EnglishEspañol
Wyoming flag

Wyoming

Wyoming Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 5 primary sources cited on this page. How we verify our legal content

Wyoming Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Wyoming have a biometric privacy law?

Wyoming does not have a standalone biometric privacy law. Biometric data is protected only through the state's breach notification statute (Wyo. Stat. 40-12-501 through 40-12-511), which requires businesses to notify affected residents when a data breach compromises their personal identifying information, including unique biometric data.

Can my employer collect my fingerprints without consent in Wyoming?

Yes. Wyoming law does not require employers to obtain consent before collecting biometric data. There are no state requirements for notice, consent, retention schedules, or data destruction related to employer-collected biometric information such as fingerprints, facial scans, or iris scans.

What biometric data is protected under Wyoming's breach notification law?

Wyoming protects unique biometric data generated from measurements or analysis of human body characteristics for authentication purposes. This includes fingerprint scans, facial recognition templates, iris scans, voiceprints, and similar biometric identifiers used for identity verification.

What are the penalties for failing to report a biometric data breach in Wyoming?

The Wyoming Attorney General can enforce the breach notification law through the Consumer Protection Act. The statute does not specify a maximum penalty amount or a per-individual violation count. Under Wyo. Stat. 40-12-502(f), the AG may bring an action in law or equity to compel compliance and recover damages. There is no private right of action.

How quickly must a company notify me if my biometric data is breached in Wyoming?

Wyoming requires notification in the most expedient time possible and without unreasonable delay. The notice must include a toll-free number for reaching the business and the major credit reporting agencies, the types of data compromised, a description of the breach, the approximate date, actions taken to secure the system, and advice to monitor credit reports. Notification may be delayed only if law enforcement determines it would impede a criminal investigation.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the breach notification citations to Wyo. Stat. 40-12-501 through 40-12-511 and attributed the notice duty to 40-12-502, added the toll-free number that a compliant Wyoming breach notice must contain, clarified that the Genetic Data Privacy Act carries a fixed $2,500 per-violation civil penalty alongside a criminal fine and a private right of action, and updated the legislative outlook to reflect that Wyoming government data privacy law is now enacted at Wyo. Stat. 9-21-201 through 9-21-203.

Corrected this page's breach-notice methods (removed a nonexistent 'telephone notice' option), removed overstated penalty claims not in the statute (a per-individual violation count and restitution/investigation-cost remedies), repointed the Genetic Data Privacy Act citation to the actual law (Wyo. Stat. 35-32-101 et seq.) instead of an unrelated Attorney General privacy notice, and corrected the description of Nebraska's biometric-data protections, which are stronger than stated.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected the source of Wyoming's biometric-data definition (it lives in W.S. 6-3-901, not 40-12-501, which was repealed and now cross-references it), removed an unsupported $10,000-per-violation penalty cap the breach notification statute does not contain, and fixed the substitute-notice dollar/class thresholds to show the lower figures that apply to Wyoming-based businesses.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Wyo. Stat. 40-12-501 - Definitions (Breach Notification)(law.justia.com)
  2. Wyo. Stat. 40-12-502 - Computer Security Breach Notice(law.justia.com)
  3. Wyoming Legislature - State Statutes(wyoleg.gov).gov
  4. Wyoming Title 40 - Trade and Commerce (Full Text)(wyoleg.gov).gov
  5. Wyoming Attorney General - Privacy(ag.wyo.gov).gov
  6. Wyoming AG - Consumer Protection Unit(ag.wyo.gov).gov
  7. Wyo. Stat. 35-32-101 et seq. - Genetic Data Privacy Act(wyoleg.gov).gov
  8. Wyo. Stat. 9-21-201 through 9-21-203 - Data Privacy, Government Entities (Title 9 Full Text)(wyoleg.gov)
Share: