Michigan
Michigan Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 15 primary sources cited on this page. How we verify our legal content

Michigan has no dedicated biometric privacy law. The Identity Theft Protection Act (MCL 445.63) classifies biometric data as personal identifying information, but that classification alone does not trigger breach notification: the Act's notification duty under MCL 445.72 is tied to a narrower, separately defined term, personal information, that currently covers only a name paired with a Social Security number, driver's license or state ID number, or financial account number. There is no private right of action under the Identity Theft Protection Act, although the Michigan Consumer Protection Act separately lets a person who suffers loss from a deceptive practice sue. Two pending bills, SB 359 and SB 360, could add consent requirements and, in SB 360's case, add biometrics to the breach notification definition for the first time.
Michigan takes a different approach to biometric privacy than states like Illinois and Texas. Rather than enacting a dedicated biometric information privacy act, Michigan protects biometric data through its existing Identity Theft Protection Act and Consumer Protection Act. For residents wondering whether their fingerprints, facial scans, or voiceprints have legal protection, the answer is yes, but with important limitations.
This guide breaks down how Michigan law currently treats biometric data, what businesses must do when biometric information is compromised, and how pending legislation could bring Michigan closer to the comprehensive biometric protections found in other states.
For broader context on Michigan privacy protections, see the parent guide to Michigan Data Privacy Laws.
What Counts as Biometric Data Under Michigan Law
Only one Michigan consumer statute mentions biometrics by name. A second, the Consumer Protection Act, never uses the word, but can still reach biometric practices through its general ban on deceptive conduct.
Identity Theft Protection Act (MCL 445.63)
The Identity Theft Protection Act, enacted as Act 452 of 2004, defines "personal identifying information" as a name, number, or other information used to identify a specific person or provide access to financial accounts. The statute explicitly lists biometrics as a category of personal identifying information alongside driver's license numbers, Social Security numbers, and financial account credentials.
This classification does not by itself extend Michigan's breach notification framework to biometric data. The Identity Theft Protection Act's notification duty under MCL 445.72 is triggered only by exposure of personal information, a separately defined and narrower term limited to a name paired with a Social Security number, driver's license or state ID number, or financial account number. Biometric data on its own does not currently trigger notification obligations unless it happens to be exposed alongside one of those elements.
Michigan Consumer Protection Act (MCL 445.903)
The Michigan Consumer Protection Act (MCPA), Act 331 of 1976, does not mention biometric data at all. However, the MCPA prohibits unfair, unconscionable, or deceptive trade practices. The Michigan Attorney General has the authority to pursue enforcement actions under the MCPA against businesses that collect or handle biometric data in ways that mislead consumers or violate reasonable privacy expectations.
Types of Biometric Identifiers
Michigan's consumer statutes do not define biometric data. MCL 445.63(q) lists the bare word "biometrics" with no definition and no examples, so there is no current Michigan consumer-law list of what counts. The categories below come from pending Senate Bill 359, which would define biometric data as "data generated by automatic measurements of an individual's biological characteristics that can be used to identify a specific individual, including, but not limited to, a fingerprint, a voiceprint, eye retinas, irises, or other unique biological patterns or characteristics":
- Fingerprints and palm prints
- Voiceprints
- Retina and iris scans
- Facial geometry measurements
- Other unique biological patterns used for identification
SB 359 would also exclude physical or digital photographs, video recordings, and audio recordings, plus data derived from them, unless that data is generated specifically to identify an individual. That exclusion is proposed law, not current law. The only definition of "biometric data" on Michigan's books today, MCL 28.241a(b), governs arrest and booking records rather than consumer data, and it runs the other way: it expressly includes "digital images recorded during the arrest or booking process, including a full-face capture, left and right profile, and scars, marks, and tattoos." Do not assume images sit outside the term in every Michigan context.
Breach Notification Requirements for Biometric Data
Biometrics fall within Michigan's broader definition of personal identifying information, but the breach notification rules in MCL 445.72 are keyed to a narrower, separately defined term, personal information, limited to a name paired with a Social Security number, driver's license or state ID number, or financial account number. Biometric data by itself is not currently part of that triggering definition, a gap SB 360 would close.
Who Must Comply
Any person or agency that owns or licenses data containing personal information of Michigan residents must comply. This includes private businesses, government agencies, and nonprofits. Holding a database of biometric records does not by itself put an entity under the notification duty, because biometrics are not part of the personal information definition that triggers MCL 445.72. A person or agency that merely maintains data it does not own or license has a separate and narrower obligation under MCL 445.72(2): it notifies the owner or licensor, not the affected residents.
When Notification Is Required
An entity must notify affected Michigan residents after discovering a security breach that results in the unauthorized access and acquisition of unencrypted and unredacted personal information, meaning a name paired with a Social Security number, driver's license or state ID number, or financial account number. Biometric data alone is not currently included in that definition. Notification is not required if the entity determines that the breach is unlikely to cause substantial loss, injury, or identity theft.
Notification Timeline
Under current law, notification must be provided "without unreasonable delay." Delays are permitted only when necessary to determine the scope of the breach or when law enforcement requests a postponement for an ongoing criminal investigation.
How to Notify
Michigan law allows several notification methods depending on the number of affected individuals and the cost of notification:
- Written notice sent by postal mail
- Electronic notice if the affected individual previously consented to electronic communications
- Telephone notice through a live representative, with written follow-up
- Substitute notice for breaches affecting more than 500,000 residents or costing more than $250,000, which includes email notification, conspicuous website posting, and notification to major statewide media
Third-Party Obligations
Entities that maintain personal information on behalf of another organization must notify the data owner of any breach. The data owner then bears the responsibility for notifying affected individuals.
Penalties for Biometric Data Violations
Michigan enforces biometric data protections primarily through its breach notification penalty framework and the Consumer Protection Act.
Breach Notification Penalties
Under MCL 445.72, knowingly failing to provide required breach notification carries civil fines of up to $250 per failure to notify. The total liability for a single breach event is capped at $750,000.
Filing a false breach notification with intent to defraud is a misdemeanor. First offenses carry up to 93 days of imprisonment or a $250 fine. Penalties increase for repeat violations, reaching up to $750 for a third offense.
Consumer Protection Act Enforcement
The Michigan Attorney General can bring enforcement actions under the Consumer Protection Act against entities that engage in unfair or deceptive practices involving biometric data. Remedies can include injunctive relief, restitution, and civil penalties.
No Private Right of Action for Data Breaches
Unlike Illinois, where individuals can sue companies directly for biometric privacy violations under BIPA, Michigan does not currently provide a private right of action specifically for biometric data breaches. Enforcement of the breach notification statute rests with the Michigan Attorney General and county prosecuting attorneys.
That limit is narrower than it sounds. A consumer harmed by a deceptive practice involving biometric data can still sue under the Consumer Protection Act: MCL 445.911 lets a person who suffers loss from a violation seek a declaratory judgment or an injunction, or recover actual damages or $250, whichever is greater, together with reasonable attorney fees. The section also allows class actions.
How Michigan Compares to Other States
Michigan's biometric protections are moderate compared to other states. Understanding the differences helps businesses operating across state lines assess their compliance obligations.
Illinois has the strongest biometric privacy law in the country through the Biometric Information Privacy Act (BIPA), which requires written consent before collection, mandates retention and destruction policies, and provides a private right of action with statutory damages of $1,000 to $5,000 per violation.
Texas requires consent before capturing biometric identifiers under the Capture or Use of Biometric Identifier Act (CUBI), but only the Texas Attorney General can enforce it.
Michigan currently has no standalone consent requirement for biometric collection. Protection is limited to general consumer protection enforcement, since biometric data alone does not currently trigger the state's breach notification law. If SB 359 or SB 360 passes, Michigan would gain affirmative opt-in consent requirements and would extend breach notification duties to cover biometric identifiers directly.

Employer Use of Biometric Data in Michigan
Michigan does not have a specific statute governing employer collection of biometric data for purposes like time clocks, building access, or identity verification. However, several legal frameworks apply.
Background Check Fingerprinting
The Public Employee Fingerprint-Based Criminal History Check Act (Act 427 of 2018) requires fingerprint-based background checks for public employees who will have access to federal information databases. The Michigan State Police Biometrics and Identification Division processes these fingerprint submissions through the state's Automated Fingerprint Identification System (AFIS).
Certain regulated industries, including security businesses under MCL 338.1068, must submit employee fingerprints to the Michigan State Police before the employee begins work.
Best Practices for Employers
Even without a dedicated biometric consent law, Michigan employers collecting biometric data should:
- Provide written notice explaining what biometric data is collected, how it will be used, and how long it will be stored
- Obtain written consent before collecting fingerprints, facial scans, or other biometric identifiers
- Establish a retention and destruction policy that permanently destroys biometric data when the employment relationship ends or the data is no longer needed
- Limit access to biometric data to authorized personnel only
- Use encryption for stored and transmitted biometric information
These practices align with the requirements proposed in SB 359 and help employers prepare for potential future legislation.

Pending Legislation: What Could Change
SB 360 passed the Michigan Senate in August 2025 and is pending in the House; SB 359 remains before the Senate Committee of the Whole without a floor vote as of August 2026. If enacted, they would substantially strengthen biometric privacy protections.
SB 359: Personal Data Privacy Act
Senate Bill 359, introduced by Senator Rosemary Bayer on June 5, 2025, would create Michigan's first comprehensive consumer data privacy law. The bill was reported favorably by the Senate Finance, Insurance, and Consumer Protection Committee and referred to the Committee of the Whole.
Key biometric provisions in SB 359 include:
- Biometric data as sensitive data. The bill classifies biometric data as a category of sensitive data alongside precise geolocation, data about known children, and certain health information.
- Opt-in consent required. Controllers must obtain a consumer's affirmative consent before processing any sensitive data, including biometric identifiers.
- Data minimization. Collection and processing of biometric data must be limited to what is strictly necessary to provide or maintain the specific product or service requested by the consumer.
- Consumer rights. Michigan residents would gain the right to access, correct, delete, and port their personal data, plus the right to opt out of data sales and targeted advertising.
- Attorney General enforcement. SB 359 would be enforced exclusively by the Michigan Attorney General, with no private right of action.
The bill would apply to entities doing business in Michigan that process data on at least 100,000 consumers per year, or at least 25,000 consumers if they derive any revenue from selling personal data.
SB 360: Identity Theft Protection Act Amendments
Senate Bill 360, part of a five-bill package (SB 360-364), passed the Michigan Senate on August 26, 2025, and has been referred to the House Committee on Government Operations.
Key changes proposed by SB 360 include:
- Expanded personal information definition. The bill would explicitly add "any genetic information or biometric information that is used to authenticate or ascertain the individual's identity, such as a fingerprint, voice print, retina, or iris image" to the definition of personal information in the breach notification statute.
- 45-day notification deadline. Entities must notify affected individuals and the Attorney General within 45 days of determining a breach occurred, replacing the current "without unreasonable delay" standard.
- Attorney General notification. Breaches affecting 100 or more Michigan residents would require notification to the Attorney General.
- Mandatory security programs. Entities must implement reasonable security procedures, designate a security coordinator, and follow the NIST Cybersecurity Framework 2.0 or an equivalent industry standard.
- Enhanced enforcement. The Attorney General would gain expanded powers to issue written demands, accept assurances of discontinuance, and pursue civil fines of up to $2,000 per security procedure violation or investigation failure.

Michigan State Police and Biometric Data
The Michigan State Police (MSP) operates one of the largest biometric databases in the state through its Biometrics and Identification Division. Two systems are particularly relevant to biometric privacy.
Automated Fingerprint Identification System (AFIS)
The MSP's Automated Print Identification Section maintains fingerprint records for criminal justice purposes. Fingerprints collected during arrests, background checks, and licensing processes are stored in AFIS and can be searched against state and FBI databases.
Statewide Network of Agency Photos (SNAP)
The SNAP system allows law enforcement to conduct facial recognition searches against a database of booking photos. The MSP's SNAP Acceptable Use Policy restricts facial recognition searches to five purposes: consent of the individual, probable cause to arrest, a court order or search warrant, identification of a vulnerable or impaired person, or identification of a deceased individual.
The MSP does not use real-time facial recognition surveillance. The department has stated publicly that it does not own the technology to scan crowds or identify people from live video feeds.
This article provides general legal information about Michigan biometric privacy laws. It is not legal advice. Biometric privacy law is evolving rapidly in Michigan, and the pending legislation discussed here may change before enactment. Consult a qualified Michigan attorney for guidance on your specific situation.
More Michigan Laws
Frequently Asked Questions
Does Michigan have a biometric privacy law like Illinois BIPA?
No. Michigan does not have a standalone biometric privacy statute. The Identity Theft Protection Act (MCL 445.61 et seq.) classifies biometrics as personal identifying information, but that term is broader than the personal information definition that actually triggers the Act's breach notification duty, so biometric data exposure alone does not currently require notice. Violations of biometric data handling can also be pursued under the Michigan Consumer Protection Act as unfair trade practices. However, Michigan does not currently require prior consent for biometric data collection, and it provides no private right of action specifically for biometric privacy violations, although MCL 445.911 lets a consumer harmed by a deceptive practice sue under the Consumer Protection Act.
What happens if a company fails to notify Michigan residents after a biometric data breach?
Under MCL 445.72, knowingly failing to provide required breach notification carries civil fines of up to $250 per failure to notify, with total liability capped at $750,000 per breach event. The Michigan Attorney General and county prosecuting attorneys can bring enforcement actions. Filing a false breach notification is a misdemeanor punishable by up to 93 days imprisonment or fines ranging from $250 to $750 depending on the number of prior offenses.
Can Michigan employers require fingerprint scans for time clocks or building access?
Yes, under current Michigan law. There is no state statute that prohibits employers from collecting fingerprints or other biometric data for workplace purposes like time tracking or access control. However, if SB 359 passes, employers processing biometric data of Michigan consumers would need to obtain opt-in consent and follow data minimization requirements. Employers should adopt written consent and retention policies now to prepare for potential legislative changes.
Will Michigan pass a comprehensive biometric privacy law?
It is possible. SB 359, the Personal Data Privacy Act, was introduced in June 2025 and classifies biometric data as sensitive data requiring opt-in consent before processing. The bill remains before the Senate Committee of the Whole without a floor vote. SB 360, which would expand breach notification to explicitly cover biometric identifiers and impose a 45-day notification deadline, passed the full Senate in August 2025 and is pending in the Michigan House as of August 2026.
Does Michigan use facial recognition technology, and are there privacy protections?
The Michigan State Police operates the Statewide Network of Agency Photos (SNAP) system for facial recognition searches against booking photos. Use is restricted to five authorized purposes under the SNAP Acceptable Use Policy: individual consent, probable cause to arrest, court order or search warrant, identification of vulnerable or impaired persons, and identification of deceased individuals. The MSP does not conduct real-time surveillance or scan crowds using facial recognition. All SNAP data is classified as highly restricted personal information under state and federal CJIS policies.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected who the breach notification duty applies to, clarified that the Michigan Consumer Protection Act does allow a private lawsuit even though the breach statute does not, and re-attributed the list of biometric identifiers to pending SB 359 rather than current Michigan law.
Corrected SB 359 to its actual short title (Personal Data Privacy Act) and legislative status, and repaired the Illinois BIPA citation link.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected a sitewide claim that biometric data exposure triggers Michigan's breach notification law: MCL 445.72's notice duty is tied to the narrower "personal information" definition (SSN/driver's license/financial account), not the broader "personal identifying information" definition that includes biometrics, so biometric exposure alone does not currently require notice.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Michigan Compiled Laws
§ 445.72Notice of security breach; requirementsIn forcecited in 7 of our articles
(1) Unless the person or agency determines that the security breach has not or is not likely to cause substantial loss or injury to, or result in identity theft with respect to, 1 or more residents of this state, a person or agency that owns or licenses data that are included in a database that discovers a security breach, or receives notice of a security breach under subsection (2), shall provide a notice of the security breach to each resident of this state who meets 1 or more of the following: (a) That resident's unencrypted and unredacted personal information was accessed and acquired by an unauthorized person. (b) That resident's personal information was accessed and acquired in encrypted form by a person with unauthorized access to the encryption key.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 8 court opinions in our collectionLatest citing opinion in our collection: 2025
In the courts (editorial summary, independently checked):Federal courts differ on private enforcement. In re Target Corp. Customer Data Security Breach Litigation (2014) read subsection (15) to imply consumers may sue through Michigan's consumer protection act. Angus v. Flagstar Bank, FSB (2025) held that a 445.72 violation cannot support an MCPA claim.
Opinions citing this section in our collection:
- In re Target Corp. Customer Data Security Breach Litigation (District Court, D. Minnesota 2014, 66 F. Supp. 3d 1154)✓Hackers took card and personal data of roughly 110 million Target shoppers; on a motion to dismiss the court read the subsection preserving other civil remedies as implying consumers may enforce the section 445.72 notice duty through other Michigan laws.
- In re Equifax, Inc. (District Court, N.D. Georgia 2019, 362 F. Supp. 3d 1295)✓Hackers took the personal data of nearly 150 million people from Equifax; following Target, the court declined to dismiss the section 445.72 claim for lack of a private right of action, relying on the subsection preserving other civil remedies.
- Negron v. Ascension Health (District Court, E.D. Missouri 2025)“…XVI. Michigan Identity Theft Protection Act, Mich. Comp. Laws § 445.72 XVII. Michigan Consumer Protection A…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Michigan Data Privacy Laws: Consumer Rights & Protections (2026), Michigan Data Breach Notification Laws: Reporting Rules & Timelines (2026), Michigan Identity Theft Laws: Penalties and Victim Resources
§ 445.63DefinitionsIn forcecited in 7 of our articles
As used in this act: (a) "Agency" means a department, board, commission, office, agency, authority, or other unit of state government of this state. The term includes an institution of higher education of this state. The term does not include a circuit, probate, district, or municipal court. (b) "Breach of the security of a database" or "security breach" means the unauthorized access and acquisition of data that compromises the security or confidentiality of personal information maintained by a person or agency as part of a database of personal information regarding multiple individuals. These terms do not include unauthorized access to data by an employee or other individual if the access meets all of the following: (i) The employee or other individual acted in good faith in accessing the data. (ii) The access was related to the activities of the agency or person. (iii) The employee or other individual did not misuse any personal information or disclose any personal information to an unauthorized person. (c) "Child or spousal support" means support for a child or spouse, paid or provided pursuant to state or federal law under a court order or judgment.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 5 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- People v. Perry (Michigan Court of Appeals 2016, 317 Mich. App. 589)“…license or state personal identification card number . . .” MCL 445.63(q). Circumstantial evidence and reasona…”
- Michigan Federation of Teachers & School Related Personnel v. University of Michigan (Michigan Supreme Court 2008, 481 Mich. 657)“…very type of information sought by plaintiff in this case. MCL 445.63(o). See also, e.g., Identity Theft and…”
- Deidre Goldsmith v. Faith Hope & Love Outreach Center Inc (Michigan Court of Appeals 2026)“…d for the purpose of identifying a specific person . . . .” MCL 445.63(q). Defendants argue that the…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 445.903Unfair, unconscionable, or deceptive methods, acts, or practices in conduct of trade or commerce; rules; applicability of subsection (1)(hh)In forcecited in 6 of our articles
(1) Unfair, unconscionable, or deceptive methods, acts, or practices in the conduct of trade or commerce are unlawful and are defined as follows: (a) Causing a probability of confusion or misunderstanding as to the source, sponsorship, approval, or certification of goods or services. (b) Using deceptive representations or deceptive designations of geographic origin in connection with goods or services. (c) Representing that goods or services have sponsorship, approval, characteristics, ingredients, uses, benefits, or quantities that they do not have or that a person has sponsorship, approval, status, affiliation, or connection that he or she does not have. (d) Representing that goods are new if they are deteriorated, altered, reconditioned, used, or secondhand. (e) Representing that goods or services are of a particular standard, quality, or grade, or that goods are of a particular style or model, if they are of another. (f) Disparaging the goods, services, business, or reputation of another by false or misleading representation of fact. (g) Advertising or representing goods or services with intent not to dispose of those goods or services as advertised or represented.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 210 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Smith v. Globe Life Insurance (Michigan Supreme Court 1999, 460 Mich. 446)“…its reading of the terms “specifically authorized.” Under MCL 445.903; MSA 19.418(3), the MCPA protects consu…”
- Gorman v. American Honda Motor Co. (Michigan Court of Appeals 2013, 302 Mich. App. 113)“…acts, or practices in the conduct of trade or commerce[.]” MCL 445.903(1). The act defines “trade or commerce”…”
- Dell v. Citizens Insurance Company of America (Michigan Court of Appeals 2015, 312 Mich. App. 734)“…e or commerce as set forth in the [MCPA] . . . . See, e.g., MCL 445.903(1)(a), (c), (e), (n), (s), (x)…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 445.61Short titleIn forcecited in 7 of our articles
This act shall be known and may be cited as the "identity theft protection act".
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 4 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Michigan Federation of Teachers & School Related Personnel v. University of Michigan (Michigan Supreme Court 2008, 481 Mich. 657)“…ure enacted 2004 PA 452, the Identity Theft Protection Act, MCL 445.61 et seq., whose title states, among othe…”
- Deidre Goldsmith v. Faith Hope & Love Outreach Center Inc (Michigan Court of Appeals 2026)“…ing identity theft under the Identity Theft Protection Act, MCL 445.61 et seq., forfeiture of property under M…”
- Keffer Development Services, LLC v. Hartford Casualty Insurance Company (District Court, W.D. Pennsylvania 2026)“…ations Act; (4) the Michigan Identity Theft Protection Act (MCL 445.61 et seq.); and (5) Ohio data security l…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 338.1068Employment of unqualified employees; fingerprints; fee; background check of prospective employee; employment application; refusal to surrender identificationIn forcecited in 2 of our articles
(1) A licensee shall not knowingly employ any person who fails to meet the requirements of section 17. (2) The licensee shall cause fingerprints to be taken of all prospective employees who are direct providers of the security business, which fingerprints shall be submitted to the department of state police and the federal bureau of investigation for a state and national criminal history background check. The fingerprints shall be accompanied by a fingerprint processing fee in the amount prescribed by section 3 of 1935 PA 120, MCL 28.273, as well as any fees imposed by the federal bureau of investigation. The results of the national criminal history background check as returned by the federal bureau of investigation to the department of state police shall be used by the department to make a fitness determination. A licensee shall not employ a person who is a direct provider of the security business before submitting fingerprints to the department of state police. (3) The fingerprints required to be taken under subsection (2) may be taken by a law enforcement agency or any other person determined by the department of state police to be qualified to take fingerprints.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 1985
Opinions citing this section in our collection:
- International Union, United Plant Guard Workers v. Department of State Police (Michigan Supreme Court 1985, 422 Mich. 432)“…guards, submitted the information to the State Police. See MCL 338.1068(1); MSA 18.185(18)(1). More important…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Identity Theft Protection Act (Act 452 of 2004)(legislature.mi.gov).gov
- MCL 445.63 - Personal Identifying Information Definitions(legislature.mi.gov).gov
- MCL 445.72 - Breach Notification Requirements(legislature.mi.gov).gov
- Michigan Consumer Protection Act (MCL 445.903)(legislature.mi.gov).gov
- SB 359 - Personal Data Privacy Act (2025)(legislature.mi.gov).gov
- SB 360 - Identity Theft Protection Act Amendments (2025)(legislature.mi.gov).gov
- SB 360 As Passed Senate(legislature.mi.gov).gov
- Public Employee Fingerprint-Based Criminal History Check Act (Act 427 of 2018)(legislature.mi.gov).gov
- Michigan State Police Biometrics and Identification Division(michigan.gov).gov
- MSP Facial Recognition FAQ(michigan.gov).gov
- MSP Automated Print Identification Section(michigan.gov).gov
- Michigan Attorney General(michigan.gov).gov
- NIST Cybersecurity Framework 2.0(nist.gov).gov
- Illinois Biometric Information Privacy Act (BIPA)(ilga.gov).gov
- Texas Capture or Use of Biometric Identifier Act (CUBI)(statutes.capitol.texas.gov).gov
- MCL 445.911 - Michigan Consumer Protection Act private actions and remedies(legislature.mi.gov)
- MCL 28.241a - Definitions, including 'biometric data' for arrest and booking records(legislature.mi.gov)
- SB 359 as introduced - biometric data definition (section 5(3))(legislature.mi.gov)