EnglishEspañol
New Mexico flag

New Mexico

New Mexico Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 7, 2026. · 7 primary sources cited on this page. How we verify our legal content

New Mexico Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does New Mexico require consent before collecting biometric data?

No. New Mexico does not have a law requiring businesses or employers to obtain consent before collecting fingerprints, facial scans, or other biometric data. The state's Data Breach Notification Act requires reasonable security procedures, proper disposal of records once they are no longer reasonably needed, and notification after a breach, but it sets no consent or collection rules.

What happens if a company fails to notify residents about a biometric data breach in New Mexico?

The New Mexico Attorney General can bring an enforcement action against the company. Courts may impose civil penalties of the greater of $25,000 or $10 per instance of failed notification, up to a $150,000 cap, for knowing or reckless violations of the Data Breach Notification Act, plus injunctive relief and damages for actual costs and losses suffered by affected individuals.

Are employers in New Mexico required to have a biometric data retention policy?

Not a biometric-specific one. New Mexico does not require a written biometric retention policy or a fixed destruction deadline the way Illinois does. But two statutory duties still apply to employee biometrics: N.M. Stat. Ann. 57-12C-3 requires proper disposal of records containing personal identifying information once they are no longer reasonably needed for business purposes, and N.M. Stat. Ann. 57-12C-4 requires reasonable security procedures and practices to protect that data.

Can individuals sue over biometric data misuse in New Mexico?

Not under the Data Breach Notification Act, which has no private right of action. Only the Attorney General can enforce that statute. However, individuals may have claims under the New Mexico Unfair Practices Act (N.M. Stat. Ann. 57-12-1 et seq.) if a business's handling of biometric data involves deceptive or unconscionable trade practices.

Does New Mexico's biometric data law apply to healthcare providers and banks?

Entities covered by HIPAA (healthcare providers, health plans, clearinghouses) and entities subject to the Gramm-Leach-Bliley Act (financial institutions) are exempt from New Mexico's Data Breach Notification Act, provided they comply with the breach notification requirements under those federal laws.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the page to state that New Mexico's Data Breach Notification Act imposes affirmative data-security, disposal, and service-provider duties on businesses holding biometric data rather than only post-breach notification, fixed the lede citation to N.M. Stat. Ann. 57-12C-1 et seq., and reclassified Nebraska as a comprehensive-privacy-law state in the state comparison table.

Independently fact-checked against the cited primary sources

Corrected the civil-penalty description: the Data Breach Notification Act sets the penalty at the greater of $25,000 or $10 per instance of failed notification, up to a $150,000 cap, not a flat $25,000 (fixed in KeyTakeaways, body, and FAQ).

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. New Mexico Data Breach Notification Act (HB 15, 2017)(nmlegis.gov).gov
  2. N.M. Stat. Ann. 57-12C-2 Definitions(law.justia.com)
  3. N.M. Stat. Ann. 57-12C-6 Notification of Security Breach(law.justia.com)
  4. N.M. Stat. Ann. 57-12C-10 AG and Credit Reporting Agency Notification(law.justia.com)
  5. N.M. Stat. Ann. 57-12C-11 Attorney General Enforcement (Data Breach Notification Act, HB 15 enacted text)(nmlegis.gov).gov
  6. Internet Privacy and Safety Act (HB 307, 2025)(nmlegis.gov).gov
  7. Community and Health Information Safety and Privacy Act (SB 53, 2026)(nmlegis.gov).gov
  8. Artificial Intelligence Transparency Act (HB 28, 2026)(nmlegis.gov).gov
  9. Gramm-Leach-Bliley Act(ftc.gov).gov
  10. HIPAA(hhs.gov).gov
  11. New Mexico Unfair Practices Act(law.justia.com)
  12. Neb. Rev. Stat. 87-1112 (Nebraska Data Privacy Act): consent required before processing sensitive data(nebraskalegislature.gov)
  13. Neb. Rev. Stat. 87-1102 (Nebraska Data Privacy Act): sensitive data includes biometric data processed to uniquely identify an individual(nebraskalegislature.gov)
Share: