Nebraska
Nebraska Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Nebraska has no standalone biometric privacy statute. The Nebraska Data Privacy Act (NDPA), Neb. Rev. Stat. sections 87-1101 through 87-1130, effective January 1, 2025, classifies biometric data as sensitive personal data requiring opt-in consent. The Nebraska Attorney General enforces the law exclusively; no private right of action exists.
Nebraska does not have a standalone biometric privacy statute like Illinois's BIPA or Texas's CUBI. Instead, biometric data protections in the state come primarily from the Nebraska Data Privacy Act (NDPA), a comprehensive consumer privacy law that classifies biometric identifiers as sensitive data requiring affirmative consent before collection or processing.
Governor Jim Pillen signed LB 1074 into law on April 17, 2024, making Nebraska one of the growing number of states with comprehensive consumer data privacy protections. The NDPA took effect on January 1, 2025.
For an overview of Nebraska's broader privacy framework, see the parent guide to Nebraska Data Privacy Laws.
How the NDPA Defines Biometric Data
The NDPA defines biometric data under Neb. Rev. Stat. section 87-1102 as data generated by automatic measurements of an individual's biological characteristics that are used to identify a specific individual. The statute lists these examples:
- Fingerprints
- Voiceprints
- Retina images
- Iris images
- Other unique biological patterns or characteristics

The law draws a clear boundary around what does not qualify. A physical or digital photograph, a video or audio recording, or data generated from those recordings is not biometric data unless that data is specifically generated to identify a specific individual.
This definition follows the approach used in several other state comprehensive privacy statutes including Connecticut and Kentucky. It is narrower than the definition used in Illinois's BIPA, which covers a broader set of biometric identifiers without the same exclusions.
Sensitive Data Classification and Consent
Under the NDPA, biometric data processed for the purpose of uniquely identifying an individual qualifies as "sensitive data." This is the highest protection category in the law.
Other categories of sensitive data under Neb. Rev. Stat. section 87-1102 include:
- Data revealing racial or ethnic origin
- Religious beliefs
- Mental or physical health diagnoses
- Sexual orientation
- Citizenship or immigration status
- Genetic data processed for identification
- Precise geolocation data (within a 1,750-foot radius)
- Personal data collected from a known child under 13
Consent requirement. Controllers must obtain a consumer's opt-in consent before processing sensitive data, including biometric data. Under section 87-1112, a business cannot collect your fingerprint, faceprint, or iris scan for identification purposes without first asking for and receiving your affirmative agreement.
This consent must be a "clear and affirmative act" that is freely given, specific, informed, and unambiguous. A buried clause in a terms-of-service agreement does not meet this standard. The NDPA explicitly states that agreements obtained through dark patterns do not constitute valid consent.

Who Must Comply
The NDPA applies to entities that conduct business in Nebraska or produce products or services targeted to Nebraska residents and that:
- Process or engage in the sale of personal data, and
- Are not classified as a small business under the federal Small Business Act (as of January 1, 2024)
Nebraska's approach is notable because it does not set a numeric processing threshold the way many other state privacy laws do. Instead, it relies on the Small Business Administration's size standards to separate covered businesses from exempt ones. This potentially sweeps in more mid-sized companies than states with rigid 100,000-consumer thresholds.
Even small businesses face one key restriction: under section 87-1118, they cannot sell sensitive personal data, including biometric data, without first obtaining the consumer's consent.
Key Exemptions
The NDPA carves out several categories of entities and data types from coverage.
Entity exemptions:
- HIPAA-covered entities and their business associates
- Financial institutions subject to the Gramm-Leach-Bliley Act (GLBA)
- Nonprofit organizations
- Higher education institutions
- State agencies and political subdivisions
- Electric suppliers and natural gas utilities
Data exemptions:
- Data regulated under HIPAA
- Data governed by the Fair Credit Reporting Act (FCRA)
- Data covered by the Family Educational Rights and Privacy Act (FERPA)
- Data under the Driver's Privacy Protection Act (DPPA)
- Employment-related data
Employee data exemption. The NDPA defines a "consumer" as an individual residing in Nebraska who is acting in a personal or household context. Individuals acting in a commercial or employment context are excluded. This means that if your employer collects your fingerprints for a timekeeping system or uses facial recognition for building access, the NDPA does not apply to that collection.
Nebraska does not currently have a separate law that specifically regulates employer use of biometric data.
Consumer Rights Over Biometric Data
Because biometric data is sensitive personal data under the NDPA, Nebraska consumers have the following rights under section 87-1107:
Right to confirm and access. You can ask any covered business whether it is processing your biometric data and request access to that data.
Right to correct. If a business holds inaccurate biometric data about you, you can request a correction.
Right to delete. You can request that a business delete the biometric data it holds about you.
Right to data portability. You can obtain a copy of your biometric data in a portable and readily usable format.
Right to opt out. You can opt out of the processing of your personal data for targeted advertising, the sale of personal data, or profiling that produces legal or similarly significant effects.
Right to non-discrimination. Businesses cannot penalize you for exercising any of these rights by denying goods or services, charging different prices, or providing a different quality of service.
Businesses must respond to consumer rights requests within 45 days. They may extend this period by an additional 45 days when reasonably necessary, but must notify the consumer of the extension and the reason for it.
Enforcement and Penalties
The Nebraska Attorney General holds exclusive enforcement authority over the NDPA. There is no private right of action under the law.
30-day cure period. Before filing an enforcement action, the Attorney General must provide the alleged violator with written notice identifying the specific provisions believed to have been violated. The business then has 30 days to cure the violation. If the business provides a written statement that it has addressed the alleged violation and commits to no future violations, the Attorney General must stop the action. See section 87-1122.
Penalties. If a violation is not cured, the Attorney General can seek:
- Civil penalties up to $7,500 per violation
- Injunctive relief
- Recovery of attorney fees and investigative costs
The Protect the Good Life initiative from the Nebraska Attorney General's Office provides consumer guidance and accepts data privacy complaints.

Breach Notification and Biometric Data
Nebraska's separate Financial Data Protection and Consumer Notification of Data Security Breach Act (Neb. Rev. Stat. sections 87-801 to 87-808) provides an additional layer of protection for biometric data.
Under section 87-802, personal information includes a Nebraska resident's first name or first initial and last name combined with any of these unencrypted data elements:
- Social Security number
- Driver's license or state identification number
- Account number, credit card, or debit card number with security codes
- Unique electronic identifier or routing code combined with access credentials
- Unique biometric data, such as a fingerprint, voiceprint, or retina or iris image, or other unique physical representation
The law also covers username or email address combined with a password or security question and answer that would permit access to an online account.
When a business becomes aware of a breach involving biometric data, it must conduct a prompt investigation to determine the likelihood that the information has been or will be used for an unauthorized purpose. If unauthorized use has occurred or is reasonably likely, the business must notify affected Nebraska residents.
The Attorney General may issue subpoenas and seek direct economic damages for each affected resident.
Cybersecurity Safe Harbor (LB 241)
In March 2025, Governor Pillen signed LB 241, which provides businesses with class action immunity for cybersecurity events unless the business acted with willful, wanton, or grossly negligent conduct.
The law defines protected "nonpublic information" to include biometric records alongside Social Security numbers, financial account data, and other sensitive identifiers.
Key features of the safe harbor:
- Applies to class actions only. Individual lawsuits and regulatory enforcement actions by the Attorney General are not affected.
- No framework requirement. Unlike similar laws in Ohio and Connecticut, Nebraska does not require businesses to follow a specific cybersecurity framework (such as NIST) to claim the safe harbor.
- Covers biometric records. A data breach involving biometric data is covered by the immunity, provided the business was not grossly negligent.
This law creates a practical incentive for businesses to maintain reasonable cybersecurity measures while offering protection against costly class action litigation.
Pending Legislation: Biometric Autonomy Liberty Law
The Nebraska Legislature is also considering LB 204, the Biometric Autonomy Liberty Law, introduced by Senator Kauth in January 2025. If enacted, this law would:
- Establish biometric data as the property of the individual from whom it was collected
- Allow individuals to sell or consent to the use of their biometric data
- Prohibit private and public entities from requiring or coercing individuals to submit to biometric data collection
- Ban mandatory implantable devices and devices that collect biometric data
As of March 2026, LB 204 has been referred to the Banking, Commerce and Insurance Committee and received a hearing on March 17, 2025, but has not advanced to a floor vote. A companion bill, LB 729, was introduced in the 2026 session.
How Nebraska Compares to Other States
Nebraska's approach to biometric privacy through a comprehensive privacy act places it in the same category as states like Virginia, Colorado, and Connecticut, which protect biometric data through their broader privacy frameworks.
| Feature | Nebraska (NDPA) | Illinois (BIPA) | Texas (CUBI) |
|---|---|---|---|
| Standalone biometric law | No | Yes | Yes |
| Private right of action | No | Yes | No |
| Consent required | Opt-in for sensitive data | Written informed consent | Informed consent |
| Enforcement | AG only | AG + private lawsuits | AG only |
| Employee data covered | No | Yes | Yes |
| Penalties | $7,500/violation | $1,000-$5,000/violation | $25,000/violation |
| Cure period | 30 days | None | 30 days |
The most significant difference is the employee exemption. Illinois BIPA and Texas CUBI apply to employers who collect fingerprints, facial geometry, and other biometric data from workers. Nebraska's NDPA does not protect employees in this context.
This article is for informational purposes only and does not constitute legal advice. Biometric privacy laws change frequently. Consult a qualified attorney licensed in Nebraska for guidance on your specific situation.
More Nebraska Laws
Frequently Asked Questions
Does Nebraska have a standalone biometric privacy law?
No. Nebraska protects biometric data through the Nebraska Data Privacy Act (NDPA), a comprehensive consumer privacy law that classifies biometric data as sensitive personal data requiring opt-in consent. The state does not have a standalone law similar to Illinois BIPA. However, the legislature is considering LB 204, the Biometric Autonomy Liberty Law, which would create dedicated biometric protections if enacted.
What biometric data does the Nebraska Data Privacy Act cover?
The NDPA covers data generated by automatic measurements of biological characteristics used to identify a specific individual, including fingerprints, voiceprints, retina images, iris images, and other unique biological patterns. Photographs, video recordings, and audio recordings are excluded unless they are specifically generated to identify someone.
Does Nebraska law require consent before collecting biometric data?
Yes. Under the NDPA, biometric data is classified as sensitive data, and controllers must obtain opt-in consent from consumers before processing it. This consent must be a clear, affirmative act that is freely given, specific, informed, and unambiguous. Agreements obtained through dark patterns do not qualify as valid consent.
Are employers in Nebraska required to get consent before collecting employee biometric data?
The NDPA does not apply to biometric data collected in an employment context. The law defines consumers as individuals acting in a personal or household capacity, which excludes employees. Nebraska does not currently have a separate law governing employer use of biometric data such as fingerprint timekeeping systems or facial recognition for building access.
What happens if a company suffers a data breach involving biometric data in Nebraska?
Nebraska's Financial Data Protection and Consumer Notification of Data Security Breach Act (Neb. Rev. Stat. 87-801 to 87-808) requires businesses to notify affected Nebraska residents when unencrypted biometric data is compromised in a security breach. The Attorney General can issue subpoenas and seek direct economic damages. Additionally, under the 2025 cybersecurity safe harbor law (LB 241), businesses have class action immunity for data breaches unless they acted with willful, wanton, or grossly negligent conduct.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 10 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Nebraska Revised Statutes, Chapter 87: TRADE PRACTICES
§ 87-1101Act, how citedIn forcecited in 3 of our articles
Sections 87-1101 to 87-1130 shall be known and may be cited as the Data Privacy Act.
Official text (excerpt) · as of 2026-07-29 · Read the full section at nebraskalegislature.gov
Also relied on in: Nebraska AI Meeting Recording Laws (2026), What Is the NDPA? Nebraska Data Privacy Law (2026)
§ 87-1102Terms, definedIn forcecited in 4 of our articles
For purposes of the Data Privacy Act: (1) Affiliate means a legal entity that controls, is controlled by, or is under common control with another legal entity or shares common branding with another legal entity. For purposes of this subdivision, control or controlled means: (a) The ownership of, or power to vote, more than fifty percent of the outstanding shares of any class of voting security of a company; (b) The control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or (c) The power to exercise controlling influence over the management of a company; (2) Authenticate means to verify through reasonable means that the consumer who is entitled to exercise the consumer's rights under sections 87-1107 to 87-1111, or a person on behalf of such consumer, is the same consumer exercising those consumer rights with respect to the personal data at issue; (3)(a) Biometric data means data that is generated to identify a specific individual through an automatic measurement of a biological characteristic of such individual and includes any: (i) Fingerprint; (ii) Voice print; (iii) Retina image; (iv) Iris image; or (v)…
Official text (excerpt) · as of 2026-07-29 · Read the full section at nebraskalegislature.gov
Also relied on in: NDPA Consumer Rights: Nebraska Data Privacy (2026), Nebraska Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
§ 87-1107Consumer rights; request to exerciseIn forcecited in 3 of our articles
(1) A consumer may at any time submit a request to a controller specifying the consumer rights the consumer wishes to exercise. With respect to the processing of personal data belonging to a known child, a parent or legal guardian of the child may exercise the consumer rights on behalf of the known child. (2) A controller shall comply with an authenticated consumer request to exercise the right to: (a) Confirm whether a controller is processing the consumer's personal data and to access the personal data; (b) Correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (c) Delete personal data provided by or obtained about the consumer; (d) If the data is available in a digital format and the processing is completed by automated means, obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance; or (e) Opt out of the processing of the personal data for purposes…
Official text (excerpt) · as of 2026-07-29 · Read the full section at nebraskalegislature.gov
Also relied on in: Nebraska Data Privacy Laws: Consumer Rights Guide (2026)
§ 87-1112Controller; personal data; requirements on collection and useIn forcecited in 4 of our articles
(1) A controller: (a) Shall limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which that personal data is processed, as disclosed to the consumer; and (b) For purposes of protecting the confidentiality, integrity, and accessibility of personal data, shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices that are appropriate to the volume and nature of the personal data at issue.
Official text (excerpt) · as of 2026-07-29 · Read the full section at nebraskalegislature.gov
Also relied on in: NDPA Compliance Checklist: Nebraska Privacy (2026)
§ 87-1118Sensitive data; sale; consent requiredIn forcecited in 4 of our articles
(1) A person described by subdivision (1)(c) of section 87-1103 shall not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer. (2) A person who violates this section is subject to the penalty under section 87-1124.
Official text (excerpt) · as of 2026-07-29 · Read the full section at nebraskalegislature.gov
§ 87-1122Controller or processor; notification of violations; responseIn forcecited in 3 of our articles
Before bringing an action under section 87-1124, the Attorney General shall notify a controller or processor in writing, not later than the thirtieth day before bringing the action, identifying the specific provisions of the Data Privacy Act the Attorney General alleges have been or are being violated. The Attorney General may not bring an action against the controller or processor if: (1) Within the thirty-day period, the controller or processor cures the identified violation; and (2) The controller or processor provides the Attorney General: (a) A written statement that the controller or processor cured the alleged violation and supportive documentation to show how such violation was cured; and (b) An express written statement that the controller or processor shall not commit any such violation after the alleged violation has been cured.
Official text (excerpt) · as of 2026-07-29 · Read the full section at nebraskalegislature.gov
§ 87-1124Violation; penalty; actions authorizedIn forcecited in 4 of our articles
(1) A person who violates the Data Privacy Act following the cure period described by section 87-1122 or who breaches a written statement provided to the Attorney General under such section is liable for a civil penalty in an amount not to exceed seven thousand five hundred dollars for each violation. (2) The Attorney General may bring an action in the name of the State of Nebraska to: (a) Recover a civil penalty under this section; (b) Restrain or enjoin the person from violating the Data Privacy Act; or (c) Recover the civil penalty and seek injunctive relief. (3) The Attorney General may recover reasonable attorney's fees and other reasonable expenses incurred in investigating and bringing an action under this section. (4) All money collected under this section shall be remitted to the State Treasurer for distribution in accordance with Article VII, section 5, of the Constitution of Nebraska.
Official text (excerpt) · as of 2026-07-29 · Read the full section at nebraskalegislature.gov
§ 87-1125Private right of actionIn force
The Data Privacy Act shall not be construed as providing a basis for, or being subject to, a private right of action for a violation of the Data Privacy Act or any other law.
Official text (excerpt) · as of 2026-07-29 · Read the full section at nebraskalegislature.gov
§ 87-801Act, how citedIn forcecited in 2 of our articles
Sections 87-801 to 87-808 shall be known and may be cited as the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006.
Official text (excerpt) · as of 2026-07-29 · Read the full section at nebraskalegislature.gov
Also relied on in: Nebraska Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 87-802Terms, definedIn forcecited in 2 of our articles
For purposes of the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006: (1) Breach of the security of the system means the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by an individual or a commercial entity. Good faith acquisition of personal information by an employee or agent of an individual or a commercial entity for the purposes of the individual or the commercial entity is not a breach of the security of the system if the personal information is not used or subject to further unauthorized disclosure.
Official text (excerpt) · as of 2026-07-29 · Read the full section at nebraskalegislature.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Nebraska Data Privacy Act (Neb. Rev. Stat. 87-1101 to 87-1130)(nebraskalegislature.gov).gov
- NDPA Definitions (Neb. Rev. Stat. 87-1102)(nebraskalegislature.gov).gov
- NDPA Consumer Rights (Neb. Rev. Stat. 87-1107)(nebraskalegislature.gov).gov
- NDPA Personal Data Collection Requirements (Neb. Rev. Stat. 87-1112)(nebraskalegislature.gov).gov
- NDPA Small Business Sensitive Data Restriction (Neb. Rev. Stat. 87-1118)(nebraskalegislature.gov).gov
- NDPA Enforcement and Cure Period (Neb. Rev. Stat. 87-1122)(nebraskalegislature.gov).gov
- NDPA Penalties (Neb. Rev. Stat. 87-1124)(nebraskalegislature.gov).gov
- NDPA No Private Right of Action (Neb. Rev. Stat. 87-1125)(nebraskalegislature.gov).gov
- LB 1074 Enrolled Bill Text(nebraskalegislature.gov).gov
- Nebraska Breach Notification Act (Neb. Rev. Stat. 87-801)(nebraskalegislature.gov).gov
- Breach Notification Definitions (Neb. Rev. Stat. 87-802)(nebraskalegislature.gov).gov
- Protect the Good Life - Nebraska AG Data Privacy(protectthegoodlife.nebraska.gov).gov
- LB 204 - Biometric Autonomy Liberty Law(nebraskalegislature.gov).gov
- LB 729 - Biometric Autonomy Liberty Law (2026)(nebraskalegislature.gov).gov