EnglishEspañol
Minnesota flag

Minnesota

Minnesota Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 15 primary sources cited on this page. How we verify our legal content

Minnesota Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Minnesota have a standalone biometric privacy law like Illinois?

No. Minnesota does not have a dedicated biometric privacy statute. Instead, the Minnesota Consumer Data Privacy Act (MCDPA), effective July 31, 2025, classifies biometric data as sensitive data within its comprehensive consumer privacy framework. The MCDPA requires businesses to obtain opt-in consent before processing biometric data for identification purposes, but it does not include the detailed retention schedules, destruction timelines, or private right of action found in Illinois BIPA.

Can I sue a company in Minnesota for collecting my fingerprints without consent?

Not under the MCDPA. The Minnesota Attorney General has exclusive enforcement authority, and the law does not include a private right of action. If you believe a company collected your biometric data without consent, you can file a complaint through the AG's Consumer Division at ag.state.mn.us. The AG can investigate and pursue civil penalties of up to $7,500 per violation. Since February 2026, the AG no longer needs to provide advance notice before taking enforcement action.

Does the MCDPA protect my biometric data at work?

No. The MCDPA exempts personal data collected about job applicants, employees, and individuals acting as business representatives when processed in an employment context. If your employer collects fingerprints for timekeeping, uses facial recognition for building access, or requires biometric scans for security purposes, the MCDPA does not regulate that activity. Minnesota does not have a separate law governing employer use of biometric data.

What happens if a biometric data breach occurs in Minnesota?

Minnesota's breach notification law (Minn. Stat. 325E.61) does not explicitly list biometric data as a category of personal information triggering notification. However, the MCDPA requires controllers to maintain reasonable security practices for all personal data, including biometric data. A failure to protect biometric data could lead to AG enforcement under the MCDPA even if the breach notification statute does not technically apply. If the breach also involves Social Security numbers, financial account numbers, or driver's license numbers alongside biometric data, the breach notification law does apply.

Is Minnesota considering stronger biometric privacy protections?

Yes. Several bills in the 94th Minnesota Legislature (2025-2026) could expand protections. HF 3661 would ban government use of facial recognition technology. SF 3270 would require express written consent for biometric data collection in public accommodations using a broader definition than the MCDPA. HF 4131 would address surveillance-based discrimination involving biometric data. As of August 2026, none of these bills had advanced beyond committee referral. HF 3661's most recent recorded action remains a March 2026 committee referral, with no further movement since.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the MCDPA signing date to May 24, 2024 and clarified that postsecondary institutions face a deferred July 31, 2029 compliance deadline rather than a statutory exemption.

Corrected the nonprofit and financial-institution exemption descriptions to match the MCDPA's narrower statutory scope, added the MCDPA's right to challenge profiling decisions and receive a third-party disclosure list, noted the controller data-inventory security duty, and refreshed the pending-legislation status through August 2026.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Minnesota Consumer Data Privacy Act (Chapter 325M)(revisor.mn.gov).gov
  2. Minn. Stat. 325M.11 - MCDPA Definitions(revisor.mn.gov).gov
  3. Minn. Stat. 325M.12 - Applicability(revisor.mn.gov).gov
  4. Minn. Stat. 325M.14 - Consumer Rights(revisor.mn.gov).gov
  5. Minn. Stat. 325M.16 - Controller Obligations(revisor.mn.gov).gov
  6. Minn. Stat. 325M.18 - Data Protection Assessments(revisor.mn.gov).gov
  7. Minn. Stat. 325M.20 - Enforcement(revisor.mn.gov).gov
  8. HF 4757 - MCDPA Bill(revisor.mn.gov).gov
  9. Minn. Stat. 325E.61 - Breach Notification(revisor.mn.gov).gov
  10. AG Ellison - MCDPA Takes Effect(ag.state.mn.us).gov
  11. AG Ellison - MCDPA Full Enforcement(ag.state.mn.us).gov
  12. Minnesota AG - Consumer Data Privacy(ag.state.mn.us).gov
  13. HF 3661 - Facial Recognition Ban(revisor.mn.gov).gov
  14. SF 3270 - Biometric Consent in Public Accommodations(revisor.mn.gov).gov
  15. HF 4131 - Surveillance-Based Discrimination(revisor.mn.gov).gov
  16. HF 4757 (2024) Bill Status - Governor approval May 24, 2024, Laws 2024 ch. 121(revisor.mn.gov)
Share: