Georgia
Georgia Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Georgia has no biometric-specific privacy law and no comprehensive consumer privacy statute. A bill from the 2025-2026 session, SB 111 (the Georgia Consumer Privacy Protection Act), would have classified biometric data processed to uniquely identify a person as sensitive data and required covered businesses to obtain consent before processing it, but a House committee stripped the privacy provisions and replaced the bill with an unrelated rural hospital tax-credit measure before final passage. Governor Kemp signed that substitute into law as Act 462 on May 11, 2026; the privacy requirements never took effect. The Personal Identity Protection Act (O.C.G.A. 10-1-910 et seq.) separately requires breach notification but excludes biometric data from its definition of personal information, leaving biometric-only breaches without a state-level notification requirement.
Georgia is one of the majority of U.S. states that has not enacted a dedicated biometric privacy law. Residents who use fingerprint scanners at work, submit to facial recognition at public venues, or provide biometric data to apps and devices have limited state-level legal protections governing how that data is collected, stored, shared, or destroyed.
This guide explains what Georgia law currently does and does not cover when it comes to biometric information, what happened to the Georgia Consumer Privacy Protection Act (SB 111) and why it never took effect, and what federal protections fill the remaining gaps.
For broader context on Georgia's overall privacy framework, see the parent guide to Georgia Data Privacy Laws.
What Counts as Biometric Data
Biometric data includes unique physical or behavioral characteristics used to identify an individual. Common examples include fingerprints, facial geometry (used in facial recognition), iris and retina scans, voiceprints, palm prints, and gait analysis.
States with dedicated biometric privacy laws, such as Illinois (BIPA) and Texas (CUBI), define these identifiers in statute and regulate how entities handle them. Georgia has not taken this step.
Georgia's Current Legal Framework
Personal Identity Protection Act (O.C.G.A. 10-1-910 et seq.)
Georgia's primary data protection law is the Personal Identity Protection Act, enacted in 2005 and amended in 2007. This law requires "information brokers" (businesses that sell personal data to third parties) and government data collectors to notify Georgia residents when a breach compromises personal information.
However, the statute defines "personal information" under O.C.G.A. 10-1-911 as an individual's name combined with one or more of the following:
- Social Security number
- Driver's license or state ID number
- Financial account, credit card, or debit card numbers (with access codes)
- Account passwords or PINs
Biometric data such as fingerprints, facial scans, and voiceprints are not included in this definition. A breach involving only biometric records would not trigger notification obligations under current Georgia law.
Fair Business Practices Act (O.C.G.A. 10-1-390 et seq.)
Georgia's Fair Business Practices Act prohibits unfair and deceptive trade practices. While the statute does not mention biometric data specifically, a business that made false promises about how it handles biometric information could theoretically face enforcement action under this law.
The Georgia Attorney General enforces the FBPA. There is no private right of action that would allow individual consumers to sue for biometric data misuse under this statute alone.
Record Disposal Law (O.C.G.A. 10-15-1 et seq.)
One Georgia statute does name biometric identifiers directly. The state's business record disposal law defines "personally identifiable" in O.C.G.A. 10-15-1(10)(A) as data capable of being associated with a particular customer through identifiers "including, but not limited to, a customer's fingerprint, photograph, or computerized image," listed alongside Social Security numbers, passport numbers, and dates of birth.
O.C.G.A. 10-15-2 then bars a business from discarding a customer record that contains personal information unless it shreds the record, erases the information, makes it unreadable, or takes other steps it reasonably believes will keep unauthorized people from reaching the data before the record is destroyed.
Three limits keep this from operating as a biometric privacy law:
- It is a destruction duty only. Nothing in the chapter requires consent, notice, a retention schedule, or any limit on collecting, using, or sharing biometric data.
- It reaches customer records. O.C.G.A. 10-15-1(4) defines a customer as an individual who provides personal information to buy or lease a product or obtain a service, so employee fingerprints and facial scans fall outside it entirely.
- The record's content must fit one of four categories listed in O.C.G.A. 10-15-1(9): a customer's medical condition; account or identification numbers and balances; data provided when opening an account or applying for a loan or credit; and income tax return data. A biometric identifier captured outside those contexts, such as a facial scan at a venue entrance, is not covered.
The Attorney General enforces the chapter and may impose a penalty of up to $500 for each customer record wrongfully discarded under O.C.G.A. 10-15-6(a), capped at $10,000.00 in total, subject to an affirmative defense for a business that used due diligence. There is no private right of action, and the chapter does not apply to banks covered by the Gramm-Leach-Bliley Act or to hospitals covered by HIPAA.
No Employer-Specific Biometric Rules

Georgia does not restrict employers from collecting fingerprints, facial scans, or other biometric data from employees. Businesses that use biometric time clocks, fingerprint-based access controls, or facial recognition for security purposes are not required by state law to:
- Obtain written consent before collecting biometric data
- Disclose how biometric data will be stored or used
- Establish retention schedules or destruction timelines
- Limit sharing of biometric data with third parties
This stands in sharp contrast to states like Illinois, where the Biometric Information Privacy Act requires informed written consent and imposes statutory damages of $1,000 to $5,000 per violation.
SB 111: Georgia's Failed Consumer Privacy Protection Act (2026)

The most significant recent development for biometric privacy in Georgia is SB 111, the Georgia Consumer Privacy Protection Act, which would have covered biometric data as sensitive data but never became law. Governor Kemp signed a substitute bill as Act 462 on May 11, 2026, and that substitute is an unrelated rural hospital tax-credit measure, not a privacy law.
What SB 111 Would Have Done for Biometric Data
As passed by the Senate, SB 111 would have classified biometric data processed for the purpose of uniquely identifying an individual as "sensitive data." The Senate-passed version would have:
- Required covered businesses to obtain explicit consumer consent before processing biometric data
- Mandated clear notices when a business sells or shares sensitive data, including biometric information
- Required data protection assessments for activities involving sensitive data processing
- Authorized the Georgia Attorney General to seek civil penalties of up to $7,500 per violation, with treble damages for knowing or willful violations
None of these provisions are in effect, because they were removed before the bill passed.
What Actually Happened
SB 111 passed the Georgia Senate on March 3, 2025, by a vote of 53-2, as a comprehensive privacy bill. The House withdrew and recommitted the bill in March 2025 and did not act on it before the 2025 session adjourned. When the House took the bill back up in 2026, a House committee replaced the entire bill with a substitute unrelated to privacy, amending the state's rural hospital tax credit statute instead. The House passed that substitute 162-1 on March 31, 2026, the Senate agreed to it on April 2, 2026, and Governor Kemp signed it into law as Act 462 on May 11, 2026. The Governor's own press release describes Act 462 solely as expanding tax-credit eligibility for rural hospitals, with no mention of consumer privacy.
The ACLU of Georgia had criticized the Senate-passed privacy version for high applicability thresholds before it was stripped out: it would have applied only to entities that exceed $25 million in annual revenue and process personal information of at least 175,000 Georgia residents, or 25,000 residents if the entity derives more than 50% of revenue from selling personal data.
Georgia has no comprehensive consumer privacy law and no biometric-specific statute today.
Federal Protections That Apply in Georgia
Because SB 111's privacy provisions never became law, and Georgia's record disposal law reaches only the narrow slice of customer records described above, federal statutes are the primary legal guardrails for biometric data in Georgia.
Section 5 of the FTC Act allows the Federal Trade Commission to bring enforcement actions against companies engaged in unfair or deceptive practices involving biometric data. The FTC has taken action against companies for deceptive facial recognition practices and inadequate data security.
HIPAA protects biometric data when it is collected or used by covered healthcare entities and their business associates. Fingerprint or facial recognition data used in a healthcare setting falls under HIPAA's Privacy Rule.
FERPA restricts how educational institutions handle student biometric data. Schools that use fingerprint-based lunch payment systems or facial recognition must comply with FERPA's privacy requirements.
COPPA imposes strict requirements on the collection of biometric data from children under 13, including parental consent requirements enforced by the FTC.
How Georgia Compares to Other States
Georgia falls into the least protective tier of states for biometric privacy. For comparison:
- Illinois has the strongest biometric law in the country (BIPA), with a private right of action and statutory damages of $1,000 to $5,000 per violation
- Texas and Washington have biometric-specific statutes enforced by their attorneys general
- States with comprehensive privacy laws (like Colorado, Connecticut, and Virginia) classify biometric data as sensitive and require consent for processing
- Georgia has no biometric-specific statute and no comprehensive privacy law. SB 111 would have classified biometric data as sensitive and required consent from covered businesses, but the House stripped those provisions before passage, so none of it became law
This article provides general legal information about Georgia biometric privacy laws. It is not legal advice. Laws and regulations change frequently, and this content may not reflect the most recent developments. Consult a qualified attorney licensed in Georgia for advice about your specific situation.
More Georgia Laws
Frequently Asked Questions
Does Georgia have a biometric privacy law?
No. Georgia has no biometric-specific statute like Illinois' BIPA, and no comprehensive consumer privacy law at all. A bill from the 2025-2026 session, SB 111 (the Georgia Consumer Privacy Protection Act), would have classified biometric data processed to uniquely identify a person as sensitive data requiring consent, but a House committee stripped those provisions before passage. Governor Kemp signed a substitute bill as Act 462 on May 11, 2026, and that substitute is an unrelated rural hospital tax-credit measure.
Can my employer require fingerprint scans in Georgia?
Yes. Georgia law does not restrict employers from collecting biometric data such as fingerprints or facial scans. Employers are not required to obtain written consent, disclose how biometric data will be used, or establish retention and destruction schedules. SB 111, the bill that would have created consent requirements for biometric data, never became law, and it would have exempted employee and contractor data anyway. This differs significantly from states like Illinois, where employers must obtain informed written consent before collecting any biometric information.
What happens if my biometric data is breached in Georgia?
Georgia's Personal Identity Protection Act (O.C.G.A. 10-1-912) requires breach notification, but only when the breach involves personal information as defined by the statute, which includes Social Security numbers, driver's license numbers, and financial account numbers. Biometric data is not included in this definition, so a breach involving only biometric records would not trigger notification requirements under current state law.
Can I sue a company in Georgia for misusing my biometric data?
No. Georgia has no biometric privacy statute at all, so there is no state law right of action for biometric data misuse. Unlike Illinois, where individuals can sue under BIPA and recover statutory damages, Georgia residents must rely on common-law tort theories such as invasion of privacy or negligence, federal protections like the FTC Act, or a complaint to the Georgia Attorney General. SB 111, which would have given the Attorney General enforcement authority over biometric consent requirements, never became law.
Has Georgia passed a biometric privacy law?
No. Georgia has not enacted a dedicated biometric privacy statute or a comprehensive consumer privacy law. The Georgia Consumer Privacy Protection Act (SB 111) would have covered biometric data as sensitive data requiring consent, but a House committee stripped those provisions before the bill passed. Governor Kemp signed a substitute bill, an unrelated rural hospital tax-credit measure, into law as Act 462 on May 11, 2026. The privacy provisions, including Attorney General enforcement with penalties up to $7,500 per violation, never took effect.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected a leftover sentence that described SB 111's biometric consent requirement as if it were current Georgia law, clarified that SB 111 was a bill from the 2025-2026 session rather than a 2026 bill, and added a section on Georgia's business record disposal law (O.C.G.A. 10-15-1 et seq.), the one state statute that names fingerprints and photographs among covered identifiers and the narrow duty it actually imposes.
Corrected this page to reflect that Georgia's SB 111 (Georgia Consumer Privacy Protection Act) never became law: its biometric-data consent and enforcement provisions were stripped by a House committee, and the bill Governor Kemp signed as Act 462 on May 11, 2026 is an unrelated rural hospital tax-credit measure. Georgia has no comprehensive privacy law and no biometric-specific statute. Also fixed a dead Illinois BIPA citation link and relabeled two SB 111 citations to reflect the bill's actual status.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Corrected the article: Georgia’s SB 111 (the Georgia Consumer Privacy Protection Act) was not left stalled in the legislature as previously stated — Governor Kemp signed it into law as Act 462 on May 11, 2026 (effective July 1, 2026), and it now requires consent before covered businesses process biometric data as sensitive data. Updated the intro, KeyTakeaways, legislation section, comparison table, and FAQs to reflect enactment, and relabeled the stale bill-page citation.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Official Code of Georgia Annotated
§ 10-1-911Definitions.In forcecited in 3 of our articles
As used in this article, the term: (1) "Breach of the security of the system" means unauthorized acquisition of an individual's electronic data that compromises the security, confidentiality, or integrity of personal information of such individual maintained by an information broker or data collect
Official text (excerpt) · last checked 2026-08-04 · Read the full text in our law library · Verify at legis.ga.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2018
Opinions citing this section in our collection:
- McCONNELL Et Al. v. DEPARTMENT OF LABOR (Court of Appeals of Georgia 2016, 337 Ga. App. 457)“…stribution, and content of the notices. OCGA §10-1-912. See OCGA § 10-1-911 (1) (definition of a “breach of the sec…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Georgia Data Privacy Laws: Breach Notification & Consumer Rights (2026), Georgia Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 10-1-912Notification required upon breach of security regarding personal information.In forcecited in 3 of our articles
(a) Any information broker or data collector that maintains computerized data that includes personal information of individuals shall give notice of any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of this state…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legis.ga.gov
Cited in 3 court opinions in our collectionLatest citing opinion in our collection: 2019
Opinions citing this section in our collection:
- McCONNELL Et Al. v. DEPARTMENT OF LABOR (Court of Appeals of Georgia 2016, 337 Ga. App. 457)“…is of the timing, distribution, and content of the notices. OCGA §10-1-912. See OCGA § 10-1-911 (1) (definition of…”
- In re Equifax, Inc. (District Court, N.D. Georgia 2019, 362 F. Supp. 3d 1295)“…The Court agrees that the absence of any such language in O.C.G.A. § 10-1-912 counsels strongly against inferring a p…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 10-1-910Legislative findings.In force
The General Assembly finds and declares as follows: (1) The privacy and financial security of individuals is increasingly at risk due to the ever more widespread collection of personal information by both the private and public sectors; (2) Credit card transactions, magazine subscriptions, real es
Official text (excerpt) · last checked 2026-08-04 · Read the full text in our law library · Verify at legis.ga.gov
Cited in 16 court opinions in our collectionLatest citing opinion in our collection: 2022
Opinions citing this section in our collection:
- McCONNELL Et Al. v. DEPARTMENT OF LABOR (Court of Appeals of Georgia 2016, 337 Ga. App. 457)“…s underlying the Georgia Personal Identity Protection Act, OCGA §§ 10-1-910 through 10-1-915 (the “GPIPA”), enacte…”
- Dep't of Labor v. Mcconnell (Supreme Court of Georgia 2019, 305 Ga. 812)“…radley Center . McConnell also argues that two statutes, OCGA §§ 10-1-910 and 10-1-393.8, created a legal duty on…”
- COLLINS v. ATHENS ORTHOPEDIC CLINIC, P.A (Supreme Court of Georgia 2019, 307 Ga. 555)“…17 under either OCGA § 10-1-393.8, OCGA § 10-1-910, or purported common law duty “to all…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 10-1-390Short title.In forcecited in 2 of our articles
This part shall be known and may be cited as the "Fair Business Practices Act of 1975." (Ga. L. 1975, p. 376, § 1; Ga. L. 2015, p. 1088, § 2/SB 148.)
Official text (excerpt) · last checked 2021-08-17 · Read the full text in our law library
Cited in 171 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Larson v. TANDY CORPORATION (Court of Appeals of Georgia 1988, 187 Ga. App. 893)“…es in violation of the Fair Business Practices Act of 1975, OCGA § 10-1-390 et seq. 1. Larson asserts that his bu…”
- Robin v. Bellsouth Advertising & Publishing Co. (Court of Appeals of Georgia 1996, 221 Ga. App. 360)“…lations, and violations of the Fair Business Practices Act, OCGA § 10-1-390 et seq. Tucked amid large and sm…”
- ANTOINETTE MARQUES v. JP MORGAN CHASE BANK, N.A. (Court of Appeals of Georgia 2023)“…10-1-370 et seq., and the Fair Business Practices Act, OCGA §§ 10-1-390 et seq. She alleged that those acts an…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Georgia Lemon Law (2026): How to Qualify & Get a Refund
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Georgia Personal Identity Protection Act breach notification requirements(law.justia.com)
- O.C.G.A. 10-1-911 definitions of personal information(law.justia.com)
- Georgia Fair Business Practices Act(law.justia.com)
- Georgia General Assembly: SB 111 (2025-2026) bill history -- Senate-passed as a privacy bill, House substituted with an unrelated rural-hospital tax-credit measure that was enacted as Act 462 on May 11, 2026(legis.ga.gov).gov
- SB 111 as passed by the Senate, March 2025 (privacy text; later replaced by a House substitute and not the enacted law)(legis.ga.gov).gov
- ACLU of Georgia report on SB 111(acluga.org)
- FTC Act Section 5 enforcement authority(ftc.gov).gov
- HIPAA Privacy Rule(hhs.gov).gov
- FERPA privacy requirements(www2.ed.gov).gov
- COPPA rule on children online privacy(ftc.gov).gov
- Illinois Biometric Information Privacy Act, 740 ILCS 14/20 (right of action and statutory damages)(ilga.gov).gov
- O.C.G.A. 10-15-1 definitions, including subsection (10)(A) defining 'personally identifiable' to include a customer's fingerprint, photograph, or computerized image, and subsection (9) listing the four categories of covered personal information(law.justia.com)