Wisconsin
Wisconsin Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 8 primary sources cited on this page. How we verify our legal content

Wisconsin has no standalone biometric privacy law, but its breach notification statute (Wis. Stat. 134.98) explicitly includes biometric data and DNA profiles as protected personal information. Businesses must notify affected residents within 45 days of a breach, unless the acquisition does not create a material risk of identity theft or fraud. The law does not require consent before collecting biometric data and provides no private right of action.
Wisconsin occupies a middle ground in the national biometric privacy landscape. The state does not have a standalone biometric privacy law like Illinois or Texas, but its breach notification statute provides more protection than many states by explicitly covering biometric data and DNA profiles.
What makes Wisconsin noteworthy is the breadth of its breach notification definitions. While states like West Virginia exclude biometric data entirely from breach notification, Wisconsin casts a wider net that includes fingerprints, voiceprints, retina images, and even DNA profiles as separate protected categories.
For a broader overview of privacy protections in the state, see the parent guide to Wisconsin Data Privacy Laws.
How Wisconsin Law Defines Biometric Data

Wisconsin's breach notification statute, Wis. Stat. 134.98, defines personal information to include an individual's unique biometric data. Under Wis. Stat. 134.98(1)(b)5., the covered biometric data types include:
- Fingerprints
- Voiceprints
- Retina or iris images
- Any other unique physical representation
This definition is broad enough to cover emerging biometric technologies such as facial geometry scans, hand geometry measurements, and vein pattern recognition, so long as they qualify as a "unique physical representation."
DNA Profile: A Separate Category
Wisconsin stands out by separately listing an individual's DNA profile as a protected data element under Wis. Stat. 134.98. The DNA profile definition references Wis. Stat. 939.74(2d)(a), which defines it in the context of criminal proceedings.
By covering DNA profiles as their own category alongside biometric data, Wisconsin provides one of the more comprehensive breach notification definitions for biological identifiers in the country.
Breach Notification Requirements
When a breach exposes biometric data or DNA profiles, Wisconsin's notification requirements apply.
Who Must Comply
Under Wis. Stat. 134.98(2)(a), any entity whose principal place of business is in Wisconsin, or any entity that maintains or licenses personal information in Wisconsin, must make reasonable efforts to notify each subject of the personal information after an unauthorized acquisition.
The duty also reaches businesses with no Wisconsin base. Under Wis. Stat. 134.98(2)(b), an entity whose principal place of business is not located in Wisconsin must make reasonable efforts to notify each Wisconsin resident whose personal information was acquired without authorization. An out-of-state company is therefore covered as to Wisconsin residents, even though it falls outside paragraph (2)(a).
A separate rule applies to vendors and other custodians. Under Wis. Stat. 134.98(2)(bm), a person other than an individual that stores personal information about a Wisconsin resident, but does not own or license it and has no contract with the owner or licensor, must notify the owner or licensor of the unauthorized acquisition as soon as practicable.
What Triggers Notification
A notification obligation arises when an entity knows that personal information in its possession has been acquired by a person whom the entity has not authorized to acquire the information. This applies when the unauthorized acquisition involves biometric data, DNA profiles, or other covered personal information that has not been encrypted, redacted, or otherwise rendered unreadable.
The duty is not unconditional. Under Wis. Stat. 134.98(2)(cm), an entity is not required to provide notice if either of the following applies:
- The acquisition of the personal information does not create a material risk of identity theft or fraud to the subject of the information
- The personal information was acquired in good faith by an employee or agent of the entity, and the information is used for a lawful purpose of the entity
These exceptions override the notice paragraphs described above, including the consumer reporting agency notice. The entity makes the material-risk assessment itself, so a business that relies on the exception should document the basis for its conclusion.
45-Day Notification Timeline
Under Wis. Stat. 134.98(3)(a), an entity that must give notice has to provide it within a reasonable time, not to exceed 45 days after the entity learns of the unauthorized acquisition. The determination of what is reasonable considers the number of notices the entity must send and the communication methods available.
This 45-day maximum is stricter than states that use a vague "without unreasonable delay" standard but more lenient than states like Colorado (30 days).
Notification Methods
The entity must provide notice by mail or by a method the entity has previously employed to communicate with the affected individual. If the entity has an email address but has not previously communicated with the individual by email, mail is the default method.
Substitute Notice
Wisconsin's breach notification statute does not set a dollar-cost or headcount threshold for substitute notice, unlike many other states' breach laws. If an entity cannot with reasonable diligence determine the mailing address of an affected individual, and has not previously communicated with that individual, the entity must provide notice by a method reasonably calculated to provide actual notice to the individual. The statute does not enumerate specific substitute methods such as email, website posting, or media notice.
Exemption for Federally Regulated Entities
Wisconsin's statute does not merely deem federally regulated entities compliant. Under Wis. Stat. 134.98(3m), the entire section does not apply to either of the following:
- An entity subject to, and in compliance with, the privacy and security requirements of 15 USC 6801 to 6827 (the Gramm-Leach-Bliley Act safeguards provisions), or a person that has a contractual obligation to such an entity, if that entity or person has in effect a policy concerning breaches of information security
- An entity described in 45 CFR 164.104(a) that complies with the requirements of 45 CFR part 164 (the HIPAA privacy and security rules)
Note what the Gramm-Leach-Bliley exemption actually requires: compliance with the federal privacy and security requirements plus a standing information security breach policy. There is no separate condition that the entity send individual notices in the form Wisconsin would otherwise require. An exempt entity's notification duties come from the federal scheme, not from Wis. Stat. 134.98.
Consumer Reporting Agency Notification
Under Wis. Stat. 134.98(2)(br), if a breach requires notification of 1,000 or more individuals, the entity must also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis. This is an additional requirement that applies on top of individual notification.
Enforcement and Penalties

Wisconsin's breach notification statute takes an unusual approach to enforcement. Under Wis. Stat. 134.98(4), the statute explicitly states that failure to comply is not negligence or a breach of any duty, but may be evidence of negligence or a breach of a legal duty.
This means:
- There are no specific civil penalties in the statute for failing to provide breach notification
- Non-compliance cannot by itself support a negligence claim
- However, non-compliance can be used as evidence in a civil lawsuit to support a claim that the entity was negligent or breached a duty
The Wisconsin Department of Agriculture, Trade and Consumer Protection (DATCP) provides guidance on the breach notification law and can receive consumer complaints. The Wisconsin Attorney General may also pursue enforcement actions related to unfair or deceptive business practices.
What Wisconsin Law Does Not Cover
Despite including biometric data in breach notification, Wisconsin's protections have significant gaps.
No Collection Consent Requirements
Wisconsin law does not require businesses or employers to obtain consent before collecting biometric data. A company can implement fingerprint scanners, facial recognition cameras, or voice authentication systems without providing notice or obtaining any form of permission.
No Retention or Destruction Rules
There are no requirements to set retention schedules for biometric data, publish data retention policies, or destroy biometric data after a set period or when the purpose for collection ends.
No Purpose Limitation
Businesses that collect biometric data in Wisconsin face no restrictions on how they use, share, or sell that data.
No Private Right of Action for Biometric Violations
While non-compliance with the breach notification law can serve as evidence in a negligence claim, there is no standalone private right of action for biometric data collection or misuse.
Wisconsin's Failed Data Privacy Act (AB 172/SB 166)

Wisconsin legislators introduced comprehensive privacy legislation in 2025 that would have strengthened biometric data protections, but the bill failed to pass.
Assembly Bill 172 / Senate Bill 166 (2025)
In 2025, Wisconsin introduced AB 172 in the Assembly and its companion SB 166 in the Senate. The proposed Wisconsin Data Privacy Act would:
- Define biometric data as data generated by automatic measurements of biological characteristics, including fingerprints, voiceprints, eye retinas, irises, or other unique biological patterns used to identify a specific individual
- Classify biometric data as sensitive data requiring opt-in consent before processing
- Grant consumers rights to access, delete, and port their personal data
- Require data controllers to recognize opt-out preference signals
- Mandate data protection assessments for processing activities involving sensitive data
- Establish Attorney General enforcement authority
SB 166 was referred to the Senate Committee on Licensing, Regulatory Reform, State and Federal Affairs in March 2025. AB 172 later cleared the Assembly Committee on State Affairs on a 10-0 vote in January 2026 and was referred to the Rules Committee, but neither bill passed: AB 172 failed to pass pursuant to Senate Joint Resolution 1 on March 23, 2026, when the legislative session closed. A previous version of the bill passed the Assembly in 2023 but also failed to advance in the Senate.
Had it passed, the Wisconsin Data Privacy Act would have significantly expanded biometric data protections beyond the current breach notification framework. As of March 2026, Wisconsin has no comprehensive privacy law and no enacted biometric privacy statute beyond the breach notification law described above.
How Wisconsin Compares to Neighboring States
Wisconsin's approach to biometric privacy is stronger than some neighbors but weaker than others.
Illinois has the strongest protections in the region with its Biometric Information Privacy Act (BIPA), which includes a private right of action and has generated thousands of lawsuits. Minnesota enacted comprehensive consumer data privacy legislation with biometric data provisions.
Iowa passed its Consumer Data Protection Act, which classifies biometric data as sensitive. Michigan has considered biometric privacy legislation but has not yet enacted comprehensive protections.
Wisconsin's inclusion of biometric data and DNA profiles in breach notification puts it ahead of states that lack even that level of coverage.
Practical Guidance for Wisconsin Residents
Wisconsin residents should be aware that while their biometric data is protected in the event of a breach, there are no restrictions on its collection or use before a breach occurs.
If you believe your biometric data was compromised in a breach and you never received notification, contact the Wisconsin DATCP to file a complaint. Keep in mind that an entity may withhold notice if it concluded the acquisition created no material risk of identity theft or fraud, and that federally regulated financial and health care entities are exempt from the state statute altogether.
Review privacy policies before providing biometric data to businesses or apps. While Wisconsin does not require consent, understanding how your data will be used can help you make informed decisions.
Sources and References
This article references Wisconsin statutes available through the Wisconsin Legislature website. For consumer guidance on data breaches, visit the Wisconsin DATCP. For proposed legislation, see AB 172. For consumer complaints, contact the Wisconsin Attorney General.
This article provides general legal information about Wisconsin biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Wisconsin government sources.
More Wisconsin Laws
Frequently Asked Questions
Does Wisconsin have a biometric privacy law?
Wisconsin does not have a standalone biometric privacy law. However, the state's breach notification statute (Wis. Stat. 134.98) explicitly includes biometric data and DNA profiles in the definition of personal information that triggers notification requirements when a breach occurs. Businesses must notify affected residents within 45 days of discovering a breach, unless the acquisition does not create a material risk of identity theft or fraud or the information was acquired in good faith by an employee or agent for a lawful purpose.
Can my employer collect my fingerprints without consent in Wisconsin?
Yes. Wisconsin law does not require employers to obtain consent before collecting biometric data. There are no state requirements for notice, consent, retention schedules, or data destruction related to employer-collected biometric information. Federal laws like HIPAA may apply in specific health care employment contexts.
What biometric data is protected under Wisconsin's breach notification law?
Wis. Stat. 134.98 protects fingerprints, voiceprints, retina or iris images, and any other unique physical representation. Wisconsin also separately protects DNA profiles, making it one of the few states to cover genetic data as its own category alongside biometric data.
Does Wisconsin's breach notification law apply to out-of-state companies?
Yes. Wis. Stat. 134.98(2)(b) requires an entity whose principal place of business is not located in Wisconsin to make reasonable efforts to notify each Wisconsin resident whose personal information was acquired without authorization. A separate provision, Wis. Stat. 134.98(2)(bm), requires a company that only stores personal information for someone else, without a contract with the owner or licensor, to notify that owner or licensor as soon as practicable.
What happens if a company fails to notify me of a biometric data breach in Wisconsin?
Wisconsin's breach notification law does not establish specific civil penalties for non-compliance. However, failure to comply may be used as evidence of negligence or breach of a legal duty in a civil lawsuit. You can also file a complaint with the Wisconsin DATCP or the Attorney General's office. Note that the statute does not apply at all to an entity complying with the Gramm-Leach-Bliley requirements in 15 USC 6801 to 6827 that has an information security breach policy in effect, or to an entity under 45 CFR 164.104(a) that complies with 45 CFR part 164.
Will Wisconsin pass a comprehensive biometric privacy law?
Wisconsin lawmakers introduced the Wisconsin Data Privacy Act (AB 172/SB 166) in 2025, which would have classified biometric data as sensitive and required opt-in consent for processing, but the bill failed to pass and died on March 23, 2026. A previous version passed the Assembly in 2023 but also failed in the Senate. Wisconsin currently has no comprehensive privacy law; check the Wisconsin Legislature website at docs.legis.wisconsin.gov for any newly introduced bills.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the federal exemption in Wis. Stat. 134.98(3m), which fully exempts qualifying Gramm-Leach-Bliley and HIPAA entities rather than deeming them compliant, and added the 134.98(2)(cm) exceptions to the notice duty along with the out-of-state and non-owner-storer obligations in 134.98(2)(b) and (2)(bm).
Updated this page to reflect that Wisconsin's proposed data privacy bill (AB 172/SB 166) failed to pass on March 23, 2026 and Wisconsin still has no comprehensive privacy or biometric statute; also fixed a broken statute link.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Corrected three mis-cited Wis. Stat. 134.98 subsection numbers (biometric-data definition is (1)(b)5. not 4.; the 45-day notice deadline is (3)(a) not (3m); the 1,000-person consumer-reporting-agency notice rule is (2)(br) not (4)) and removed a fabricated $100,000/175,000-threshold substitute-notice provision that does not appear anywhere in the statute.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Wisconsin Statutes, Chapter 134: Miscellaneous Trade Regulations
§ 134.98Notice of unauthorized acquisition of personal information.In forcecited in 5 of our articles
(1) Definitions. In this section: (a) 1. “Entity” means a person, other than an individual, that does any of the following: a. Conducts business in this state and maintains personal information in the ordinary course of business. b. Licenses personal information in this state. c. Maintains for a resident of this state a depository account as defined in s. 815.18 (2) (e). d. Lends money to a resident of this state. 2. “Entity” includes all of the following: a. The state and any office, department, independent agency, authority, institution, association, society, or other body in state government created or authorized to be created by the constitution or any law, including the legislature and the courts. b. A city, village, town, or county. (am) “Name” means an individual’s last name combined with the individual’s first name or first initial. (b) “Personal information” means an individual’s last name and the individual’s first name or first initial, in combination with and linked to any of the following elements, if the element is not publicly available information and is not encrypted, redacted, or altered in a manner that renders the element unreadable: 1.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at docs.legis.wisconsin.gov
Cited in 5 court opinions in our collectionLatest citing opinion in our collection: 2025
In the courts (editorial summary, independently checked):Federal courts that analyzed Wis. Stat. 134.98 under Wisconsin implied right of action doctrine found no private suit. Fox, Yvonne v. Iowa Health System (2019) and Negron v. Ascension Health (2025) dismissed 134.98 counts, while In re Equifax, Inc. (2019) had let one proceed only absent Wisconsin authority.
Opinions citing this section in our collection:
- In re Target Corp. Customer Data Security Breach Litigation (District Court, D. Minnesota 2014, 66 F. Supp. 3d 1154)✓Hackers stole card and personal data from about 110 million Target shoppers in 2013 and consumers sued over delayed breach notice; the court noted Wis. Stat. 134.98 is silent on enforcement and, absent authority barring private suits, declined to dismiss the Wisconsin claim.
- In re Equifax, Inc. (District Court, N.D. Georgia 2019, 362 F. Supp. 3d 1295)✓Hackers exploited an unpatched Apache Struts flaw to take personal data on about 147 million people from Equifax, disclosed seven weeks later; the court read Wis. Stat. 134.98(4) as not barring private suit and, treating the statute as silent, let the Wisconsin claim proceed.
- Fox, Yvonne v. Iowa Health System (District Court, W.D. Wisconsin 2019)✓Patients sued UnityPoint Health after its email system was hacked in 2017 and 2018, exposing health data and Social Security numbers; the court held Wis. Stat. 134.98 creates no private right of action, relying on subsection (4), and dismissed the Wisconsin notification claim.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Wisconsin Data Privacy Laws: Breach Notification & Consumer Rights (2026), Wisconsin Data Breach Notification Laws: Reporting Rules & Timelines (2026), Wisconsin Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
Wisconsin Statutes, Chapter 939: Crimes
§ 939.74Time limitations on prosecutions.In forcecited in 4 of our articles
(1) Except as provided in subs. (2) and (2d) and s. 946.88 (1), prosecution for a felony must be commenced within 6 years and prosecution for a misdemeanor or for adultery within 3 years after the commission thereof. Within the meaning of this section, a prosecution has commenced when a warrant or summons is issued, an indictment is found, or an information is filed. (2) Notwithstanding that the time limitation under sub. (1) has expired: (a) 1. A prosecution under s. 940.01, 940.02, 940.03, 940.05, 940.225 (1), 948.02 (1), or 948.025 (1) (a), (b), (c), or (d) may be commenced at any time. 2. A prosecution for an attempt to commit a violation of s. 940.01, 940.05, 940.225 (1), or 948.02 (1) may be commenced at any time. (am) A prosecution under s. 940.06 may be commenced within 15 years after the commission of the violation. (ap) A prosecution under s. 940.11 (2) may be commenced within the applicable time under sub. (1) or within 6 years of the date the corpse was discovered or identified, whichever is later. (ar) A prosecution for a violation of s. 940.225 (2) may be commenced within 20 years after the commission of the violation. A prosecution for a violation of s.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at docs.legis.wisconsin.gov
Cited in 26 court opinions in our collectionLatest citing opinion in our collection: 2022
Opinions citing this section in our collection:
- State v. Joel M. Hurley (Wisconsin Supreme Court 2015, 361 Wis. 2d 529)“…(1) (a), (b), (c), or (d) "may be commenced at any time." Wis. Stat. § 939.74 (2)(a)(l) (2011 — 12). A prosecution un…”
- State v. Sweat (Wisconsin Supreme Court 1997, 208 Wis. 2d 409)“…tions that applies in the underlying criminal proceedings, Wis. Stat. § 939.74 , [2] including its tolling provisions…”
- State v. McGuire (Wisconsin Supreme Court 2010, 328 Wis. 2d 289)“…are subject to the six-year statute of limitations under Wis. Stat. § 939.74 (1) (2007-08), 1 the statute of limita…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Wisconsin Statute of Limitations: Filing Deadlines by Case Type
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Wis. Stat. 134.98 - Breach Notification Law(docs.legis.wisconsin.gov).gov
- Wis. Stat. 134.98(1)(b)5. - Biometric Data Definition(docs.legis.wisconsin.gov).gov
- Wis. Stat. 134.98(3)(a) - 45-Day Notification Timeline(docs.legis.wisconsin.gov).gov
- Wis. Stat. 134.98(2) - Notification Requirements(docs.legis.wisconsin.gov).gov
- Wis. Stat. 134.98(4) - Enforcement Provisions(docs.legis.wisconsin.gov).gov
- Wisconsin DATCP - Data Breach Notification Guidance(datcp.wi.gov).gov
- AB 172 - Wisconsin Data Privacy Act (2025)(docs.legis.wisconsin.gov).gov
- Wisconsin DATCP - Privacy Laws Overview(datcp.wi.gov).gov
- Wis. Stat. 134.98(3m) - Regulated Entities Exempt (GLBA and HIPAA)(docs.legis.wisconsin.gov)