West Virginia
West Virginia Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 7 primary sources cited on this page. How we verify our legal content

West Virginia has no dedicated biometric privacy law. The state breach notification statute, W.V. Code 46A-2A-101, omits biometric data from its definition of personal information, leaving fingerprints, facial scans, and similar identifiers without specific state-level collection, consent, or breach-notification protections.
West Virginia has one of the most limited biometric privacy frameworks in the country. The state's breach notification law does not explicitly cover biometric data, and no comprehensive consumer data privacy statute addresses biometric identifiers. This places West Virginia behind most of its neighbors in protecting residents' fingerprints, facial recognition templates, and other biometric information.
Lawmakers have looked at the issue. In February 2026, legislators introduced HB 5567, a Biometric Information Privacy Act modeled on Illinois's BIPA. The bill died in committee when the 2026 regular session ended, so it would have to be introduced again in a future session to become law. Had it passed, it would have made West Virginia one of the few states with a standalone biometric privacy statute that includes a private right of action.
For a broader overview of privacy protections in the state, see the parent guide to West Virginia Data Privacy Laws.
Current Law: Breach Notification Without Biometric Coverage

West Virginia's breach notification law is codified at W.V. Code 46A-2A-101 through 46A-2A-105. The law requires businesses to notify West Virginia residents when a data breach compromises their personal information.
What Counts as Personal Information
Under W.V. Code 46A-2A-101, "personal information" is defined as a person's first name or first initial and last name linked to any one or more of the following unencrypted data elements:
- Social Security number
- Driver's license number or state identification card number
- Financial account number, credit card number, or debit card number in combination with any required security code, access code, or password
Biometric data is not listed among these elements. This means that a breach exposing fingerprints, facial recognition templates, iris scans, or voiceprints does not, by itself, trigger West Virginia's breach notification requirements.
What Triggers Notification
A "breach of the security of a system" under W.V. Code 46A-2A-101 means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information, and that causes the entity to reasonably believe the breach has caused or will cause identity theft or other fraud to a West Virginia resident.
Notification Requirements
When a covered breach occurs, the entity must provide notice to affected individuals "without unreasonable delay." Unlike many states that set a specific timeline (such as 30, 45, or 60 days), West Virginia uses the "without unreasonable delay" standard, giving businesses discretion in timing.
West Virginia does not require notice to the Attorney General or to any other state regulator. Under W.V. Code 46A-2A-102, the notice duties run to the affected residents, to the owner or licensee of the data when the breached entity only maintains it rather than owning it, and, when more than 1,000 persons must be notified in a single breach, to the consumer reporting agencies that compile and maintain files on a nationwide basis as defined by 15 U.S.C. 1681a(p).
Good Faith Exception
The law includes a good faith exception under W.V. Code 46A-2A-101. If an employee or agent of the entity acquires personal information in good faith for the entity's lawful purposes, and the information is not used improperly or subject to further unauthorized disclosure, it is not considered a breach.
The Gap: No Biometric Data Protection
The absence of biometric data from West Virginia's breach notification law creates a significant gap in consumer protection.
No Collection Consent Requirements
West Virginia law does not require any form of notice or consent before businesses or employers collect biometric data. A company can implement fingerprint scanners, facial recognition systems, or voice authentication without providing notice to or obtaining permission from the individuals affected.
No Retention or Destruction Requirements
There are no state requirements to set retention schedules for biometric data, to publish data retention policies, or to destroy biometric data after a set period or when the purpose for collection has ended.
No Purpose Limitation
Businesses that collect biometric data in West Virginia face no restrictions on how they use, share, or sell that data. There are no state-level prohibitions on selling biometric information to third parties.
No Private Right of Action
Individual West Virginia residents cannot file lawsuits over biometric data collection or misuse under current law.
No Specific Penalties for Biometric Violations
Because no law specifically governs biometric data, there are no dedicated penalties for collecting, misusing, or failing to secure biometric information.
Proposed Biometric Information Privacy Act (HB 5567)

West Virginia legislators introduced HB 5567 on February 16, 2026. The bill would have created a standalone Biometric Information Privacy Act, making West Virginia one of the few states to adopt a law specifically dedicated to biometric data protection. It never received a committee vote and died when the session ended, but its text remains the clearest indication of what a West Virginia biometric law might look like if lawmakers take the issue up again.
Key Definitions
Under the proposed bill, a "biometric identifier" would mean:
- Retina or iris scan
- Fingerprint
- Voiceprint
- Scan of hand or face geometry
The bill would exclude writing samples, written signatures, photographs, human biological samples used for scientific testing, demographic data, tattoo descriptions, and physical descriptions such as height, weight, hair color, or eye color. Medical data collected under HIPAA would also be excluded.
What the Bill Would Require
If enacted, HB 5567 would regulate the retention, collection, disclosure, and destruction of biometric identifiers. Based on the legislative summary, the bill would establish requirements for:
- Notice and consent before collecting biometric data
- Limitations on how biometric data can be disclosed or sold
- Retention schedules and destruction requirements
- Security standards for stored biometric data
Private Right of Action
One of the most significant provisions of HB 5567 was the inclusion of a private right of action. This would have allowed individuals to sue businesses that violate the act, similar to the provision in Illinois's BIPA that has generated thousands of lawsuits.
Civil Penalties
The bill would have created civil penalties for violations, though the specific dollar amounts would have depended on the final version of the legislation.
Current Status
HB 5567 was filed and introduced on February 16, 2026, and referred the same day to the House Committee on Health and Human Resources, with a further reference to the Judiciary Committee. That referral is the last recorded action on the bill. The 2026 regular session ran from January 14 to March 14, 2026, and the bill never received a committee vote, so it died in committee when the session ended. A biometric privacy act would have to be introduced again in a future session to move forward. Previous biometric privacy bills introduced in West Virginia (including similar bills in 2020, 2022, and 2023) also did not advance beyond committee.
Federal Laws That Apply in West Virginia

Because West Virginia lacks state-level biometric data protections, federal laws provide the primary framework in certain sectors.
HIPAA
Health care providers, insurers, and their business associates in West Virginia must comply with HIPAA when handling biometric data in a health care context. This includes requirements for patient consent, data security, and breach notification when biometric health data is compromised.
Gramm-Leach-Bliley Act (GLBA)
Financial institutions that collect biometric data for customer authentication must comply with GLBA security requirements. West Virginia's breach notification law acknowledges compliance with federal regulators' requirements.
Children's Online Privacy Protection Act (COPPA)
Companies collecting biometric data from children under 13 must comply with COPPA, which requires verifiable parental consent before collecting biometric identifiers.
Enforcement Under Current Law
The West Virginia Attorney General has general enforcement authority over consumer protection matters under the state's Consumer Credit and Protection Act (W.V. Code Chapter 46A). While there is no specific biometric data enforcement mechanism, the AG can potentially pursue cases involving deceptive or unfair practices related to data handling.
For breach notification violations, W.V. Code 46A-2A-104 treats a failure to comply with the article's notice provisions as an unfair or deceptive act under W.V. Code 46A-6-104, enforceable by the Attorney General through the enforcement provisions of Chapter 46A. The Attorney General has exclusive authority to bring such an action, and the remedy is limited in two ways that matter: no civil penalty may be assessed unless the court finds the defendant engaged in a course of repeated and willful violations, and no civil penalty may exceed $150,000 per breach or per series of breaches of a similar nature discovered in a single investigation. Violations by a licensed financial institution are enforceable exclusively by that institution's primary functional regulator.
How West Virginia Compares to Neighboring States
West Virginia lags behind most of its neighbors in biometric data protection.
Virginia enacted the Consumer Data Protection Act, which classifies biometric data as sensitive and requires opt-in consent for processing. Maryland has adopted strong biometric data protections through its Online Data Privacy Act.
Kentucky enacted the Kentucky Consumer Data Protection Act with biometric data provisions. Ohio and Pennsylvania have considered biometric privacy legislation but have not yet enacted comprehensive protections.
If a bill like HB 5567 is reintroduced and enacted, West Virginia would leapfrog many of these states by adopting a standalone biometric privacy act with a private right of action.
Practical Guidance for West Virginia Residents
Without dedicated biometric privacy protections, West Virginia residents should take proactive steps.
Ask businesses and employers about their biometric data practices before providing fingerprints, facial scans, or other biometric information. While they are not legally required to disclose their practices, many organizations have privacy policies that address biometric data.
If you believe a company has mishandled your personal data, you can file a consumer complaint with the West Virginia Attorney General's Consumer Protection Division.
HB 5567 died in committee, so there is no pending bill to track. Watch the West Virginia Legislature website for a reintroduced biometric privacy bill in a future session, since a law of that kind would significantly change the biometric privacy landscape in the state.
Sources and References
This article references West Virginia statutes available through the West Virginia Code website. For the text of the proposed Biometric Information Privacy Act, see HB 5567. For consumer complaints, contact the West Virginia Attorney General.
This article provides general legal information about West Virginia biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official West Virginia government sources.
More West Virginia Laws
Frequently Asked Questions
Does West Virginia have a biometric privacy law?
Not yet. West Virginia does not currently have a law specifically protecting biometric data. The state's breach notification law (W.V. Code 46A-2A-101) does not include biometric data in its definition of protected personal information. HB 5567, a proposed Biometric Information Privacy Act, was introduced in February 2026 but died in committee when the regular session ended, so it would have to be introduced again in a future session.
Can my employer collect my fingerprints without consent in West Virginia?
Yes, under current law. West Virginia has no statute requiring employers to obtain consent before collecting biometric data. Employers can implement fingerprint scanners, facial recognition systems, and other biometric technologies without providing notice or obtaining permission. HB 5567 would have changed that, but it died in committee, so nothing has changed under state law.
Does West Virginia's breach notification law cover biometric data?
No. The current breach notification law (W.V. Code 46A-2A-101) only covers Social Security numbers, driver's license numbers, and financial account information. A breach that exposes fingerprints, facial recognition data, or other biometric identifiers does not trigger notification requirements under existing West Virginia law.
Can I sue a company in West Virginia for misusing my biometric data?
Not under current law. West Virginia does not provide a private right of action for biometric data misuse. The proposed HB 5567 would have created a private right of action, but the bill died in committee. Until such a law is enacted, the Attorney General is the primary enforcement mechanism through general consumer protection statutes.
What would HB 5567 have done if passed?
HB 5567 would have created a Biometric Information Privacy Act covering fingerprints, voiceprints, iris scans, and face and hand geometry scans. It would have regulated the collection, retention, disclosure, and destruction of biometric data, created a private right of action for individuals to sue over violations, and established civil penalties. The bill was modeled on Illinois's BIPA, which has been the most impactful biometric privacy law in the country. It died in committee in the 2026 session and would have to be reintroduced.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the breach-notification section, which wrongly said companies must notify the West Virginia Attorney General; restated the actual enforcement limits under W.V. Code 46A-2A-104 (repeated and willful violations, $150,000 cap); and updated HB 5567, which died in committee when the 2026 regular session ended, rather than remaining a pending bill to monitor.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
West Virginia Code
§ 46A-2A-101Definitions.In forcecited in 5 of our articles
As used in this article: (1) "Breach of the security of a system" means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes the individual or entity to reasonably believe that the breach of security has caused or will cause identity theft or other fraud to any resident of this state. Good faith acquisition of personal information by an employee or agent of an individual or entity for the purposes of the individual or the entity is not a breach of the security of the system, provided that the personal information is not used for a purpose other than a lawful purpose of the individual or entity or subject to further unauthorized disclosure.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at code.wvlegislature.gov
Also relied on in: West Virginia Data Privacy Laws: Breach Notification & Consumer Rights (2026), West Virginia Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 46A-2A-102Notice of breach of security of computerized personal information.In forcecited in 6 of our articles
(a) An individual or entity that owns or licenses computerized data that includes personal information shall give notice of any breach of the security of the system following discovery or notification of the breach of the security of the system to any resident of this state whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and that causes, or the individual or entity reasonably believes has caused or will cause, identity theft or other fraud to any resident of this state. Except as provided in subsection (e) of this section or in order to take any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the system, the notice shall be made without unreasonable delay.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at code.wvlegislature.gov
Also relied on in: West Virginia Identity Theft Laws: Penalties and Victim Rights
§ 46A-2A-104Violations.In forcecited in 3 of our articles
(a) Except as provided by subsection (c) of this section, failure to comply with the notice provisions of this article constitutes an unfair or deceptive act of practice in violation of section one hundred four, article six, chapter forty-six-a of this code, which may be enforced by the Attorney General pursuant to the enforcement provisions of this chapter. (b) Except as provided by subsection (c) of this section, the Attorney General shall have exclusive authority to bring action. No civil penalty may be assessed in an action unless the court finds that the defendant has engaged in a course of repeated and willful violations of this article. No civil penalty shall exceed $150,000 per breach of security of the system or series of breaches of a similar nature that are discovered in a single investigation. (c) A violation of this article by a licensed financial institution shall be enforceable exclusively by the financial institution's primary functional regulator.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at code.wvlegislature.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- W.V. Code 46A-2A-101 - Breach Notification Definitions(code.wvlegislature.gov).gov
- W.V. Code 46A-2A-102 - Notice of Breach Required(code.wvlegislature.gov).gov
- W.V. Code Article 46A-2A - Breach of Security of Consumer Information(code.wvlegislature.gov).gov
- W.V. Code 46A-2A-104 - Violations(code.wvlegislature.gov).gov
- HB 5567 - Biometric Information Privacy Act (2026)(wvlegislature.gov).gov
- HB 5567 Full Bill Text (PDF)(wvlegislature.gov).gov
- West Virginia Attorney General(ago.wv.gov).gov
- HB 5567 Bill History (2026 Regular Session) - West Virginia Legislature(wvlegislature.gov)