EnglishEspañol
Alabama flag

Alabama

Alabama Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Alabama Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Alabama have a biometric privacy law?

Not yet in a comprehensive way. Alabama does not have a standalone biometric privacy statute like Illinois BIPA, and its Data Breach Notification Act of 2018 (Ala. Code 8-38-1 et seq.) does not include biometric data among the categories that trigger a breach notice. That changes on May 1, 2027, when the Alabama Personal Data Protection Act (HB 351, enacted 2026) takes effect and requires covered businesses to obtain opt-in consent before processing biometric data used to identify a person.

Can my employer collect my fingerprints without consent in Alabama?

Yes, under current law. Alabama has no statute requiring employers to obtain consent before collecting biometric data such as fingerprints or facial scans from employees, and employers can implement fingerprint time clocks, facial recognition access systems, or other biometric tools without providing written notice or obtaining approval. A breach that exposes only biometric data does not by itself trigger a notification duty under Alabama''s current breach notification law. The Alabama Personal Data Protection Act does not close this gap when it takes effect on May 1, 2027. The Act defines a consumer to exclude an individual acting in a commercial or employment context or as an employee, owner, director, officer, or contractor, and its opt-in consent duty reaches only sensitive data concerning a consumer, so biometric data an employer collects from its own workforce in that role falls outside it.

What are the penalties for a biometric data breach in Alabama?

Alabama''s Data Breach Notification Act does not treat a breach of biometric data alone as a reportable breach, so its penalties apply only if the biometric data was exposed together with a name and another covered category, such as a Social Security or financial account number. In that scenario, Ala. Code 8-38-9 sets two separate penalty tracks: a covered entity that knowingly violates the notice requirements faces a civil penalty under Ala. Code 8-19-11, capped at $500,000 per breach, while any covered entity that fails to take reasonable action to comply, regardless of intent, is separately liable for up to $5,000 per day for each day of non-compliance, with no stated dollar cap on that track. The Attorney General has exclusive enforcement authority. Starting May 1, 2027, the Alabama Personal Data Protection Act adds separate consent obligations for biometric data, also enforced by the Attorney General.

Can I sue a company in Alabama for collecting my biometric data without permission?

No. Alabama does not provide a private right of action for the unauthorized collection of biometric data. The state''s breach notification law also does not allow individuals to sue directly. Only the Alabama Attorney General can bring enforcement actions. This differs from Illinois, where individuals can recover $1,000 to $5,000 per violation of the Biometric Information Privacy Act.

Does Alabama require businesses to delete biometric data?

No. Alabama does not have a law that requires businesses to delete biometric data after a specific period or upon request. The state has no retention schedule or destruction mandate for biometric information held by private entities. The only data-related destruction requirement exists within the breach notification framework, which focuses on notification obligations rather than data lifecycle management.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected two errors: Alabama does restrict law enforcement use of facial recognition match results under Ala. Code 15-10-111, and the Alabama Personal Data Protection Act's 2027 opt-in consent duty covers consumers, not employees.

Corrected the description of Alabama's breach-notification penalties, which are two separate tracks (an uncapped $5,000-per-day track and a $500,000-per-breach cap that applies only to knowing violations) rather than one $5,000/day-capped-at-$500,000 structure; fixed a mischaracterization of a 2026 bill (SB272) as a competing privacy proposal when it is an unrelated public-records bill; and replaced several dead source links, including one that pointed to the wrong statutory section.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected the page's central premise: Alabama's Data Breach Notification Act (Ala. Code 8-38-2) does not define or cover biometric data, so a biometric-only breach does not trigger the 45-day notice. Added the real, newly enacted protection: the Alabama Personal Data Protection Act (HB 351, signed April 2026, effective May 1, 2027) classifies biometric data as sensitive data requiring opt-in consent. Also swapped two competitor-domain (Justia) citations for official Alabama Legislature sources.

Governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Alabama Code 8-38-2, definitions of sensitive personally identifying information (does not include biometric data)(law.justia.com)
  2. Alabama Data Breach Notification Act of 2018 (Acts 2018-396)(alabamaag.gov).gov
  3. Ala. Code 8-38-5 individual breach notification requirements(law.justia.com)
  4. Ala. Code 8-38-9: two penalty tracks -- up to $5,000/day (uncapped) for any noncompliant covered entity, and separately up to $500,000 per breach under 8-19-11 for knowing violations(law.justia.com)
  5. Alabama Attorney General data breach notification page(alabamaag.gov).gov
  6. Alabama SB272 (2026 Regular Session)(alison.legislature.state.al.us).gov
  7. Alabama HB283 Personal Data Protection Act (2025)(alison.legislature.state.al.us).gov
  8. FTC Act Section 5 enforcement authority(ftc.gov).gov
  9. HIPAA Privacy Rule(hhs.gov).gov
  10. COPPA rule on children online privacy(ftc.gov).gov
  11. Alabama HB 351 (2026), Alabama Personal Data Protection Act, enrolled bill (signed April 2026, effective May 1, 2027)(alison.legislature.state.al.us)
  12. Alabama SB56 (2022 Regular Session), enrolled: prohibits state and local law enforcement from using facial recognition match results as the sole basis for probable cause or arrest (Act 2022-420)(alison.legislature.state.al.us)
  13. Ala. Code 15-10-111, use of facial recognition technology match results to establish probable cause or to make an arrest(alison.legislature.state.al.us)
Share: