WHAT THIS BILL REGULATES · 1 REQUIREMENT TYPE
How Is This Bill Enforced
Verbatim statutory text on the left; plain-language analysis and a per-section checklist on the right. Numbered markers cross-link to the matching checklist row.
subd. 1 For purposes of this section, "biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.
Subdivision 1 establishes the definition of biometric data for the entire section. The definition covers facial images, facial features, retina, iris, fingerprint, voiceprint, hand geometry, and face geometry — any of which may be used singly or in combination with other information to identify an individual. This is a broad definition that captures most common biometric identifiers used in AI and non-AI contexts alike.
subd. 2 1 A person is prohibited from collecting biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 from an individual unless the person receives the individual's consent to collect the biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 before the collection occurs.
Subdivision 2 establishes the bill's foundational consent requirement: no person may collect biometric data from an individual unless the individual's consent is obtained before collection occurs. The obligation applies to any person, not a defined category of covered entity, making this a broadly applicable requirement. The statute does not specify the form of consent (written vs. oral), nor does it require disclosure of the specific identifier type or purpose — a narrower notice requirement than Illinois BIPA's written-release model.
(1)(i)–(iv) 2 A person who obtains biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1: (1) must not sell, lease, or otherwise disclose the biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 to another person unless: (i) the individual consents to the disclosure for identification purposes in the event of the individual's disappearance or death; (ii) the disclosure completes a financial transaction that the individual requested or authorized; (iii) the disclosure is required or permitted by a federal or state law; or (iv) the disclosure is made by or to a law enforcement agency for a law enforcement purpose in response to a warrant;
(2) 3 must store, transmit, and protect from disclosure the biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 using reasonable care and in a manner that is at least as or more protective than the manner in which the person stores, transmits, and protects other confidential information the person possesses; and
(3) 4 must delete and destroy the biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 within a reasonable time, but no later than one year from the date the purpose for collecting the data expires, unless the data is maintained pursuant to a federal or state law that requires a longer retention period, in which case the biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 must be destroyed within a reasonable time frame but no later than one year from the date that the state or federal law retention period expires. If an employer collects an employee's biometric dataBiometric data"biometric data" means an image, description, or recording of a face, facial features, a retina, an iris, a fingerprint, a voiceprint, hand geometry, or face geometry that may be used, singly or in combination with each other or other information, to identify an individual.Minn. Stat. § 325M.40, subd. 1 for security purposes, the purpose for collecting the data expires upon termination of the employment relationship.
Subdivision 3 imposes three distinct post-collection obligations on any person who obtains biometric data. First, a prohibition on selling, leasing, or disclosing biometric data except in four narrow circumstances: individual consent for identification in case of disappearance or death, completing an individual-authorized financial transaction, disclosure required or permitted by law, or disclosure to/by law enforcement pursuant to a warrant. Second, an affirmative data-security obligation requiring reasonable care in storage, transmission, and protection — benchmarked against how the person protects other confidential information. Third, a mandatory deletion obligation requiring destruction within a reasonable time but no later than one year after the collection purpose expires, with a carve-out for federally or state-mandated longer retention periods. The subdivision also specifies that employer-collected biometric data for security purposes must be treated as having an expired purpose upon termination of employment.
subd. 4 A person who violates this section is subject to a civil penalty of not more than $25,000 for each violation. The attorney general may bring an action to recover the civil penalty.
Subdivision 4 provides the bill's sole enforcement mechanism: civil penalties of up to $25,000 per violation, recoverable exclusively by the attorney general. No private right of action is created. This is a significant departure from the Illinois BIPA model, which provides a private right of action with statutory damages per violation — the absence of private enforcement substantially limits the bill's practical exposure profile for regulated entities.
subd. 5 This section does not apply to voiceprint data retained by a financial institution or an affiliate of a financial institution, as those terms are defined by United States Code, title 15, section 6809.
Subdivision 5 exempts voiceprint data retained by financial institutions or their affiliates, as defined under 15 U.S.C. § 6809 (the Gramm-Leach-Bliley Act definitions). This carve-out accommodates voice-authentication systems used by banks and financial services companies for account security. The exemption is narrow — it applies only to voiceprint data and only when held by GLBA-defined financial institutions.