EnglishEspañol
New York flag

New York

New York Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 11 primary sources cited on this page. How we verify our legal content

New York Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does New York have a biometric privacy law similar to Illinois BIPA?

Not yet at the state level. New York currently relies on the SHIELD Act for biometric breach notification and data security, but it lacks a comprehensive biometric privacy statute with a private right of action. However, the pending NY Biometric Privacy Act (S1422/A6031), modeled on Illinois BIPA, would create one if passed. New York City does have Local Law 3 of 2021, which requires biometric disclosure signage for commercial establishments and allows private lawsuits.

Can my employer in New York require me to use a fingerprint scanner to clock in?

It depends on who your employer is. New York Labor Law Section 201-a prohibits employers from requiring fingerprinting as a condition of employment, but the statute expressly does not apply to employees of the state or any municipal subdivision or department, or to employees of legally incorporated hospitals, affiliated medical colleges, or private proprietary hospitals. Those workers sit outside the protection entirely. For everyone else, fingerprinting is still allowed where a separate law mandates it, such as for law enforcement, certain financial institution employees, and childcare or school staff. Otherwise employers may offer fingerprint scanning on a voluntary basis or use hand geometry scanners, which measure the shape of the hand without capturing a fingerprint.

What are the penalties for a biometric data breach under the SHIELD Act?

Where a court determines the violation was knowing or reckless, it may impose a civil penalty of the greater of $5,000 or up to $20 per instance of failed notification, with that per-instance amount capped at $250,000. Separately, the New York Attorney General can seek up to $5,000 per violation for failure to maintain reasonable data security safeguards, plus injunctive relief and restitution. Businesses must notify affected individuals within 30 days of discovering the breach, as required by the December 2024 amendment.

Does the NYC biometric law apply to all businesses in New York City?

No. NYC Local Law 3 of 2021 applies only to commercial establishments, defined as places of entertainment, retail stores, and food and drink establishments. It does not apply to government agencies, financial institutions regulated by state or federal law, or businesses outside these three categories such as office-based companies or healthcare providers.

What would change if the NY Biometric Privacy Act (S1422) passes?

The bill would create a statewide biometric privacy framework requiring written consent before collecting biometric data, mandatory retention and destruction policies, a prohibition on selling biometric data, and a private right of action allowing individuals to sue for $1,000 per negligent violation or $5,000 per intentional violation plus attorney fees. This would significantly strengthen protections beyond the current SHIELD Act, which only the Attorney General can enforce.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the NYDFS encryption-in-transit compliance date to November 1, 2024, restated the SHIELD Act breach-notification penalty to include its $5,000 floor and knowing-or-reckless predicate, clarified that the December 2024 amendment added the Department of Financial Services to the offices that must be notified, added Labor Law 201-a's express exclusions for public-sector and hospital employees, and added a section on State Technology Law 106-b covering biometrics in schools.

Updated the pending NY Biometric Privacy Act section to reflect that the Senate passed S1422A 41-20 on June 3, 2026, corrected its data-retention period (60 days / one year, not three years) and biometric-identifier definition to match the amended bill, fixed the NYDFS encryption compliance date to May 1, 2025, and replaced an uncorroborated Madison Square Garden lawsuit claim with the sourced 2026 data-breach class action and the active "Ban the Scan" legislative push.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. SHIELD Act overview and requirements(ag.ny.gov).gov
  2. GBL Section 899-aa breach notification law(nysenate.gov).gov
  3. GBL Section 899-bb data security safeguards(nysenate.gov).gov
  4. NYC Local Law 3 of 2021 biometric identifier information(legistar.council.nyc.gov).gov
  5. NYC DCWP biometric identifier disclosure sign(nyc.gov).gov
  6. NY Biometric Privacy Act (S1422)(nysenate.gov).gov
  7. NY Biometric Privacy Act (A6031 Assembly companion)(nysenate.gov).gov
  8. NY Labor Law Section 201-a employee fingerprinting prohibition(nysenate.gov).gov
  9. NYDFS Cybersecurity Resource Center(dfs.ny.gov).gov
  10. 23 NYCRR 500 amended cybersecurity regulation text(dfs.ny.gov).gov
  11. NYC DCWP new laws and rules(nyc.gov).gov
  12. NY State Technology Law Section 106-b - Use of biometric identifying technology in schools(nysenate.gov)
  13. NYDFS Second Amendment to 23 NYCRR Part 500, official adopted text (transitional periods at 500.22(d))(dfs.ny.gov)
  14. NY S2659B (2024), chapter 647 - SHIELD Act amendment setting the 30-day notification deadline and adding the Department of Financial Services to the notification list(nysenate.gov)
Share: