Wisconsin

Wisconsin Privacy Law

Wisconsin is one of a minority of states whose right of privacy is a creature of statute rather than of common law. Section 995.50 codifies four kinds of invasion — intrusion, commercial misappropriation of a name or likeness, publicity given to private facts, and conduct amounting to criminal stalking or harassment — and provides equitable relief, compensatory damages measured either by the plaintiff’s loss or the defendant’s unjust enrichment, and attorney fees. The breach-notification section takes the opposite posture: it counts a DNA profile and unique biometric data among the elements that trigger notice, but its own annotation records that it creates no private right of action, and a separate subsection expressly bars municipalities from legislating on the subject.

Sector-Specific Privacy Laws in Wisconsin

Right of privacy (Wis. Stat. § 995.50)

Subsection (1) provides that one whose privacy is unreasonably invaded is entitled to equitable relief to prevent and restrain the invasion — expressly excluding prior restraint against constitutionally protected communication privately and through the public media — to compensatory damages “based either on plaintiff’s loss or defendant’s unjust enrichment”, and to a reasonable amount for attorney fees. Subsection (2) enumerates what counts. Intrusion covers intrusion upon another’s privacy of a nature highly offensive to a reasonable person, in a place a reasonable person would consider private or in a manner actionable for trespass. Misappropriation covers the use, for advertising purposes or purposes of trade, of the name, portrait or picture of a living person without first obtaining written consent. Publicity given to private facts covers disclosure of matters highly offensive to a reasonable person where the defendant acted unreasonably or recklessly as to whether there was a legitimate public interest. The fourth category incorporates conduct prohibited under §§ 942.09 and 942.095, and applies regardless of whether a criminal action relating to the conduct has been brought.

Access to personal internet accounts (Wis. Stat. § 995.55)

The section reaches three relationships that most state social-media-password laws address separately. An employer may not request or require an employee or applicant to disclose access information for, or otherwise grant access to, a personal internet account, and may not discharge or otherwise discriminate against someone who refuses. An educational institution may not require a student or prospective student to do so, or expel or discipline for refusal. A landlord may not require a tenant or prospective tenant to do so, or discriminate for refusal. The exceptions preserve an employer’s right to request access information for employer-supplied devices and accounts, and to investigate the unauthorized transfer of the employer’s proprietary or confidential information on reasonable cause; educational institutions and landlords may view information available in the public domain. Violations carry a forfeiture of up to $1,000, and an affected employee or student may file a complaint processed in the manner of an employment discrimination claim before the Department of Workforce Development, with tenants proceeding under the comparable housing-discrimination procedure.

Disposal of records containing personal information (Wis. Stat. § 134.97)

The section applies to a financial institution, a medical business or a tax preparation business, and defines “personal information” by category rather than by identifier pairing: personally identifiable data about an individual’s medical condition that is not generally public knowledge, data containing an account or customer number, balance, balance owing, credit balance or credit limit relating to an account with a financial institution, data provided on opening an account or applying for a loan or credit, and data about an individual’s federal, state or local tax returns. “Medical business” is defined broadly enough to cover any for-profit or not-for-profit organisation holding information about a person’s physical or mental health, medical history or treatment, other than personnel records. Subsection (2) forbids disposing of such a record unless it is shredded, the personal information erased, or the record modified to make the information unreadable — or unless the business takes actions it reasonably believes will keep unauthorized persons from the information between disposal and destruction. Subsection (3) makes the business liable for damages to the person whose information was disposed of in violation, and makes anyone who uses information from an improperly disposed record liable both to the individual and to the business. Subsection (4) adds a forfeiture of up to $1,000, with acts arising from the same incident counted as a single violation, and makes possession of such a record with intent to use the information punishable by a fine of up to $1,000, up to 90 days’ imprisonment, or both.

Data Breach Notification in Wisconsin

Section 134.98 is keyed to acquisition by an unauthorized person rather than to access, and its list of triggering elements is longer than most: a name combined with a Social Security number, a driver’s license or state identification number, a financial account number with any code permitting access, the individual’s deoxyribonucleic acid profile as defined in § 939.74(2d)(a), or the individual’s unique biometric data including a fingerprint, voice print, retina or iris image, or any other unique physical representation. The element must not be publicly available information and must not be encrypted, redacted or altered so as to be unreadable. “Entity” expressly includes the state and its agencies, the legislature and the courts, and cities, villages, towns and counties, so government bodies notify on the same terms as businesses. Subsection (2)(a) and (b) split the duty by where the entity’s principal place of business sits; (bm) requires a person storing information it does not own or license, and has no contract with the owner, to notify the owner as soon as practicable; (br) requires notice to all nationwide consumer reporting agencies where a single incident forces notice to 1,000 or more individuals. Subsection (2)(cm) removes the duty where the acquisition does not create a material risk of identity theft or fraud, or where an employee or agent acquired the information in good faith for a lawful purpose of the entity. Subsection (3)(a) sets the outer limit at 45 days from when the entity learns of the acquisition, with reasonableness judged against the number of notices required and the methods of communication available. Subsection (3)(c) gives a notified person the right, on written request, to be told what personal information was acquired. Subsection (3m) exempts entities subject to and complying with the Gramm-Leach-Bliley privacy and security requirements at 15 U.S.C. 6801 to 6827 and entities described in 45 C.F.R. 164.104(a) complying with 45 C.F.R. part 164.

