New Mexico
New Mexico Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 7, 2026. · 7 primary sources cited on this page. How we verify our legal content

New Mexico has no standalone biometric privacy law. Biometric data is protected under the Data Breach Notification Act (N.M. Stat. Ann. 57-12C-1 et seq.), which requires organizations to secure and properly dispose of that data and to notify affected residents within 45 days of a breach, but imposes no consent or collection rules. The Attorney General enforces the law; individuals have no private right of action.
New Mexico takes a breach-notification approach to biometric privacy. The state has no dedicated statute governing how businesses collect, store, or use biometric identifiers. Instead, biometric data falls under the umbrella of the Data Breach Notification Act (N.M. Stat. Ann. 57-12C-1 through 57-12C-12), which requires organizations to notify residents when their personal information, including biometric data, is compromised in a security breach.
This means New Mexico employers and businesses can collect fingerprints, facial scans, and other biometric identifiers without obtaining advance consent or following specific collection procedures. Consent is the gap, not security. Once a business holds that data, N.M. Stat. Ann. 57-12C-3 through 57-12C-5 require it to store the data under reasonable security procedures, to dispose of the records properly once they are no longer reasonably needed, and to bind its service providers to the same standard by contract.
For an overview of the state's broader privacy framework, see the parent guide to New Mexico Data Privacy Laws.
How New Mexico Defines Biometric Data
The Data Breach Notification Act defines biometric data under N.M. Stat. Ann. 57-12C-2 as a record generated by automatic measurements of an identified individual's biological characteristics. The statute specifically lists:
- Fingerprints
- Voice prints
- Iris or retina patterns
- Facial characteristics
- Hand geometry

There is an important qualifier. The biometric data must be "used to uniquely and durably authenticate an individual's identity when the individual accesses a physical location, device, system or account." Biometric measurements collected for research, analytics, or purposes other than authentication do not qualify as protected personal identifying information under this statute.
This authentication-linked definition is narrower than the definitions used in states with dedicated biometric privacy laws, such as Illinois or Washington.
What the Data Breach Notification Act Requires
Personal Identifying Information
Biometric data is one of several categories that qualify as personal identifying information (PII) under the Act. The full list includes a person's first name or first initial and last name combined with any of the following:
- Social Security number
- Driver's license number or government-issued identification number
- Account number, credit card number, or debit card number combined with any required security code, access code, or password
- Biometric data
Publicly available information and information found in government records are excluded from this definition.
Security, Disposal, and Service-Provider Duties
The Act is not purely reactive. Three of its sections impose affirmative duties that apply before any breach occurs, and biometric data carries them because it is personal identifying information under N.M. Stat. Ann. 57-12C-2(C)(1)(e).
Under N.M. Stat. Ann. 57-12C-4, a person that owns or licenses personal identifying information of a New Mexico resident "shall implement and maintain reasonable security procedures and practices appropriate to the nature of the information" to protect it from unauthorized access, destruction, use, modification or disclosure.
Under N.M. Stat. Ann. 57-12C-3, a person that owns or licenses records containing that information "shall arrange for proper disposal of the records when they are no longer reasonably needed for business purposes." Proper disposal means shredding, erasing or otherwise modifying the information to make it unreadable or undecipherable.
Under N.M. Stat. Ann. 57-12C-5, a business that discloses personal identifying information to a service provider under contract must require by contract that the service provider implement and maintain the same reasonable security procedures and practices.
One limit shapes how far these duties reach. Biometric data is personal identifying information only when it is combined with an individual's first name or first initial and last name and is not protected through encryption or redaction, so encrypting biometric records both satisfies the security duty and removes the record from the notification trigger.
Breach Notification Timeline
When a security breach compromises biometric data or other PII, the organization must notify affected New Mexico residents "in the most expedient time possible, but not later than forty-five calendar days following discovery of the security breach" under N.M. Stat. Ann. 57-12C-6.
The 45-day clock starts at discovery, not at the time the breach actually occurred. This distinction matters because breaches are often detected weeks or months after the initial intrusion.
What the Notification Must Include
Written notices sent to affected individuals must contain specific information under the Act:
- The name and contact information of the entity reporting the breach
- A list of the types of personal identifying information believed to have been compromised
- The date of the security breach or the estimated date range
- A general description of the breach incident
- Toll-free telephone numbers and addresses for major consumer reporting agencies
- Advice to review personal account statements and credit reports for unusual activity
- Information about the individual's rights under the federal Fair Credit Reporting Act
Attorney General Notification
Under N.M. Stat. Ann. 57-12C-10, when a breach affects more than 1,000 New Mexico residents, the organization must also notify the New Mexico Attorney General and major consumer reporting agencies within 45 calendar days. The AG notification must include the number of residents who received breach notices and a copy of the notification sent to affected individuals.
Harm Threshold Exception
Notification is not required if, after an appropriate investigation, the organization determines that the security breach does not give rise to a significant risk of identity theft or fraud. Organizations that rely on this exception should document their investigation and reasoning thoroughly, as the Attorney General may later question that determination.
Exemptions Under the Act
Two categories of entities are fully exempt from the Data Breach Notification Act's requirements:
GLBA-covered entities. Financial institutions that comply with the data security and breach notification provisions of the Gramm-Leach-Bliley Act do not need to follow New Mexico's separate notification procedures.
HIPAA-covered entities. Healthcare providers, health plans, and healthcare clearinghouses that comply with the breach notification requirements of the Health Insurance Portability and Accountability Act are similarly exempt.
These exemptions recognize that federal law already imposes breach notification obligations on these industries. However, organizations should verify they are actually complying with the applicable federal requirements, not just that they fall within the regulated industry.
Encryption Safe Harbor
The Act does not apply to breaches involving personal identifying information that was encrypted, redacted, or otherwise rendered unreadable at the time of the breach. This safe harbor applies as long as the encryption key itself was not also compromised in the incident.
Organizations that encrypt biometric data at rest and in transit gain meaningful protection from notification obligations under this provision.
Enforcement and Penalties

Attorney General Authority
The New Mexico Attorney General has exclusive enforcement authority over the Data Breach Notification Act. Under N.M. Stat. Ann. 57-12C-11, when the AG has a reasonable belief that a violation has occurred, the office may bring an action on behalf of affected individuals and in the name of the state.
Civil Penalties
Courts can impose civil penalties of the greater of $25,000 or $10 per instance of failed notification, up to a maximum of $150,000, when a person or entity violates the Act knowingly or recklessly. The AG may also seek injunctive relief and damages for actual costs and losses suffered by affected individuals.
No Private Right of Action
New Mexico residents cannot file private lawsuits under the Data Breach Notification Act. Only the Attorney General can pursue enforcement. This limits the litigation risk for organizations compared to states like Illinois, where individuals can sue directly under BIPA and recover statutory damages.
However, individuals may still have claims under the New Mexico Unfair Practices Act (N.M. Stat. Ann. 57-12-1 et seq.) if a business's handling of biometric data involves deceptive or unconscionable trade practices.
Employer Use of Biometric Data

New Mexico has no biometric-specific employment statute, so there is no state-level mandate requiring employers to:
- Obtain written consent before collecting fingerprints or facial scans
- Publish a biometric data retention and destruction schedule
- Limit biometric data storage to a fixed number of years
- Destroy biometric data on a set deadline tied to the end of employment
The Data Breach Notification Act's general duties still apply to employee biometrics, and they are statutory obligations rather than best practices. An employer running biometric time clocks, fingerprint scanners for facility access, or facial recognition systems owns or licenses personal identifying information, so N.M. Stat. Ann. 57-12C-4 requires it to implement and maintain reasonable security procedures and practices for that data, and N.M. Stat. Ann. 57-12C-3 requires proper disposal of those records once they are no longer reasonably needed for business purposes. An employer that hands biometric data to a payroll, timekeeping, or access-control vendor must also require that vendor by contract, under N.M. Stat. Ann. 57-12C-5, to maintain reasonable security procedures and practices. A breach of employee biometric information triggers the same 45-day notification obligation as any other PII breach under the Act.
Pending Legislation and Future Outlook
New Mexico lawmakers have introduced several privacy bills in recent sessions that would expand biometric data protections if enacted.
Internet Privacy and Safety Act (HB 307, 2025)
House Bill 307 from the 2025 session proposed comprehensive consumer privacy protections. The bill defined biometric data broadly as "data about a consumer generated by measurements of the consumer's unique biological characteristics, such as a faceprint, a fingerprint, a voiceprint, a retina or an iris image." It would have classified biometric data as sensitive personal data, prohibited its use for targeted advertising, required opt-in consent for processing, and imposed civil penalties up to $7,500 per intentional violation with a private right of action. The bill did not become law during the 2025 session.
Community and Health Information Safety and Privacy Act (SB 53, 2026)
Senate Bill 53, known as CHISPA, was introduced in January 2026. It included a similar broad definition of biometric data and aimed to make online privacy the default by requiring opt-in consent for data collection. Despite receiving a "Do Pass" recommendation from the Senate Health and Public Affairs Committee on February 5, 2026, the bill was postponed indefinitely and did not advance further.
Artificial Intelligence Transparency Act (HB 28, 2026)
House Bill 28 from the 2026 session addressed AI systems making consequential decisions but did not directly regulate biometric data collection; like SB 53, it was postponed indefinitely and died when the session ended. It focuses on transparency and accountability for automated decision-making in employment, financial services, healthcare, and other areas.
What This Means Going Forward
The repeated introduction of privacy bills with biometric provisions signals growing legislative interest in this area. New Mexico may eventually adopt a comprehensive consumer privacy law that includes dedicated biometric data protections. Until then, the Data Breach Notification Act remains the primary safeguard.
How New Mexico Compares to Other States
New Mexico falls into a group of states that protect biometric data only through data-security and breach-notification requirements, without a dedicated biometric privacy statute or comprehensive consumer privacy law. This places it behind states with stronger protections:
| Protection Level | States |
|---|---|
| Dedicated biometric privacy statute | Illinois, Texas, Washington |
| Comprehensive privacy law covering biometrics | California, Colorado, Connecticut, Nebraska, Virginia |
| Breach notification only (like New Mexico) | Arkansas, North Carolina |
The key difference is that states with dedicated biometric privacy laws or comprehensive privacy laws regulate the collection and use of biometric data proactively, while New Mexico's law governs how the data is secured and disposed of but never asks whether it should have been collected in the first place.
This article provides general legal information about New Mexico biometric privacy laws and is not legal advice. Statutes and regulations change over time. Consult a qualified attorney licensed in New Mexico for guidance on your specific situation.
More New Mexico Laws
Frequently Asked Questions
Does New Mexico require consent before collecting biometric data?
No. New Mexico does not have a law requiring businesses or employers to obtain consent before collecting fingerprints, facial scans, or other biometric data. The state's Data Breach Notification Act requires reasonable security procedures, proper disposal of records once they are no longer reasonably needed, and notification after a breach, but it sets no consent or collection rules.
What happens if a company fails to notify residents about a biometric data breach in New Mexico?
The New Mexico Attorney General can bring an enforcement action against the company. Courts may impose civil penalties of the greater of $25,000 or $10 per instance of failed notification, up to a $150,000 cap, for knowing or reckless violations of the Data Breach Notification Act, plus injunctive relief and damages for actual costs and losses suffered by affected individuals.
Are employers in New Mexico required to have a biometric data retention policy?
Not a biometric-specific one. New Mexico does not require a written biometric retention policy or a fixed destruction deadline the way Illinois does. But two statutory duties still apply to employee biometrics: N.M. Stat. Ann. 57-12C-3 requires proper disposal of records containing personal identifying information once they are no longer reasonably needed for business purposes, and N.M. Stat. Ann. 57-12C-4 requires reasonable security procedures and practices to protect that data.
Can individuals sue over biometric data misuse in New Mexico?
Not under the Data Breach Notification Act, which has no private right of action. Only the Attorney General can enforce that statute. However, individuals may have claims under the New Mexico Unfair Practices Act (N.M. Stat. Ann. 57-12-1 et seq.) if a business's handling of biometric data involves deceptive or unconscionable trade practices.
Does New Mexico's biometric data law apply to healthcare providers and banks?
Entities covered by HIPAA (healthcare providers, health plans, clearinghouses) and entities subject to the Gramm-Leach-Bliley Act (financial institutions) are exempt from New Mexico's Data Breach Notification Act, provided they comply with the breach notification requirements under those federal laws.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the page to state that New Mexico's Data Breach Notification Act imposes affirmative data-security, disposal, and service-provider duties on businesses holding biometric data rather than only post-breach notification, fixed the lede citation to N.M. Stat. Ann. 57-12C-1 et seq., and reclassified Nebraska as a comprehensive-privacy-law state in the state comparison table.
Independently fact-checked against the cited primary sources
Corrected the civil-penalty description: the Data Breach Notification Act sets the penalty at the greater of $25,000 or $10 per instance of failed notification, up to a $150,000 cap, not a flat $25,000 (fixed in KeyTakeaways, body, and FAQ).
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
New Mexico Statutes Annotated 1978, Chapter 57
§ 57-12C-6Notification of security breachIn forcecited in 5 of our articles
A. Except as provided in Subsection C of this section, a person that owns or licenses elements that include personal identifying information of a New Mexico resident shall provide notification to each New Mexico resident whose personal identifying information is reasonably believed to have been subject to a security breach. Notification shall be made in the most expedient time possible, but not later than forty- five calendar days following discovery of the security breach, except as provided in Section 9 [57-12C-9 NMSA 1978] of the Data Breach Notification Act. B. Notwithstanding Subsection A of this section, notification to affected New Mexico residents is not required if, after an appropriate investigation, the person determines that the security breach does not give rise to a significant risk of identity theft or fraud. C.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at nmonesource.com
Also relied on in: New Mexico Data Privacy Laws: Breach Notification, AG Enforcement & 2026 Legislation, New Mexico Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 57-12C-2DefinitionsIn forcecited in 4 of our articles
As used in the Data Breach Notification Act: A. "biometric data" means a record generated by automatic measurements of an identified individual's fingerprints, voice print, iris or retina patterns, facial characteristics or hand geometry that is used to uniquely and durably authenticate an individual's identity when the individual accesses a physical location, device, system or account; B. "encrypted" means rendered unusable, unreadable or indecipherable to an unauthorized person through a security technology or methodology generally accepted in the field of information security; C.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
§ 57-12C-11Attorney general enforcement; civil penaltyIn forcecited in 4 of our articles
A. When the attorney general has a reasonable belief that a violation of the Data Breach Notification Act has occurred, the attorney general may bring an action on the behalf of individuals and in the name of the state alleging a violation of that act. B. In any action filed by the attorney general pursuant to the Data Breach Notification Act, the court may: (1) issue an injunction; and (2) award damages for actual costs or losses, including consequential financial losses. C. If the court determines that a person violated the Data Breach Notification Act knowingly or recklessly, the court may impose a civil penalty of the greater of twenty- five thousand dollars ($25,000) or, in the case of failed notification, ten dollars ($10.00) per instance of failed notification up to a maximum of one hundred fifty thousand dollars ($150,000).
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
§ 57-12C-10Notification to attorney general and credit reporting agencies.In forcecited in 4 of our articles
A person that is required to issue notification of a security breach pursuant to the Data Breach Notification Act to more than one thousand New Mexico residents as a result of a single security breach shall notify the office of the attorney general and major consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in 15 U.S.C. Section 1681a(p), of the security breach in the most expedient time possible, and no later than forty-five calendar days, except as provided in Section 9 [57-12C-9 NMSA 1978] of the Data Breach Notification Act. A person required to notify the attorney general and consumer reporting agencies pursuant to this section shall notify the attorney general of the number of New Mexico residents that received notification pursuant to Section 6 of that act [57-12C-6 NMSA 1978] and shall provide a copy of the notification that was sent to affected residents within forty-five calendar days following discovery of the security breach, except as provided in Section 9 of the Data Breach Notification Act.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cross-referenced in the statute itself: § 57-12C-6
§ 57-12C-1Short titleIn forcecited in 6 of our articles
This act [57-12C-1 to 57-12C-12 NMSA 1978] may be cited as the "Data Breach Notification Act".
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2022
Opinions citing this section in our collection:
- Charlie v. Rehoboth McKinley Christian Health Care Services (District Court, D. New Mexico 2022)“…s’ data under the New Mexico Data Breach Notification Act, N.M. Stat. Ann. § 57-12C-1, et seq. (2017).”); id. at 13 (“Defenda…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 57-12-1Short titleIn forcecited in 7 of our articles
Chapter 57, Article 12 NMSA 1978 may be cited as the "Unfair Practices Act".
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cited in 239 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Romero v. Philip Morris Inc. (New Mexico Supreme Court 2010, 148 N.M. 713)“…MSA 1978, §§ 57-1-1 to -15 (1979, as amended through 1987); NMSA 1978, §§ 57-12-1 to -22 (1967, as amended through 1999).…”
- Cordova v. World Finance Corp. of NM (New Mexico Supreme Court 2009, 146 N.M. 256)“…hin the meaning of the New Mexico Unfair Practices Act. See NMSA 1978, §§ 57-12-1 to -24 (1967, as amended through 2003).…”
- Quynh Truong v. Allstate Insurance (New Mexico Supreme Court 2010, 147 N.M. 583)“…cability of an exemption to the Unfair Practices Act (UPA), NMSA 1978, Sections 57-12-1 to -22 (1967, as amended through 1999),…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: New Mexico Lemon Law (2026): How to Qualify & Get a Refund
Explore the law
The laws cited above reference these related sections in their own text:
- New Mexico Statutes Annotated 1978, Chapter 57 § 57-12C-12 — State of New Mexico and political subdivisions exempted. view in our statute record · read at the official source
- New Mexico Statutes Annotated 1978, Chapter 57 § 57-12C-9 — Delayed notification view in our statute record · read at the official source
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- New Mexico Data Breach Notification Act (HB 15, 2017)(nmlegis.gov).gov
- N.M. Stat. Ann. 57-12C-2 Definitions(law.justia.com)
- N.M. Stat. Ann. 57-12C-6 Notification of Security Breach(law.justia.com)
- N.M. Stat. Ann. 57-12C-10 AG and Credit Reporting Agency Notification(law.justia.com)
- N.M. Stat. Ann. 57-12C-11 Attorney General Enforcement (Data Breach Notification Act, HB 15 enacted text)(nmlegis.gov).gov
- Internet Privacy and Safety Act (HB 307, 2025)(nmlegis.gov).gov
- Community and Health Information Safety and Privacy Act (SB 53, 2026)(nmlegis.gov).gov
- Artificial Intelligence Transparency Act (HB 28, 2026)(nmlegis.gov).gov
- Gramm-Leach-Bliley Act(ftc.gov).gov
- HIPAA(hhs.gov).gov
- New Mexico Unfair Practices Act(law.justia.com)
- Neb. Rev. Stat. 87-1112 (Nebraska Data Privacy Act): consent required before processing sensitive data(nebraskalegislature.gov)
- Neb. Rev. Stat. 87-1102 (Nebraska Data Privacy Act): sensitive data includes biometric data processed to uniquely identify an individual(nebraskalegislature.gov)