Minnesota · House File · Ninety-Fourth Session
HF4005
Minnesota H.F. No. 4005 — A bill for an act relating to biometric data; requiring consent for collection; prohibiting sale; requiring deletion; imposing civil penalties; proposing coding for new law in Minnesota Statutes, chapter 325M

Status ● Introduced Effective N/A Passage Likelihood M

WHAT THIS BILL REGULATES · 1 REQUIREMENT TYPE

How Is This Bill Enforced

Enforcement Authority
Attorney general enforcement only. The attorney general may bring a civil action to recover civil penalties. No private right of action is created.
Private Right of Action
No private right of action. Enforcement is exclusive to the designated authority.
Penalties
Civil penalty of not more than $25,000 for each violation, recoverable by the attorney general. No private damages, injunctive relief, or attorney fees provisions are specified.

What This Bill Requires

Verbatim statutory text on the left; plain-language analysis and a per-section checklist on the right. Numbered markers cross-link to the matching checklist row.

Statutory Text
Analysis & Obligations
Minn. Stat. § 325M.40, subd. 1
Biometric data defined

subd. 1 For purposes of this section, "biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.

Subdivision 1 establishes the definition of biometric data for the entire section. The definition covers facial images, facial features, retina, iris, fingerprint, voiceprint, hand geometry, and face geometry — any of which may be used singly or in combination with other information to identify an individual. This is a broad definition that captures most common biometric identifiers used in AI and non-AI contexts alike.

Minn. Stat. § 325M.40, subd. 2
Consent required for biometric data collection
Deployer

subd. 2 1 A person is prohibited from collecting biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 from an individual unless the person receives the individual's consent to collect the biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 before the collection occurs.

Subdivision 2 establishes the bill's foundational consent requirement: no person may collect biometric data from an individual unless the individual's consent is obtained before collection occurs. The obligation applies to any person, not a defined category of covered entity, making this a broadly applicable requirement. The statute does not specify the form of consent (written vs. oral), nor does it require disclosure of the specific identifier type or purpose — a narrower notice requirement than Illinois BIPA's written-release model.

Compliance actions 1 item
1
Any person must obtain an individual's consent before collecting biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 from that individual. Consent must be received prior to the collection occurring.
D-01.8
Minn. Stat. § 325M.40, subd. 3
Prohibitions; safeguards; retention
Deployer

(1)(i)–(iv) 2 A person who obtains biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1: (1) must not sell, lease, or otherwise disclose the biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 to another person unless: (i) the individual consents to the disclosure for identification purposes in the event of the individual's disappearance or death; (ii) the disclosure completes a financial transaction that the individual requested or authorized; (iii) the disclosure is required or permitted by a federal or state law; or (iv) the disclosure is made by or to a law enforcement agency for a law enforcement purpose in response to a warrant;

(2) 3 must store, transmit, and protect from disclosure the biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 using reasonable care and in a manner that is at least as or more protective than the manner in which the person stores, transmits, and protects other confidential information the person possesses; and

(3) 4 must delete and destroy the biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 within a reasonable time, but no later than one year from the date the purpose for collecting the data expires, unless the data is maintained pursuant to a federal or state law that requires a longer retention period, in which case the biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 must be destroyed within a reasonable time frame but no later than one year from the date that the state or federal law retention period expires. If an employer collects an employee's biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 for security purposes, the purpose for collecting the data expires upon termination of the employment relationship.

Subdivision 3 imposes three distinct post-collection obligations on any person who obtains biometric data. First, a prohibition on selling, leasing, or disclosing biometric data except in four narrow circumstances: individual consent for identification in case of disappearance or death, completing an individual-authorized financial transaction, disclosure required or permitted by law, or disclosure to/by law enforcement pursuant to a warrant. Second, an affirmative data-security obligation requiring reasonable care in storage, transmission, and protection — benchmarked against how the person protects other confidential information. Third, a mandatory deletion obligation requiring destruction within a reasonable time but no later than one year after the collection purpose expires, with a carve-out for federally or state-mandated longer retention periods. The subdivision also specifies that employer-collected biometric data for security purposes must be treated as having an expired purpose upon termination of employment.

Compliance actions 3 items
2
Any person who obtains biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 must not sell, lease, or otherwise disclose it to another person, except where: (1) the individual consents to disclosure for identification purposes in the event of the individual's disappearance or death; (2) the disclosure completes a financial transaction the individual requested or authorized; (3) the disclosure is required or permitted by federal or state law; or (4) the disclosure is made by or to a law enforcement agency for a law enforcement purpose in response to a warrant.
D-01.4
3
Any person who obtains biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 must store, transmit, and protect the data from disclosure using reasonable care, in a manner that is at least as protective as the manner in which the person stores, transmits, and protects other confidential information in its possession.
D-01.12
4
Any person who obtains biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 must delete and destroy it within a reasonable time, but no later than one year from the date the purpose for collecting the data expires. If a federal or state law requires a longer retention period, the data must be destroyed within a reasonable time but no later than one year after that statutory retention period expires. For employers who collect employee biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 for security purposes, the collection purpose expires upon termination of the employment relationship.
D-01.4
Minn. Stat. § 325M.40, subd. 4
Enforcement

subd. 4 A person who violates this section is subject to a civil penalty of not more than $25,000 for each violation. The attorney general may bring an action to recover the civil penalty.

Subdivision 4 provides the bill's sole enforcement mechanism: civil penalties of up to $25,000 per violation, recoverable exclusively by the attorney general. No private right of action is created. This is a significant departure from the Illinois BIPA model, which provides a private right of action with statutory damages per violation — the absence of private enforcement substantially limits the bill's practical exposure profile for regulated entities.

Minn. Stat. § 325M.40, subd. 5
Exemptions

subd. 5 This section does not apply to voiceprint data retained by a financial institution or an affiliate of a financial institution, as those terms are defined by United States Code, title 15, section 6809.

Subdivision 5 exempts voiceprint data retained by financial institutions or their affiliates, as defined under 15 U.S.C. § 6809 (the Gramm-Leach-Bliley Act definitions). This carve-out accommodates voice-authentication systems used by banks and financial services companies for account security. The exemption is narrow — it applies only to voiceprint data and only when held by GLBA-defined financial institutions.

Passage Likelihood

Medium
Status Introduced
Chamber No passage
Committee No action
Majority party Yes
Bipartisan Yes
Prior session None

Legislative History

2026-03-05 Introduction and first reading, referred to Judiciary Finance and Civil Law
2026-03-25 Author added Feist

Entry Last Reviewed

2026-05-20
AI generated