EnglishEspañol
Wisconsin flag

Wisconsin

Wisconsin Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 8 primary sources cited on this page. How we verify our legal content

Wisconsin Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Wisconsin have a biometric privacy law?

Wisconsin does not have a standalone biometric privacy law. However, the state's breach notification statute (Wis. Stat. 134.98) explicitly includes biometric data and DNA profiles in the definition of personal information that triggers notification requirements when a breach occurs. Businesses must notify affected residents within 45 days of discovering a breach, unless the acquisition does not create a material risk of identity theft or fraud or the information was acquired in good faith by an employee or agent for a lawful purpose.

Can my employer collect my fingerprints without consent in Wisconsin?

Yes. Wisconsin law does not require employers to obtain consent before collecting biometric data. There are no state requirements for notice, consent, retention schedules, or data destruction related to employer-collected biometric information. Federal laws like HIPAA may apply in specific health care employment contexts.

What biometric data is protected under Wisconsin's breach notification law?

Wis. Stat. 134.98 protects fingerprints, voiceprints, retina or iris images, and any other unique physical representation. Wisconsin also separately protects DNA profiles, making it one of the few states to cover genetic data as its own category alongside biometric data.

Does Wisconsin's breach notification law apply to out-of-state companies?

Yes. Wis. Stat. 134.98(2)(b) requires an entity whose principal place of business is not located in Wisconsin to make reasonable efforts to notify each Wisconsin resident whose personal information was acquired without authorization. A separate provision, Wis. Stat. 134.98(2)(bm), requires a company that only stores personal information for someone else, without a contract with the owner or licensor, to notify that owner or licensor as soon as practicable.

What happens if a company fails to notify me of a biometric data breach in Wisconsin?

Wisconsin's breach notification law does not establish specific civil penalties for non-compliance. However, failure to comply may be used as evidence of negligence or breach of a legal duty in a civil lawsuit. You can also file a complaint with the Wisconsin DATCP or the Attorney General's office. Note that the statute does not apply at all to an entity complying with the Gramm-Leach-Bliley requirements in 15 USC 6801 to 6827 that has an information security breach policy in effect, or to an entity under 45 CFR 164.104(a) that complies with 45 CFR part 164.

Will Wisconsin pass a comprehensive biometric privacy law?

Wisconsin lawmakers introduced the Wisconsin Data Privacy Act (AB 172/SB 166) in 2025, which would have classified biometric data as sensitive and required opt-in consent for processing, but the bill failed to pass and died on March 23, 2026. A previous version passed the Assembly in 2023 but also failed in the Senate. Wisconsin currently has no comprehensive privacy law; check the Wisconsin Legislature website at docs.legis.wisconsin.gov for any newly introduced bills.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the federal exemption in Wis. Stat. 134.98(3m), which fully exempts qualifying Gramm-Leach-Bliley and HIPAA entities rather than deeming them compliant, and added the 134.98(2)(cm) exceptions to the notice duty along with the out-of-state and non-owner-storer obligations in 134.98(2)(b) and (2)(bm).

Updated this page to reflect that Wisconsin's proposed data privacy bill (AB 172/SB 166) failed to pass on March 23, 2026 and Wisconsin still has no comprehensive privacy or biometric statute; also fixed a broken statute link.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Corrected three mis-cited Wis. Stat. 134.98 subsection numbers (biometric-data definition is (1)(b)5. not 4.; the 45-day notice deadline is (3)(a) not (3m); the 1,000-person consumer-reporting-agency notice rule is (2)(br) not (4)) and removed a fabricated $100,000/175,000-threshold substitute-notice provision that does not appear anywhere in the statute.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Wis. Stat. 134.98 - Breach Notification Law(docs.legis.wisconsin.gov).gov
  2. Wis. Stat. 134.98(1)(b)5. - Biometric Data Definition(docs.legis.wisconsin.gov).gov
  3. Wis. Stat. 134.98(3)(a) - 45-Day Notification Timeline(docs.legis.wisconsin.gov).gov
  4. Wis. Stat. 134.98(2) - Notification Requirements(docs.legis.wisconsin.gov).gov
  5. Wis. Stat. 134.98(4) - Enforcement Provisions(docs.legis.wisconsin.gov).gov
  6. Wisconsin DATCP - Data Breach Notification Guidance(datcp.wi.gov).gov
  7. AB 172 - Wisconsin Data Privacy Act (2025)(docs.legis.wisconsin.gov).gov
  8. Wisconsin DATCP - Privacy Laws Overview(datcp.wi.gov).gov
  9. Wis. Stat. 134.98(3m) - Regulated Entities Exempt (GLBA and HIPAA)(docs.legis.wisconsin.gov)
Share: