A widespread assumption holds that Minnesota has its own biometric privacy law, one that forces businesses to obtain informed consent before scanning a fingerprint or a face, gives individuals the right to access and delete that data, and lets them sue a company that gets it wrong. Minnesota has enacted no such statute. The state has no standalone biometric privacy act comparable to Illinois’s Biometric Information Privacy Act. The only Minnesota law that addresses business use of biometric data is the Minnesota Consumer Data Privacy Act, which treats biometric data as one category of sensitive data inside a broader consumer-privacy framework rather than as the subject of a dedicated biometric regime.
For a Minnesota business, that distinction changes the practical picture. The Minnesota Consumer Data Privacy Act, Minn. Stat. §§ 325M.10 to 325M.21, reaches only organizations that meet defined size thresholds, it protects consumers acting in their individual capacity rather than employees, and it is enforced by the Attorney General alone. There is no lawsuit by the individual whose data was collected. Knowing where the Act applies, and where it does not, is what separates a sensibly scoped biometric-data practice from one built around obligations that Minnesota law does not actually impose.
Key Takeaways
- Minnesota has not enacted a biometric-specific privacy law. Businesses sometimes assume the state mirrors Illinois’s Biometric Information Privacy Act. It does not.
- The only Minnesota statute that addresses biometric data is the Minnesota Consumer Data Privacy Act, which classifies biometric data used to identify a person as sensitive data.
- The Act applies only to controllers that meet its size thresholds, and only to data about consumers, a term that by definition excludes people acting in an employment or commercial context.
- Processing a consumer’s sensitive data requires that consumer’s consent, but this rule does not reach employee biometric data or businesses that fall below the thresholds.
- Enforcement belongs to the Attorney General, who may seek a civil penalty of not more than $7,500 per violation. The Act creates no private right of action, and Minnesota’s breach-notification statute does not count biometric data among the elements that trigger notice.
The Governing Reality: Minnesota Has No Standalone Biometric Privacy Law
Minnesota regulates the privacy of personal data, but it has never passed a law devoted specifically to biometric identifiers. That absence is the single most important fact for any business evaluating its obligations.
The comparison people have in mind usually comes from Illinois. Illinois enacted a dedicated Biometric Information Privacy Act, a statute widely known for requiring informed consent before a private business collects biometric identifiers, for imposing retention and destruction requirements, and for allowing individuals to sue for violations. Minnesota has no counterpart. A business cannot be sued in Minnesota under a biometric privacy act because Minnesota has not created one.
What Minnesota does have is the Minnesota Consumer Data Privacy Act, which took effect on July 31, 2025. It is a general consumer-privacy statute, and biometric data enters the picture only as one item on its list of sensitive data. The Act does not single out biometric identifiers for special treatment beyond that classification, and it applies only within the boundaries the statute sets for who must comply and whose data is protected.
How Minnesota’s Consumer Data Privacy Act Treats Biometric Data
Under the Consumer Data Privacy Act, biometric data means “data generated by automatic measurements of an individual’s biological characteristics, including a fingerprint, a voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual.” Minn. Stat. § 325M.11. The definition has an important limit. Biometric data “does not include” a digital or physical photograph, an audio or video recording, or data generated from a photograph or recording, “unless the data is generated to identify a specific individual.” A security photograph or a recording, standing alone, is therefore not biometric data under the Act. It becomes biometric data only when a business processes it to identify a particular person, as with facial-recognition matching.
Biometric data that is used to identify an individual is classified as sensitive data. The Act defines sensitive data to include “the processing of biometric data or genetic information for the purpose of uniquely identifying an individual.” That classification is what triggers the Act’s one biometric-specific obligation: a controller “may not process sensitive data concerning a consumer without obtaining the consumer’s consent.” Consent under the Act must be a “freely given, specific, informed, and unambiguous indication of the consumer’s wishes,” and acceptance of a broad terms-of-use document does not qualify.
Two conditions have to be met before that consent requirement applies. The business must be a controller that meets the Act’s size thresholds, and the person whose biometric data is at issue must be a consumer as the Act defines that term. Both conditions carry real limits.
Who the Act Covers, and Who It Does Not
The Consumer Data Privacy Act does not apply to every business. It reaches only legal entities that conduct business in Minnesota, or that target products or services to Minnesota residents, and that also cross one of two size thresholds: controlling or processing the personal data of 100,000 or more consumers during a calendar year, or deriving over 25 percent of gross revenue from the sale of personal data while controlling or processing the personal data of 25,000 or more consumers. Minn. Stat. § 325M.12. A business that meets neither threshold is generally outside the Act. Small businesses, as defined by the United States Small Business Administration, are expressly excluded, with one narrow exception: a small business may not sell a consumer’s sensitive data without prior consent.
The Act also protects a specific group of people. It defines a consumer as “a natural person who is a Minnesota resident acting only in an individual or household context,” and it states plainly that a consumer “does not include a natural person acting in a commercial or employment context.” Employees are therefore not consumers when it comes to their workplace biometric data. The Act reinforces this with a separate exclusion for data collected in the course of a person acting as a job applicant, employee, owner, director, officer, or contractor of a business, where the data is used solely within that role.
The practical consequence is significant. A fingerprint time clock, a hand-geometry scanner at a warehouse door, or facial recognition used for employee building access falls outside the Consumer Data Privacy Act, because the people being scanned are employees rather than consumers. The Act’s consent requirement is aimed at consumer relationships, not the employment relationship.
Consumer Rights, Enforcement, and Penalties
For the consumers the Act does protect, it provides a set of data rights: the right to confirm and access the personal data a controller processes, to correct inaccurate data, to delete data, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Minn. Stat. § 325M.14. These rights run to consumers against the controllers that process their data. They are not workplace rights, and they do not give an employee a statutory claim to access or delete biometric data an employer collects for employment purposes.
Enforcement is centralized. The Attorney General may bring a civil action to enforce the Act, and a violator “is subject to an injunction and liable for a civil penalty of not more than $7,500 for each violation.” Minn. Stat. § 325M.20. The same section is explicit that the Act creates no private lawsuit: “Nothing in sections 325M.10 to 325M.21 establishes a private right of action.” An individual who believes a business mishandled biometric data cannot sue under this statute. The recourse is a complaint to the Attorney General, who decides whether to act.
That is a meaningful contrast with the Illinois model, where private lawsuits have driven most of the litigation. In Minnesota, the enforcement risk for a covered business runs to the state, not to a class of individual plaintiffs.
Biometric Data and Minnesota’s Breach-Notification Law
A separate question is whether a business must notify people when biometric data is exposed in a data breach. Minnesota’s breach-notification statute, Minn. Stat. § 325E.61, requires a business to notify affected residents when unencrypted personal information is acquired by an unauthorized person. The statute defines personal information narrowly. It means a person’s first name or first initial and last name in combination with a Social Security number, a driver’s license or Minnesota identification card number, or a financial account number together with any access code that would permit access to the account.
Biometric data is not on that list. A breach involving only biometric identifiers does not, by itself, trigger the notice requirement, because the statute’s definition of personal information does not include biometric data. That said, biometric data is often stored alongside a person’s name and other identifiers, and if a breach exposes one of the listed data elements, the statute’s notice obligation attaches to that element regardless of the biometric data. The point is narrow but useful: in Minnesota, biometric data on its own is not a breach-notification trigger.
Businesses Operating in More Than One State
Minnesota law is not the only law a business has to think about. A company that collects biometric data from residents of other states may be subject to those states’ requirements, and some states have enacted biometric-specific statutes or broader privacy laws that address biometric identifiers. Illinois is the prominent example, with a dedicated biometric statute that imposes consent and retention duties and allows private suits. A Minnesota business with customers, users, or employees in other states should evaluate its obligations state by state rather than assume that Minnesota’s comparatively light treatment governs everywhere it operates.
The Misconception, Restated Correctly
The inverted rule sounds authoritative: Minnesota requires informed consent before any business collects biometric data, gives individuals rights to access and delete it, and exposes companies to private lawsuits and breach-notification duties when they get it wrong. Almost none of that describes Minnesota law.
Minnesota has no standalone biometric privacy act. The one statute that addresses biometric data, the Consumer Data Privacy Act, treats it as a category of sensitive data, requires consent only from controllers that meet the size thresholds and only as to consumers, excludes employees and small businesses from most of its reach, and is enforced by the Attorney General with no private right of action. Minnesota’s breach-notification law does not list biometric data as a trigger. What remains true is narrower and more specific than the common assumption, and it is the version a business should plan around.
Practical Guidance
- Confirm whether the Act even applies. Before assuming any Minnesota obligation, determine whether the business meets the Consumer Data Privacy Act’s size thresholds and whether the biometric data concerns consumers or employees. Many Minnesota businesses fall outside the Act entirely.
- Do not rely on an Illinois-style rulebook. Minnesota has no biometric statute imposing written consent, fixed retention schedules, or private lawsuits. Compliance steps built on those assumptions solve for a law Minnesota has not enacted.
- Treat consent and retention as prudence, not mandate. For most Minnesota businesses, obtaining clear consent before collecting biometric data and adopting a written retention and deletion policy are sound practices that build trust and reduce risk, even though the Act does not require them outside its scope.
- Vet vendors and secure the data. Whether or not the Act applies, biometric identifiers are sensitive, permanent, and attractive to attackers. Reasonable security, access controls, and diligence on any biometric technology vendor protect the business regardless of statutory coverage.
- Map obligations across every state where you operate. If the business collects biometric data from residents of other states, evaluate those states’ laws, because other states impose requirements that Minnesota does not.
Frequently Asked Questions
Does Minnesota have a biometric privacy law like Illinois’s BIPA?
No. Minnesota has not enacted a standalone biometric privacy act. Illinois’s Biometric Information Privacy Act is a separate Illinois statute, and its consent, retention, and private-lawsuit provisions are features of Illinois law, not Minnesota law. The only Minnesota statute that addresses biometric data is the Minnesota Consumer Data Privacy Act, which treats biometric data as one category of sensitive data.
Must a Minnesota employer get consent before collecting an employee’s biometric data?
Not under the Consumer Data Privacy Act. That Act protects consumers, and it expressly excludes people acting in an employment context, so an employee’s workplace fingerprint or facial scan is outside its consent requirement. Obtaining consent and adopting a clear policy remain sensible practices, but they are prudence rather than a mandate the Consumer Data Privacy Act imposes on the employment relationship.
Does the Consumer Data Privacy Act apply to every Minnesota business that uses biometric data?
No. The Act applies only to entities that meet its size thresholds, which turn on processing the personal data of large numbers of consumers or on deriving significant revenue from selling personal data. Minn. Stat. § 325M.12. Small businesses are largely excluded. A business below the thresholds generally has no obligation under the Act, whether or not it uses biometric data.
Can an individual sue a Minnesota business for mishandling biometric data?
Not under the Consumer Data Privacy Act. The Act states that nothing in it establishes a private right of action. Minn. Stat. § 325M.20. Enforcement rests with the Attorney General, who may seek an injunction and a civil penalty of not more than $7,500 per violation. An individual’s recourse is to complain to the Attorney General rather than to file suit under the Act.
Does a biometric-data breach trigger Minnesota’s breach-notification law?
Not by itself. Minnesota’s breach-notification statute defines the personal information that triggers notice as a name combined with a Social Security number, a driver’s license or state identification number, or a financial account number with an access code. Minn. Stat. § 325E.61. Biometric data is not among those elements, so a breach limited to biometric identifiers does not on its own require notification, though a breach that also exposes a listed element does.