Establishes provisions relating to release of certain liabilities for unauthorized or negligent disclosure of biometric identifiers or information
SB 448 creates a new section of Missouri law governing the handling of biometric identifiers and biometric information by private entities. The bill defines biometric identifiers to include items such as retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry, while excluding a range of medical, genetic, and ordinary identifying information. It also defines biometric information as information derived from those identifiers when used to identify an individual, and it defines confidential and sensitive information to include items like account numbers, PINs, driver’s license numbers, and Social Security numbers.
The core of the bill is a liability limitation: a private entity in possession of biometric identifiers or biometric information is not liable for damages for unauthorized or negligent disclosure if it meets specified notice, disclosure, retention, destruction, and security requirements. Those requirements include posting a warning notice, informing individuals of the purpose for collection, adopting a public retention and destruction policy, following that policy unless required otherwise by warrant or subpoena, and protecting biometric data at least as securely as other sensitive information. The bill also requires a visible warning notice or contract notice stating that the entity collects biometric data, complies with Missouri law, and is not liable for certain disclosures.
SB 448 would affect private businesses and other non-governmental entities that collect biometric data, while expressly excluding state and local government agencies, courts, and certain financial institutions subject to federal law. It also carves out several areas from its reach, including HIPAA-covered health care information, genetic testing data, certain medical imaging, organ and tissue-related information, and matters governed by other Missouri statutes and federal privacy laws. In practical terms, the bill would add a state-law framework for biometric data retention and disclosure practices, while limiting exposure to damages for entities that comply with the statute.
The overall sentiment reflected by the bill text is precautionary and business-protective rather than punitive: it seeks to encourage notice, retention limits, and data security while giving compliant private entities immunity from damages for certain disclosures. Because no committee transcripts or votes are provided, there is no recorded debate or formal vote history to indicate broader support or opposition. Based on the structure of the bill, the likely policy goal is to balance privacy concerns with liability protection for entities using biometric technologies.
The main points of contention likely center on whether the bill provides enough consumer protection, how broad the liability shield is, and whether the exemptions for health care, financial institutions, and other regulated data categories are too expansive. Privacy advocates could view the measure as insufficient because it does not create a general damages remedy and instead conditions liability protection on compliance. Businesses and other private entities that use biometric systems would likely favor the bill because it offers clearer rules and reduced litigation risk.
SB 448 would add section 537.323 to Missouri’s tort and liability laws, creating a statutory framework for private entities that collect or store biometric identifiers and biometric information. It would not broadly regulate all biometric use; instead, it would condition a liability shield on notice, public retention policies, destruction timelines, and security practices, while excluding government entities, certain health-care-related information, and financial institutions covered by federal law. The bill would therefore affect private employers, retailers, technology vendors, and other businesses using fingerprint, facial recognition, voiceprint, or similar systems, and it would limit damages claims for unauthorized or negligent disclosure when the statute’s requirements are met.
The bill’s tone is generally supportive of biometric data use by private entities, but with privacy-oriented safeguards. Its structure suggests an attempt to reassure businesses that compliance will reduce liability while also giving the public notice and retention protections. Because there are no committee transcripts or recorded votes in the provided materials, there is no direct evidence of partisan or stakeholder opposition, but the statutory design implies a compromise between privacy concerns and business liability concerns.
The likely areas of contention are the scope of the liability protection and the adequacy of the consumer protections. Privacy advocates may object that the bill does not impose a broad prohibition on disclosure or create strong enforcement mechanisms, instead offering immunity if a private entity follows notice and retention procedures. Businesses may support the bill but could be concerned about compliance costs, retention deadlines, and the requirement to publicly disclose collection and destruction policies. Additional tension may arise over the bill’s exemptions for HIPAA-covered information, genetic testing, medical imaging, and financial institutions, which narrow the statute’s reach and could leave some biometric uses outside the new protections.