Louisiana
Louisiana Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 12 primary sources cited on this page. How we verify our legal content

Louisiana has no standalone biometric privacy statute. The state's Database Security Breach Notification Law (La. R.S. 51:3071 et seq.) protects biometric data by requiring entities to notify affected residents within 60 days of a breach. A separate law (La. R.S. 17:100.8) requires written parental consent before schools collect student biometric information.
Louisiana does not have a standalone biometric privacy law. Unlike Illinois, Texas, and Washington, the state has not enacted legislation that specifically regulates how private businesses collect, store, use, or share biometric identifiers such as fingerprints, facial geometry, or iris scans.
What Louisiana does have is a breach notification law that includes biometric data in its definition of protected personal information, and a separate student-specific biometric law. These protections are limited compared to states with dedicated biometric statutes, but they do create real obligations for businesses and schools that handle biometric data in Louisiana.
This guide explains the current legal framework, what protections exist, where the gaps are, and what changes when the state's newly enacted privacy law takes effect in 2027.
For broader context on Louisiana's overall privacy framework, see the parent guide to Louisiana Data Privacy Laws.
How Louisiana Defines Biometric Data
Louisiana's Database Security Breach Notification Law defines "biometric data" under La. R.S. 51:3073 as:
Data generated by automatic measurements of an individual's biological characteristics, such as fingerprints, voice print, eye retina or iris, or other unique biological characteristic that is used by the owner or licensee to uniquely authenticate an individual's identity when the individual accesses a system or account.
This definition is narrower than what states like Illinois use. It only covers biometric data used for authentication purposes, meaning fingerprints or facial scans used to unlock a system or verify identity. Biometric data collected for other purposes, such as surveillance cameras using facial recognition to track foot traffic, may fall outside this definition.
The law also requires that the biometric data be paired with an individual's first name (or first initial) and last name to qualify as protected "personal information."
Database Security Breach Notification Law (La. R.S. 51:3071 et seq.)
Louisiana's primary biometric protection comes from the Database Security Breach Notification Law, originally enacted in 2005 and significantly amended in 2018 by Senate Bill 361. The 2018 amendments added biometric data to the list of protected personal information elements.
What the Law Requires
Any person or business that conducts business in Louisiana and owns or licenses computerized data containing personal information must take several steps under this law.
Reasonable security measures. Entities must implement and maintain "reasonable security procedures and practices appropriate to the nature of the information" to protect personal data from unauthorized access, destruction, use, modification, or disclosure (La. R.S. 51:3074).
Breach notification within 60 days. If a breach compromises biometric data (combined with an individual's name), the entity must notify affected Louisiana residents "in the most expedient time possible and without unreasonable delay but not later than sixty days from the discovery of the breach."
Attorney General notification. This duty comes from the Attorney General's own regulation, not from the breach notification statute. Under La. Admin. Code tit. 16, Pt. III, Sec. 701, an entity that has to notify Louisiana residents of a breach must also send written notice to the Attorney General's Consumer Protection Section, and that notice must include the names of all Louisiana citizens affected by the breach. Notice to the Attorney General is timely if it is received within 10 days of distributing notice to residents. La. R.S. 51:3074 itself imposes only two Attorney-General-facing duties: a written explanation of any delay in notifying residents (Subsection E), and, on written request, a copy of a no-harm determination (Subsection I).
Data destruction. When personal information (including biometric data) is no longer needed, entities must destroy or erase records so the data "cannot be read or reconstructed."

Penalties for Non-Compliance
Violations of the breach notification law carry real consequences.
A failure to comply is treated as an unfair trade practice under La. R.S. 51:1405(A). That section declares the conduct unlawful and opens the door to enforcement by the Louisiana Attorney General, but it sets no penalty amount of its own.
Two separate $5,000 figures are easy to confuse. Under the Attorney General's breach-reporting regulation, La. Admin. Code tit. 16, Pt. III, Sec. 701, failure to provide timely notice to the Attorney General "may be punishable by a fine not to exceed $5,000 per violation," and each day notice is not received by the Attorney General is deemed a separate violation. Separately, La. R.S. 51:1407(B) lets a court impose a civil penalty of up to $5,000 for each violation of the Unfair Trade Practices Act, but by the terms of that subsection the penalty is available where the court finds the practice was "entered into with the intent to defraud."
Individuals also have a private right of action. Louisiana residents can sue for actual damages caused by a failure to provide timely breach notification.
If a court finds that a violation was committed knowingly after the entity was put on notice by the Attorney General, the court can award treble damages (three times actual damages) plus reasonable attorney fees and costs.
Exemptions
The law includes several exceptions. Entities that determine after a reasonable investigation that there is "no reasonable likelihood of harm" to affected residents may skip notification, but they must keep written documentation of that determination for five years and provide it to the Attorney General within 30 days upon request.
Financial institutions that comply with the Gramm-Leach-Bliley Act and federal interagency guidance on data security are considered compliant with Louisiana's breach notification requirements.
Encrypted data is also exempt. The statute does not apply to personal information that has been encrypted or redacted.

Student Biometric Protections (La. R.S. 17:100.8)
Louisiana has a separate, more protective law specifically for student biometric data. La. R.S. 17:100.8 regulates the collection and use of biometric information by schools and school governing authorities.
This law defines "biometric information" more broadly than the breach notification statute. It covers "the noninvasive electronic measurement and evaluation of any physical characteristics that are attributable to a single person," including fingerprint characteristics, eye characteristics, hand characteristics, vocal characteristics, facial characteristics, and any other physical characteristics used for electronic identification.
Key Requirements for Schools
Schools that collect student biometric data must follow these rules:
Written parental consent. Schools must obtain written permission from a student's parent or legal guardian (or the student if 18 or older) before collecting any biometric information. The consent form must be a standalone document created specifically for this purpose and cannot be bundled with enrollment forms.
Full disclosure. Schools must develop policies that explain what biometric data will be collected, how it will be collected and stored, and how it will be used.
Limited use. Student biometric data can only be used for identification or fraud prevention purposes. Schools cannot repurpose it for other uses.
Encryption required. Student biometric information must be encrypted using an algorithmic process that transforms the data into a form with a "low probability of assigning meaning" without a confidential key.
Mandatory destruction. Schools must discontinue use and destroy all biometric data within 30 days when a student graduates, withdraws, or when a parent submits a written request to stop collection.
No denial of services. A student cannot be refused services because a parent declines to consent to biometric data collection.
What Louisiana Law Does Not Cover
Louisiana's existing laws leave significant gaps in biometric privacy protection.
No general consent requirement (changing for covered businesses in 2027). Outside of the school context, Louisiana does not currently require businesses or employers to obtain consent before collecting biometric data from adults. Starting January 1, 2027, the Louisiana Data Privacy Act (Act 502 of 2026) will require a covered controller to get opt-in consent before processing biometric data used to identify a consumer, though the law exempts data handled in an employment context. Because of that exemption, an employer can still implement fingerprint time clocks or facial recognition systems without notifying employees or getting their approval.
No retention or destruction timelines for private entities. The breach notification law requires destruction of data that is no longer needed, but it does not mandate specific retention schedules or destruction timelines for biometric data held by businesses.
No restrictions on biometric data sales (changing for covered businesses in 2027). Louisiana does not currently prohibit or restrict the sale or sharing of biometric data with third parties. Starting January 1, 2027, the Louisiana Data Privacy Act (Act 502 of 2026) adds sale-side duties: a controller that sells personal data that is biometric data must post a conspicuous notice reading "NOTICE: We may sell your biometric personal data," and an entity described in R.S. 51:1780.2(A)(3) may not sell personal data that is sensitive data, a category that includes biometric data processed to uniquely identify an individual, without first receiving the consumer's consent.
No private right of action for collection practices. While individuals can sue over a failure to notify them of a breach, there is no private right of action for the unauthorized collection, use, or storage of biometric data itself.
No law enforcement restrictions. Louisiana has not enacted limits on government or law enforcement use of facial recognition or other biometric surveillance technologies.

Employer Use of Biometric Data
Louisiana has no state law that restricts employers from collecting biometric data from employees. Companies operating in Louisiana that use fingerprint scanners for timekeeping, facial recognition for building access, or other biometric systems are not required by state law to:
- Provide written notice before collecting biometric data
- Obtain employee consent
- Establish data retention policies
- Limit sharing of employee biometric data with vendors or third parties
This stands in sharp contrast to Illinois, where employers face statutory damages of $1,000 to $5,000 per violation of the Biometric Information Privacy Act.
That said, employers in Louisiana should still implement reasonable security measures for biometric data. If a breach occurs that exposes employee biometric data alongside names, the employer must comply with the 60-day breach notification requirement or face penalties under the Unfair Trade Practices Act.

The Louisiana Data Privacy Act (Enacted 2026)
Louisiana has seen two major privacy bills in recent years: one that failed and one that became law.
Louisiana Consumer Privacy Act (HB 947, 2024). This bill was introduced in April 2024 and would have created a comprehensive consumer privacy framework. The bill was referred to the House Committee on Commerce but did not advance beyond committee.
Louisiana Data Privacy Act (SB 386, Act 502 of 2026). Governor Jeff Landry signed SB 386 into law as Act 502 on May 29, 2026, creating the Louisiana Data Privacy Act. The law takes effect January 1, 2027, and applies to businesses that do business in Louisiana and either have more than $25 million in annual gross revenue, buy, sell, or share the personal data of 75,000 or more consumers, households, or devices, or derive 50 percent or more of revenue from selling personal data.
Once effective, the law classifies biometric data processed to uniquely identify a person as sensitive data and bars a covered controller from processing it without the consumer's opt-in consent. That consent duty is separate from a narrower notice requirement: a controller that sells biometric personal data must post a conspicuous notice reading "NOTICE: We may sell your biometric personal data." The law defines "consumer" to exclude a person acting in an employment context, so it will not change the employer practices described below.
SB 386 brings Louisiana into the group of states, including Colorado, Connecticut, and Virginia, that classify biometric data as sensitive information requiring affirmative consent.
Federal Protections That Apply in Louisiana
Because Louisiana lacks a comprehensive biometric privacy law, federal statutes provide additional protections for residents.
Section 5 of the FTC Act allows the Federal Trade Commission to take enforcement action against companies engaged in unfair or deceptive practices involving biometric data, including failures to secure biometric information or deceptive collection practices.
HIPAA protects biometric data collected or used by covered healthcare entities and their business associates under the Privacy Rule.
FERPA restricts how schools handle student biometric data at the federal level, supplementing Louisiana's state-level student biometric protections under La. R.S. 17:100.8.
COPPA requires parental consent before collecting biometric data from children under 13, enforced by the FTC.
How Louisiana Compares to Other States
Louisiana falls into a lower tier of states for biometric privacy protection. While the inclusion of biometric data in the breach notification law is meaningful, the state lacks the collection-level protections found in more protective states.
- Illinois has the strongest biometric law in the nation (BIPA), with a private right of action and statutory damages of $1,000 to $5,000 per violation
- Texas and Washington have biometric-specific statutes enforced by their attorneys general
- States with comprehensive privacy laws (Colorado, Connecticut, Virginia, and Louisiana starting January 1, 2027) classify biometric data as sensitive and require opt-in consent
- Louisiana protects biometric data today through breach notification, student biometric rules, and general unfair trade practices enforcement, and will add opt-in consent requirements for covered businesses when the Louisiana Data Privacy Act (Act 502 of 2026) takes effect on January 1, 2027
This article provides general legal information about Louisiana biometric privacy laws. It is not legal advice. Laws and regulations change frequently, and this content may not reflect the most recent developments. Consult a qualified attorney licensed in Louisiana for advice about your specific situation.
More Louisiana Laws
Frequently Asked Questions
Does Louisiana have a biometric privacy law?
Louisiana does not have a standalone biometric privacy statute like Illinois BIPA. However, the state does protect biometric data through its Database Security Breach Notification Law (La. R.S. 51:3071 et seq.), which requires companies to notify residents within 60 days if a breach exposes their biometric data. Louisiana also has a separate student biometric law (La. R.S. 17:100.8) that requires parental consent before schools collect fingerprints or other biometric data from students. Starting January 1, 2027, the Louisiana Data Privacy Act (Act 502 of 2026) will also require covered businesses to get a consumer's opt-in consent before processing biometric data used to identify that consumer.
Can my employer collect my fingerprints without consent in Louisiana?
Yes. Louisiana has no law requiring employers to obtain consent before collecting biometric data such as fingerprints or facial scans from employees. Employers can implement fingerprint time clocks, facial recognition access systems, or other biometric tools without providing written notice or obtaining approval. However, if biometric data is breached, the employer must notify affected individuals within 60 days under the state breach notification law.
What happens if my biometric data is breached in Louisiana?
If a breach exposes your biometric data combined with your name, the entity that owned or licensed the data must notify you within 60 days. Under the Attorney General's breach-reporting regulation (La. Admin. Code tit. 16, Pt. III, Sec. 701), it must also report the breach to the Louisiana Attorney General, including the names of affected Louisiana citizens, and that report is timely if received within 10 days of distributing notice to residents. A late report may be punishable by a fine of up to $5,000 per violation, with each day the Attorney General does not receive notice deemed a separate violation. Failure to comply is also an unfair trade practice, and La. R.S. 51:1407(B) allows a civil penalty of up to $5,000 per violation where a court finds the practice was entered into with the intent to defraud. You can also sue for actual damages caused by the delayed or missing notification.
Can I sue a company in Louisiana for collecting my biometric data without permission?
No. Louisiana does not provide a private right of action for the unauthorized collection of biometric data. You can sue if a company fails to notify you of a breach involving your biometric data, but there is no state law allowing you to sue simply because a company collected your fingerprints or facial scan without your consent. This differs from Illinois, where individuals can recover $1,000 to $5,000 per violation of the Biometric Information Privacy Act.
Does Louisiana protect students' biometric data?
Yes. Louisiana R.S. 17:100.8 requires schools to obtain written parental consent on a standalone form before collecting biometric data from students. Schools must disclose what data they collect and how it will be used, encrypt all biometric information, limit use to identification or fraud prevention, and destroy the data within 30 days of a student's graduation, withdrawal, or parental request to stop collection. Students cannot be denied services if parents decline consent.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the source of Louisiana's Attorney General breach-reporting rules and the $5,000 penalty, which come from La. Admin. Code tit. 16, Pt. III, Sec. 701 and La. R.S. 51:1407(B) rather than La. R.S. 51:3074 or 51:1405, and noted the biometric data sale duties that take effect January 1, 2027.
Updated this page to reflect that Louisiana's SB 386 was signed into law as Act 502 on May 29, 2026, creating the Louisiana Data Privacy Act (effective January 1, 2027, with an opt-in consent duty for biometric data used to identify a person), corrected how the law's sale-notice requirement works, and fixed a citation link that pointed to the wrong statute section.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Louisiana Revised Statutes
§ 51:3074Protection of personal information; disclosure upon breach in the security of personal information; notification requirements; exemptionIn forcecited in 6 of our articles
A. Any person that conducts business in the state or that owns or licenses computerized data that includes personal information, or any agency that owns or licenses computerized data that includes personal information, shall implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. B. Any person that conducts business in the state or that owns or licenses computerized data that includes personal information, or any agency that owns or licenses computerized data that includes personal information shall take all reasonable steps to destroy or arrange for the destruction of the records within its custody or control containing personal information that is no longer to be retained by the person or business by shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any means. C.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legis.la.gov
Cross-referenced in the statute itself: § 51:1405
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2007
Opinions citing this section in our collection:
- Ponder v. Pfizer, Inc. (District Court, M.D. Louisiana 2007, 522 F. Supp. 2d 793)“…believed to have been, acquired by an unauthorized person.” La. R.S. 51:3074(A). Notification, which “shall be made…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Louisiana Data Privacy Laws: Comprehensive Guide (2026), Louisiana Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 17:100.8Student biometric information; collection and useIn forcecited in 2 of our articles
A. For the purposes of this Section, "biometric information" means the noninvasive electronic measurement and evaluation of any physical characteristics that are attributable to a single person, including fingerprint characteristics, eye characteristics, hand characteristics, vocal characteristics, facial characteristics, and any other physical characteristics used for the purpose of electronically identifying that person with a high degree of certainty. B. The governing authority of each public elementary and secondary school that collects biometric information from students shall develop, adopt, and implement policies governing the collection and use of such information that, at a minimum, shall: (1) Contain a full explanation of what type of biometric information will be collected, how it will be collected and stored, and the purposes for which such information will be used. (2) Require written permission from the student's parent or other legal guardian, or the student if he or she is eighteen years of age or older, prior to the collection of any biometric information.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at legis.la.gov
§ 51:3073DefinitionsIn forcecited in 4 of our articles
As used in this Chapter, the following terms shall have the following meanings: (1) "Agency" means the state, a political subdivision of the state, and any officer, agency, board, commission, department or similar body of the state or any political subdivision of the state. (2) "Breach of the security of the system" means the compromise of the security, confidentiality, or integrity of computerized data that results in, or there is a reasonable likelihood to result in, the unauthorized acquisition of and access to personal information maintained by an agency or person. Good faith acquisition of personal information by an employee or agent of an agency or person for the purposes of the agency or person is not a breach of the security of the system, provided that the personal information is not used for, or is subject to, unauthorized disclosure. (3) "Person" means any individual, corporation, partnership, sole proprietorship, joint stock company, joint venture, or any other legal entity.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at legis.la.gov
§ 51:1405Unfair acts or practices; interpretation and rulemaking authorityIn forcecited in 4 of our articles
A. Unfair methods of competition and unfair or deceptive acts or practices in the conduct of any trade or commerce are hereby declared unlawful. B. The attorney general may make rules and regulations interpreting the provisions of this Chapter consistent with the provisions in R.S. 51:1 through 461.1. Such rules and regulations shall be adopted in the form and manner prescribed by the Administrative Procedure Act, R.S. 49:950 et seq. The validity or applicability of a rule may be determined in an action for declaratory judgment in the district court of the parish in which the division is located or in the parish in which the plaintiff resides or is domiciled. Appeals may be had from any ruling of a district court in accordance with the Code of Civil Procedure, except that such appeals shall be given preference and heard in priority to other appeals.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at legis.la.gov
Cited in 214 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Thibaut v. Thibaut (Louisiana Court of Appeal 1992, 607 So. 2d 587)“…de practices allegedly committed against the partnership. La.R.S. 51:1405 declares that "[u]nfair methods of comp…”
- Capitol House v. PERRYMAN CONSULT., INC. (Louisiana Court of Appeal 1998, 725 So. 2d 523)“…uct of any trade or commerce are hereby declared unlawful." La. R.S. 51:1405(A). The broad language of this statute…”
- McFadden v. Import One, Inc. (Louisiana Court of Appeal 2011, 10 La.App. 3 Cir. 952)“…minal determination of whether an entity is in violation of La.R.S. 51:1405 is fact based, the standard of review a…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 51:3071Short titleIn forcecited in 7 of our articles
This Chapter may be cited as the "Database Security Breach Notification Law".
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at legis.la.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2007
Opinions citing this section in our collection:
- Ponder v. Pfizer, Inc. (District Court, M.D. Louisiana 2007, 522 F. Supp. 2d 793)“…ated Louisiana’s Database Security Breach Notification Law, La. R.S. 51:3071, et seq. (Doc. 21, ¶ 24).…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Louisiana Data Privacy Act Becomes Law: SB 386 Signed as Act 502
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Louisiana Database Security Breach Notification Law (La. R.S. 51:3071)(legis.la.gov).gov
- La. R.S. 51:3073 definitions including biometric data(legis.la.gov).gov
- La. R.S. 51:3074 breach notification and security requirements(legis.la.gov).gov
- Louisiana Unfair Trade Practices and Consumer Protection Law (La. R.S. 51:1405)(legis.la.gov).gov
- La. R.S. 17:100.8 student biometric information collection and use(legis.la.gov).gov
- 2018 Senate Bill 361 adding biometric data to breach notification law(legis.la.gov).gov
- HB 947 Louisiana Consumer Privacy Act (2024)(legis.la.gov).gov
- SB 386 (Act 502 of 2026), the Louisiana Data Privacy Act(legis.la.gov).gov
- Louisiana Attorney General consumer protection enforcement(ag.louisiana.gov).gov
- FTC Act Section 5 enforcement authority(ftc.gov).gov
- HIPAA Privacy Rule(hhs.gov).gov
- COPPA rule on children online privacy(ftc.gov).gov
- La. Admin. Code tit. 16, Pt. III, Sec. 701 (Attorney General breach reporting requirements)(law.cornell.edu)
- La. R.S. 51:1407 civil penalties under the Unfair Trade Practices Act(legis.la.gov)
- Enrolled SB 386 (Act 502 of 2026), Louisiana Data Privacy Act, full text(legis.la.gov)