The question arrives in some version of this: we are installing a fingerprint timeclock — do we need the written consent form?
Under Minnesota law, no private employer is required by statute to obtain a signed biometric consent, publish a retention schedule, or destroy the template when the employee leaves. Minnesota has no analogue to Illinois’s Biometric Information Privacy Act, the statute behind most of the biometric litigation in the country.
Unless the employer is a Minnesota government entity. There, a statute enacted in the 1970s has imposed a notice-at-collection duty, a use restriction, and a private damages remedy the whole time — and nobody thinks of it as a biometric statute, because it never uses the word.
Getting to that inversion responsibly means being careful about the negative claim first, because “there is no law” is the easiest thing in this area to say and the hardest to support.
Does Minnesota have a biometric privacy act?
Not one that a private employer or vendor has to comply with. Here is what that rests on.
The word “biometric” appears in 17 sections of the 2025 edition of Minnesota Statutes. The same edition returns one section for “voiceprint,” one for “biometric identifier,” two for “facial recognition,” and zero for “faceprint,” “iris scan,” and “retina scan.” The 2026 session laws return one chapter. Read against what they do, those 17 sections fall into four buckets, none a privacy regime:
- Licensure and background checks — fingerprint or “other biometric data” checks under the interstate medical, psychology, social work, and criminal-record compacts (§§ 147.38, 148.9051, 148E.43, 299C.58) and predatory-offender address verification (§ 243.166).
- Secure access and authentication — biometric controls permitted on automated drug distribution systems (§ 151.58), secure treatment facility records (§ 253B.23), remote online notarization (§ 358.645), and a sales-tax-exempt access system (§ 297A.68); “inherence factors” for multifactor authentication in the financial and insurance data-security definitions (§§ 46A.01, 60A.985, subd. 9).
- Health care coverage — remote monitoring of “biometric data” as a covered service (§§ 62A.673, 256B.0625).
- Definitions that classify — “biometric records” as nonpublic information under the insurance data-security law (§ 60A.985, subd. 10); a biometric identifier as criminal-justice credentialing data (§ 299C.41); the enhanced-driver’s-license RFID carve-out (§ 171.07, subd. 9a(b)); and the two Consumer Data Privacy Act sections below.
What no Minnesota section does: require a private entity, across the board, to give written notice before collecting a biometric identifier, obtain a written release, publish a retention schedule, or destroy the identifier when its purpose is satisfied. Sale is the one BIPA-style restriction Minnesota does impose, and only on one class of company — § 325M.17 bars a small business from selling sensitive data without prior consent, discussed below.
One caution about method. Word searches undercount: § 626.19 restricts “facial recognition or other biometric-matching technology,” and the hyphenated compound never appeared in the “biometric” result set. The conclusion does not rest on the absence of a word. It rests on what the statutes that do exist say — and on the fact that a general biometric consent regime would sit in chapter 325M with consumer privacy or chapter 181 with employment regulation, and it is in neither.
What does Illinois’s BIPA require that Minnesota does not?
Written notice, written release, a published retention schedule, mandatory destruction, a ban on profiting from the identifier — and liquidated damages.
Under 740 ILCS 14/15(b), no private entity may collect a biometric identifier unless it first informs the subject in writing that an identifier “is being collected or stored,” informs the subject in writing of “the specific purpose and length of term for which” it is collected, stored, and used, and receives a written release. Section 15(a) requires a public written policy with a retention schedule and destruction guidelines — destruction when the initial purpose is satisfied “or within 3 years of the individual’s last interaction with the private entity, whichever occurs first.” Section 15(c) bars profiting from it.
The engine is § 20(a): “Any person aggrieved by a violation of this Act shall have a right of action,” recovering for a negligent violation “liquidated damages of $1,000 or actual damages, whichever is greater,” and for an intentional or reckless violation “liquidated damages of $5,000 or actual damages, whichever is greater,” plus fees and costs.
Minnesota has no statute assembling that package for private entities, and nothing carrying BIPA’s per-violation private claim. Pieces of it exist scattered across unrelated chapters — the sections catalogued below — but a Minnesota company cannot read any one of them as the operating manual an Illinois company reads BIPA to be. A Minnesota employer with Illinois employees still has BIPA, which is why the question keeps arriving here.
Is biometric data regulated under Minnesota’s consumer privacy law?
Yes — as “sensitive data,” requiring consent. But the statute excludes the employment context, so the timeclock is outside it.
The Minnesota Consumer Data Privacy Act defines “biometric data” as “data generated by automatic measurements of an individual’s biological characteristics, including a fingerprint, a voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual” — excluding photographs and audio or video recordings, and anything derived from them “unless the data is generated to identify a specific individual.” § 325M.11(d)(1)–(3).
“Sensitive data” includes “the processing of biometric data or genetic information for the purpose of uniquely identifying an individual.” § 325M.11(v)(2). And § 325M.16, subd. 2(d), supplies the duty: “a controller may not process sensitive data concerning a consumer without obtaining the consumer’s consent,” or, for a known child, the consent of a parent or lawful guardian under COPPA. Consent under § 325M.11(f) must be “freely given, specific, informed, and unambiguous,” cannot come from acceptance of broad terms of use, and is invalid if obtained by a dark pattern.
Three limits make that far narrower than it sounds:
- “Consumer” excludes employees — the term means “a natural person who is a Minnesota resident acting only in an individual or household context,” and “does not include a natural person acting in a commercial or employment context.” § 325M.11(g).
- Most companies are outside the thresholds — 100,000 consumers, or 25,000 plus more than 25 percent of gross revenue from selling personal data. § 325M.12, subd. 1(a). One provision escapes them: § 325M.17 forbids any small business, as defined by the SBA regulations, from selling “a consumer’s sensitive data without the consumer’s prior consent.”
- There is no private right of action. “Nothing in sections 325M.10 to 325M.21 establishes a private right of action, including under section 8.31, subdivision 3a, for a violation of sections 325M.10 to 325M.21 or any other law.” § 325M.20(d). Enforcement is the Attorney General’s, at not more than $7,500 per violation. § 325M.20(b)–(c). That expressly forecloses Minnesota’s private attorney general statute.
And one provision runs opposite to what a consumer would expect. Section 325M.14(i) directs that in response to an access request a controller must not disclose six categories of information but “must instead inform the consumer with sufficient particularity that the controller has collected that type of information” — and clause (6) is “biometric data.” Minnesota’s consumer privacy statute forbids a company from handing you back your own faceprint.
If a company loses our biometric templates, does Minnesota require notice?
Under the general breach statute, no — but there is one industry where the answer flips, and it is worth knowing which. Section 325E.61, subd. 1(e), defines “personal information” as a name in combination with a Social Security number, a driver’s license or Minnesota identification card number, or a financial account number with its access credential. Biometric data is not on that list, and the notice duty in subd. 1(a) runs only to a breach of “personal information” as so defined. For most companies, a breach of nothing but faceprints triggers no Minnesota notice. That statute’s mechanics are covered in Minnesota’s data breach notification law, and its place beside the MCDPA and chapter 13 in Minnesota’s three privacy regimes.
Insurance licensees are the exception. Minnesota’s insurance data security law puts “biometric records” squarely inside its definition of protected data: § 60A.985, subd. 10(1)(v). And § 60A.9853, subd. 1, requires a licensee to notify the commissioner of commerce or of health “without unreasonable delay but in no event later than five business days from a determination that a cybersecurity event has occurred,” on the conditions that subdivision sets out. Note what that is and is not — it is a duty running to the regulator, not a notice to the affected individual, and it applies only to licensees. But for an insurer or producer, the flat answer that Minnesota law says nothing about a biometric breach is wrong.
Who does have a claim over biometrics in Minnesota?
A public employee — under chapter 13, which has provided all of it since the 1970s.
Follow the chain. A city, county, school district, or state agency that fingerprints an employee is collecting personnel data, and § 13.43, subd. 4, provides that “[a]ll other personnel data is private data on individuals but may be released pursuant to a court order.” Three things then follow automatically:
- Notice at collection. Section 13.04, subd. 2, requires that an individual asked to supply private data be told the purpose and intended use within the collecting entity, whether supplying it is optional, the known consequences either way, and “the identity of other persons or entities authorized by state or federal law to receive the data.” That is the Tennessen warning — closer to BIPA § 15(b) than anything in Minnesota’s private-sector law.
