LB204 would create the “Biometric Autonomy Liberty Law,” a new state framework governing the collection, possession, use, disclosure, retention, and destruction of biometric data. The bill defines biometric data broadly to include fingerprints, voiceprints, retina and iris images, and other unique biological patterns used to identify an individual, while excluding certain photographs, recordings, and health-care-related information. It declares biometric data to be the property of the individual from whom it was collected and allows that individual to consent to its use or transfer.
The bill generally prohibits private entities from requiring people to submit to implantable devices or wearables that collect biometric data, from compelling collection of biometric data, and from selling, leasing, trading, or using biometric data without prior written consent. It also requires written consent forms to include clear warnings, and it imposes retention and destruction rules, including a default requirement to permanently destroy biometric data after the purpose is satisfied, after one year of inactivity, or when consent is withdrawn, unless longer retention is authorized. The bill creates exceptions for law enforcement, security purposes, court orders, subpoenas, criminal and civil proceedings, and certain disclosures needed to prevent or investigate safety concerns or public health issues.
LB204 would also give the Attorney General authority to investigate violations, issue subpoenas, and seek civil actions for direct economic damages and injunctive relief. A violation would be treated as a consumer protection violation, and the bill includes a 60-day cure period before an action may proceed. It further states that waivers of the law are void unless made with written consent, and it specifies that the law does not affect admissibility of biometric evidence in legal proceedings.
The bill’s impact on state law would be significant because it would impose new privacy, consent, security, and retention obligations on private entities and public entities handling biometric data in Nebraska, while also creating a new enforcement mechanism through the Attorney General. It expressly carves out several areas where the law would not apply, including certain federal privacy regimes, emergency medical care, DMV facial recognition for fraud detection, financial institutions and GLBA-covered data, and biometric data collected for security purposes. It also states that the law does not apply to health-care treatment, payment, or operations information already covered by HIPAA.
The general sentiment reflected in the bill text is strongly protective of individual privacy and skeptical of biometric surveillance and commercial use of biometric data. There is no committee transcript or vote record provided showing debate or opposition, but the structure of the bill suggests a policy preference for limiting biometric collection and giving individuals control over their data. Likely points of contention would include the breadth of the definition of biometric data, the scope of the private-entity restrictions, the property-rights framing of biometric data, and the practical burdens of consent, retention, and destruction requirements on businesses and public entities.
LB204 would add a new chapter of Nebraska law regulating biometric data and would create enforceable duties for private entities and some public entities regarding collection, storage, transfer, disclosure, and destruction of biometric identifiers. It would give individuals ownership-like control over their biometric data, require written consent for most collection and use, prohibit coercive collection practices, and authorize Attorney General enforcement and consumer-protection remedies. The bill also creates multiple statutory exemptions and clarifies that it does not override certain existing state and federal privacy, health, financial, law-enforcement, and evidentiary rules.
The bill is framed in strongly privacy-protective terms, emphasizing identity theft risk, public concern about biometric surveillance, and the need to regulate emerging technology. Because no committee transcript or vote history is provided, there is no recorded floor or committee sentiment to summarize beyond the bill’s text. Based on the drafting, the measure appears intended to appeal to privacy advocates and to limit biometric data practices rather than to expand them.
Likely areas of contention include whether biometric data should be treated as the property of the individual, whether the consent and destruction rules are too restrictive for businesses and public agencies, and whether the bill’s exceptions are broad enough for law enforcement, security, health care, and financial services. The bill’s carveouts for HIPAA, GLBA, DMV fraud detection, and security purposes suggest anticipated pushback from regulated industries and government users, while privacy advocates would likely focus on ensuring the exceptions do not swallow the rule. The 60-day cure period and the limitation of civil actions to direct economic damages may also be debated as either necessary safeguards or insufficient remedies.