Massachusetts
Massachusetts Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 12 primary sources cited on this page. How we verify our legal content

Massachusetts has no standalone biometric privacy statute. Businesses collecting biometric data must comply with the data security regulation 201 CMR 17.00, the breach notification law under Chapter 93H, the record disposal statute Chapter 93I, which expressly counts a biometric indicator as personal information, and the consumer protection statute Chapter 93A, which requires double to treble damages for willful or knowing violations. A comprehensive law, the MDPA, has passed both the Senate and House in different forms and is now before a conference committee reconciling the two versions as of August 2026.
Massachusetts takes data security seriously, but it has not yet enacted a dedicated biometric privacy law. Unlike Illinois, which passed the Biometric Information Privacy Act (BIPA) in 2008, or Texas, which enacted its Capture or Use of Biometric Identifier Act (CUBI), Massachusetts currently relies on a combination of general data security regulations and consumer protection statutes to address biometric data.
That may change soon. The Massachusetts Data Privacy Act passed the state Senate unanimously in September 2025 and the House 146-0 in June 2026, and the two chambers are now reconciling their versions in conference committee; it includes robust protections for biometric information. Until that bill becomes law, businesses operating in Massachusetts must navigate the existing legal framework carefully.
For a broader overview of the state's privacy landscape, see the parent guide to Massachusetts Data Privacy Laws.
Current Legal Framework for Biometric Data
Massachusetts protects biometric data through several existing laws rather than a single biometric-specific statute. Each law covers a different aspect of data handling, from security requirements to breach notification to consumer protection enforcement.

201 CMR 17.00: Data Security Regulation
The Standards for the Protection of Personal Information (201 CMR 17.00) is the backbone of Massachusetts data security law. Issued by the Office of Consumer Affairs and Business Regulation, it requires every person or business that owns or licenses personal information about a Massachusetts resident to develop, implement, and maintain a comprehensive written information security program (WISP).
The regulation applies to biometric data indirectly. While the definition of "personal information" under 201 CMR 17.00 focuses on names combined with Social Security numbers, driver's license numbers, or financial account numbers, the regulation specifically references biometric technologies as an acceptable authentication method. Any business using fingerprint scanners, facial recognition, or other biometric identifiers for system access must protect those systems under the WISP requirement.
Key obligations under 201 CMR 17.00 include:
- Designating one or more employees to maintain the information security program
- Identifying and assessing reasonably foreseeable internal and external risks to personal information
- Developing security policies for employee access to records containing personal information
- Restricting physical access to records containing personal information
- Requiring encryption of all transmitted records and files containing personal information across public networks or wirelessly
- Monitoring the security program and documenting responsive actions taken in connection with any breach
Violations of 201 CMR 17.00 are enforceable through Chapter 93A, the state consumer protection statute.
Chapter 93H: Breach Notification
The Massachusetts breach notification law (Mass. Gen. Laws ch. 93H) requires businesses to notify affected residents, the Attorney General, and the Director of Consumer Affairs and Business Regulation when a breach of security compromises personal information.
Under Section 1 of Chapter 93H, encryption is defined as "the transformation of data through the use of a 128-bit or higher algorithmic process into a form in which there is a low probability of assigning meaning without use of a confidential process or key." This sets a concrete technical standard that applies to any personal information a business stores or transmits.
The current definition of "personal information" in Chapter 93H covers a resident's name combined with Social Security numbers, driver's license numbers, and financial account numbers. Biometric identifiers are not explicitly listed in Chapter 93H's own definition, though the separate record disposal statute, Chapter 93I, does expressly include "a biometric indicator" in its definition of personal information. Businesses that use biometric data alongside other personal information must still comply with the Chapter 93H notification requirements if a breach compromises any covered data elements.
Under Section 3 of Chapter 93H, notice must be sent "as soon as practicable and without unreasonable delay," but the required contents differ depending on the recipient.
The notice to the Attorney General and the Director of Consumer Affairs and Business Regulation must include:
- The nature of the breach or unauthorized acquisition
- The number of Massachusetts residents affected
- The types of personal information compromised
- Steps the organization has taken or plans to take in response
The notice to the affected resident must NOT include the nature of the breach or the number of residents affected. Chapter 93H Section 3 expressly bars including either item in the resident notice. Instead, the resident notice must include:
- The resident's right to obtain a police report
- How the resident may request a security freeze, including confirmation that there is no charge for one
- Information about available mitigation services
Chapter 93I: Secure Disposal of Records Containing Biometric Data
Chapter 93I is the one enacted Massachusetts statute that names biometric data outright. Section 1 defines "personal information" as a resident's name combined with a Social Security number, a driver's license or Massachusetts identification card number, a financial account or card number, or "a biometric indicator."
Section 2 then sets minimum standards for disposing of any record containing that information:
- Paper documents must be "redacted, burned, pulverized or shredded so that personal data cannot practicably be read or reconstructed"
- Electronic media and other non-paper media must be "destroyed or erased so that personal information cannot practicably be read or reconstructed"
- A business that contracts disposal out to a third party must use a vendor that implements and monitors policies barring unauthorized access to the data during collection, transportation, and disposal
Section 2 sets the penalty at a civil fine of not more than $100 per data subject affected, capped at $50,000 for each instance of improper disposal, recoverable by the Attorney General in superior or district court. Section 3 separately lets the Attorney General bring an action under Chapter 93A Section 4 to remedy violations of the chapter.
Because a biometric indicator is expressly covered, a business that throws out fingerprint templates, face-scan records, or the drives holding them without rendering the data unreadable faces direct statutory exposure, even though Massachusetts has no BIPA-style collection statute.

Chapter 93A: Consumer Protection Enforcement
Chapter 93A of the Massachusetts General Laws prohibits unfair or deceptive acts or practices in trade or commerce. This statute serves as the primary enforcement tool for data security violations in Massachusetts, including those involving biometric data.
The law provides two enforcement paths. The Attorney General can bring actions under Section 4 to restrain violations and impose civil penalties. Individual consumers can also bring private lawsuits under Section 9.
What makes Chapter 93A particularly powerful for biometric data cases is the damages structure:
- The base recovery under Section 9(3) is actual damages or $25, whichever is greater. If the defendant willfully or knowingly violated the law, or refused to grant relief in bad faith, multiplied damages are mandatory, not discretionary: recovery is "up to three but not less than two times such amount," so at least double and as much as triple
- Attorney's fees are recoverable by prevailing plaintiffs, making it one of the few Massachusetts statutes that shifts fee-shifting to the plaintiff's advantage
- Before filing suit, a consumer must send a 30-day demand letter to the business, giving it an opportunity to make a reasonable settlement offer
The Massachusetts Attorney General has used Chapter 93A to pursue data breach enforcement actions aggressively. In recent years, the AG's office has reached settlements in excess of $795,000 against companies that failed to protect personal information as required by 201 CMR 17.00.
For businesses collecting biometric data from Massachusetts residents, this means that any failure to secure that data properly could trigger a Chapter 93A action carrying double to treble damages exposure.

The Massachusetts Data Privacy Act: Pending Biometric Protections
The most significant development in Massachusetts biometric privacy law is the Massachusetts Data Privacy Act (MDPA), originally filed as S.2608 and reprinted as S.2619 after amendments. The Massachusetts Senate passed the bill unanimously (40-0) on September 25, 2025.
How the MDPA Would Classify Biometric Data
The MDPA designates biometric data, specifically face scans and fingerprints, as sensitive personal data. This classification triggers the highest level of protection under the proposed law.
For regular personal data, businesses would only be allowed to collect what is "reasonably necessary" to provide their product or service. For biometric data and other sensitive categories, the standard is stricter: collection is permitted only when it is "strictly necessary" to provide the product or service.
Key Biometric Provisions in the MDPA
If enacted, the MDPA would establish these rules for biometric data:
- Ban on sale: Businesses and nonprofits would be prohibited from selling biometric data
- Strictly necessary collection: Biometric data collection would be allowed only when strictly necessary to deliver a product or service
- Consumer consent for transfers: Transferring biometric data to third parties would require explicit consumer consent
- Right to access: Consumers could request to know what biometric data a business has collected about them
- Right to delete: Consumers could request deletion of their biometric data
- Right to correct: Consumers could request correction of inaccurate biometric data
Enforcement Under the MDPA
The bill gives the Massachusetts Attorney General broad regulatory authority to enforce its provisions. The MDPA also includes enhanced protections for minors, including a complete ban on selling children's personal data and prohibiting targeted advertising directed at minors based on their biometric or other sensitive data.
Current Status
As of August 2026, the MDPA has passed both chambers in different forms. The Senate passed S.2619 unanimously (40-0) on September 25, 2025, and the House passed its own amended version 146-0 on June 4, 2026. The Senate rejected the House's amendments on June 11, 2026, and a six-member conference committee, appointed June 11 (Senate) and June 17 (House), is now reconciling the two chambers' versions. The legislation was filed during the 194th General Court session (2025-2026).
Standalone Biometric Bill: Proposed Chapter 93M
In earlier sessions, Massachusetts legislators introduced standalone biometric privacy bills that would create a new Chapter 93M of the General Laws. H.63/HD.3053, filed by Representative Dylan Fernandes during the 2023-2024 legislative session, would have established protections similar to Illinois BIPA. That bill did not pass and expired at the end of the 2023-2024 session; it is no longer pending.
The expired H.63/HD.3053 would have defined "biometric information" as measurable biological or behavioral characteristics used for verification, recognition, or identification, including:
- Fingerprints
- Retina and iris patterns
- Voiceprints
- Facial characteristics and face geometry
- Gait, handwriting, and keystroke dynamics
That bill would have required handwritten, non-electronic consent before collecting biometric data for identification purposes, with consent expiring after three years or when the original purpose was fulfilled, whichever came first. It would also have prohibited monetizing biometric information entirely and allowed individuals to sue with a rebuttable presumption of harm. For intentional or reckless violations, penalties could have reached 0.5% of annual global revenue or $5,000 per violation, whichever was greater; for negligent conduct, the floor would have been 0.1% of global revenue or $1,000 per violation.
The live successor bill in the current 2025-2026 session is S.43, "An Act to protect personal biometric data", filed by Senator Mark Montigny. S.43 received a favorable committee report and moved to the Senate Committee on Ways and Means on May 12, 2025. Unlike the expired H.63, S.43 allows written consent to be given electronically, requires destruction of biometric data within one year of an individual's last interaction (or when the collection purpose is satisfied), and bars selling, leasing, trading, or otherwise profiting from biometric data. Its penalty structure sets statutory damages of at least $5,000 per violation, or actual damages if greater, rising to two to three times that amount for willful or knowing violations, without the revenue-based penalty tiers or rebuttable-presumption-of-harm language that H.63 proposed.
This standalone bill track has not advanced as far as the MDPA, but S.43's committee-approved status signals the legislative direction Massachusetts is heading on biometric privacy.
Practical Compliance Guidance
Businesses that collect or use biometric data from Massachusetts residents should take these steps under current law:
Written Information Security Program: Under 201 CMR 17.00, any business handling personal information of Massachusetts residents must maintain a WISP. If your business uses biometric authentication systems, those systems must be covered by the WISP.
Encryption: Biometric data transmitted across public networks or wirelessly should be encrypted. The 128-bit figure is statutory, not regulatory: Chapter 93H Section 1 defines encryption as a "128-bit or higher algorithmic process," and adds that this applies "unless further defined by regulation of the department of consumer affairs and business regulation."
Breach Response Plan: Prepare a notification plan that meets the "as soon as practicable and without unreasonable delay" standard under Chapter 93H Section 3. Include the Attorney General and the Office of Consumer Affairs and Business Regulation in your notification procedures.
Monitor Legislative Developments: The MDPA is now before a conference committee reconciling the House and Senate versions as of August 2026 and could become law once that process concludes. Businesses should plan for the "strictly necessary" collection standard and the ban on selling biometric data. Building consent mechanisms now will ease the transition if the law passes.
Secure Disposal: Chapter 93I Section 2 treats a biometric indicator as personal information and requires paper records to be redacted, burned, pulverized, or shredded and electronic media to be destroyed or erased so the data cannot practicably be read or reconstructed. Put biometric templates on a written retention schedule, document the destruction step, and impose the same standard on any disposal vendor. Improper disposal carries a fine of up to $100 per data subject affected, capped at $50,000 per instance.
Limit Collection: Even without a dedicated biometric statute, the Chapter 93A multiplied damages exposure creates strong incentives to minimize biometric data collection. Collect only what you need, retain it only as long as necessary, destroy it to the Chapter 93I standard when you are done, and document your justification for collection.
Sources and References
This article references Massachusetts statutes, regulations, and official government publications. For the full text of 201 CMR 17.00, visit the Massachusetts Office of Consumer Affairs. For Chapter 93H, Chapter 93I, and Chapter 93A, visit the Massachusetts Legislature website. For updates on the Massachusetts Data Privacy Act, see the S.2608 bill page.
This article provides general legal information about Massachusetts biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Massachusetts government sources.
More Massachusetts Laws
Frequently Asked Questions
Does Massachusetts have a biometric privacy law?
Massachusetts does not have a standalone biometric privacy statute as of August 2026. Biometric data protections currently come from the data security regulation (201 CMR 17.00), the breach notification law (Mass. Gen. Laws ch. 93H), and the consumer protection statute (Chapter 93A). The Massachusetts Data Privacy Act (S.2608/S.2619) passed the Senate unanimously in September 2025 and the House 146-0 in June 2026, and would add comprehensive biometric protections once a conference committee reconciles the two chambers' versions and the bill is enacted.
Can a business collect fingerprints or facial recognition data in Massachusetts?
Under current law, yes, but with obligations. Businesses that use biometric data for authentication must secure it under a written information security program as required by 201 CMR 17.00. If the pending Massachusetts Data Privacy Act becomes law, businesses would only be allowed to collect biometric data when it is strictly necessary to provide their product or service, and selling biometric data would be banned.
What penalties exist for mishandling biometric data in Massachusetts?
Under current law, the primary penalty mechanism is Chapter 93A. On a willful or knowing violation, or a bad-faith refusal to grant relief after a demand letter, Section 9(3) requires the court to award at least two times and up to three times the base amount, plus attorney fees. The Attorney General can also bring enforcement actions with civil penalties. Recent AG settlements for data security failures have exceeded $795,000. Separately, improperly disposing of a record containing a biometric indicator carries a civil fine of up to $100 per data subject affected under Chapter 93I, capped at $50,000 per instance. The pending MDPA would give the AG additional enforcement authority specifically over biometric data violations.
Does the Massachusetts breach notification law cover biometric data?
The definition of personal information in Chapter 93H itself focuses on names combined with Social Security numbers, driver's license numbers, and financial account numbers, and biometric identifiers are not listed there. That is a point about Chapter 93H, not about Massachusetts law generally: a separate statute, Mass. Gen. Laws ch. 93I, does expressly include a biometric indicator in its definition of personal information and requires records containing it to be destroyed or erased so they cannot practicably be read or reconstructed. Under Chapter 93H, if biometric data is compromised alongside covered data elements, the breach notification requirements apply. The pending MDPA would expand protections to cover biometric data directly.
What would the Massachusetts Data Privacy Act change for biometric data?
The MDPA (S.2608/S.2619) would classify biometric data, including face scans and fingerprints, as sensitive personal data. It would impose a strictly necessary collection standard, ban the sale of biometric data, require explicit consent for data transfers, and give consumers the right to access, correct, and delete their biometric information. The bill passed the Senate 40-0 in September 2025 and the House 146-0 in June 2026; a conference committee is now reconciling the two chambers' versions as of August 2026.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Added Massachusetts General Laws chapter 93I, the record disposal statute that expressly counts a biometric indicator as personal information, and corrected the Chapter 93A damages description: on a willful or knowing violation the court must award at least two and up to three times the base amount, rather than merely being permitted to award treble damages.
Corrected the Massachusetts Data Privacy Act's status (the House passed its own version 146-0 on June 4, 2026, and the bill is now in conference committee, not awaiting House action), replaced references to the dead 2023-2024 standalone biometric bill H.63/HD.3053 with its live 2025-2026 successor S.43, split the Chapter 93H breach-notice bullet list so it no longer tells businesses to include breach details in resident notices that the statute forbids, and re-attributed the encryption mandate from Chapter 93H to 201 CMR 17.00.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Massachusetts General Laws, Chapter 93I
§ 2Standards for disposal of records containing personal information; disposal by third party; enforcementIn force
Section 2. When disposing of records, each agency or person shall meet the following minimum standards for proper disposal of records containing personal information: (a) paper documents containing personal information shall be either redacted, burned, pulverized or shredded so that personal data cannot practicably be read or reconstructed; (b) electronic media and other non-paper media containing personal information shall be destroyed or erased so that personal information cannot practicably be read or reconstructed. Any agency or person disposing of personal information may contract with a third party to dispose of personal information in accordance with this chapter. Any third party hired to dispose of material containing personal information shall implement and monitor compliance with policies and procedures that prohibit unauthorized access to or acquisition of or use of personal information during the collection, transportation and disposal of personal information.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at malegislature.gov
Explore the law
This article also draws on these acts and chapters (opening at their first section): Massachusetts General Laws, Chapter 93A § 1 (Definitions) · Massachusetts General Laws, Chapter 93H § 1 (Definitions)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- 201 CMR 17.00: Standards for the Protection of Personal Information(mass.gov).gov
- Mass. Gen. Laws ch. 93H - Security Breaches(malegislature.gov).gov
- Chapter 93H Section 1 - Definitions(malegislature.gov).gov
- Chapter 93H Section 3 - Breach Notification Requirements(malegislature.gov).gov
- Mass. Gen. Laws ch. 93A - Consumer Protection(malegislature.gov).gov
- S.2608 - Massachusetts Data Privacy Act(malegislature.gov).gov
- S.2619 - MDPA (Reprinted with Amendments)(malegislature.gov).gov
- Fact Sheet: The Massachusetts Data Privacy Act S.2608(malegislature.gov).gov
- Senate Passes the Massachusetts Data Privacy Act(malegislature.gov).gov
- H.63/HD.3053 - Expired 2023-2024 Session Proposed Chapter 93M Bill (superseded by S.43)(malegislature.gov).gov
- The Massachusetts Consumer Protection Law (Chapter 93A)(mass.gov).gov
- AG Campbell $795,000 Data Security Settlement(mass.gov).gov
- Mass. Gen. Laws ch. 93I - Dispositions and Destruction of Records(malegislature.gov)
- Chapter 93I Section 1 - Definitions (personal information includes a biometric indicator)(malegislature.gov)
- Chapter 93I Section 2 - Standards for Disposal of Records Containing Personal Information(malegislature.gov)
- Chapter 93I Section 3 - Attorney General Enforcement(malegislature.gov)
- Chapter 93A Section 9 - Civil Actions and Damages(malegislature.gov)