Minnesota Has No Biometric Privacy Act — and the Statute That Comes Closest Reaches Only Government Employers

August 9, 2026 · David J.S. Madgett · Updated October 1, 2026

The question lands in my inbox in some version of this: we are installing a fingerprint timeclock — do we need the written consent form?

Under Minnesota law, no private employer is required by statute to obtain a signed biometric consent, publish a retention schedule, or destroy the template when the employee leaves. Minnesota has nothing like Illinois’s Biometric Information Privacy Act, the statute behind most of the biometric litigation in the country.

Unless the employer is a Minnesota government entity. There, a statute from the 1970s has imposed a notice-at-collection duty, a use restriction, and a private damages remedy the whole time. Nobody thinks of it as a biometric statute, because it never uses the word.

That’s the twist. First, though, the negative needs support, because “there is no law” is the easiest thing to say in this area and the hardest to back up.


Does Minnesota have a biometric privacy act?

Not one that a private employer or vendor has to comply with. Here’s what that rests on.

The word “biometric” shows up in 17 sections of the 2025 edition of Minnesota Statutes. The same edition returns one section for “voiceprint,” one for “biometric identifier,” two for “facial recognition,” and zero for “faceprint,” “iris scan,” and “retina scan.” The 2026 session laws return one chapter. Read for what they actually do, those 17 sections sort into four buckets, and none of them is a privacy regime:

  1. Licensure and background checks — fingerprint or “other biometric data” checks under the interstate medical, psychology, social work, and criminal-record compacts (§§ 147.38, 148.9051, 148E.43, 299C.58) and predatory-offender address verification (§ 243.166).
  2. Secure access and authentication — biometric controls permitted on automated drug distribution systems (§ 151.58), secure treatment facility records (§ 253B.23), remote online notarization (§ 358.645), and a sales-tax-exempt access system (§ 297A.68); “inherence factors” for multifactor authentication in the financial and insurance data-security definitions (§§ 46A.01, 60A.985, subd. 9).
  3. Health care coverage — remote monitoring of “biometric data” as a covered service (§§ 62A.673, 256B.0625).
  4. Definitions that classify — “biometric records” as nonpublic information under the insurance data-security law (§ 60A.985, subd. 10); a biometric identifier as criminal-justice credentialing data (§ 299C.41); the enhanced-driver’s-license RFID carve-out (§ 171.07, subd. 9a(b)); and the two Consumer Data Privacy Act sections below.

Here’s what no Minnesota section does: require a private entity, across the board, to give written notice before collecting a biometric identifier, get a written release, publish a retention schedule, or destroy the identifier once its purpose is satisfied. Sale is the one BIPA-style restriction Minnesota does impose, and only on one class of company. Section 325M.17 bars a small business from selling sensitive data without prior consent. More on that below.

A word on method. Word searches undercount. Take § 626.19, which restricts “facial recognition or other biometric-matching technology,” and that hyphenated compound never turned up in the “biometric” results. So the conclusion doesn’t rest on a missing word. It rests on what the statutes that do exist say, and on a simple fact: a general biometric consent regime would live in chapter 325M with consumer privacy or chapter 181 with employment regulation. It isn’t in either one.

What does Illinois’s BIPA require that Minnesota doesn’t?

Written notice, a written release, a published retention schedule, mandatory destruction, a ban on profiting from the identifier — and liquidated damages.

Under 740 ILCS 14/15(b), no private entity may collect a biometric identifier unless it first tells the subject in writing that an identifier “is being collected or stored,” tells the subject in writing “the specific purpose and length of term for which” it is collected, stored, and used, and gets a written release. Section 15(a) requires a public written policy with a retention schedule and destruction guidelines — destruction when the initial purpose is satisfied “or within 3 years of the individual’s last interaction with the private entity, whichever occurs first.” Section 15(c) bars profiting from it.

The engine is § 20(a): “Any person aggrieved by a violation of this Act shall have a right of action,” recovering for a negligent violation “liquidated damages of $1,000 or actual damages, whichever is greater,” and for an intentional or reckless violation “liquidated damages of $5,000 or actual damages, whichever is greater,” plus fees and costs.

Minnesota has no statute that puts that package together for private entities, and nothing with BIPA’s per-violation private claim. Pieces of it are scattered across unrelated chapters, and I walk through them below. But a Minnesota company can’t pick up any one of them and use it the way an Illinois company uses BIPA, as the operating manual. And a Minnesota employer with Illinois employees still has BIPA. That’s why the question keeps landing on my desk.

The consumer privacy law regulates biometrics — and excludes the timeclock

The Minnesota Consumer Data Privacy Act treats biometrics as “sensitive data,” and that takes consent. Then it carves out the employment context, so the timeclock sits outside it.

The Minnesota Consumer Data Privacy Act defines “biometric data” as “data generated by automatic measurements of an individual’s biological characteristics, including a fingerprint, a voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual” — excluding photographs and audio or video recordings, and anything derived from them “unless the data is generated to identify a specific individual.” § 325M.11(d)(1)–(3).

“Sensitive data” includes “the processing of biometric data or genetic information for the purpose of uniquely identifying an individual.” § 325M.11(v)(2). And § 325M.16, subd. 2(d), supplies the duty: “a controller may not process sensitive data concerning a consumer without obtaining the consumer’s consent,” or, for a known child, the consent of a parent or lawful guardian under COPPA. Consent under § 325M.11(f) must be “freely given, specific, informed, and unambiguous,” can’t come from accepting broad terms of use, and is invalid if it’s obtained through a dark pattern.

Three limits make that a lot narrower than it sounds:

  • “Consumer” excludes employees — the term means “a natural person who is a Minnesota resident acting only in an individual or household context,” and “does not include a natural person acting in a commercial or employment context.” § 325M.11(g).
  • Most companies are outside the thresholds — 100,000 consumers, or 25,000 plus more than 25 percent of gross revenue from selling personal data. § 325M.12, subd. 1(a). One provision escapes them: § 325M.17 forbids any small business, as defined by the SBA regulations, from selling “a consumer’s sensitive data without the consumer’s prior consent.”
  • There is no private right of action. “Nothing in sections 325M.10 to 325M.21 establishes a private right of action, including under section 8.31, subdivision 3a, for a violation of sections 325M.10 to 325M.21 or any other law.” § 325M.20(d). Enforcement belongs to the Attorney General, at not more than $7,500 per violation. § 325M.20(b)–(c). That expressly shuts the door on Minnesota’s private attorney general statute.

And one provision runs the opposite way from what you’d expect. Section 325M.14, subd. 4(i) says that in response to an access request a controller must not disclose six categories of information but “must instead inform the consumer with sufficient particularity that the controller has collected that type of information” — and clause (6) is “biometric data.” Minnesota’s consumer privacy statute forbids a company from handing you back your own faceprint.

If a company loses our biometric templates, does Minnesota require notice?

Under the general breach statute, no. But there’s one industry where the answer flips, and you should know which one. Section 325E.61, subd. 1(e), defines “personal information” as a name in combination with a Social Security number, a driver’s license or Minnesota identification card number, or a financial account number with its access credential. Biometric data isn’t on that list, and the notice duty in subd. 1(a) runs only to a breach of “personal information” as so defined. For most companies, a breach of nothing but faceprints triggers no Minnesota notice. I cover that statute’s mechanics in Minnesota’s data breach notification law, and where it sits beside the MCDPA and chapter 13 in Minnesota’s three privacy regimes.

Insurance licensees are the exception. Minnesota’s insurance data security law puts “biometric records” squarely inside its definition of protected data: § 60A.985, subd. 10(1)(v). And § 60A.9853, subd. 1, requires a licensee to notify the commissioner of commerce or of health “without unreasonable delay but in no event later than five business days from a determination that a cybersecurity event has occurred,” on the conditions that subdivision sets out. Look at what that is. It’s a duty running to the regulator, not a notice to the affected individual, and it applies only to licensees. But for an insurer or producer, the flat answer that Minnesota law says nothing about a biometric breach is wrong.

Who does have a claim over biometrics in Minnesota?

A public employee — under chapter 13, which has provided all of it since the 1970s.

Follow the chain. A city, county, school district, or state agency that fingerprints an employee is collecting personnel data, and § 13.43, subd. 4, provides that “[a]ll other personnel data is private data on individuals but may be released pursuant to a court order.” From there, three things follow automatically:

  • Notice at collection. Section 13.04, subd. 2, requires that an individual asked to supply private data be told the purpose and intended use within the collecting entity, whether supplying it is optional, the known consequences either way, and “the identity of other persons or entities authorized by state or federal law to receive the data.” That’s the Tennessen warning, and it’s closer to BIPA § 15(b) than anything in Minnesota’s private-sector law.
  • A binding purpose limit. Under § 13.05, subd. 4, private data “shall not be collected, stored, used, or disseminated by government entities for any purposes other than those stated to the individual at the time of collection” — subject to five enumerated exceptions. A template collected for door access can’t be repurposed for attendance discipline without going back to the employee.
  • A private damages remedy. Section 13.08, subd. 1, makes a violating entity “liable to a person … who suffers any damage as a result of the violation,” for damages “plus costs and reasonable attorney fees,” and for exemplary damages “of not less than $1,000, nor more than $15,000 for each violation” where the violation was willful.

I lay out that machinery in the data-subject’s guide to chapter 13. The point here is narrower: a Minnesota public employee whose biometric template was collected without a proper Tennessen warning, or used for a purpose never disclosed, has a statutory claim with fees attached. A private-sector employee in the identical situation does not.

Same fingerprint, same timeclock. Different employer, different answer.

Five statutes actually reach the body

Two of them reach ordinary private employment, and both carry real remedies.

Voice, but only for honesty testing. Minn. Stat. § 181.75, subd. 1: “No employer or agent thereof shall directly or indirectly solicit or require a polygraph, voice stress analysis, or any test purporting to test the honesty of any employee or prospective employee.” A violation is a misdemeanor, and subdivision 4 adds that “any person injured by a violation of this section may bring a civil action to recover any and all damages recoverable at law, together with costs and disbursements, including costs of investigation and reasonable attorney’s fees, and receive other equitable relief as determined by the court.” So there’s a private right of action that reaches a voice-based measurement. But it’s an honesty-testing statute that happens to name one voice technology. It isn’t a voiceprint statute.

Genetic information, from everyone. Minn. Stat. § 13.386, subd. 3(a), is a rare chapter 13 provision that reaches beyond government: genetic information “may be collected by a government entity … or any other person only with the written informed consent of the individual,” may be used and stored only as consented to, and may be disseminated only on a signed, dated consent that, absent other law, “is valid for one year or for a lesser period specified in the consent.” Genetic information isn’t biometric data — the MCDPA lists them separately in the same clause — but this is Minnesota’s one consent-at-collection rule that binds private parties handling data taken from the body. One catch: § 13.08’s liability language runs to “a responsible authority or government entity,” and § 13.386 carries no remedy of its own, so enforcement against a private violator is an open question, not a settled claim.

Genetic testing, in private employment, with teeth. Minn. Stat. § 181.974 is the closest thing Minnesota has to BIPA in structure, and in my experience almost nobody cites it. Its “employer” is “any person having one or more employees in Minnesota” — there’s no size threshold. Subdivision 2(a) bars an employer or employment agency from directly or indirectly administering “a genetic test or request, require, or collect protected genetic information regarding a person as a condition of employment,” or from affecting the terms of employment based on protected genetic information; subdivision 2(b) extends the bar to any person who provides or interprets that information for an employer. And subdivision 3 supplies what § 13.386 lacks: “[a]ny person aggrieved by a violation of this section may bring a civil action,” in which the court may award up to three times actual damages, punitive damages, costs and attorney fees, and equitable relief. Genetic information isn’t biometric data, and I’m not saying this statute covers faceprints. I’m saying that when the legislature decides to regulate a bodily measurement in private employment, it knows exactly how.

Fingerprints of schoolchildren. Section 123B.07 lets a district run a voluntary fingerprinting program to help locate missing children, fenced in by the most BIPA-like conditions in Minnesota law: “No child may be required to participate in the program”; a parent or guardian must authorize participation on a signed form; and “[n]o copy of the fingerprint card may be retained by the law enforcement agency, school, or district.” Subd. 3(a)–(d). Consent, a purpose limit, and mandatory non-retention, all in one narrow program.

Faces, from the air. Section 626.19, subd. 4(b): “A law enforcement agency must not deploy a UAV with facial recognition or other biometric-matching technology unless expressly authorized by a warrant.” Subdivision 7 makes information obtained in violation inadmissible against the data subject; subdivision 8 lets an aggrieved party sue the agency. One wrinkle: subd. 6(b) provides that “[s]ection 13.04, subdivision 2, does not apply to data collected by a UAV” — so there’s no Tennessen warning for drone data.

Compare what Minnesota does when it decides to regulate a bodily test in private employment: §§ 181.950 to 181.954 govern drug and alcohol testing in detail, and § 181.956 supplies damages, fees on a knowing or reckless violation, injunctive relief, and reinstatement with back pay. See the drug and alcohol testing statute. Nothing like that exists for biometrics. I read that as a choice, not an oversight.

Is there a common-law claim?

Yes, and it’s the one I’d actually reach for today. In Lake v. Wal-Mart Stores, Inc., 582 N.W.2d 231 (Minn. 1998), the Minnesota Supreme Court held: “Thus we recognize a right to privacy present in the common law of Minnesota, including causes of action in tort for intrusion upon seclusion, appropriation, and publication of private facts, but we decline to recognize the tort of false light publicity.” Id. at 236. It took the Restatement formulation — one who “intentionally intrudes, physically or otherwise, upon the solitude or seclusion of another or his private affairs or concerns * * * if the intrusion would be highly offensive to a reasonable person.” Id. at 233.

A covert faceprint fits that tort better than a disclosed timeclock does. But “highly offensive to a reasonable person” is a real hurdle, and there are no liquidated damages behind it. See also Minnesota’s recording and surveillance consent rules.

What changes on July 1, 2027?

Minnesota gets its first statutory text naming facial templates and gait metrics — for children, on social media platforms, and nowhere else.

Section 325M.40, added by Laws 2026, ch. 111, § 2, defines “personal information” to include “any photograph or biometric information that is used or could reasonably be used to identify the account holder, including but not limited to fingerprints, voiceprints, iris or retina imagery scans, facial templates, or gait imagery or metrics” — and, in the same sentence, geolocation information. Subd. 1(i). The section carries a private right of action with $10,000 in statutory damages for a reckless or knowing violation, limited to covered social media platforms and Minnesota children. I cover it in full in the Social Media Manipulation Act piece.

It isn’t a general regime. I treat it as a marker worth watching. But it’s the first time the Legislature has written the vocabulary of biometric identification into a statute that gives an individual a claim.


At Madgett Law, LLC I advise Minnesota employers and vendors on biometric, consumer-privacy, and Data Practices Act obligations, and I represent people whose personal information has been collected or used without the notice or consent the law requires. If you’re deciding whether a biometric system needs a consent program, or you’re a public employee whose fingerprint or faceprint was taken without a Tennessen warning, send us a message or call 612-470-6529.


Sources: Minn. Stat. § 13.04, subd. 2 (Tennessen warning; the four required disclosures); § 13.05, subd. 4 (private or confidential data may not be used or disseminated for purposes other than those stated at collection, subject to ¶¶ (a)–(e)); § 13.08, subd. 1 (damages, costs and reasonable attorney fees; exemplary damages of not less than $1,000 nor more than $15,000 for each willful violation; and the phrase “a responsible authority or government entity” that limits who is liable); § 13.386, subds. 1 and 3(a) (definition of genetic information; collection, use, storage, and dissemination by “a government entity … or any other person” only with written informed consent); § 13.43, subd. 4 (all other personnel data is private data on individuals); § 62A.673 and § 256B.0625 (remote monitoring of biometric data as a covered service); § 46A.01 and § 60A.985, subds. 9–10 (inherence factors in multifactor authentication; “biometric records” within nonpublic information); § 123B.07, subd. 3(a)–(d) (voluntary school fingerprinting program: no child may be required to participate; parental authorization on a signed form; fingerprinting by law enforcement personnel; no copy of the card may be retained by the agency, school, or district); § 147.38, § 148.9051, § 148E.43, § 243.166, § 299C.41, § 299C.58 (fingerprint and biometric checks in licensure compacts, offender registration, and criminal-justice credentialing); § 151.58, § 253B.23, § 297A.68, § 358.645 (biometric access control and authentication); § 171.07, subd. 9a(b) (enhanced driver’s license or identification card RFID technology that “does not include biometric data or any information other than the citizenship status of the license holder or cardholder”); § 181.75, subds. 1 and 4 (prohibition on soliciting or requiring a polygraph, voice stress analysis, or honesty test; individual civil remedy with costs of investigation and reasonable attorney’s fees); § 181.974, subd. 1(b) (“employer” means “any person having one or more employees in Minnesota”), subd. 2(a)(1)–(2) and (b) (no employer or employment agency may administer a genetic test or request, require, or collect protected genetic information as a condition of employment, or affect the terms of employment on that basis; no person may provide or interpret such information for an employer), and subd. 3(1)–(4) (civil action; up to three times actual damages, punitive damages, costs and attorney fees, and equitable relief); § 60A.9853, subd. 1 (insurance licensee must notify the commissioner of commerce or of health “without unreasonable delay but in no event later than five business days from a determination that a cybersecurity event has occurred,” on the conditions stated — a duty running to the regulator, not to the individual); §§ 181.950–181.954 and § 181.956 (drug and alcohol testing in employment, and its remedies); § 325E.61, subd. 1(a) and (e) (breach notice duty; three-element definition of “personal information”); § 325M.11(d), (f), (g), (v)(2) (definitions of biometric data and its exclusions, consent, consumer excluding the employment context, and sensitive data); § 325M.12, subd. 1(a) (coverage thresholds); § 325M.14, subd. 4(i)(6) (controller must not disclose biometric data in response to a consumer request and must instead identify the category with sufficient particularity); § 325M.16, subd. 2(d) (no processing of sensitive data without consent); § 325M.17 (small business may not sell sensitive data without prior consent); § 325M.20(b)–(d) (Attorney General enforcement, $7,500 per violation, no private right of action including under § 8.31, subd. 3a); § 626.19, subd. 4(b) (no UAV facial recognition or biometric-matching technology without a warrant), subd. 6(b) (§ 13.04, subd. 2, does not apply to UAV data), subd. 7 (inadmissibility), and subd. 8 (civil action against the agency) — all from the Minnesota Office of the Revisor of Statutes, 2025 Minnesota Statutes. Session law: Laws 2026, ch. 111 (H.F. No. 4138), § 2, adding Minn. Stat. § 325M.40, subd. 1(i) (definition of “personal information” including fingerprints, voiceprints, iris or retina imagery scans, facial templates, and gait imagery or metrics) and subd. 9 (private right of action; $10,000 statutory damages), effective July 1, 2027, from the Revisor’s session law database. Illinois: 740 ILCS 14/15(a)–(c) and 14/20(a), Biometric Information Privacy Act, from the Illinois General Assembly’s official ILCS text at ilga.gov. Case law: Lake v. Wal-Mart Stores, Inc., 582 N.W.2d 231, 233, 236 (Minn. 1998) (recognizing intrusion upon seclusion, appropriation, and publication of private facts; declining false light; quoting the Restatement (Second) of Torts formulation of intrusion upon seclusion), Caselaw Access Project archive.

Method note on the negative claim: the statements that Minnesota has no biometric consent statute rest on keyword searches of the 2025 edition of Minnesota Statutes run through the Revisor’s own search service on August 9, 2026 — “biometric” (17 sections), “voiceprint” (1), “biometric identifier” (1), “facial recognition” (2), “faceprint” (0), “iris scan” (0), “retina scan” (0) — plus a search of the 2026 Regular Session laws for “biometric” (1 chapter, Laws 2026, ch. 111), and on reading each hit. Keyword searching undercounts: § 626.19 uses the hyphenated “biometric-matching” and did not appear in the “biometric” result set. The conclusion stated here is about what the identified statutes do and do not require, not about the absence of a word.

This article is general legal information about Minnesota law, not legal advice, and reading it does not create an attorney–client relationship. Whether a particular biometric system is regulated depends on the entity, the workforce, the states involved, and the use, and Illinois, Texas, Washington, and other states’ laws frequently apply to Minnesota companies independently. No outcome is promised or implied.

Get new guides by email

Plain-English guides to Minnesota law, sent when a new one is written. No schedule, nothing for sale.

Used only to send these guides. Unsubscribe from any email. This is attorney advertising — subscribing does not create an attorney–client relationship.

← All news & articles