16 provide a separate layer of protection by requiring controllers to maintain reasonable security practices for all personal data, including biometric data. A failure to maintain adequate security could still lead to AG enforcement under the MCDPA, even if the breach notification statute does not apply.
Enforcement and Penalties
The Minnesota Attorney General has exclusive enforcement authority over the MCDPA under Minn. Stat. 325M.20. There is no private right of action, meaning individual consumers cannot file lawsuits against businesses for MCDPA violations.
Enforcement resources. The legislature appropriated funding for four new attorneys and one investigator in the AG's office dedicated to MCDPA enforcement. The AG's office received over 200 MCDPA complaints in the first six months of the law and sent dozens of warning letters to companies identifying problems with privacy policies and procedures.
Cure period (expired). From July 31, 2025, through January 31, 2026, the law required the AG to notify businesses in writing of alleged violations and provide 30 days to cure. This grace period expired on January 31, 2026. Since February 2026, the AG can bring enforcement actions immediately without advance notice.

Penalties. The AG can initiate civil actions against businesses that violate the MCDPA with penalties of up to $7,500 per violation. Multiple violations involving biometric data collection without consent could result in substantial aggregate penalties.
Pending Minnesota Biometric Legislation
Several bills in the 94th Minnesota Legislature (2025-2026) could expand biometric privacy protections:
HF 3661 would prohibit government entities from acquiring or using facial recognition technology. Introduced in February 2026, it was referred to the House Judiciary Finance and Civil Law Committee.
SF 3270 would require express written consent for biometric data collection in places of public accommodation, using a broader definition that includes facial features, gestures, and movements.
HF 4131 would address surveillance-based price and wage discrimination, defining "surveillance data" to include biometric information. If passed, it would take effect August 1, 2026.
None of these bills have advanced beyond committee referral as of March 2026.
How Minnesota Compares to Other States
Minnesota's approach to biometric privacy falls in the middle of the spectrum among U.S. states:
Stronger than states with no protections. Many states still lack any specific biometric data protections. Minnesota's classification of biometric data as sensitive data requiring consent, combined with active AG enforcement, puts it ahead of states with no comprehensive privacy law.
Weaker than dedicated biometric privacy laws. States like Illinois, Texas, and Washington have standalone biometric privacy statutes with specific requirements for notice, consent, retention schedules, and data destruction. Illinois's BIPA includes a private right of action that has produced billions in litigation and settlements.
Similar to other comprehensive privacy law states. Minnesota's approach closely mirrors Kentucky, Connecticut, Indiana, and Montana, which all classify biometric data as sensitive data within their comprehensive consumer privacy frameworks and require opt-in consent for processing.
Notable gap. Unlike states with dedicated biometric breach notification provisions, Minnesota's breach notification statute (Minn. Stat. 325E.61) does not explicitly cover biometric data, leaving a potential gap when breaches involve biometric information without other personal identifiers.
Sources and References
This article references Minnesota statutes and official state government publications. For the full text of the MCDPA, visit the Minnesota Revisor of Statutes. For guidance on consumer rights and filing complaints, visit the Minnesota Attorney General's MCDPA page.
This article provides general legal information about Minnesota biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Minnesota government sources.
More Minnesota Laws
Frequently Asked Questions
Does Minnesota have a standalone biometric privacy law like Illinois?
No. Minnesota does not have a dedicated biometric privacy statute. Instead, the Minnesota Consumer Data Privacy Act (MCDPA), effective July 31, 2025, classifies biometric data as sensitive data within its comprehensive consumer privacy framework. The MCDPA requires businesses to obtain opt-in consent before processing biometric data for identification purposes, but it does not include the detailed retention schedules, destruction timelines, or private right of action found in Illinois BIPA.
Can I sue a company in Minnesota for collecting my fingerprints without consent?
Not under the MCDPA. The Minnesota Attorney General has exclusive enforcement authority, and the law does not include a private right of action. If you believe a company collected your biometric data without consent, you can file a complaint through the AG's Consumer Division at ag.state.mn.us. The AG can investigate and pursue civil penalties of up to $7,500 per violation. Since February 2026, the AG no longer needs to provide advance notice before taking enforcement action.
Does the MCDPA protect my biometric data at work?
No. The MCDPA exempts personal data collected about job applicants, employees, and individuals acting as business representatives when processed in an employment context. If your employer collects fingerprints for timekeeping, uses facial recognition for building access, or requires biometric scans for security purposes, the MCDPA does not regulate that activity. Minnesota does not have a separate law governing employer use of biometric data.
What happens if a biometric data breach occurs in Minnesota?
Minnesota's breach notification law (Minn. Stat. 325E.61) does not explicitly list biometric data as a category of personal information triggering notification. However, the MCDPA requires controllers to maintain reasonable security practices for all personal data, including biometric data. A failure to protect biometric data could lead to AG enforcement under the MCDPA even if the breach notification statute does not technically apply. If the breach also involves Social Security numbers, financial account numbers, or driver's license numbers alongside biometric data, the breach notification law does apply.
Is Minnesota considering stronger biometric privacy protections?
Yes. Several bills in the 94th Minnesota Legislature (2025-2026) could expand protections. HF 3661 would ban government use of facial recognition technology. SF 3270 would require express written consent for biometric data collection in public accommodations using a broader definition than the MCDPA. HF 4131 would address surveillance-based discrimination involving biometric data. None of these bills had advanced beyond committee referral as of March 2026.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 7 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Minnesota Statutes, Chapter 325E: TRADE PRACTICES
§ 325E.61DATA WAREHOUSES; NOTICE REQUIRED FOR CERTAIN DISCLOSURESIn forcecited in 2 of our articles
Subdivision 1. Disclosure of personal information; notice required. (a) Any person or business that conducts business in this state, and that owns or licenses data that includes personal information, shall disclose any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of this state whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in paragraph (c), or with any measures necessary to determine the scope of the breach, identify the individuals affected, and restore the reasonable integrity of the data system. (b) Any person or business that maintains data that includes personal information that the person or business does not own shall notify the owner or licensee of the information of any breach of the security of the data immediately following discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.
Official text (excerpt) · as of 2026-07-29 · Read the full section at revisor.mn.gov
Also relied on in: Minnesota Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Minnesota Statutes, Chapter 325M: CONSUMER DIGITAL AND DATA PRIVACY
§ 325M.11DEFINITIONSIn force
(a) For purposes of sections 325M.10 to 325M.21, the following terms have the meanings given. (b) "Affiliate" means a legal entity that controls, is controlled by, or is under common control with another legal entity. For purposes of this paragraph, "control" or "controlled" means: ownership of or the power to vote more than 50 percent of the outstanding shares of any class of voting security of a company; control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or the power to exercise a controlling influence over the management of a company. (c) "Authenticate" means to use reasonable means to determine that a request to exercise any of the rights under section 325M.14, subdivision 1, paragraphs (b) to (h), is being made by or rightfully on behalf of the consumer who is entitled to exercise the rights with respect to the personal data at issue. (d) "Biometric data" means data generated by automatic measurements of an individual's biological characteristics, including a fingerprint, a voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual.
Official text (excerpt) · as of 2026-07-29 · Read the full section at revisor.mn.gov
§ 325M.12SCOPE; EXCLUSIONSIn forcecited in 5 of our articles
Subdivision 1. Scope. (a) Sections 325M.10 to 325M.21 apply to legal entities that conduct business in Minnesota or produce products or services that are targeted to residents of Minnesota, and that satisfy one or more of the following thresholds: (1) during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more. (b) A controller or processor acting as a technology provider under section 13.32 shall comply with sections 13.32 and 325M.10 to 325M.21, except that when the provisions of section 13.32 conflict with sections 325M.10 to 325M.21, section 13.32 prevails. Subd. 2. Exclusions.
Official text (excerpt) · as of 2026-07-29 · Read the full section at revisor.mn.gov
Also relied on in: Minnesota Data Privacy Laws: Consumer Rights Guide (2026), Minnesota MCDPA Compliance Checklist (Minn. Stat. 325M), What Is the Minnesota Consumer Data Privacy Act (MCDPA)?
§ 325M.14CONSUMER PERSONAL DATA RIGHTSIn forcecited in 5 of our articles
Subdivision 1. Consumer rights provided. (a) Except as provided in sections 325M.10 to 325M.21, a controller must comply with a request to exercise the consumer rights provided in this subdivision. (b) A consumer has the right to confirm whether or not a controller is processing personal data concerning the consumer and access the categories of personal data the controller is processing. (c) A consumer has the right to correct inaccurate personal data concerning the consumer, taking into account the nature of the personal data and the purposes of the processing of the personal data. (d) A consumer has the right to delete personal data concerning the consumer. (e) A consumer has the right to obtain personal data concerning the consumer, which the consumer previously provided to the controller, in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means.
