Massachusetts 2025-2026 Regular Session

Massachusetts Senate Bill S43 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 1 of 1
22 SENATE DOCKET, NO. 2204 FILED ON: 1/17/2025
33 SENATE . . . . . . . . . . . . . . No. 43
44 The Commonwealth of Massachusetts
55 _________________
66 PRESENTED BY:
77 Mark C. Montigny
88 _________________
99 To the Honorable Senate and House of Representatives of the Commonwealth of Massachusetts in General
1010 Court assembled:
1111 The undersigned legislators and/or citizens respectfully petition for the adoption of the accompanying bill:
1212 An Act to protect personal biometric data.
1313 _______________
1414 PETITION OF:
1515 NAME:DISTRICT/ADDRESS :Mark C. MontignySecond Bristol and Plymouth 1 of 6
1616 SENATE DOCKET, NO. 2204 FILED ON: 1/17/2025
1717 SENATE . . . . . . . . . . . . . . No. 43
1818 By Mr. Montigny, a petition (accompanied by bill, Senate, No. 43) of Mark C. Montigny for
1919 legislation to protect personal biometric data. Advanced Information Technology, the Internet
2020 and Cybersecurity.
2121 [SIMILAR MATTER FILED IN PREVIOUS SESSION
2222 SEE SENATE, NO. 195 OF 2023-2024.]
2323 The Commonwealth of Massachusetts
2424 _______________
2525 In the One Hundred and Ninety-Fourth General Court
2626 (2025-2026)
2727 _______________
2828 An Act to protect personal biometric data.
2929 Be it enacted by the Senate and House of Representatives in General Court assembled, and by the authority
3030 of the same, as follows:
3131 1 The General Laws, as appearing in the 2022 Official Edition, are hereby amended by
3232 2inserting after chapter 93L the following chapter:-
3333 3 Chapter 93M. Biometric Information Privacy Act.
3434 4 Section 1. Definitions.
3535 5 As used in this chapter, the following words shall, unless the context clearly requires
3636 6otherwise, have the following meanings:
3737 7 "Biometric identifier" means a physiological or biological characteristic that is used by or
3838 8on behalf of a private entity, singly or in combination, to identify, or assist in identifying, an
3939 9individual, including, but not limited to a retina or iris scan, fingerprint, voiceprint, pattern of 2 of 6
4040 10gait or movement, or scan of hand or face geometry. Biometric identifiers do not include writing
4141 11samples, written signatures, photographs, human biological samples used for valid scientific
4242 12testing or screening, demographic data, tattoo descriptions, or physical descriptions such as
4343 13height, weight, hair color, or eye color. Biometric identifiers do not include donated organs or
4444 14tissues or blood or serum stored on behalf of recipients or potential recipients of living or
4545 15cadaveric transplants and obtained or stored by a federally designated organ procurement
4646 16agency. Biometric identifiers do not include information captured from a patient in a health care
4747 17setting or information collected, used, or stored for health care treatment, payment, or operations
4848 18under the federal Health Insurance Portability and Accountability Act of 1996. Biometric
4949 19identifiers do not include an X-ray, roentgen process, computed tomography, MRI, PET scan,
5050 20mammography, or other image or film of the human anatomy used to diagnose, prognose, or
5151 21treat an illness or other medical condition or to further validate scientific testing or screening.
5252 22 "Biometric information" means any information, regardless of how it is captured,
5353 23converted, stored, or shared, based on an individual's biometric identifier used to identify an
5454 24individual. Biometric information does not include information derived from items or procedures
5555 25excluded under the definition of biometric identifiers.
5656 26 "Commercial Establishment" means a place of entertainment, a retail store, or a food and
5757 27drink establishment.
5858 28 "Confidential and sensitive information" means personal information that can be used to
5959 29uniquely identify an individual or an individual's account or property. Examples of confidential
6060 30and sensitive information include, but are not limited to, a genetic marker, genetic testing 3 of 6
6161 31information, a unique identifier number to locate an account or property, an account number, a
6262 32PIN number, a pass code, a driver's license number, or a social security number.
6363 33 "Private entity" means any individual, partnership, corporation, limited liability company,
6464 34association, or other group, however organized.
6565 35 "Written consent " means informed written consent.
6666 36 Section 2. Collection, Retention, Destruction, and Disclosure of Biometric Information.