- A binding purpose limit. Under § 13.05, subd. 4, private data “shall not be collected, stored, used, or disseminated by government entities for any purposes other than those stated to the individual at the time of collection” — subject to five enumerated exceptions. A template collected for door access cannot be repurposed for attendance discipline without going back to the employee.
- A private damages remedy. Section 13.08, subd. 1, makes a violating entity “liable to a person … who suffers any damage as a result of the violation,” for damages “plus costs and reasonable attorney fees,” and for exemplary damages “of not less than $1,000, nor more than $15,000 for each violation” where the violation was willful.
That machinery is set out in the data-subject’s guide to chapter 13. The point here is narrower: a Minnesota public employee whose biometric template was collected without a proper Tennessen warning, or used for a purpose never disclosed, has a statutory claim with fees attached. A private-sector employee in the identical situation does not.
Which Minnesota statutes actually reach the body?
Five — and two of them reach ordinary private employment, both with real remedies attached.
Voice, but only for honesty testing. Minn. Stat. § 181.75, subd. 1: “No employer or agent thereof shall directly or indirectly solicit or require a polygraph, voice stress analysis, or any test purporting to test the honesty of any employee or prospective employee.” Violation is a misdemeanor, and subdivision 4 adds that “any person injured by a violation of this section may bring a civil action to recover any and all damages recoverable at law, together with costs and disbursements, including costs of investigation and reasonable attorney’s fees, and receive other equitable relief as determined by the court.” A private right of action reaching a voice-based measurement — but an honesty-testing statute that names one voice technology, not a voiceprint statute.
Genetic information, from everyone. Minn. Stat. § 13.386, subd. 3(a), is a rare chapter 13 provision reaching beyond government: genetic information “may be collected by a government entity … or any other person only with the written informed consent of the individual,” may be used and stored only as consented to, and may be disseminated only on a signed, dated consent that, absent other law, “is valid for one year or for a lesser period specified in the consent.” Genetic information is not biometric data — the MCDPA lists them separately in the same clause — but this is Minnesota’s one consent-at-collection rule binding private parties who handle data taken from the body. One caveat, plainly: § 13.08’s liability language runs to “a responsible authority or government entity,” and § 13.386 carries no remedy of its own, so enforcement against a private violator is an open question, not a settled claim.
Genetic testing, in private employment, with teeth. Minn. Stat. § 181.974 is the closest thing Minnesota has to BIPA in structure, and almost nobody cites it. Its “employer” is “any person having one or more employees in Minnesota” — there is no size threshold. Subdivision 2(a) bars an employer or employment agency from directly or indirectly administering “a genetic test or request, require, or collect protected genetic information regarding a person as a condition of employment,” or from affecting the terms of employment based on protected genetic information; subdivision 2(b) extends the bar to any person who provides or interprets such information for an employer. And subdivision 3 supplies what § 13.386 lacks: “[a]ny person aggrieved by a violation of this section may bring a civil action,” in which the court may award up to three times actual damages, punitive damages, costs and attorney fees, and equitable relief. Genetic information is not biometric data, and the article’s point is not that this statute covers faceprints — it is that when the legislature has decided to regulate a bodily measurement in private employment, it has known exactly how to do it.
Fingerprints of schoolchildren. Section 123B.07 lets a district run a voluntary fingerprinting program to help locate missing children, hedged with the most BIPA-like conditions in Minnesota law: “No child may be required to participate in the program”; a parent or guardian must authorize participation on a signed form; and “[n]o copy of the fingerprint card may be retained by the law enforcement agency, school, or district.” Subd. 3(a)–(d). Consent, purpose limitation, and mandatory non-retention, in one narrow program.
