Skip to main content

Biometric Data Collection at Work in Georgia: Your Rights

Last reviewed: June 2026

Quick Answer

Georgia does not have a state law restricting employer collection of biometric data like fingerprints, facial recognition, or iris scans. Unlike California and Illinois, which have strict biometric privacy laws, Georgia employers may collect biometric information without explicit written consent. However, employers must still comply with federal laws such as the Fair Credit Reporting Act (15 U.S.C. § 1681) when using biometrics for background checks, and they must notify employees if biometric data is breached under Georgia's Data Breach Notification Law (O.C.G.A. § 10-1-670).

Key Facts

  • Georgia has no comprehensive biometric privacy law restricting employer collection of biometric data.
  • Federal BIPA does not apply in Georgia; employers have broad discretion to collect biometrics.
  • Employers may collect fingerprints, facial scans, and iris data without explicit consent requirements.
  • Georgia employers must comply with general data security and privacy standards under state law.
  • Employees have limited statutory remedies if biometric data is mishandled or breached.

Federal Law: The Baseline

Federal law does not comprehensively regulate employer collection of biometric data. The primary federal framework is the Gramm-Leach-Bliley Act (GLBA), 15 U.S.C. § 6801, which requires financial institutions to safeguard nonpublic personal information, including biometrics. The Fair Credit Reporting Act (FCRA), 15 U.S.C. § 1681 et seq., applies when employers use biometric data as part of background checks; employers must obtain written consent and provide disclosures before using consumer reports that include biometric analysis.

The Health Insurance Portability and Accountability Act (HIPAA), 45 U.S.C. § 1301 et seq., protects biometric health data in healthcare settings. The Americans with Disabilities Act (ADA), 42 U.S.C. § 12101 et seq., prohibits using biometric collection to discriminate against employees with disabilities, though it does not prohibit collection itself. The Equal Employment Opportunity Commission (EEOC) enforces ADA biometric protections, while the Federal Trade Commission (FTC) enforces FCRA and data security standards under Section 5 of the FTC Act, 15 U.S.C. § 45.

Federal courts have not established a constitutional right to biometric privacy, though some states have enacted their own biometric privacy laws. Employers in non-biometric-privacy states like Georgia face fewer restrictions at the federal level, provided they comply with FCRA disclosure requirements and maintain reasonable data security.

Georgia Law: What's Different

Georgia does not have a dedicated biometric privacy statute comparable to the Illinois Biometric Information Privacy Act (BIPA) or California Consumer Privacy Act (CCPA). This means Georgia employers enjoy broad discretion to collect, store, and use employee biometric data without explicit statutory consent requirements specific to biometrics.

However, Georgia law does impose obligations on employers handling any sensitive employee data. The Georgia Data Breach Notification Law (O.C.G.A. § 10-1-670 et seq.) requires employers to notify employees if a breach of security compromises "personal information," which includes biometric identifiers. Notification must occur "without unreasonable delay," generally interpreted as within 30 days. This law applies to all employers operating in Georgia, regardless of size, and creates a private right of action if an employer fails to notify.

Under the Georgia Payment of Wages Law (O.C.G.A. § 34-6-2), employers must maintain accurate employee records, which could include biometric time and attendance systems. Employers using biometric timekeeping must ensure accuracy and must comply with wage payment requirements. Georgia also recognizes common law privacy torts, including intrusion upon seclusion under Georgia common law, though this provides limited protection because employers generally have legitimate business reasons for biometric collection.

Georgia employers are not required to provide notice or obtain written consent before collecting biometric data, unlike states with biometric privacy laws. However, employers must comply with the FCRA if biometric data influences hiring decisions, and they must adhere to general data security standards. The absence of Georgia-specific biometric privacy law means remedies are limited to federal FCRA violations, data breach notification failures, or common law tort claims—a significantly weaker framework than exists in California, Illinois, or Texas.

Key Numbers & Thresholds

Georgia Data Breach Notification Law: notification must occur 'without unreasonable delay,' generally interpreted as within 30 days of discovery. No employee count threshold applies; law covers all Georgia employers. No minimum amount of biometric data triggers notification; any unauthorized access to personal information requires notice. Federal FCRA: written consent required before using biometric consumer reports for hiring; applies to all employers. No Georgia-specific biometric consent or retention timeline exists.

Exceptions & Special Cases

Georgia law contains no biometric-specific exceptions to employer collection rights. However, several general exceptions and defenses apply:

Lawful Business Purpose: Employers may collect biometric data for legitimate business reasons, including time and attendance tracking, physical security access control, payroll administration, identity verification, and fraud prevention. Courts are unlikely to impose liability if the collection serves a demonstrable business need.

FCRA Exemption for Non-Employment Reports: If biometric data is collected for purposes other than hiring, promotion, or firing decisions (e.g., facility access), the FCRA consent requirement may not apply. Employers using biometrics solely for physical security are not subject to FCRA disclosure requirements.

ADA Intersection: While the ADA does not prevent biometric collection, employers cannot use biometric data to discriminate based on disability. For example, using facial recognition to identify employees with visible disabilities and excluding them from certain roles violates the ADA, but the collection itself is not prohibited.

Consent Defense: Although Georgia does not require advance biometric consent, employers who obtain employee consent are protected from intrusion upon seclusion claims under Georgia common law. This is a practical, not statutory, defense.

Data Security Harbor: Georgia does not provide a safe harbor for data breaches, but employers that implement reasonable security measures may have stronger defenses in breach notification litigation and are less likely to trigger notification obligations if the data was reasonably protected.

Union Exceptions: If employees are unionized, the collective bargaining agreement may restrict biometric collection or require notice and negotiation. This is a contractual exception, not a statutory one.

What to Do If Your Rights Are Violated

Step 1: Document Everything. If you believe your employer unlawfully collected or misused your biometric data, document the dates, types of biometric data collected (fingerprints, facial scan, iris scan, voice), how it was collected, who had access, and any written policies or consent forms provided. Retain emails, handbooks, consent agreements, and any evidence of data breach or misuse. Keep records of when you first learned biometric data was collected and how you discovered it. This documentation is essential for proving the employer's conduct and for any future legal action.

Step 2: Review Employer Policy and Raise Internal Concerns. Check your employee handbook, onboarding documents, and any signed agreements for biometric data language. If your employer has a compliance or human resources department, submit a written complaint requesting information about what biometric data is being collected, how it is stored, how long it is retained, who has access, and whether consent was required. Request a copy of the company's data security policy. In Georgia, there is no legal requirement for employers to respond, but internal documentation of your complaint is useful for establishing awareness and intent if litigation becomes necessary.

Step 3: Determine Which Agency to File With. If biometric data was collected as part of a background check for hiring or promotion, file a complaint with the Federal Trade Commission (FTC) for FCRA violations at reportidentitytheft.ftc.gov or by calling 1-877-IDTHEFT (1-877-438-4338). If a data breach occurred involving biometric information, file a complaint with the Georgia Attorney General's Consumer Protection Division at oag.state.ga.us or call (404) 656-3300. If the employer is a federal contractor, file with the Office of Federal Contract Compliance Programs (OFCCP) at www.dol.gov/agencies/ofccp if ADA or other discrimination is involved. There is no state-specific biometric privacy agency in Georgia; federal remedies are your primary avenue.

Step 4: Understand the Investigation Process. The FTC investigates FCRA complaints by contacting the employer and requesting documentation of consent, disclosures, and data handling procedures. The investigation typically takes 30-60 days. The Georgia Attorney General's office investigates data breach notification failures by determining whether the employer provided timely notice and whether reasonable security was in place; this process may take 60-90 days. If the investigation finds a violation, the FTC can pursue enforcement, but no private right of action exists for FCRA violations. The Georgia Data Breach Notification Law creates a private right of action if notice was not provided; injured employees may sue for damages in state court.

Step 5: Consult an Attorney. Because Georgia has no dedicated biometric privacy statute, consult a lawyer specializing in data privacy or employment law to evaluate your specific situation. An attorney can assess whether a federal FCRA violation occurred, whether a state data breach notification violation applies, whether the HIPAA or ADA provides protection, or whether a common law intrusion upon seclusion claim is viable. Expect to provide the attorney with copies of all consent forms, company policies, breach notification letters (if any), and documentation of the type and use of biometric data collected. If you have been discriminated against based on biometric data, consult an employment discrimination attorney who can evaluate ADA or Title VII claims.

Relevant Agency

Georgia Attorney General, Consumer Protection Division

https://oag.state.ga.us/consumer-protection

(404) 656-3300

If you need guidance navigating Georgia's biometric data laws or have experienced unauthorized data collection, consider consulting an employment attorney who specializes in privacy and data protection.

Get notified when employment law changes

Laws change every year. We'll email you when something changes that affects this topic.

Frequently Asked Questions

Does my Georgia employer need my written consent before collecting fingerprints or facial recognition data?

No. Georgia does not have a biometric privacy law requiring written consent before employers collect biometric data such as fingerprints, facial scans, or iris recognition. Unlike California and Illinois, Georgia employers may collect biometrics without explicit consent, provided they comply with federal laws. However, if the biometric data is used in a background check for hiring or promotion decisions, the Fair Credit Reporting Act (FCRA) requires the employer to provide written notice and obtain consent before running the background check. If your employer collects biometrics for time and attendance tracking or physical security access (not hiring decisions), no FCRA consent is required. It is good practice for employers to disclose biometric collection in the employee handbook, but Georgia law does not mandate this. If an employer uses biometric data deceptively or without any legitimate business purpose, you may have a common law intrusion upon seclusion claim, though this is difficult to prove in Georgia courts.

What happens if my employer loses or breaches my biometric data in Georgia?

If your employer's biometric data is breached, Georgia's Data Breach Notification Law (O.C.G.A. § 10-1-670) requires the employer to notify you without unreasonable delay, generally interpreted as within 30 days of discovery. The notification must describe what biometric information was compromised, when the breach occurred, what steps the employer is taking to address it, and what precautions you should take. If the employer fails to provide timely notice, you can sue for damages in Georgia state court. You do not need to prove actual financial harm; the failure to notify itself is a violation. The damages can include costs of credit monitoring, identity theft recovery, emotional distress, and attorney fees. You should also file a complaint with the Georgia Attorney General at oag.state.ga.us. If the breach exposed biometric data collected for a background check, you may also file a complaint with the Federal Trade Commission (FTC) for failure to maintain FCRA compliance under data security requirements.

Can my Georgia employer use facial recognition to monitor me at work?

Yes, Georgia law does not prohibit employers from using facial recognition to monitor employees at work, provided the monitoring occurs in non-private areas (e.g., not in bathrooms or locker rooms). However, the employer should have a legitimate business purpose, such as security, time tracking, or fraud prevention. If facial recognition is used to track protected characteristics—such as identifying employees with disabilities, racial minorities, or other protected classes to disadvantage them—it may violate the Americans with Disabilities Act (ADA) or Title VII of the Civil Rights Act. For example, if an employer uses facial recognition to identify employees with visible disabilities and prevent them from working customer-facing roles, this is discriminatory and illegal. Georgia's common law right to privacy (intrusion upon seclusion) provides limited protection; courts allow employer monitoring for legitimate business purposes even without consent. If you believe facial recognition is being used to discriminate against you, file a complaint with the Equal Employment Opportunity Commission (EEOC) at eeoc.gov or (800) 669-4000 within 180 days of the discriminatory conduct.

How long can my Georgia employer keep my biometric data on file?

Georgia law does not specify a retention limit for biometric data. The employer determines how long to retain fingerprints, facial scans, or iris data based on business needs. If the biometric data is part of a background check, the Fair Credit Reporting Act (FCRA) does not mandate destruction, but the employer must maintain reasonable security for as long as the data is kept. Best practice is for employers to delete biometric data once it is no longer needed for the original purpose (e.g., when an employee leaves the company or the timekeeping system is upgraded). Some employers retain biometric data indefinitely for security purposes, which is legally permissible in Georgia unless a breach occurs, at which point the employer must notify you. If you want your biometric data deleted, you can request it from your employer, but Georgia law does not require employers to comply. In contrast, California's CCPA requires deletion upon request, and Illinois's BIPA requires destruction within 3 years of collection. If your employer breaches your biometric data, the retention period is relevant to damages; longer retention with poor security strengthens a breach notification claim.

What is my remedy if my Georgia employer collects biometric data unlawfully?

Georgia's limited biometric privacy protections mean your remedies are narrower than in other states. Your primary remedy is a data breach notification claim under O.C.G.A. § 10-1-670 if the employer failed to notify you of a breach within a reasonable time (generally 30 days). You can sue for actual damages (e.g., costs of credit monitoring, identity theft recovery) and may recover attorney fees. If biometric data was collected as part of a background check, you can file an FCRA complaint with the Federal Trade Commission (FTC) if the employer failed to provide proper disclosures and consent; however, the FCRA does not provide a private right of action, so the FTC must pursue enforcement on your behalf. If biometric collection or use involves discrimination based on a protected characteristic (race, disability, gender, age, religion, national origin, or sexual orientation), file a charge with the Equal Employment Opportunity Commission (EEOC) at eeoc.gov or (800) 669-4000 within 180 days of the discriminatory conduct; the EEOC can investigate and sue on your behalf. You may also pursue a common law intrusion upon seclusion claim in Georgia state court if biometric collection was highly offensive to a reasonable person and not justified by a legitimate business purpose, though this is difficult to prove. Consult an employment attorney to evaluate which remedy applies to your situation.

Related Topics in Georgia

See biometric data collection laws in every state →

Sources & References

  • 15 U.S.C. § 1681 et seq. (Fair Credit Reporting Act)Governs use of biometric data in background checks; applies nationwide
  • O.C.G.A. § 34-6-2 (Georgia Payment of Wages Law)Requires employers to maintain records; does not address biometric collection
  • O.C.G.A. § 10-1-670 et seq. (Georgia Data Breach Notification Law)Requires notification if biometric data is compromised; applies to all employers

Informational only. Not legal advice. Laws change — always verify with a licensed attorney.

Editorial standards: This guide is reviewed against primary government sources and cites 3 statutes. Last reviewed June 2026. Scheduled for re-verification by June 2027.

See our editorial policy for how content is created and verified, or report an inaccuracy.