EnglishEspañol
Georgia flag

Georgia

Georgia Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Georgia Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Georgia have a biometric privacy law?

No. Georgia has no biometric-specific statute like Illinois' BIPA, and no comprehensive consumer privacy law at all. A bill from the 2025-2026 session, SB 111 (the Georgia Consumer Privacy Protection Act), would have classified biometric data processed to uniquely identify a person as sensitive data requiring consent, but a House committee stripped those provisions before passage. Governor Kemp signed a substitute bill as Act 462 on May 11, 2026, and that substitute is an unrelated rural hospital tax-credit measure.

Can my employer require fingerprint scans in Georgia?

Yes. Georgia law does not restrict employers from collecting biometric data such as fingerprints or facial scans. Employers are not required to obtain written consent, disclose how biometric data will be used, or establish retention and destruction schedules. SB 111, the bill that would have created consent requirements for biometric data, never became law, and it would have exempted employee and contractor data anyway. This differs significantly from states like Illinois, where employers must obtain informed written consent before collecting any biometric information.

What happens if my biometric data is breached in Georgia?

Georgia's Personal Identity Protection Act (O.C.G.A. 10-1-912) requires breach notification, but only when the breach involves personal information as defined by the statute, which includes Social Security numbers, driver's license numbers, and financial account numbers. Biometric data is not included in this definition, so a breach involving only biometric records would not trigger notification requirements under current state law.

Can I sue a company in Georgia for misusing my biometric data?

No. Georgia has no biometric privacy statute at all, so there is no state law right of action for biometric data misuse. Unlike Illinois, where individuals can sue under BIPA and recover statutory damages, Georgia residents must rely on common-law tort theories such as invasion of privacy or negligence, federal protections like the FTC Act, or a complaint to the Georgia Attorney General. SB 111, which would have given the Attorney General enforcement authority over biometric consent requirements, never became law.

Has Georgia passed a biometric privacy law?

No. Georgia has not enacted a dedicated biometric privacy statute or a comprehensive consumer privacy law. The Georgia Consumer Privacy Protection Act (SB 111) would have covered biometric data as sensitive data requiring consent, but a House committee stripped those provisions before the bill passed. Governor Kemp signed a substitute bill, an unrelated rural hospital tax-credit measure, into law as Act 462 on May 11, 2026. The privacy provisions, including Attorney General enforcement with penalties up to $7,500 per violation, never took effect.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected a leftover sentence that described SB 111's biometric consent requirement as if it were current Georgia law, clarified that SB 111 was a bill from the 2025-2026 session rather than a 2026 bill, and added a section on Georgia's business record disposal law (O.C.G.A. 10-15-1 et seq.), the one state statute that names fingerprints and photographs among covered identifiers and the narrow duty it actually imposes.

Corrected this page to reflect that Georgia's SB 111 (Georgia Consumer Privacy Protection Act) never became law: its biometric-data consent and enforcement provisions were stripped by a House committee, and the bill Governor Kemp signed as Act 462 on May 11, 2026 is an unrelated rural hospital tax-credit measure. Georgia has no comprehensive privacy law and no biometric-specific statute. Also fixed a dead Illinois BIPA citation link and relabeled two SB 111 citations to reflect the bill's actual status.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Corrected the article: Georgia’s SB 111 (the Georgia Consumer Privacy Protection Act) was not left stalled in the legislature as previously stated — Governor Kemp signed it into law as Act 462 on May 11, 2026 (effective July 1, 2026), and it now requires consent before covered businesses process biometric data as sensitive data. Updated the intro, KeyTakeaways, legislation section, comparison table, and FAQs to reflect enactment, and relabeled the stale bill-page citation.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Georgia Personal Identity Protection Act breach notification requirements(law.justia.com)
  2. O.C.G.A. 10-1-911 definitions of personal information(law.justia.com)
  3. Georgia Fair Business Practices Act(law.justia.com)
  4. Georgia General Assembly: SB 111 (2025-2026) bill history -- Senate-passed as a privacy bill, House substituted with an unrelated rural-hospital tax-credit measure that was enacted as Act 462 on May 11, 2026(legis.ga.gov).gov
  5. SB 111 as passed by the Senate, March 2025 (privacy text; later replaced by a House substitute and not the enacted law)(legis.ga.gov).gov
  6. ACLU of Georgia report on SB 111(acluga.org)
  7. FTC Act Section 5 enforcement authority(ftc.gov).gov
  8. HIPAA Privacy Rule(hhs.gov).gov
  9. FERPA privacy requirements(www2.ed.gov).gov
  10. COPPA rule on children online privacy(ftc.gov).gov
  11. Illinois Biometric Information Privacy Act, 740 ILCS 14/20 (right of action and statutory damages)(ilga.gov).gov
  12. O.C.G.A. 10-15-1 definitions, including subsection (10)(A) defining 'personally identifiable' to include a customer's fingerprint, photograph, or computerized image, and subsection (9) listing the four categories of covered personal information(law.justia.com)
Share: