Minnesota just did something genuinely good and genuinely strange in the same law.

The good part: as of July 31, 2025, Minnesota's Consumer Data Privacy Act treats your biometric data — your faceprint — as "sensitive data" that a business cannot process without your consent. If a retailer wants to run facial recognition on you as you walk the aisles, it has to get permission first. That's real protection, and most states don't have it.

The strange part: the same law exempts government entities entirely. So the private company at the mall needs your consent to scan your face — but the police department running facial recognition on that identical face need nothing at all. The strongest face-privacy right Minnesota has ever passed stops precisely at the government's door, which is exactly where the most consequential face-scanning happens.

I'm a consumer-protection lawyer, and I'll tell you plainly: that's backwards. The entity that can arrest you should be more constrained than the entity that can sell you a sweater, not less.

Who's actually scanning faces in Minnesota

This isn't hypothetical. The documented users:

And here's the accountability gap in a single fact: in February 2021, the Minneapolis City Council voted 13–0 to ban the police department from using facial recognition, Clearview specifically. Good. But the Hennepin County Sheriff's Office has its own Clearview relationship and isn't covered by a city ban. So you can be scanned by the county in the same city where the police are forbidden to do it. A patchwork of one-city bans against a countywide, statewide technology is not a policy. It's a suggestion with gaps you can drive a squad car through.

Why this is dangerous even if you've done nothing wrong

Facial recognition doesn't just watch — it accuses, and it accuses unevenly. The federal government's own testing lab, NIST, found in a landmark study that many facial-recognition algorithms produce false matches 10 to 100 times more often for Asian and African American faces than for white faces, with Black women misidentified most of all in database searches.

That's not an abstraction. At least six Americans have been wrongfully arrested on facial-recognition misidentifications — the first documented, Robert Williams, was arrested in front of his family in Detroit in January 2020 for a crime he didn't commit, fingered by a bad algorithmic match. A tool that's wrong more often about Black faces, pointed by police at a population, produces exactly the kind of injustice the technology's boosters swear it prevents.

And it's not only the cameras. Federal investigators have been able to search state driver's-license photo databases — the GAO found the FBI's face unit could reach 21 states' DMV photos, more than 640 million images. Every Minnesotan who got a license photo may be in a searchable lineup they never consented to join.

What works — and Minnesota knows it, because it did it for consumers

Here's the tell that Minnesota already understands how to fix this: it built the fix for the private sector and just didn't point it at the government.

Illinois passed a biometric privacy law with the one feature that changes corporate behavior — a private right of action. People can sue. That single design choice produced a $650 million settlement from Facebook and a $92 million one from TikTok over faceprints collected without consent. Texas's biometric law drove a $1.4 billion Meta settlement. When you give people the power to enforce their own face-privacy, companies suddenly comply.

On the government side, Massachusetts became the first state to require a warrant before police use facial recognition — keeping the tool available for real investigations while stopping suspicionless, dragnet scanning. That's the model: not a ban that throws away a legitimate forensic tool, but a rule that makes the government show cause first.

What we can do

Close the government exemption. The single most important fix is to say that Minnesota's face-privacy protection applies to the government too — or to pass a companion law that does. The entity with handcuffs should not be the one entity that gets to scan your face freely.

Require a warrant for police facial recognition. Follow Massachusetts. Keep it available to solve serious crimes with judicial oversight; forbid the routine, suspicionless scanning of everyone.

Give Minnesotans standing. As the privacy-law article in this series documented, Minnesota's data law has no private right of action — only the Attorney General can enforce it, and enforcement so far is invisible. Illinois proved that letting people sue over their own faceprints is what actually makes the law bite. A Minnesota biometric law with teeth should let the person whose face was taken be the one who enforces it.

And protect the DMV database. No agency, state or federal, should be able to run facial recognition against Minnesotans' license photos without a warrant and public reporting.

Your face is the one password you can never change. Minnesota decided a store can't take it without asking. It's time to tell the government the same thing.

First the facts. Then the fix.


Sources

Minnesota Consumer Data Privacy Act, Minn. Stat. §§ 325M.10–.21, verified against raw text at revisor.mn.gov: biometric data as "sensitive data" requiring consent (§§ 325M.11 and 325M.16(d)); the government-entity exemption (§ 325M.12); Attorney-General-only enforcement with no private right of action (§ 325M.20(d)). Minnesota facial-recognition users as documented: Minneapolis Police Department and Hennepin County Sheriff's Office use of Clearview AI, and the Minneapolis City Council's 13–0 vote (Feb. 12, 2021) barring city use — with the Hennepin County Sheriff's Office not covered by the city ban — per TechCrunch reporting; the Minnesota Commerce Fraud Bureau's testing of Clearview; Mall of America's activation of facial recognition (June 26, 2024). Bias data: NIST Interagency Report 8280 (Dec. 19, 2019), finding false-positive rates 10 to 100 times higher for Asian and African American faces. Wrongful arrests: at least six documented U.S. cases from facial-recognition misidentification, beginning with Robert Williams (Detroit, January 2020). Driver's-license database access: GAO-19-579T (2019), on FBI face-search access to state DMV photo databases across 21 states and more than 640 million images. What works: Illinois Biometric Information Privacy Act and its private right of action, driving the Facebook ($650 million) and TikTok ($92 million) settlements; Texas's biometric law driving the Meta settlement ($1.4 billion, July 2024); Massachusetts's warrant requirement for police facial recognition (2021).

Washington and Utah biometric-law specifics, whether Minnesota runs facial recognition on license applicants, and airport-specific deployments were not independently confirmed this pass and are not asserted. Corrections: campaign@madgettformn.com.

More in Minnesota by the Numbers

Every article in this series is built from primary sources and lists what it could not verify.

2026 Voter Guides →  •  The Platform →