Minnesota
Minnesota Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 15 primary sources cited on this page. How we verify our legal content

Minnesota has no standalone biometric privacy statute. The Minnesota Consumer Data Privacy Act (MCDPA), Minn. Stat. Chapter 325M, effective July 31, 2025, classifies biometric data as sensitive personal data and requires opt-in consent before businesses can collect or process it. The Attorney General enforces the law; consumers have no private right of action.
Minnesota does not have a standalone biometric privacy statute like Illinois's BIPA or Texas's CUBI. Instead, the state protects biometric data through the Minnesota Consumer Data Privacy Act (MCDPA), a comprehensive consumer privacy law that classifies biometric identifiers as sensitive data requiring affirmative consent before collection or processing.
Governor Tim Walz signed HF 4757 into law on May 24, 2024 (Laws 2024, ch. 121). The MCDPA took effect on July 31, 2025, making Minnesota one of a growing number of states with comprehensive privacy legislation that covers biometric data.
For an overview of Minnesota's broader privacy framework, see the parent guide to Minnesota Data Privacy Laws.
How the MCDPA Defines Biometric Data
The MCDPA defines biometric data under Minn. Stat. 325M.11(d) as data generated by automatic measurements of an individual's biological characteristics that are used to identify a specific individual. The statute lists these examples:
- Fingerprints
- Voiceprints
- Eye retinas
- Irises
- Other unique biological patterns or characteristics
The law draws a clear line around what does not qualify. A physical or digital photograph, a video or audio recording, or data generated from those recordings is not biometric data unless that data is specifically generated to identify a specific individual.

This definition follows the same approach used in several other state comprehensive privacy statutes, including Connecticut and Kentucky. It is narrower than the definition used in Illinois's BIPA, which covers a broader set of biometric identifiers without the same exclusions.
Sensitive Data Classification and Consent
Under the MCDPA, biometric data processed for the purpose of uniquely identifying an individual qualifies as "sensitive data" per Minn. Stat. 325M.11(v). This is the highest protection category in the law.
Other categories of sensitive data under the MCDPA include:
- Data revealing racial or ethnic origin
- Religious beliefs
- Mental or physical health condition or diagnosis
- Sexual orientation
- Citizenship or immigration status
- Genetic data processed for identification
- Specific geolocation data
- Personal data of a known child under 13
Consent requirement. Under Minn. Stat. 325M.16(2)(d), controllers cannot process sensitive data, including biometric data, without first obtaining consumer consent. This means a business cannot collect your fingerprint, faceprint, or iris scan for identification purposes without your affirmative agreement.

Revocation right. Under Minn. Stat. 325M.16(2)(e), consumers can revoke consent at any time. Controllers must provide a revocation mechanism that is at least as easy to use as the original consent process. Once a consumer revokes consent, the controller must stop processing their biometric data within 15 days.
Who Must Comply
The MCDPA applies to entities that conduct business in Minnesota or produce products or services targeted to Minnesota residents and meet one of these thresholds under Minn. Stat. 325M.12:
- Process personal data of 100,000 or more consumers during a calendar year, excluding data processed solely for completing payment transactions, or
- Process personal data of 25,000 or more consumers and derive over 25% of gross revenue from the sale of personal data
Small businesses as defined by the U.S. Small Business Administration receive limited exemptions but must still obtain consent before selling sensitive data, including biometric data.
Key Exemptions
The MCDPA exempts several categories of entities and data from coverage:
Entity exemptions (a partial list; the statute contains additional narrower carve-outs):
- State- or federally-chartered banks and credit unions, and affiliates or subsidiaries principally engaged in financial activities
- Insurance companies, insurance producers, and third-party administrators of self-insurance
- Nonprofit organizations established to detect and prevent fraudulent acts in connection with insurance (a narrow carve-out; most Minnesota nonprofits are not exempt and remain covered if they meet the applicability thresholds)
- HIPAA-covered entities and their business associates
- Government agencies and federally recognized Indian tribes
- Air carriers, for data covered by the Airline Deregulation Act
Deferred compliance, not an exemption. Postsecondary institutions regulated by the Minnesota Office of Higher Education are covered by the MCDPA. They are not on the statute's list of excluded entities. The effective-date note to Minn. Stat. 325M.12 states that the section, as added by Laws 2024, ch. 121, art. 5, is effective July 31, 2025, "except that postsecondary institutions regulated by the Office of Higher Education are not required to comply until July 31, 2029." The practical effect through that date resembles an exemption, but the deadline sits in the session law's effective-date clause, not in the statute's exclusions.
Data exemptions (a partial list; the statute contains additional narrower carve-outs):
- Data regulated under HIPAA
- Data governed by the Gramm-Leach-Bliley Act (GLBA)
- Data governed by the Fair Credit Reporting Act (FCRA)
- Data covered by the Family Educational Rights and Privacy Act (FERPA)
- Data under the Driver's Privacy Protection Act (DPPA)
Employee data exemption. The MCDPA does not apply to personal data collected about job applicants, employees, or individuals acting as business representatives when that data is processed in the context of the employment relationship. If your employer collects your fingerprints for a timekeeping system or uses facial recognition for building access, the MCDPA does not regulate that collection. Minnesota does not have a separate law governing employer use of biometric data.
Consumer Rights Over Biometric Data
Because biometric data is sensitive personal data under the MCDPA, Minnesota consumers have these rights under Minn. Stat. 325M.14:
Right to confirm and access. You can ask any covered business whether it is processing your biometric data and request access to that data. However, controllers are not required to disclose biometric data itself in response to access requests. Instead, they must inform you that they have collected such information.
Right to correct. If a business holds inaccurate biometric data about you, you can request a correction.
Right to delete. You can request that a business delete the biometric data it holds about you.
Right to data portability. You can obtain a copy of your personal data in a portable and readily usable format.
Right to opt out. You can opt out of the processing of your personal data for targeted advertising, the sale of personal data, or profiling that produces legal or similarly significant effects.
Right to question profiling decisions. If a business uses automated profiling, such as biometric identification like facial recognition, to make a decision about you, you can ask the business why the profiling produced that decision and, if feasible, what you could have done to get a different outcome.
Right to a list of third-party recipients. You can request a list of the specific third parties a business has disclosed your personal data to.
Right to non-discrimination. Businesses cannot penalize you for exercising any of these rights by denying goods or services, charging different prices, or providing a different quality of service.
Businesses must respond to consumer rights requests within 45 days. They can extend this period by an additional 45 days when reasonably necessary, but must notify the consumer of the extension and the reason for it.
Data Protection Assessments for Biometric Data
Controllers that process sensitive data, including biometric data, must conduct data protection assessments under Minn. Stat. 325M.18. These assessments must weigh the benefits of processing against potential risks to consumers, including:
- Unfair or deceptive treatment or unlawful disparate impact
- Financial, physical, or reputational injury
- Intrusion upon solitude or seclusion
- Other substantial injury
Controllers must also establish and maintain reasonable administrative, technical, and physical data security practices proportional to the volume and nature of the biometric data they process. Under Minn. Stat. 325M.16, those practices must include maintaining an inventory of the data managed to meet these responsibilities. The Minnesota Attorney General can request these assessments during an investigation.
Breach Notification and Biometric Data
Minnesota's separate breach notification law at Minn. Stat. 325E.61 requires businesses to notify affected individuals when a security breach compromises unencrypted personal information. However, the statute's definition of personal information is limited to Social Security numbers, driver's license or ID numbers, and financial account numbers with security codes.
Biometric data is not explicitly listed as a category of personal information triggering breach notification under Minn. Stat. 325E.61. This creates a gap in Minnesota's data protection framework. A breach that exposes biometric data alone, without an accompanying Social Security or financial account number, may not trigger the breach notification requirement under the older statute.
The MCDPA's data security requirements under Minn. Stat. 325M.16 provide a separate layer of protection by requiring controllers to maintain reasonable security practices for all personal data, including biometric data. A failure to maintain adequate security could still lead to AG enforcement under the MCDPA, even if the breach notification statute does not apply.
Enforcement and Penalties
The Minnesota Attorney General has exclusive enforcement authority over the MCDPA under Minn. Stat. 325M.20. There is no private right of action, meaning individual consumers cannot file lawsuits against businesses for MCDPA violations.
Enforcement resources. The legislature appropriated funding for four new attorneys and one investigator in the AG's office dedicated to MCDPA enforcement. The AG's office received over 200 MCDPA complaints in the first six months of the law and sent dozens of warning letters to companies identifying problems with privacy policies and procedures.
Cure period (expired). From July 31, 2025, through January 31, 2026, the law required the AG to notify businesses in writing of alleged violations and provide 30 days to cure. This grace period expired on January 31, 2026. Since February 2026, the AG can bring enforcement actions immediately without advance notice.

Penalties. The AG can initiate civil actions against businesses that violate the MCDPA with penalties of up to $7,500 per violation. Multiple violations involving biometric data collection without consent could result in substantial aggregate penalties.
Pending Minnesota Biometric Legislation
Several bills in the 94th Minnesota Legislature (2025-2026) could expand biometric privacy protections:
HF 3661 would prohibit government entities from acquiring or using facial recognition technology. Introduced in February 2026, it was referred to the House Judiciary Finance and Civil Law Committee.
SF 3270 would require express written consent for biometric data collection in places of public accommodation, using a broader definition that includes facial features, gestures, and movements.
HF 4131 would address surveillance-based price and wage discrimination, defining "surveillance data" to include biometric information. If passed, it would take effect August 1, 2026.
As of August 2026, none of these bills has advanced beyond committee referral. HF 3661's most recent recorded action remains the March 5, 2026 addition of a co-author, with no further movement since.
How Minnesota Compares to Other States
Minnesota's approach to biometric privacy falls in the middle of the spectrum among U.S. states:
Stronger than states with no protections. Many states still lack any specific biometric data protections. Minnesota's classification of biometric data as sensitive data requiring consent, combined with active AG enforcement, puts it ahead of states with no comprehensive privacy law.
Weaker than dedicated biometric privacy laws. States like Illinois, Texas, and Washington have standalone biometric privacy statutes with specific requirements for notice, consent, retention schedules, and data destruction. Illinois's BIPA includes a private right of action that has produced billions in litigation and settlements.
Similar to other comprehensive privacy law states. Minnesota's approach closely mirrors Kentucky, Connecticut, Indiana, and Montana, which all classify biometric data as sensitive data within their comprehensive consumer privacy frameworks and require opt-in consent for processing.
Notable gap. Unlike states with dedicated biometric breach notification provisions, Minnesota's breach notification statute (Minn. Stat. 325E.61) does not explicitly cover biometric data, leaving a potential gap when breaches involve biometric information without other personal identifiers.
Sources and References
This article references Minnesota statutes and official state government publications. For the full text of the MCDPA, visit the Minnesota Revisor of Statutes. For guidance on consumer rights and filing complaints, visit the Minnesota Attorney General's MCDPA page.
This article provides general legal information about Minnesota biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Minnesota government sources.
More Minnesota Laws
Frequently Asked Questions
Does Minnesota have a standalone biometric privacy law like Illinois?
No. Minnesota does not have a dedicated biometric privacy statute. Instead, the Minnesota Consumer Data Privacy Act (MCDPA), effective July 31, 2025, classifies biometric data as sensitive data within its comprehensive consumer privacy framework. The MCDPA requires businesses to obtain opt-in consent before processing biometric data for identification purposes, but it does not include the detailed retention schedules, destruction timelines, or private right of action found in Illinois BIPA.
Can I sue a company in Minnesota for collecting my fingerprints without consent?
Not under the MCDPA. The Minnesota Attorney General has exclusive enforcement authority, and the law does not include a private right of action. If you believe a company collected your biometric data without consent, you can file a complaint through the AG's Consumer Division at ag.state.mn.us. The AG can investigate and pursue civil penalties of up to $7,500 per violation. Since February 2026, the AG no longer needs to provide advance notice before taking enforcement action.
Does the MCDPA protect my biometric data at work?
No. The MCDPA exempts personal data collected about job applicants, employees, and individuals acting as business representatives when processed in an employment context. If your employer collects fingerprints for timekeeping, uses facial recognition for building access, or requires biometric scans for security purposes, the MCDPA does not regulate that activity. Minnesota does not have a separate law governing employer use of biometric data.
What happens if a biometric data breach occurs in Minnesota?
Minnesota's breach notification law (Minn. Stat. 325E.61) does not explicitly list biometric data as a category of personal information triggering notification. However, the MCDPA requires controllers to maintain reasonable security practices for all personal data, including biometric data. A failure to protect biometric data could lead to AG enforcement under the MCDPA even if the breach notification statute does not technically apply. If the breach also involves Social Security numbers, financial account numbers, or driver's license numbers alongside biometric data, the breach notification law does apply.
Is Minnesota considering stronger biometric privacy protections?
Yes. Several bills in the 94th Minnesota Legislature (2025-2026) could expand protections. HF 3661 would ban government use of facial recognition technology. SF 3270 would require express written consent for biometric data collection in public accommodations using a broader definition than the MCDPA. HF 4131 would address surveillance-based discrimination involving biometric data. As of August 2026, none of these bills had advanced beyond committee referral. HF 3661's most recent recorded action remains a March 2026 committee referral, with no further movement since.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the MCDPA signing date to May 24, 2024 and clarified that postsecondary institutions face a deferred July 31, 2029 compliance deadline rather than a statutory exemption.
Corrected the nonprofit and financial-institution exemption descriptions to match the MCDPA's narrower statutory scope, added the MCDPA's right to challenge profiling decisions and receive a third-party disclosure list, noted the controller data-inventory security duty, and refreshed the pending-legislation status through August 2026.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Minnesota Statutes, Chapter 325M: CONSUMER DIGITAL AND DATA PRIVACY
§ 325M.16RESPONSIBILITIES OF CONTROLLERSIn forcecited in 4 of our articles
Subdivision 1. Transparency obligations. (a) Controllers must provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes: (1) the categories of personal data processed by the controller; (2) the purposes for which the categories of personal data are processed; (3) an explanation of the rights contained in section 325M.14 and how and where consumers may exercise those rights, including how a consumer may appeal a controller's action with regard to the consumer's request; (4) the categories of personal data that the controller sells to or shares with third parties, if any; (5) the categories of third parties, if any, with whom the controller sells or shares personal data; (6) the controller's contact information, including an active email address or other online mechanism that the consumer may use to contact the controller; (7) a description of the controller's retention policies for personal data; and (8) the date the privacy notice was last updated.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at revisor.mn.gov
Also relied on in: Minnesota Data Privacy Laws: Consumer Rights Guide (2026), Minnesota MCDPA Consumer Rights (Minn. Stat. 325M.14), Minnesota MCDPA Compliance Checklist (Minn. Stat. 325M)
§ 325M.11DEFINITIONSIn forcecited in 2 of our articles
(a) For purposes of sections 325M.10 to 325M.21, the following terms have the meanings given. (b) "Affiliate" means a legal entity that controls, is controlled by, or is under common control with another legal entity. For purposes of this paragraph, "control" or "controlled" means: ownership of or the power to vote more than 50 percent of the outstanding shares of any class of voting security of a company; control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or the power to exercise a controlling influence over the management of a company. (c) "Authenticate" means to use reasonable means to determine that a request to exercise any of the rights under section 325M.14, subdivision 1, paragraphs (b) to (h), is being made by or rightfully on behalf of the consumer who is entitled to exercise the rights with respect to the personal data at issue. (d) "Biometric data" means data generated by automatic measurements of an individual's biological characteristics, including a fingerprint, a voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at revisor.mn.gov
Also relied on in: Minnesota Workplace Recording Laws: Employee and Employer Rights
§ 325M.12SCOPE; EXCLUSIONSIn forcecited in 5 of our articles
Subdivision 1. Scope. (a) Sections 325M.10 to 325M.21 apply to legal entities that conduct business in Minnesota or produce products or services that are targeted to residents of Minnesota, and that satisfy one or more of the following thresholds: (1) during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more. (b) A controller or processor acting as a technology provider under section 13.32 shall comply with sections 13.32 and 325M.10 to 325M.21, except that when the provisions of section 13.32 conflict with sections 325M.10 to 325M.21, section 13.32 prevails. Subd. 2. Exclusions.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at revisor.mn.gov
Also relied on in: What Is the Minnesota Consumer Data Privacy Act (MCDPA)?, Minnesota Employee Monitoring Laws (2026): Cameras, GPS & Privacy
§ 325M.14CONSUMER PERSONAL DATA RIGHTSIn forcecited in 5 of our articles
Subdivision 1. Consumer rights provided. (a) Except as provided in sections 325M.10 to 325M.21, a controller must comply with a request to exercise the consumer rights provided in this subdivision. (b) A consumer has the right to confirm whether or not a controller is processing personal data concerning the consumer and access the categories of personal data the controller is processing. (c) A consumer has the right to correct inaccurate personal data concerning the consumer, taking into account the nature of the personal data and the purposes of the processing of the personal data. (d) A consumer has the right to delete personal data concerning the consumer. (e) A consumer has the right to obtain personal data concerning the consumer, which the consumer previously provided to the controller, in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at revisor.mn.gov
§ 325M.18DATA PRIVACY POLICIES; DATA PRIVACY AND PROTECTION ASSESSMENTSIn forcecited in 4 of our articles
(a) A controller must document and maintain a description of the policies and procedures the controller has adopted to comply with sections 325M.10 to 325M.21. The description must include, where applicable: (1) the name and contact information for the controller's chief privacy officer or other individual with primary responsibility for directing the policies and procedures implemented to comply with the provisions of sections 325M.10 to 325M.21; and (2) a description of the controller's data privacy policies and procedures which reflect the requirements in section 325M.16, and any policies and procedures designed to: (i) reflect the requirements of sections 325M.10 to 325M.21 in the design of the controller's systems; (ii) identify and provide personal data to a consumer as required by sections 325M.10 to 325M.21; (iii) establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data, including the maintenance of an inventory of the data that must be managed to exercise the responsibilities under this item; (iv) limit the collection of personal data to what…
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at revisor.mn.gov
§ 325M.20ATTORNEY GENERAL ENFORCEMENTIn forcecited in 5 of our articles
(a) In the event that a controller or processor violates sections 325M.10 to 325M.21, the attorney general, prior to filing an enforcement action under paragraph (b), must provide the controller or processor with a warning letter identifying the specific provisions of sections 325M.10 to 325M.21 the attorney general alleges have been or are being violated. If, after 30 days of issuance of the warning letter, the attorney general believes the controller or processor has failed to cure any alleged violation, the attorney general may bring an enforcement action under paragraph (b). This paragraph expires January 31, 2026. (b) The attorney general may bring a civil action against a controller or processor to enforce a provision of sections 325M.10 to 325M.21 in accordance with section 8.31. If the state prevails in an action to enforce sections 325M.10 to 325M.21, the state may, in addition to penalties provided by paragraph (c) or other remedies provided by law, be allowed an amount determined by the court to be the reasonable value of all or part of the state's litigation expenses incurred.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at revisor.mn.gov
Minnesota Statutes, Chapter 325E: TRADE PRACTICES
§ 325E.61DATA WAREHOUSES; NOTICE REQUIRED FOR CERTAIN DISCLOSURESIn forcecited in 2 of our articles
Subdivision 1. Disclosure of personal information; notice required. (a) Any person or business that conducts business in this state, and that owns or licenses data that includes personal information, shall disclose any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of this state whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in paragraph (c), or with any measures necessary to determine the scope of the breach, identify the individuals affected, and restore the reasonable integrity of the data system. (b) Any person or business that maintains data that includes personal information that the person or business does not own shall notify the owner or licensee of the information of any breach of the security of the data immediately following discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at revisor.mn.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2014
Opinions citing this section in our collection:
- In re Target Corp. Customer Data Security Breach Litigation (District Court, D. Minnesota 2014, 66 F. Supp. 3d 1154)“…general shall enforce this section ... under section 8.31.” Minn.Stat. § 325E.61, subd. 6. Plaintiffs argue that the ref…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Minnesota Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Minnesota Consumer Data Privacy Act (Chapter 325M)(revisor.mn.gov).gov
- Minn. Stat. 325M.11 - MCDPA Definitions(revisor.mn.gov).gov
- Minn. Stat. 325M.12 - Applicability(revisor.mn.gov).gov
- Minn. Stat. 325M.14 - Consumer Rights(revisor.mn.gov).gov
- Minn. Stat. 325M.16 - Controller Obligations(revisor.mn.gov).gov
- Minn. Stat. 325M.18 - Data Protection Assessments(revisor.mn.gov).gov
- Minn. Stat. 325M.20 - Enforcement(revisor.mn.gov).gov
- HF 4757 - MCDPA Bill(revisor.mn.gov).gov
- Minn. Stat. 325E.61 - Breach Notification(revisor.mn.gov).gov
- AG Ellison - MCDPA Takes Effect(ag.state.mn.us).gov
- AG Ellison - MCDPA Full Enforcement(ag.state.mn.us).gov
- Minnesota AG - Consumer Data Privacy(ag.state.mn.us).gov
- HF 3661 - Facial Recognition Ban(revisor.mn.gov).gov
- SF 3270 - Biometric Consent in Public Accommodations(revisor.mn.gov).gov
- HF 4131 - Surveillance-Based Discrimination(revisor.mn.gov).gov
- HF 4757 (2024) Bill Status - Governor approval May 24, 2024, Laws 2024 ch. 121(revisor.mn.gov)