Regulatory Tracker
2026 U.S. State Biometric Privacy Law Tracker
Table-first reference for biometric-specific statutes, comprehensive privacy-law posture, and the evidence categories organizations should be prepared to produce.
Map Key
Selected State
No state selected
Select a state on the map above to see its statute, status, enforcement route and evidence focus.
Cross-Jurisdiction Evidence Baseline
Across jurisdictions, a review tests the same thing: can you show, with dated records, what you told people, what they chose, how the data was used, and how you handled their requests.
Typical artifacts requested
- •Notice language and policy versions with effective dates
- •Records showing the person agreed, or opted out, and what they agreed to
- •Consumer-rights intake and completion logs
- •Controls on the processors and vendors you pass the data to, and what they may do with it
Why category precision matters
- •Biometric-specific statutes can constrain enrollment, retention and disclosure directly
- •Comprehensive privacy laws usually apply broader sensitive-data controls instead of BIPA-style structures
- •Proposed or inactive legislation should be treated as forward-looking, not binding
- •A bill that passed last session changes what you must produce this one. Check the date on this row before you rely on it.
Defensible proof chain (conceptual)
A defensible chain connects what was disclosed, what was authorized, what happened in processing, and how retention and deletion were carried out.
Selected-State Detail
Full detail appears for states where the sources are strong enough to carry it. The rest are summarized, so nothing here claims more certainty than it has.
Related Resources
Deeper jurisdictional write-ups and operational checklists live in the Knowledge Center.
Join the update list
Get notified when primary-source links and verified fields are expanded across all 50 states.