Montana
Montana Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 6 primary sources cited on this page. How we verify our legal content

Montana has no standalone biometric privacy statute. Instead, the Montana Consumer Data Privacy Act (MCDPA), codified at Mont. Code Ann. 30-14-2801 through 30-14-2820, classifies biometric data as sensitive personal data at Mont. Code Ann. 30-14-2802(28)(b) and bars a controller from processing it without the consumer's consent under Mont. Code Ann. 30-14-2812(2)(b). The Montana Attorney General holds exclusive enforcement authority; consumers have no private right of action.
Montana does not have a standalone biometric privacy statute like Illinois's BIPA or Texas's CUBI. Instead, biometric data protections in Big Sky Country come from the Montana Consumer Data Privacy Act (MCDPA), a comprehensive consumer privacy law that classifies biometric identifiers as sensitive data requiring affirmative consent before processing. Two narrower Montana statutes do reach biometric information directly, and both are covered below.
Governor Greg Gianforte signed SB 384 into law in May 2023, making Montana the ninth state to enact a comprehensive consumer data privacy law. The MCDPA originally took effect on October 1, 2024. In 2025, the Montana Legislature passed SB 297, which expanded enforcement authority, lowered applicability thresholds, and strengthened protections for minors and sensitive data. Those amendments took effect October 1, 2025.
For an overview of Montana's broader privacy framework, see the parent guide to Montana Data Privacy Laws.
How the MCDPA Defines Biometric Data
The MCDPA defines biometric data under Mont. Code Ann. 30-14-2802 as data generated by automatic measurements of an individual's biological characteristics that are used to identify a specific individual. The statute provides these examples:
- Fingerprints
- Voiceprints
- Eye retinas
- Irises
- Other unique biological patterns or characteristics
The law draws a clear line around what does not qualify. A physical or digital photograph, a video or audio recording, or data generated from those recordings is not biometric data unless it is specifically generated to identify a particular individual.

This definition follows the approach used in Virginia, Connecticut, and several other state comprehensive privacy statutes. It is narrower than the definition used in Illinois's BIPA, which covers a broader set of biometric identifiers without the same exclusions.
Sensitive Data Classification and Consent
Under Mont. Code Ann. 30-14-2802(28)(b), biometric data processed for the purpose of uniquely identifying an individual qualifies as "sensitive data." This is the highest protection category in the law.
Other categories of sensitive data under Mont. Code Ann. 30-14-2802 include:
- Data revealing racial or ethnic origin
- Religious beliefs
- Mental or physical health diagnoses
- Information about a person's sex life
- Sexual orientation
- Citizenship or immigration status
- Genetic data processed for identification
- Precise geolocation data
- Personal data collected from a known child under 13
Consent requirement. The operative prohibition sits at Mont. Code Ann. 30-14-2812(2)(b), which says a controller may not "process sensitive data concerning a consumer without obtaining the consumer's consent" or, where the data concerns a known child, without handling it in accordance with the federal Children's Online Privacy Protection Act. A business cannot collect your fingerprint, faceprint, or iris scan for identification purposes without first asking for and receiving your affirmative agreement.
The MCDPA defines consent as a "clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement." A buried clause in a terms-of-service agreement does not meet this standard. Pre-checked boxes, hovering over content, or closing a pop-up window also do not count. The law specifically prohibits the use of dark patterns to obtain consent.
Restricted Disclosure of Biometric Data
SB 297 added a notable provision that limits how businesses can respond to consumer access requests when biometric data is involved.
Under the amended MCDPA, controllers cannot disclose certain sensitive identifiers in response to data access requests, including:
- Biometric data
- Social security numbers
- Government-issued identification numbers
- Financial account numbers
- Health insurance or medical identification numbers
- Account passwords and security questions
Instead of handing over this raw data, businesses must inform consumers "with sufficient particularity" that such data has been collected. This prevents the access request process itself from becoming a security vulnerability.
Who Must Comply
The MCDPA applies to entities that conduct business in Montana or produce products or services targeted to Montana residents and meet one of these thresholds (as amended by SB 297):
- Process personal data of 25,000 or more Montana consumers during a calendar year (reduced from 50,000 under the original law), or
- Process personal data of 15,000 or more Montana consumers and derive over 25% of gross revenue from the sale of personal data (reduced from 25,000)
These lower thresholds mean more businesses fall under the MCDPA's requirements than when the law first took effect in 2024.
Key Exemptions
The MCDPA carves out several categories of entities and data types from coverage:
Entity exemptions under Mont. Code Ann. 30-14-2804:
- State and local government agencies
- Nonprofit organizations (narrowed under SB 297 to fraud detection in insurance only)
- Higher education institutions
- State or federally chartered banks and credit unions, and any affiliate or subsidiary principally engaged in financial activities described in 12 U.S.C. 1843(k), under 30-14-2804(1)(e)
- Insurers, insurance producers, and third-party administrators of self-insurance, under 30-14-2804(1)(h)
Data exemptions:
- Data regulated under HIPAA
- Personal data collected, processed, sold, or disclosed in accordance with Title V of the Gramm-Leach-Bliley Act, under 30-14-2804(1)(f)
- Data covered by the Fair Credit Reporting Act (FCRA)
- Data under the Family Educational Rights and Privacy Act (FERPA)
- Data regulated under the Driver's Privacy Protection Act (DPPA)
SB 297 rewrote this section, and the change is narrower than it is often described. It replaced the original broad financial institution exemption with the data-level GLBA exemption at 30-14-2804(1)(f), but entity-level coverage for the financial sector survived: chartered banks and credit unions are still exempt as entities at (1)(e), and insurers, insurance producers, and self-insurance administrators at (1)(h). The section's history note records the sequence as "En. Sec. 4, Ch. 681, L. 2023; amd. Sec. 4, Ch. 567, L. 2025."
Employee data exemption. The MCDPA excludes persons acting in a commercial or employment context from the definition of "consumer." Data processed about an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party is exempt when used in the context of that role.
This means that if your employer collects fingerprints for a timekeeping system or uses facial recognition for building access, the MCDPA does not apply to that collection. Montana does not have a separate law regulating employer use of biometric data.
Consumer Rights Over Biometric Data
Because biometric data qualifies as sensitive personal data under the MCDPA, Montana consumers have the following rights under Mont. Code Ann. 30-14-2808:

Right to confirm and access. You can ask any covered business whether it is processing your biometric data and request information about that processing.
Right to correct. If a business holds inaccurate biometric data about you, you can request a correction.
Right to delete. You can request that a business delete the biometric data it holds about you.
Right to data portability. You can obtain a copy of your personal data in a portable and readily usable format, though biometric data itself falls under the restricted disclosure provision.
Right to opt out. You can opt out of the processing of your personal data for targeted advertising, the sale of personal data, or profiling that produces legal or similarly significant effects.
Right to non-discrimination. Businesses cannot penalize you for exercising any of these rights.
Businesses must respond to consumer rights requests within 45 days. They can extend this period by an additional 45 days when reasonably necessary, provided they notify the consumer of the extension and the reason for it. If a business denies a request, it must explain why and tell the consumer how to appeal.
Data Protection Assessments
Controllers that process sensitive data, including biometric data, must conduct data protection assessments under the MCDPA. SB 297 expanded these requirements, particularly for processing that affects minors.
A data protection assessment must weigh the benefits of the processing against the potential risks to the consumer, including risks of:
- Unfair or deceptive treatment or unlawful disparate impact
- Financial, physical, or reputational injury
- Intrusion upon solitude or seclusion
- Other substantial injury
The Montana Attorney General can request these assessments during an investigation. For assessments of processing that poses a heightened risk of harm to minors, SB 297 added Mont. Code Ann. 30-14-2819, which requires controllers to retain that documentation for the longer of three years after processing ceases or the date the service, product, or feature is discontinued. The general data protection assessment requirement for sensitive data under Mont. Code Ann. 30-14-2814, which covers biometric data processing generally, sets no retention period.
Breach Notification and Biometric Data
Montana's breach notification law at Mont. Code Ann. 30-14-1704 requires businesses to notify affected individuals when a security breach compromises unencrypted personal information.
However, Montana's definition of personal information for breach notification purposes is limited to an individual's name combined with:
- Social security numbers
- Driver's license, state ID, or tribal ID numbers
- Financial account numbers with required security codes
- Medical record information
- Taxpayer identification numbers
- IRS identity protection PINs
Biometric data is not explicitly listed as a category that triggers breach notification under this statute. This creates a gap between the MCDPA's treatment of biometric data as sensitive and the breach notification law's narrower scope. A business could experience a breach involving biometric data without being required to notify affected individuals under Mont. Code Ann. 30-14-1704.
When notification is required, businesses must report breaches "without unreasonable delay" and simultaneously submit an electronic copy to the Montana Office of Consumer Protection at datarequests@mt.gov. Even a single affected Montana resident triggers the reporting requirement.
Enforcement and Penalties

The Montana Attorney General has exclusive enforcement authority over the MCDPA. There is no private right of action, which means individual consumers cannot file lawsuits against businesses for MCDPA violations.
SB 297 significantly strengthened the Attorney General's enforcement tools:
Cure period eliminated, with an unresolved statutory cross-reference. The original MCDPA gave businesses 60 days to fix violations before facing enforcement action. SB 297 eliminated that voluntary cure right. Under the current law, Mont. Code Ann. 30-14-2820(2) attaches civil penalties only to violations occurring after "the 30-day period described in 30-14-2817(3)," but 30-14-2817(3) as currently written covers the Attorney General's civil investigative demand authority and does not itself spell out a 30-day window. That leaves the exact length of any pre-penalty period unclear from the statutory text alone. What is clear is that the Attorney General no longer has to wait 60 days before acting on a violation.
Expanded investigatory power. The Attorney General can now issue civil investigative demands under Montana's Consumer Protection Act and require controllers to submit data protection assessments relevant to investigations.
Civil penalties. Violations of the MCDPA can result in penalties of up to $7,500 per violation under Mont. Code Ann. 30-14-2820. The Attorney General can also seek injunctive relief and recover reasonable attorney fees and investigation costs.
Statute of limitations. SB 297 established a five-year statute of limitations from when the cause of action accrues.
Consumers can file complaints with the Montana Office of Consumer Protection through the Montana Department of Justice website.
Genetic, Neurotechnology, and Biometric Samples Sent Overseas
The MCDPA is not the only Montana statute that names biometric data. The Genetic Information Privacy Act at Mont. Code Ann. 30-23-104, amended in 2025 to cover neurotechnology, adds a data-localization rule at subsection (10).
Genetic or neurotechnology data and biometric samples of Montana residents collected in the state may not be stored within the territorial boundaries of any country currently sanctioned by the U.S. Office of Foreign Assets Control or designated a foreign adversary under 15 CFR 7.4(a). Genetic or neurotechnology data or biometric data of Montana residents collected in the state may be transferred or stored outside the United States only with the resident's consent.
This is a narrow rule, not a general biometric privacy law. It binds only an "entity" as defined in Mont. Code Ann. 30-23-102(4), meaning a partnership, corporation, association, or public or private organization that offers consumer genetic testing products or services directly to consumers or that collects, uses, or analyzes genetic data. A retailer running a fingerprint time clock is not covered by it.
Enforcement mirrors the MCDPA's structure. Under Mont. Code Ann. 30-23-106 the Attorney General has exclusive authority and may recover a consumer's actual damages, costs, reasonable attorney fees, and $2,500 for each violation of 30-23-104. There is no private right of action here either.
Government Use of Facial Recognition Is Regulated Separately
Commercial biometric processing in Montana runs on consent. Government use of face recognition runs on something much closer to a ban. Title 44, chapter 15 of the Montana Code, titled "Facial Recognition for Government Use," was enacted in 2023 and binds a state or local government agency, law enforcement agency, public employee, or public official. It does not reach private businesses, which is why the MCDPA analysis above is unaffected by it.
The chapter's main provisions:
- Mont. Code Ann. 44-15-104 prohibits covered officials and agencies from obtaining, retaining, possessing, accessing, requesting, contracting for, or using continuous facial surveillance.
- Mont. Code Ann. 44-15-105 generally bars those same actors from using facial recognition technology at all, except as permitted by 44-15-106 and 44-15-108.
- Mont. Code Ann. 44-15-106 requires a law enforcement agency to obtain a warrant before performing a facial recognition search, subject to a narrow emergency exception.
- Mont. Code Ann. 44-15-107 requires disclosure to criminal defendants.
- Mont. Code Ann. 44-15-109 through 44-15-111 impose third-party vendor notice, policy and retention rules, meaningful human review, and audit and reporting duties.
- Mont. Code Ann. 44-15-112 sets the penalty for violations.
The practical effect is that a Montana resident's face is treated very differently depending on who is scanning it. A private business needs your opt-in consent under the MCDPA. A police department needs a warrant.
How Montana Compares to Other States
Montana's approach to biometric privacy falls in the middle of the spectrum among U.S. states:
Stronger than states with no protections. Many states still lack any specific biometric data protections. Montana's classification of biometric data as sensitive data requiring consent puts it ahead of states without comprehensive privacy laws.
Weaker than dedicated biometric privacy laws. States like Illinois, Texas, and Washington have standalone biometric privacy statutes with specific requirements for notice, consent, retention schedules, and data destruction. Illinois's BIPA includes a private right of action that has produced significant litigation and settlements.
Similar to other comprehensive privacy law states. Montana's approach closely mirrors states like Connecticut, Indiana, and Kentucky, which all classify biometric data as sensitive data within their comprehensive consumer privacy frameworks and require opt-in consent for processing.
Notable gap. Unlike some states that include biometric data in their breach notification definitions, Montana's breach notification statute does not cover biometric data. This is an area where Montana offers less protection than states that have updated their breach notification laws.
Sources and References
This article references Montana statutes and official state government publications. For the full text of the MCDPA, visit the Montana Code Annotated. For consumer complaints and guidance, visit the Montana Department of Justice Office of Consumer Protection. For breach notification requirements, see the Montana DOJ reporting page.
This article provides general legal information about Montana biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Montana government sources.
More Montana Laws
Frequently Asked Questions
Does Montana have a standalone biometric privacy law like Illinois?
No. Montana does not have a dedicated biometric privacy statute. Instead, the Montana Consumer Data Privacy Act (MCDPA), effective October 1, 2024, with amendments under SB 297 effective October 1, 2025, classifies biometric data as sensitive data within its comprehensive consumer privacy framework. The MCDPA requires businesses to obtain opt-in consent before processing biometric data for identification purposes, but it does not include the detailed retention schedules, destruction requirements, or private right of action found in Illinois BIPA. Two narrower statutes also apply: Mont. Code Ann. 30-23-104(10) restricts overseas storage and transfer of genetic, neurotechnology, and biometric samples by consumer genetic-testing entities, and Title 44, chapter 15 restricts government use of facial recognition technology.
Can I sue a company in Montana for collecting my fingerprints without consent?
Not under the MCDPA. The Montana Attorney General has exclusive enforcement authority, and the law does not include a private right of action. If you believe a company collected your biometric data without consent, you can file a complaint with the Montana Office of Consumer Protection through the Department of Justice website at dojmt.gov. The AG can investigate and pursue civil penalties of up to $7,500 per violation.
Does the MCDPA protect my biometric data at work?
No. The MCDPA exempts data collected in an employment context. If your employer collects fingerprints for timekeeping, uses facial recognition for building access, or requires biometric scans, the MCDPA does not regulate that activity. Montana has no separate law governing private employer use of biometric data, although Title 44, chapter 15 separately restricts state and local government agencies, law enforcement agencies, public employees, and public officials from using facial recognition technology. However, if a breach involving your biometric data occurs, Montana general data security obligations may still apply.
What changed for biometric data under SB 297 in 2025?
SB 297 strengthened biometric protections in several ways. It added biometric data to the list of sensitive identifiers that controllers cannot disclose in response to access requests. It lowered the applicability thresholds so more businesses are covered. It eliminated the original 60-day cure period. Civil penalties now attach to violations continuing after the 30-day period referenced in Mont. Code Ann. 30-14-2820(2), which points to the Attorney General's investigative-demand authority under 30-14-2817(3). It also added civil penalties of up to $7,500 per violation and expanded the AG investigatory powers.
Does Montana require businesses to notify me if my biometric data is breached?
Not specifically. Montana's breach notification law (Mont. Code Ann. 30-14-1704) lists categories like Social Security numbers, driver's license numbers, and financial account numbers as triggers for notification. Biometric data is not explicitly included in that list. This creates a gap where a breach involving only biometric data might not trigger the notification requirement under the breach notification statute, even though the MCDPA treats biometric data as sensitive.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the description of Montana's financial-institution exemption, which survives at the entity level for chartered banks, credit unions and insurers despite SB 297, cited the operative consent provision at Mont. Code Ann. 30-14-2812(2)(b) in place of the short-title section, and added coverage of the Genetic Information Privacy Act's overseas-storage rule for biometric samples and of Montana's separate restrictions on government use of facial recognition.
Removed a fabricated tribal-organization exemption not found in Montana's privacy statute, corrected the scope of a data-protection-assessment retention rule (it applies only to assessments involving minors, not biometric assessments generally), removed an unsourced claim about an April 2026 cure-period sunset and clarified how the current enforcement cross-reference actually reads, added a missing sensitive-data category (sex life information), and replaced two dead citation links with working government sources.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Montana Code Annotated, Title 30
§ 30-14-2812Data Processing By Controller -- LimitationsIn forcecited in 4 of our articles
30-14-2812. Data processing by controller -- limitations. (1) A controller shall: (a) limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which the personal data is processed, as disclosed to the consumer; (b) establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data appropriate to the volume and nature of the personal data at issue; and (c) provide an effective mechanism for a consumer to revoke the consumer's consent under this section that is at least as easy as the mechanism by which the consumer provided the consumer's consent and, on revocation of the consent, cease to process the personal data as soon as practicable, but not later than 45 days after the receipt of the request.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mca.legmt.gov
Also relied on in: MCDPA Compliance Checklist: Montana Privacy (2026), MCDPA Consumer Rights: Montana Privacy Rights (2026), What Is the MCDPA? Montana Data Privacy Law (2026)
§ 30-14-2802DefinitionsIn forcecited in 4 of our articles
30-14-2802. Definitions. As used in this part, unless the context clearly indicates otherwise, the following definitions apply: (1) "Adult" means an individual who is 18 years of age or older. (2) "Affiliate" means a legal entity that shares common branding with another legal entity or controls, is controlled by, or is under common control with another legal entity. (3) "Authenticate" means to use reasonable methods to determine that a request to exercise any of the rights afforded under 30-14-2808(1)(a) through (1)(e) is being made by, or on behalf of, the consumer who is entitled to exercise these consumer rights with respect to the personal data at issue. (4) (a) "Biometric data" means data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, a voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mca.legmt.gov
Also relied on in: Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026), Montana Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
§ 30-14-1704Computer Security BreachIn forcecited in 4 of our articles
30-14-1704. Computer security breach. (1) Any person or business that conducts business in Montana and that owns or licenses computerized data that includes personal information shall disclose any breach of the security of the data system following discovery or notification of the breach to any resident of Montana whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person. The disclosure must be made without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (3), or consistent with any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. (2) Any person or business that maintains computerized data that includes personal information that the person or business does not own shall notify the owner or licensee of the information of any breach of the security of the data system immediately following discovery if the personal information was or is reasonably believed to have been acquired by an unauthorized person.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mca.legmt.gov
Also relied on in: Montana Data Breach Notification Laws: Reporting Rules & Timelines (2026), Montana Identity Theft Laws: Penalties and the Identity Theft Passport
§ 30-14-2801Short TitleIn force
30-14-2801. Short title. This part may be cited as the "Consumer Data Privacy Act".
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mca.legmt.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Montana Department of Justice - Consumer Data Privacy(dojmt.gov).gov
- Mont. Code Ann. 30-14-2802 - MCDPA Definitions(mca.legmt.gov).gov
- Montana Consumer Data Privacy Act - Full Statute(mca.legmt.gov).gov
- Mont. Code Ann. 30-14-1704 - Computer Security Breach(mca.legmt.gov).gov
- Montana DOJ - Breach Reporting Requirements(dojmt.gov).gov
- Mont. Code Ann. 30-14-2801 - MCDPA Short Title (enacted Ch. 681, L. 2023)(mca.legmt.gov).gov
- Mont. Code Ann. 30-14-2812 - Data processing by controller, limitations (consent required for sensitive data at (2)(b))(mca.legmt.gov)
- Mont. Code Ann. 30-14-2804 - MCDPA exemptions (entity-level bank and credit union exemption at (1)(e), GLBA data exemption at (1)(f), insurers at (1)(h))(mca.legmt.gov)
- Mont. Code Ann. 30-23-104 - Consumer genetic or neurotechnology data; overseas storage and transfer of biometric samples at (10)(mca.legmt.gov)
- Mont. Code Ann. 30-23-106 - Genetic Information Privacy Act enforcement, $2,500 per violation(mca.legmt.gov)
- Mont. Code Ann. 44-15-104 - Prohibition of continuous facial surveillance(mca.legmt.gov)
- Mont. Code Ann. 44-15-105 - Prohibition of facial recognition technology for government use(mca.legmt.gov)
- Mont. Code Ann. 44-15-106 - Law enforcement use of facial recognition technology, warrant required(mca.legmt.gov)