EnglishEspañol
Arkansas flag

Arkansas

Arkansas Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 3 primary sources cited on this page. How we verify our legal content

Arkansas Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Arkansas have a biometric privacy law like Illinois BIPA?

No. Arkansas does not have a standalone biometric privacy statute. Instead, biometric data is included in the definition of personal information under the Personal Information Protection Act (Ark. Code Ann. 4-110-101 et seq.), which primarily governs breach notification and data security. Illinois BIPA requires consent before collection and allows private lawsuits. Arkansas does neither.

Do Arkansas employers need consent to use fingerprint scanners for time clocks?

Arkansas law does not require employers to obtain consent before collecting fingerprints or other biometric data for workplace purposes such as time clocks or building access. However, employers must implement reasonable security measures to protect that data and comply with breach notification requirements if the data is compromised.

What happens if a company has a data breach involving biometric information in Arkansas?

The company must notify affected Arkansas residents in the most expedient time possible and without unreasonable delay. If more than 1,000 people are affected, the company must also notify the Arkansas Attorney General within 45 days. Failure to comply can result in civil penalties up to $10,000 per violation under the Deceptive Trade Practices Act, and willful violations can be prosecuted as a Class A misdemeanor.

Can individuals sue companies in Arkansas for mishandling their biometric data?

No. Arkansas does not provide a private right of action under the Personal Information Protection Act. Only the Arkansas Attorney General can bring enforcement actions against businesses that violate the law. This is one of the most significant limitations of Arkansas biometric data protection compared to states like Illinois.

Will Arkansas pass a comprehensive biometric privacy law in the future?

It remains uncertain. The 2025 attempt (SB 258) included biometric provisions but they were stripped from the bill before it died in the legislature. Senator Clint Penzo has indicated interest in pursuing separate privacy legislation in future sessions. Until new legislation passes, the Personal Information Protection Act and the Deceptive Trade Practices Act remain the primary frameworks protecting biometric data in Arkansas.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the Arkansas Personal Information Protection Act citations on this page: the security and destruction duties under Ark. Code Ann. 4-110-104 had their subsection letters reversed, the definition of biometric data sits at 4-110-103(7)(E)(ii) rather than 4-110-103(1), Act 1030 of 2019 added only biometric data rather than three categories, the breach notification exception applies after a reasonable rather than a good-faith investigation, and the page now states the statutory requirement that a data element counts as personal information only when combined with the individual's name and left unencrypted.

Corrected this page's description of Arkansas's biometric-data definition: the authentication-use requirement applies only to the law's catch-all category of biometric identifiers, not to fingerprints, faceprints, retinal or iris scans, hand geometry, voiceprint, or DNA, which are protected regardless of the purpose for which they were collected. Also corrected the citation for the Class A misdemeanor penalty to Ark. Code Ann. 4-88-103 and replaced a dead source link.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Arkansas Personal Information Protection Act(law.justia.com)
  2. Act 1030 of 2019 - Arkansas State Legislature(arkleg.state.ar.us).gov
  3. Arkansas Deceptive Trade Practices Act(law.justia.com)
  4. Security or Data Breach - Arkansas Attorney General(arkansasag.gov).gov
  5. SB 258 - 2025 Session(arkleg.state.ar.us).gov
  6. Security Breach Notification Chart - Arkansas | Perkins Coie(ashurstperkinscoie.com)
  7. Arkansas Act 1030 of 2019 (HB 1943), adding biometric data to the Personal Information Protection Act at Ark. Code Ann. 4-110-103(7)(E)(arkleg.state.ar.us)
  8. Arkansas Act 1526 of 2005, enacting the Personal Information Protection Act, Ark. Code Ann. 4-110-101 et seq.(arkleg.state.ar.us)
  9. Arkansas House Bill 1943 (2019 Regular Session), the bill enacted as Act 1030(arkleg.state.ar.us)
Share: