Wyoming
Wyoming Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 5 primary sources cited on this page. How we verify our legal content

Wyoming has no dedicated biometric privacy law and no comprehensive consumer privacy statute. The state protects biometric data only through its breach notification law, Wyo. Stat. 40-12-501 through 40-12-511. Section 40-12-501 supplies the definitions, and Wyo. Stat. 40-12-502 is the section that requires businesses to investigate a breach and notify affected residents. Neither imposes consent, retention, or purpose limits before collection occurs.
Wyoming relies entirely on its breach notification law to protect biometric data. The state has not enacted a comprehensive consumer data privacy statute, a standalone biometric privacy law, or any regulation that governs the collection or use of biometric identifiers before a security breach occurs.
This places Wyoming in the same category as several other western and rural states that have been slow to adopt biometric-specific protections. While the breach notification statute does explicitly cover biometric data, the protections only activate after a security incident has already compromised that data.
For a broader overview of privacy protections in the state, see the parent guide to Wyoming Data Privacy Laws.
How Wyoming Law Defines Biometric Data

Wyoming's breach notification law relies on a cross-reference for this definition. Wyo. Stat. 40-12-501 defines "personal identifying information" as a name combined with data elements "specified in W.S. 6-3-901(b)(iii) through (xiv)." That separate statute, not 40-12-501 itself, is where "unique biometric data" is defined as data generated from measurements or analysis of human body characteristics for authentication purposes. This definition appears as one element within the broader definition of "personal identifying information" that triggers breach notification obligations.
The definition is narrower than what some other states use. By specifying "for authentication purposes," Wyoming limits coverage to biometric data that is actively used to verify identity. Biometric data collected for other purposes, such as marketing research or behavioral analytics, may fall outside the statute's scope.
Common types of biometric data covered under this definition include:
- Fingerprint scans used for device or system login
- Facial recognition templates used for identity verification
- Iris or retina scans used for secure access
- Voiceprints used for phone authentication
- Hand geometry scans used for building access or timekeeping
The statute does not specifically address whether photographs, video recordings, or audio recordings qualify as biometric data.
Wyoming's Broad Definition of Personal Identifying Information
One notable aspect of Wyoming's law is the breadth of its overall personal identifying information definition. Wyo. Stat. 40-12-501 combines the individual's first name or first initial and last name with data elements specified in W.S. 6-3-901(b)(iii) through (xiv), which include:
- Social Security number
- Driver's license or state ID number
- Tribal identification card number
- Federal or state government-issued ID card number
- Shared secrets or security tokens used for data-based authentication
- Username or email address combined with a password or security question answer
- Birth or marriage certificate
- Medical information, including medical history, mental or physical conditions, treatment, or diagnoses
- Health insurance information, including policy numbers and claims history
- Unique biometric data
- Individual taxpayer identification number
By including biometric data alongside medical information, health insurance data, and government-issued identification, Wyoming signals that biometric identifiers rank among the most sensitive categories of personal information.
The definition excludes information contained in any federal, state, or local government records or in widely distributed media that are lawfully made available to the general public.
Breach Notification Requirements
When a breach exposes personal identifying information including biometric data, Wyoming's notification requirements apply under Wyo. Stat. 40-12-502.
Who Must Comply
Any individual or commercial entity that conducts business in Wyoming and owns or licenses computerized data that includes personal identifying information must comply. This applies to both Wyoming-based entities and out-of-state businesses that hold data on Wyoming residents.
Notification Timeline
Businesses must notify affected individuals in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
A law enforcement agency may request a delay in notification if it determines that notice will impede a criminal investigation. Once the agency determines notification will no longer compromise the investigation, the entity must proceed with notice.
Required Notification Content
Wyoming requires more detailed breach notifications than many states. Under Wyo. Stat. 40-12-502(e), the notice must be clear and conspicuous and must include, at a minimum:
- A toll-free number that the individual may use to contact the business collecting the data, or its agent, and from which the individual may learn the toll-free contact telephone numbers and addresses for the major credit reporting agencies
- The types of personal identifying information that were or are reasonably believed to have been compromised
- A general description of the breach incident
- The approximate date of the breach, if reasonably possible to determine
- Actions taken to protect the system from further breaches
- Advice that the individual remain vigilant by reviewing account statements and monitoring credit reports
- Whether notification was delayed due to a law enforcement investigation
Notification Methods
Notice must be provided by one of the following methods:
- Written notice
- Electronic mail notice
- Substitute notice, but only if specific cost, class-size, or missing-contact-information conditions are met (see below)
Substitute Notice
If the entity is Wyoming-based, it may use substitute notice when the cost of individual notice would exceed $10,000 or the affected class exceeds 10,000 persons. For businesses operating in Wyoming but based elsewhere, those thresholds are higher: a cost exceeding $250,000 or an affected class exceeding 500,000 persons. Either type of entity may also use substitute notice if it lacks sufficient contact information. Substitute notice consists of:
- Email notice, when available
- Conspicuous posting on the entity's website
- Notification to major statewide media
Enforcement and Penalties
The Wyoming Attorney General enforces the breach notification law through the Wyoming Consumer Protection Act (Wyo. Stat. Title 40, Chapter 12).
The statute does not specify a maximum penalty amount or a per-individual violation count. Under Wyo. Stat. 40-12-502(f), the Attorney General may bring an action in law or equity to address any violation of the section, to recover damages, or both, and for other appropriate relief to ensure compliance.
There is no private right of action under Wyoming's breach notification statute. Only the Attorney General may bring enforcement actions.
What Wyoming Law Does Not Cover

Wyoming's breach notification law leaves significant gaps in biometric data protection.
No Collection Consent Requirements
Wyoming does not require any form of notice or consent before collecting biometric data. Businesses and employers can implement fingerprint scanners, facial recognition systems, and voice authentication without informing or obtaining agreement from the individuals whose data is collected.
No Retention or Destruction Requirements
The law imposes no limits on how long organizations can store biometric data. There are no requirements to publish retention schedules, establish destruction timelines, or delete biometric data when the purpose for collection has ended.
No Purpose Limitation
Businesses face no restrictions on how they use, share, or sell biometric data collected from Wyoming residents. The law does not prohibit the sale of biometric data to third parties or the repurposing of biometric identifiers for uses unrelated to their original collection purpose.
No Data Minimization
There are no requirements to limit biometric data collection to what is reasonably necessary for a stated purpose.
Wyoming's Genetic Data Privacy Act

While not directly a biometric privacy law, Wyoming has enacted a separate Genetic Data Privacy Act (Wyo. Stat. 35-32-101 et seq.) that provides additional protections for genetic data specifically. The act requires informed consent before genetic testing, retention, or disclosure of genetic data. Under Wyo. Stat. 35-32-104, the Attorney General may bring an enforcement action in which a violator is subject to a civil penalty of $2,500 per violation, plus actual damages for the consumers on whose behalf the action was brought and the state's costs and reasonable attorney fees. A violation is also a misdemeanor punishable by a fine of not more than $1,000 per violation, and an individual whose rights were violated may bring a civil action after giving the alleged violator written notice and a 60-day period to cure.
This law is relevant because genetic data and biometric data sometimes overlap. For example, DNA profiles used for identification purposes could qualify as both genetic data under the Genetic Data Privacy Act and biometric data under the breach notification statute.
How Wyoming Compares to Neighboring States
Wyoming's biometric data protections are limited compared to some neighbors but comparable to others in the region.
Colorado offers the strongest protections nearby, with its comprehensive privacy act classifying biometric data as sensitive and requiring opt-in consent. Montana passed the Montana Consumer Data Privacy Act with biometric provisions. Utah enacted the UCPA with an opt-out model for sensitive data including biometrics.
South Dakota shares Wyoming's approach of relying primarily on breach notification statutes without a dedicated biometric privacy law. Nebraska has no standalone biometric statute either, but its comprehensive Nebraska Data Privacy Act (effective January 2025) classifies biometric data used to identify a person as sensitive data requiring opt-in consent, a stronger protection than Wyoming's breach-only approach. Idaho similarly lacks comprehensive biometric protections.
Legislative Outlook
Wyoming has not enacted a comprehensive consumer data privacy statute or a standalone biometric privacy law. Its recent legislative work on privacy has been directed at how government handles personal data rather than at private-sector collection.
That effort is now codified law rather than a pending proposal. Wyo. Stat. 9-21-201 through 9-21-203 (Title 9, Chapter 21, Article 2, "Data Privacy - Government Entities") bars a government entity from purchasing, selling, trading, or transferring personal data without the express written consent of the person the data references, subject to listed exceptions for transfers to another government entity, to a contracted service provider, under a case-by-case approval by the entity's elected governing body, or where the transfer is permitted under HIPAA or FERPA. The article also lets a current or former Wyoming resident request a copy of their personal data and file an objection to its accuracy, retention, or dissemination. Wyo. Stat. 9-21-203, which adds collection, retention, and written-policy duties, carries an official note that the section is effective 7/1/2027.
This article reaches government entities only, so it does not change what a private business may do with biometric data. Wyo. Stat. 9-21-201(a)(ii) expressly excludes the judicial branch and Wyoming law enforcement agencies from the definition of "government entity." A future legislature could extend a similar framework to private-sector handling of biometric data, but no such law is on the books today.
Residents and businesses should monitor the Wyoming Legislature website for any proposed privacy-related bills.
Practical Guidance for Wyoming Residents
Without dedicated biometric privacy protections, Wyoming residents should take proactive steps.
Ask businesses and employers about their biometric data practices before providing fingerprints, facial scans, or other biometric information. While they are not legally required to disclose their practices, many organizations have privacy policies that address biometric data.
If you believe your biometric data was compromised in a breach and you did not receive proper notification, file a complaint with the Wyoming Attorney General's Consumer Protection Unit.
Review privacy policies before using apps, devices, or services that collect biometric data. Your rights may be stronger under the privacy laws of other states if the collecting entity is based in a state with comprehensive biometric protections.
Sources and References
This article references Wyoming statutes available through the Wyoming Legislature website. For the breach notification definitions, see Wyo. Stat. 40-12-501. For notification requirements, see Wyo. Stat. 40-12-502. For consumer complaints, contact the Wyoming Attorney General's Consumer Protection Unit.
This article provides general legal information about Wyoming biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Wyoming government sources.
More Wyoming Laws
Frequently Asked Questions
Does Wyoming have a biometric privacy law?
Wyoming does not have a standalone biometric privacy law. Biometric data is protected only through the state's breach notification statute (Wyo. Stat. 40-12-501 through 40-12-511), which requires businesses to notify affected residents when a data breach compromises their personal identifying information, including unique biometric data.
Can my employer collect my fingerprints without consent in Wyoming?
Yes. Wyoming law does not require employers to obtain consent before collecting biometric data. There are no state requirements for notice, consent, retention schedules, or data destruction related to employer-collected biometric information such as fingerprints, facial scans, or iris scans.
What biometric data is protected under Wyoming's breach notification law?
Wyoming protects unique biometric data generated from measurements or analysis of human body characteristics for authentication purposes. This includes fingerprint scans, facial recognition templates, iris scans, voiceprints, and similar biometric identifiers used for identity verification.
What are the penalties for failing to report a biometric data breach in Wyoming?
The Wyoming Attorney General can enforce the breach notification law through the Consumer Protection Act. The statute does not specify a maximum penalty amount or a per-individual violation count. Under Wyo. Stat. 40-12-502(f), the AG may bring an action in law or equity to compel compliance and recover damages. There is no private right of action.
How quickly must a company notify me if my biometric data is breached in Wyoming?
Wyoming requires notification in the most expedient time possible and without unreasonable delay. The notice must include a toll-free number for reaching the business and the major credit reporting agencies, the types of data compromised, a description of the breach, the approximate date, actions taken to secure the system, and advice to monitor credit reports. Notification may be delayed only if law enforcement determines it would impede a criminal investigation.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the breach notification citations to Wyo. Stat. 40-12-501 through 40-12-511 and attributed the notice duty to 40-12-502, added the toll-free number that a compliant Wyoming breach notice must contain, clarified that the Genetic Data Privacy Act carries a fixed $2,500 per-violation civil penalty alongside a criminal fine and a private right of action, and updated the legislative outlook to reflect that Wyoming government data privacy law is now enacted at Wyo. Stat. 9-21-201 through 9-21-203.
Corrected this page's breach-notice methods (removed a nonexistent 'telephone notice' option), removed overstated penalty claims not in the statute (a per-individual violation count and restitution/investigation-cost remedies), repointed the Genetic Data Privacy Act citation to the actual law (Wyo. Stat. 35-32-101 et seq.) instead of an unrelated Attorney General privacy notice, and corrected the description of Nebraska's biometric-data protections, which are stronger than stated.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the source of Wyoming's biometric-data definition (it lives in W.S. 6-3-901, not 40-12-501, which was repealed and now cross-references it), removed an unsupported $10,000-per-violation penalty cap the breach notification statute does not contain, and fixed the substitute-notice dollar/class thresholds to show the lower figures that apply to Wyoming-based businesses.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Wyoming Statutes, Title 40 - Trade and Commerce - Chapter 12: Consumer Protection - Article 5: Credit Freeze Reports
§ 40-12-502Computer security breach; notice to affected persons.In forcecited in 3 of our articles
(a) An individual or commercial entity that conducts business in Wyoming and that owns or licenses computerized data that includes personal identifying information about a resident of Wyoming shall, when it becomes aware of a breach of the security of the system, conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal identifying information has been or will be misused. If the investigation determines that the misuse of personal identifying information about a Wyoming resident has occurred or is reasonably likely to occur, the individual or the commercial entity shall give notice as soon as possible to the affected Wyoming resident. Notice shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system. (b) The notification required by this section may be delayed if a law enforcement agency determines in writing that the notification may seriously impede a criminal investigation.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at wyoleg.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2019
Opinions citing this section in our collection:
- In re Equifax, Inc. (District Court, N.D. Georgia 2019, 362 F. Supp. 3d 1295)“…at "[t]he provisions of this section are not exclusive"); Wyo. Stat. Ann. § 40-12-502 (f) (providing that "[t]he attorney ge…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Wyoming Data Breach Notification Laws: Reporting Rules & Timelines (2026), Wyoming Data Privacy Laws: Breach Notification & Consumer Rights (2026)
§ 40-12-501Definitions.In forcecited in 3 of our articles
(a) As used in this act: (i) "Breach of the security of the data system" means unauthorized acquisition of computerized data that materially compromises the security, confidentiality or integrity of personal identifying information maintained by a person or business and causes or is reasonably believed to cause loss or injury to a resident of this state. Good faith acquisition of personal identifying information by an employee or agent of a person or business for the purposes of the person or business is not a breach of the security of the data system, provided that the personal identifying information is not used or subject to further unauthorized disclosure; (ii) "Consumer" means any person who is utilizing or seeking credit for personal, family or household purposes; (iii) "Consumer reporting agency" means any person whose business is the assembling and evaluating of information as to the credit standing and credit worthiness of a consumer, for the purposes of furnishing credit reports, for monetary fees and dues to third parties; (iv) "Credit report" means any written or oral report, recommendation or representation of a consumer reporting agency as to the credit…
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at wyoleg.gov
Also relied on in: Wyoming Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
Wyoming Statutes, Title 35 - Public Health and Safety - Chapter 32: Genetic Data Privacy
§ 35-32-101Definitions.In force
(a) As used in this chapter unless otherwise defined: (i) "Authorized representative" means a person authorized by state or federal law to make health care decisions for an individual; (ii) "DNA" means deoxyribonucleic acid; (iii) "Genetic testing" means any laboratory test of an individual's complete DNA, regions of DNA, chromosomes or genes to determine the presence of genetic characteristics of an individual; (iv) "Genetic characteristic" means a gene or chromosome, or alteration thereof, that is scientifically or medically believed to predispose an individual to a disease, disorder, trait or syndrome, or to identify an individual or a blood relative; (v) "Genetic data" means any data, regardless of its format, that concerns an individual's genetic characteristics.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at wyoleg.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Wyo. Stat. 40-12-501 - Definitions (Breach Notification)(law.justia.com)
- Wyo. Stat. 40-12-502 - Computer Security Breach Notice(law.justia.com)
- Wyoming Legislature - State Statutes(wyoleg.gov).gov
- Wyoming Title 40 - Trade and Commerce (Full Text)(wyoleg.gov).gov
- Wyoming Attorney General - Privacy(ag.wyo.gov).gov
- Wyoming AG - Consumer Protection Unit(ag.wyo.gov).gov
- Wyo. Stat. 35-32-101 et seq. - Genetic Data Privacy Act(wyoleg.gov).gov
- Wyo. Stat. 9-21-201 through 9-21-203 - Data Privacy, Government Entities (Title 9 Full Text)(wyoleg.gov)