Faces, from the air. Section 626.19, subd. 4(b): “A law enforcement agency must not deploy a UAV with facial recognition or other biometric-matching technology unless expressly authorized by a warrant.” Subdivision 7 makes information obtained in violation inadmissible against the data subject; subdivision 8 lets an aggrieved party sue the agency. One wrinkle: subd. 6(b) provides that “[s]ection 13.04, subdivision 2, does not apply to data collected by a UAV” — no Tennessen warning for drone data.
For contrast, see what Minnesota does when it decides to regulate a bodily test in private employment: §§ 181.950 to 181.954 govern drug and alcohol testing in detail, and § 181.956 supplies damages, fees on a knowing or reckless violation, injunctive relief, and reinstatement with back pay — see the drug and alcohol testing statute. Nothing like it exists for biometrics, which suggests a choice rather than an oversight.
Is there a common-law claim?
Yes, and it is the realistic vehicle today. In Lake v. Wal-Mart Stores, Inc., 582 N.W.2d 231 (Minn. 1998), the Minnesota Supreme Court held: “Thus we recognize a right to privacy present in the common law of Minnesota, including causes of action in tort for intrusion upon seclusion, appropriation, and publication of private facts, but we decline to recognize the tort of false light publicity.” Id. at 236. It took the Restatement formulation — one who “intentionally intrudes, physically or otherwise, upon the solitude or seclusion of another or his private affairs or concerns * * * if the intrusion would be highly offensive to a reasonable person.” Id. at 233.
A covert faceprint fits that tort better than a disclosed timeclock. But “highly offensive to a reasonable person” is a real threshold, and no liquidated damages sit behind it. See also Minnesota’s recording and surveillance consent rules.
What changes on July 1, 2027?
Minnesota’s first statutory text naming facial templates and gait metrics arrives — for children, on social media platforms, nowhere else.
Section 325M.40, added by Laws 2026, ch. 111, § 2, defines “personal information” to include “any photograph or biometric information that is used or could reasonably be used to identify the account holder, including but not limited to fingerprints, voiceprints, iris or retina imagery scans, facial templates, or gait imagery or metrics” — and, in the same sentence, geolocation information. Subd. 1(i). The section carries a private right of action with $10,000 in statutory damages for a reckless or knowing violation, limited to covered social media platforms and Minnesota children. It is treated in full in the Social Media Manipulation Act piece.
A marker worth watching, not a general regime — but the first time the Legislature has written the vocabulary of biometric identification into a statute that gives an individual a claim.
Madgett Law, LLC advises Minnesota employers and vendors on biometric, consumer-privacy, and Data Practices Act obligations, and represents individuals whose personal information has been collected or used without the notice or consent the law requires. If you are deciding whether a biometric system needs a consent program, or you are a public employee whose fingerprint or faceprint was taken without a Tennessen warning, send us a message or call 612-470-6529.
Sources: Minn. Stat. § 13.04, subd. 2 (Tennessen warning; the four required disclosures); § 13.05, subd. 4 (private or confidential data may not be used or disseminated for purposes other than those stated at collection, subject to ¶¶ (a)–(e)); § 13.08, subd. 1 (damages, costs and reasonable attorney fees; exemplary damages of not less than $1,000 nor more than $15,000 for each willful violation; and the phrase “a responsible authority or government entity” that limits who is liable); § 13.386, subds. 1 and 3(a) (definition of genetic information; collection, use, storage, and dissemination by “a government entity … or any other person” only with written informed consent); § 13.43, subd. 4 (all other personnel data is private data on individuals); § 62A.673 and § 256B.0625 (remote monitoring of biometric data as a covered service); § 46A.01 and § 60A.985, subds. 