Wisconsin
Wisconsin Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Wisconsin has no standalone biometric privacy law, but its breach notification statute (Wis. Stat. 134.98) explicitly includes biometric data and DNA profiles as protected personal information. Businesses must notify affected residents within 45 days of a breach. The law does not require consent before collecting biometric data and provides no private right of action.
Wisconsin occupies a middle ground in the national biometric privacy landscape. The state does not have a standalone biometric privacy law like Illinois or Texas, but its breach notification statute provides more protection than many states by explicitly covering biometric data and DNA profiles.
What makes Wisconsin noteworthy is the breadth of its breach notification definitions. While states like West Virginia exclude biometric data entirely from breach notification, Wisconsin casts a wider net that includes fingerprints, voiceprints, retina images, and even DNA profiles as separate protected categories.
For a broader overview of privacy protections in the state, see the parent guide to Wisconsin Data Privacy Laws.
How Wisconsin Law Defines Biometric Data

Wisconsin's breach notification statute, Wis. Stat. 134.98, defines personal information to include an individual's unique biometric data. Under Wis. Stat. 134.98(1)(b)5., the covered biometric data types include:
- Fingerprints
- Voiceprints
- Retina or iris images
- Any other unique physical representation
This definition is broad enough to cover emerging biometric technologies such as facial geometry scans, hand geometry measurements, and vein pattern recognition, so long as they qualify as a "unique physical representation."
DNA Profile: A Separate Category
Wisconsin stands out by separately listing an individual's DNA profile as a protected data element under Wis. Stat. 134.98. The DNA profile definition references Wis. Stat. 939.74(2d)(a), which defines it in the context of criminal proceedings.
By covering DNA profiles as their own category alongside biometric data, Wisconsin provides one of the more comprehensive breach notification definitions for biological identifiers in the country.
Breach Notification Requirements
When a breach exposes biometric data or DNA profiles, Wisconsin's notification requirements apply.
Who Must Comply
Any entity whose principal place of business is in Wisconsin, or any entity that maintains or licenses personal information in Wisconsin, must comply with the notification requirements under Wis. Stat. 134.98(2).
What Triggers Notification
A notification obligation arises when an entity knows that personal information in its possession has been acquired by a person whom the entity has not authorized to acquire the information. This applies when the unauthorized acquisition involves biometric data, DNA profiles, or other covered personal information that has not been encrypted, redacted, or otherwise rendered unreadable.
45-Day Notification Timeline
Under Wis. Stat. 134.98(3)(a), an entity must provide notice within a reasonable time, not to exceed 45 days after the entity learns of the unauthorized acquisition. The determination of what is reasonable considers the number of notices the entity must send and the communication methods available.
This 45-day maximum is stricter than states that use a vague "without unreasonable delay" standard but more lenient than states like Colorado (30 days).
Notification Methods
The entity must provide notice by mail or by a method the entity has previously employed to communicate with the affected individual. If the entity has an email address but has not previously communicated with the individual by email, mail is the default method.
Substitute Notice
Wisconsin's breach notification statute does not set a dollar-cost or headcount threshold for substitute notice, unlike many other states' breach laws. If an entity cannot with reasonable diligence determine the mailing address of an affected individual, and has not previously communicated with that individual, the entity must provide notice by a method reasonably calculated to provide actual notice to the individual. The statute does not enumerate specific substitute methods such as email, website posting, or media notice.
Federal Preemption
Entities that comply with federal breach notification requirements under regulations such as HIPAA or GLBA are deemed to be in compliance with Wisconsin's notification law, provided the entity notifies affected individuals as required by the applicable federal law.
Consumer Reporting Agency Notification
Under Wis. Stat. 134.98(2)(br), if a breach requires notification of 1,000 or more individuals, the entity must also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis. This is an additional requirement that applies on top of individual notification.
Enforcement and Penalties

Wisconsin's breach notification statute takes an unusual approach to enforcement. Under Wis. Stat. 134.98(4), the statute explicitly states that failure to comply is not negligence or a breach of any duty, but may be evidence of negligence or a breach of a legal duty.
This means:
- There are no specific civil penalties in the statute for failing to provide breach notification
- Non-compliance cannot by itself support a negligence claim
- However, non-compliance can be used as evidence in a civil lawsuit to support a claim that the entity was negligent or breached a duty
The Wisconsin Department of Agriculture, Trade and Consumer Protection (DATCP) provides guidance on the breach notification law and can receive consumer complaints. The Wisconsin Attorney General may also pursue enforcement actions related to unfair or deceptive business practices.
What Wisconsin Law Does Not Cover
Despite including biometric data in breach notification, Wisconsin's protections have significant gaps.
No Collection Consent Requirements
Wisconsin law does not require businesses or employers to obtain consent before collecting biometric data. A company can implement fingerprint scanners, facial recognition cameras, or voice authentication systems without providing notice or obtaining any form of permission.
No Retention or Destruction Rules
There are no requirements to set retention schedules for biometric data, publish data retention policies, or destroy biometric data after a set period or when the purpose for collection ends.
No Purpose Limitation
Businesses that collect biometric data in Wisconsin face no restrictions on how they use, share, or sell that data.
No Private Right of Action for Biometric Violations
While non-compliance with the breach notification law can serve as evidence in a negligence claim, there is no standalone private right of action for biometric data collection or misuse.
Proposed Wisconsin Data Privacy Act

Wisconsin legislators have introduced comprehensive privacy legislation that would strengthen biometric data protections.
Assembly Bill 172 / Senate Bill 166 (2025)
In 2025, Wisconsin introduced AB 172 in the Assembly and its companion SB 166 in the Senate. The proposed Wisconsin Data Privacy Act would:
- Define biometric data as data generated by automatic measurements of biological characteristics, including fingerprints, voiceprints, eye retinas, irises, or other unique biological patterns used to identify a specific individual
- Classify biometric data as sensitive data requiring opt-in consent before processing
- Grant consumers rights to access, delete, and port their personal data
- Require data controllers to recognize opt-out preference signals
- Mandate data protection assessments for processing activities involving sensitive data
- Establish Attorney General enforcement authority
SB 166 was referred to the Senate Committee on Licensing, Regulatory Reform, State and Federal Affairs in March 2025. A previous version of the bill passed the Assembly in 2023 but failed to advance in the Senate.
If enacted, the Wisconsin Data Privacy Act would significantly expand biometric data protections beyond the current breach notification framework.
How Wisconsin Compares to Neighboring States
Wisconsin's approach to biometric privacy is stronger than some neighbors but weaker than others.
Illinois has the strongest protections in the region with its Biometric Information Privacy Act (BIPA), which includes a private right of action and has generated thousands of lawsuits. Minnesota enacted comprehensive consumer data privacy legislation with biometric data provisions.
Iowa passed its Consumer Data Protection Act, which classifies biometric data as sensitive. Michigan has considered biometric privacy legislation but has not yet enacted comprehensive protections.
Wisconsin's inclusion of biometric data and DNA profiles in breach notification puts it ahead of states that lack even that level of coverage.
Practical Guidance for Wisconsin Residents
Wisconsin residents should be aware that while their biometric data is protected in the event of a breach, there are no restrictions on its collection or use before a breach occurs.
If you believe your biometric data was compromised in a breach and you did not receive notification within 45 days, contact the Wisconsin DATCP to file a complaint. You may also contact the Wisconsin Attorney General for consumer protection concerns.
Review privacy policies before providing biometric data to businesses or apps. While Wisconsin does not require consent, understanding how your data will be used can help you make informed decisions.
Sources and References
This article references Wisconsin statutes available through the Wisconsin Legislature website. For consumer guidance on data breaches, visit the Wisconsin DATCP. For proposed legislation, see AB 172. For consumer complaints, contact the Wisconsin Attorney General.
This article provides general legal information about Wisconsin biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Wisconsin government sources.
More Wisconsin Laws
Frequently Asked Questions
Does Wisconsin have a biometric privacy law?
Wisconsin does not have a standalone biometric privacy law. However, the state's breach notification statute (Wis. Stat. 134.98) explicitly includes biometric data and DNA profiles in the definition of personal information that triggers notification requirements when a breach occurs. Businesses must notify affected residents within 45 days of discovering a breach.
Can my employer collect my fingerprints without consent in Wisconsin?
Yes. Wisconsin law does not require employers to obtain consent before collecting biometric data. There are no state requirements for notice, consent, retention schedules, or data destruction related to employer-collected biometric information. Federal laws like HIPAA may apply in specific health care employment contexts.
What biometric data is protected under Wisconsin's breach notification law?
Wis. Stat. 134.98 protects fingerprints, voiceprints, retina or iris images, and any other unique physical representation. Wisconsin also separately protects DNA profiles, making it one of the few states to cover genetic data as its own category alongside biometric data.
What happens if a company fails to notify me of a biometric data breach in Wisconsin?
Wisconsin's breach notification law does not establish specific civil penalties for non-compliance. However, failure to comply may be used as evidence of negligence or breach of a legal duty in a civil lawsuit. You can also file a complaint with the Wisconsin DATCP or the Attorney General's office.
Will Wisconsin pass a comprehensive biometric privacy law?
Wisconsin has introduced the Wisconsin Data Privacy Act (AB 172/SB 166 in 2025) which would classify biometric data as sensitive and require opt-in consent for processing. A previous version passed the Assembly in 2023 but failed in the Senate. The current bill is in committee. Check the Wisconsin Legislature website at docs.legis.wisconsin.gov for updates.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
Corrected three mis-cited Wis. Stat. 134.98 subsection numbers (biometric-data definition is (1)(b)5. not 4.; the 45-day notice deadline is (3)(a) not (3m); the 1,000-person consumer-reporting-agency notice rule is (2)(br) not (4)) and removed a fabricated $100,000/175,000-threshold substitute-notice provision that does not appear anywhere in the statute.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 2 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Wisconsin Statutes, Chapter 134: Miscellaneous Trade Regulations
§ 134.98Notice of unauthorized acquisition of personal information.In forcecited in 4 of our articles
(1) Definitions. In this section: (a) 1. “Entity” means a person, other than an individual, that does any of the following: a. Conducts business in this state and maintains personal information in the ordinary course of business. b. Licenses personal information in this state. c. Maintains for a resident of this state a depository account as defined in s. 815.18 (2) (e). d. Lends money to a resident of this state. 2. “Entity” includes all of the following: a. The state and any office, department, independent agency, authority, institution, association, society, or other body in state government created or authorized to be created by the constitution or any law, including the legislature and the courts. b. A city, village, town, or county. (am) “Name” means an individual’s last name combined with the individual’s first name or first initial. (b) “Personal information” means an individual’s last name and the individual’s first name or first initial, in combination with and linked to any of the following elements, if the element is not publicly available information and is not encrypted, redacted, or altered in a manner that renders the element unreadable: 1.
Official text (excerpt) · as of 2026-07-29 · Read the full section at docs.legis.wisconsin.gov
Also relied on in: Wisconsin Data Privacy Laws: Breach Notification & Consumer Rights (2026), Wisconsin Data Breach Notification Laws: Reporting Rules & Timelines (2026), Wisconsin Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
Wisconsin Statutes, Chapter 939: Crimes
§ 939.74Time limitations on prosecutions.In forcecited in 4 of our articles
(1) Except as provided in subs. (2) and (2d) and s. 946.88 (1), prosecution for a felony must be commenced within 6 years and prosecution for a misdemeanor or for adultery within 3 years after the commission thereof. Within the meaning of this section, a prosecution has commenced when a warrant or summons is issued, an indictment is found, or an information is filed. (2) Notwithstanding that the time limitation under sub. (1) has expired: (a) 1. A prosecution under s. 940.01, 940.02, 940.03, 940.05, 940.225 (1), 948.02 (1), or 948.025 (1) (a), (b), (c), or (d) may be commenced at any time. 2. A prosecution for an attempt to commit a violation of s. 940.01, 940.05, 940.225 (1), or 948.02 (1) may be commenced at any time. (am) A prosecution under s. 940.06 may be commenced within 15 years after the commission of the violation. (ap) A prosecution under s. 940.11 (2) may be commenced within the applicable time under sub. (1) or within 6 years of the date the corpse was discovered or identified, whichever is later. (ar) A prosecution for a violation of s. 940.225 (2) may be commenced within 20 years after the commission of the violation. A prosecution for a violation of s.
Official text (excerpt) · as of 2026-07-29 · Read the full section at docs.legis.wisconsin.gov
Also relied on in: Wisconsin Statute of Limitations: Filing Deadlines by Case Type
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Wis. Stat. 134.98 - Breach Notification Law(docs.legis.wisconsin.gov).gov
- Wis. Stat. 134.98(1)(b)5. - Biometric Data Definition(docs.legis.wisconsin.gov).gov
- Wis. Stat. 134.98(3)(a) - 45-Day Notification Timeline(docs.legis.wisconsin.gov).gov
- Wis. Stat. 134.98(2) - Notification Requirements(docs.legis.wisconsin.gov).gov
- Wis. Stat. 134.98(4) - Enforcement Provisions(docs.legis.wisconsin.gov).gov
- Wisconsin DATCP - Data Breach Notification Guidance(datcp.wi.gov).gov
- AB 172 - Wisconsin Data Privacy Act (2025)(docs.legis.wisconsin.gov).gov
- Wisconsin DATCP - Privacy Laws Overview(datcp.wi.gov).gov