
Massachusetts Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Massachusetts has no standalone biometric privacy law, but 201 CMR 17.00, Chapter 93A treble damages, and the pending Data Privacy Act (S.2608) protect biometric data.
Loading...
Browse our full library of legal guides, state law breakdowns, and practical legal information.
2021 articles
Browse by Category →
Massachusetts has no standalone biometric privacy law, but 201 CMR 17.00, Chapter 93A treble damages, and the pending Data Privacy Act (S.2608) protect biometric data.

Maine requires data breach notification within 30 days. Learn who must comply, what triggers notification, encryption safe harbors, and penalties under state law.

Montana MCDPA classifies biometric data as sensitive, requiring opt-in consent. AG-only enforcement with penalties up to $7,500 per violation. No private right of action.

Learn Massachusetts data breach notification rules under Chapter 93H and 201 CMR 17.00, including WISP requirements, penalties, and credit monitoring obligations.

Michigan data breach notification law requires businesses to notify residents of security breaches involving personal information. Learn timelines, penalties, and safe harbors under MCL 445.72.

North Carolina protects biometric data through breach notification laws with treble damages. Learn about NC fingerprint laws, employer rules, and pending privacy legislation.

New Jersey biometric privacy law under the NJDPA requires consent before collecting fingerprints, facial geometry, or voiceprints. Learn the rules, penalties, and your rights.

New York requires data breach notification within 30 days under the SHIELD Act. Learn who must be notified, safeguard requirements, and penalties up to $250K.

Indiana requires data breach notification within 45 days. Learn who must be notified, what personal information triggers the law, penalties up to $150,000, and the biometric data gap.

Delaware requires data breach notification within 60 days. Learn who must comply, what data triggers reporting, AG notice rules, and encryption safe harbor.

Learn how Delaware's Personal Data Privacy Act protects biometric data like fingerprints and iris scans, including consent rules, penalties, and employer obligations.

Learn how Virginia's VCDPA protects biometric data like fingerprints and iris scans. Opt-in consent required, AG enforcement, up to $7,500 per violation.