9–10 (inherence factors in multifactor authentication; “biometric records” within nonpublic information); § 123B.07, subd. 3(a)–(d) (voluntary school fingerprinting program: no child may be required to participate; parental authorization on a signed form; fingerprinting by law enforcement personnel; no copy of the card may be retained by the agency, school, or district); § 147.38, § 148.9051, § 148E.43, § 243.166, § 299C.41, § 299C.58 (fingerprint and biometric checks in licensure compacts, offender registration, and criminal-justice credentialing); § 151.58, § 253B.23, § 297A.68, § 358.645 (biometric access control and authentication); § 171.07, subd. 9a(b) (enhanced driver’s license or identification card RFID technology that “does not include biometric data or any information other than the citizenship status of the license holder or cardholder”); § 181.75, subds. 1 and 4 (prohibition on soliciting or requiring a polygraph, voice stress analysis, or honesty test; individual civil remedy with costs of investigation and reasonable attorney’s fees); § 181.974, subd. 1(b) (“employer” means “any person having one or more employees in Minnesota”), subd. 2(a)(1)–(2) and (b) (no employer or employment agency may administer a genetic test or request, require, or collect protected genetic information as a condition of employment, or affect the terms of employment on that basis; no person may provide or interpret such information for an employer), and subd. 3(1)–(4) (civil action; up to three times actual damages, punitive damages, costs and attorney fees, and equitable relief); § 60A.9853, subd. 1 (insurance licensee must notify the commissioner of commerce or of health “without unreasonable delay but in no event later than five business days from a determination that a cybersecurity event has occurred,” on the conditions stated — a duty running to the regulator, not to the individual); §§ 181.950–181.954 and § 181.956 (drug and alcohol testing in employment, and its remedies); § 325E.61, subd. 1(a) and (e) (breach notice duty; three-element definition of “personal information”); § 325M.11(d), (f), (g), (v)(2) (definitions of biometric data and its exclusions, consent, consumer excluding the employment context, and sensitive data); § 325M.12, subd. 1(a) (coverage thresholds); § 325M.14(i)(6) (controller must not disclose biometric data in response to a consumer request and must instead identify the category with sufficient particularity); § 325M.16, subd. 2(d) (no processing of sensitive data without consent); § 325M.17 (small business may not sell sensitive data without prior consent); § 325M.20(b)–(d) (Attorney General enforcement, $7,500 per violation, no private right of action including under § 8.31, subd. 3a); § 626.19, subd. 4(b) (no UAV facial recognition or biometric-matching technology without a warrant), subd. 6(b) (§ 13.04, subd. 2, does not apply to UAV data), subd. 7 (inadmissibility), and subd. 8 (civil action against the agency) — all from the Minnesota Office of the Revisor of Statutes, 2025 Minnesota Statutes. Session law: Laws 2026, ch. 111 (H.F. No. 4138), § 2, adding Minn. Stat. § 325M.40, subd. 1(i) (definition of “personal information” including fingerprints, voiceprints, iris or retina imagery scans, facial templates, and gait imagery or metrics) and subd. 9 (private right of action; $10,000 statutory damages), effective July 1, 2027, from the Revisor’s session law database. Illinois: 740 ILCS 14/15(a)–(c) and 14/20(a), Biometric Information Privacy Act, from the Illinois General Assembly’s official ILCS text at ilga.gov. Case law: Lake v. Wal-Mart Stores, Inc., 582 N.W.2d 231, 233, 236 (Minn. 1998) (recognizing intrusion upon seclusion, appropriation, and publication of private facts; declining false light; quoting the Restatement (Second) of Torts formulation of intrusion upon seclusion), read from the Caselaw Access Project archive.
Method note on the negative claim: the statements that Minnesota has no biometric consent statute rest on keyword searches of the 2025 edition of Minnesota Statutes run through the Revisor’s own search service on August 9, 2026 — “biometric” (17 sections), “voiceprint” (1), “biometric identifier” (1), “facial recognition” (2), “faceprint” (0), “iris scan” (0), “retina scan” (0) — plus a search of the 2026 Regular Session laws for “biometric” (1 chapter, Laws 2026, ch. 111), and on reading each hit. Keyword searching undercounts: § 626.19 uses the hyphenated “biometric-matching” and did not appear in the “biometric” result set. The conclusion stated here is about what the identified statutes do and do not require, not about the absence of a word.
This article is general legal information about Minnesota law, not legal advice, and reading it does not create an attorney–client relationship. Whether a particular biometric system is regulated depends on the entity, the workforce, the states involved, and the use, and Illinois, Texas, Washington, and other states’ laws frequently apply to Minnesota companies independently. No outcome is promised or implied.