Official text (excerpt) · as of 2026-07-29 · Read the full section at revisor.mn.gov
Also relied on in: Minnesota MCDPA Consumer Rights (Minn. Stat. 325M.14)
§ 325M.16RESPONSIBILITIES OF CONTROLLERSIn forcecited in 3 of our articles
Subdivision 1. Transparency obligations. (a) Controllers must provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes: (1) the categories of personal data processed by the controller; (2) the purposes for which the categories of personal data are processed; (3) an explanation of the rights contained in section 325M.14 and how and where consumers may exercise those rights, including how a consumer may appeal a controller's action with regard to the consumer's request; (4) the categories of personal data that the controller sells to or shares with third parties, if any; (5) the categories of third parties, if any, with whom the controller sells or shares personal data; (6) the controller's contact information, including an active email address or other online mechanism that the consumer may use to contact the controller; (7) a description of the controller's retention policies for personal data; and (8) the date the privacy notice was last updated.
Official text (excerpt) · as of 2026-07-29 · Read the full section at revisor.mn.gov
§ 325M.18DATA PRIVACY POLICIES; DATA PRIVACY AND PROTECTION ASSESSMENTSIn forcecited in 4 of our articles
(a) A controller must document and maintain a description of the policies and procedures the controller has adopted to comply with sections 325M.10 to 325M.21. The description must include, where applicable: (1) the name and contact information for the controller's chief privacy officer or other individual with primary responsibility for directing the policies and procedures implemented to comply with the provisions of sections 325M.10 to 325M.21; and (2) a description of the controller's data privacy policies and procedures which reflect the requirements in section 325M.16, and any policies and procedures designed to: (i) reflect the requirements of sections 325M.10 to 325M.21 in the design of the controller's systems; (ii) identify and provide personal data to a consumer as required by sections 325M.10 to 325M.21; (iii) establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data, including the maintenance of an inventory of the data that must be managed to exercise the responsibilities under this item; (iv) limit the collection of personal data to what…
Official text (excerpt) · as of 2026-07-29 · Read the full section at revisor.mn.gov
§ 325M.20ATTORNEY GENERAL ENFORCEMENTIn forcecited in 5 of our articles
(a) In the event that a controller or processor violates sections 325M.10 to 325M.21, the attorney general, prior to filing an enforcement action under paragraph (b), must provide the controller or processor with a warning letter identifying the specific provisions of sections 325M.10 to 325M.21 the attorney general alleges have been or are being violated. If, after 30 days of issuance of the warning letter, the attorney general believes the controller or processor has failed to cure any alleged violation, the attorney general may bring an enforcement action under paragraph (b). This paragraph expires January 31, 2026. (b) The attorney general may bring a civil action against a controller or processor to enforce a provision of sections 325M.10 to 325M.21 in accordance with section 8.31. If the state prevails in an action to enforce sections 325M.10 to 325M.21, the state may, in addition to penalties provided by paragraph (c) or other remedies provided by law, be allowed an amount determined by the court to be the reasonable value of all or part of the state's litigation expenses incurred.
Official text (excerpt) · as of 2026-07-29 · Read the full section at revisor.mn.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Minnesota Consumer Data Privacy Act (Chapter 325M)(revisor.mn.gov).gov
- Minn. Stat. 325M.11 - MCDPA Definitions(revisor.mn.gov).gov
- Minn. Stat. 325M.12 - Applicability(revisor.mn.gov).gov
- Minn. Stat. 325M.14 - Consumer Rights(revisor.mn.gov).gov
- Minn. Stat. 325M.16 - Controller Obligations(revisor.mn.gov).gov
- Minn. Stat. 325M.18 - Data Protection Assessments(revisor.mn.gov).gov
- Minn. Stat. 325M.20 - Enforcement(revisor.mn.gov).gov
- HF 4757 - MCDPA Bill(revisor.mn.gov).gov
- Minn. Stat. 325E.61 - Breach Notification(revisor.mn.gov).gov
- AG Ellison - MCDPA Takes Effect(ag.state.mn.us).gov
- AG Ellison - MCDPA Full Enforcement(ag.state.mn.us).gov
- Minnesota AG - Consumer Data Privacy(ag.state.mn.us).gov
- HF 3661 - Facial Recognition Ban(revisor.mn.gov).gov
- SF 3270 - Biometric Consent in Public Accommodations(revisor.mn.gov).gov
- HF 4131 - Surveillance-Based Discrimination(revisor.mn.gov).gov