6767 37 (a) A private entity in possession of biometric identifiers or biometric information must
6868 38develop a written policy, made available to the person from whom biometric information is to be
6969 39collected or was collected, establishing a retention schedule and guidelines for permanently
7070 40destroying biometric identifiers and biometric information when the initial purpose for collecting
7171 41or obtaining such identifiers or information has been satisfied or within 1 year of the individual's
7272 42last interaction with the private entity, whichever occurs first. Absent a valid order, warrant, or
7373 43subpoena issued by a court of competent jurisdiction or a local or federal governmental agency, a
7474 44private entity in possession of biometric identifiers or biometric information must comply with
7575 45its established retention schedule and destruction guidelines.
7676 46 (b) No private entity may collect, capture, purchase, receive through trade, or otherwise
7777 47obtain a person's or a customer's biometric identifier or biometric information, unless it first:
7878 48 (1) informs the subject or the subject's legally authorized representative in writing that a
7979 49biometric identifier or biometric information is being collected or stored; 4 of 6
8080 50 (2) informs the subject or the subject's legally authorized representative in writing of the
8181 51specific purpose and length of term for which a biometric identifier or biometric information is
8282 52being collected, stored, and used; and
8383 53 (3) receives written consent executed by the subject of the biometric identifier or
8484 54biometric information or the subject's legally authorized representative. Written consent may be
8585 55obtained by electronic means.
8686 56 (c) No private entity in possession of a biometric identifier or biometric information may
8787 57sell, lease, trade, or otherwise profit from a person's or a customer's biometric identifier or
8888 58biometric information.
8989 59 (d) No private entity in possession of a biometric identifier or biometric information may
9090 60disclose, redisclose, or otherwise disseminate a person's or a customer's biometric identifier or
9191 61biometric information unless:
9292 62 (1) the subject of the biometric identifier or biometric information or the subject's legally
9393 63authorized representative provides written consent to the disclosure or redisclosure;
9494 64 (2) the disclosure or redisclosure completes a financial transaction requested or
9595 65authorized by the subject of the biometric identifier or the biometric information or the subject's
9696 66legally authorized representative;
9797 67 (3) the disclosure or redisclosure is required by state or federal law or municipal
9898 68ordinance; or
9999 69 (4) the disclosure is required pursuant to a valid warrant or subpoena issued by a court of
100100 70competent jurisdiction. 5 of 6
101101 71 (e) A private entity in possession of a biometric identifier or biometric information shall:
102102 72 (1) store, transmit, and protect from disclosure all biometric identifiers and biometric
103103 73information using the reasonable standard of care within the private entity's industry; and
104104 74 (2) store, transmit, and protect from disclosure all biometric identifiers and biometric
105105 75information in a manner that is the same as or more protective than the manner in which the
106106 76private entity stores, transmits, and protects other confidential and sensitive information.
107107 77 (f) No commercial establishment shall use a person's or a customer's biometric identifier
108108 78or biometric information to identify them.
109109 79 Section 3. Right of Action.
110110 80 (a) Any person aggrieved by a violation of this chapter shall have a cause of action
111111 81pursuant to the procedures set forth in chapter 93A. Damages pursuant to any said action shall
112112 82be no less than $5,000 per violation or actual damages suffered, whichever is greater, or up to
113113 83three but not less than two times such amount if the court finds that the violation was a willful or
114114 84knowing act. Damages may also include attorneys’ fees and costs.
115115 85 (b) The attorney general may bring an action in the name of the commonwealth pursuant
116116 86to the procedures set forth in chapter 93A upon any violation or suspected violation of this
117117 87chapter. Damages pursuant to any said action shall be no less than $5,000 per violation or actual
118118 88damages suffered, whichever is greater, or up to three but not less than two times such amount if
119119 89the court finds that the violation was a willful or knowing act.
120120 90 Section 4. Construction. 6 of 6
121121 91 (a) Nothing in this chapter shall be construed to impact the admission or discovery of
122122 92biometric identifiers and biometric information in any action of any kind in any court, or before
123123 93any tribunal, board, or agency.
124124 94 (b) Nothing in this chapter shall be construed to conflict with the federal Health Insurance
125125 95Portability and Accountability Act of 1996 and the rules promulgated under said Act.