Residents must be notified within a reasonable time, not to exceed 45 days after the entity learns of the acquisition. No Attorney General notification requirement; notice to nationwide consumer reporting agencies is required at 1,000 or more individuals from a single incident. Complaints are taken by the Wisconsin Department of Justice, which enforces the statute.

How Wisconsin Enforces Its Privacy Laws

No private right of action, and the section is not negligence per se. Subsection (4) of § 134.98 states that failure to comply “is not negligence or a breach of any duty, but may be evidence of negligence or a breach of a legal duty” — a middle position that keeps the statute out of a negligence-per-se argument while leaving it available as proof. The section’s published annotation records that it does not create a private right of action, citing Fox v. Iowa Health System, 399 F. Supp. 3d 780 (2019). Chapter 134 violations are enforced by forfeiture, and § 134.99 extends liability for a chapter 134 forfeiture to anyone “concerned in the commission” of the violation — a person who directly commits it, aids and abets it, or conspires, advises, hires, counsels or otherwise procures another to commit it — whether or not the direct actor has been convicted.

Local regulation barred, and a federal-preemption sunset built in. Subsection (6m) provides that no city, village, town or county may enact or enforce an ordinance or regulation relating to notice or disclosure of the unauthorized acquisition of personal information. Subsection (7m) goes further and puts an expiry mechanism in the statute itself: if the Joint Committee on Administrative Rules determines that Congress has enacted substantially similar notice requirements that do not preempt the section, and publishes a notice of that determination in the Wisconsin administrative register, § 134.98 ceases to apply.

Law enforcement can suppress the notice entirely. Subsection (5) lets a law enforcement agency ask an entity not to give the notice, for any period of time, to protect an investigation or homeland security. While that request stands, the entity “may not provide notice of or publicize” the unauthorized acquisition except as the requesting agency authorises, and the notification clock begins only at the end of that period.

Recent Enforcement in Wisconsin

23andMe — multistate settlement of bankruptcy claims, over $275,000 to Wisconsin. The Department of Justice announced on July 14, 2026 that Wisconsin and a coalition of 41 other states had settled with the bankruptcy trustee for 23andMe over the 2023 breach of genetic data. The department reports that the settlement comprises $150 million in allowed claims for the states, that recovery is limited to $18 million payable immediately out of the bankruptcy estate because of the estate’s finite funds and competing claims, and that Wisconsin will receive over $275,000. It puts the breach at 6.9 million customers worldwide, including 78,407 in Wisconsin, describes exposed data including genetic ancestry information with subsets later offered for sale on the dark web, and states that 23andMe allegedly did not learn of the breach until months after the information was publicly available and at first denied it. A separate $46.75 million class settlement in the bankruptcy covered affected United States consumers who filed claims by February 17, 2026.

USDA SNAP data demand — temporary restraining order won, N.D. Cal., September 2025. The Department of Justice announced on September 22, 2025 that the Attorney General and a multistate coalition had obtained a temporary restraining order from a federal judge in the United States District Court for the Northern District of California preventing the federal administration from acting on its demand that states turn over personal information about Supplemental Nutrition Assistance Program recipients. The department frames the case as protecting the privacy of millions of people nationwide who rely on the program for food assistance.

Pending Privacy Legislation

The most detailed official assessment of Wisconsin’s position remains the Data Privacy and Security Report published in September 2020 by the Department of Agriculture, Trade and Consumer Protection, reporting the findings of an advisory committee the department convened over nine months. That report records that no legislation relating to consumer data security, privacy or breach had been passed in Wisconsin since 2010, and catalogues the 2019 session bills that did not become law — 2019 Senate Bill 784 and Assembly Bill 819, Assembly Bills 870, 871 and 872, and Senate Bill 851. Its closing section sets out the questions the committee identified as unresolved for any future statute: harmonising the definition of personally identifiable information, whether a breach should turn on acquisition of data or unauthorized access to it, whom a breach should be reported to and what the report should contain, breach enforceability, whether to create a private right of action, and whether consumer control of data should be opt-in or opt-out.

Federal Privacy Laws That Apply in Wisconsin

Federal privacy law applies in Wisconsin by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

Outside those federal sectors, Wisconsin obligations run through the state’s breach-notification statute and the Wisconsin Department of Justice’s general consumer-protection authority rather than through a privacy statute of its own.

Industry Rules That Reach Wisconsin Businesses

With no comprehensive state statute, most privacy obligations on a Wisconsin business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach Wisconsin businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Wisconsin itself has none, and any business holding personal information about Wisconsin residents is subject to the state’s breach-notification statute described above.

Wisconsin Privacy Law FAQ

How long does a Wisconsin entity have to give breach notice?
Section 134.98(3)(a) requires notice within a reasonable time, “not to exceed 45 days after the entity learns of the acquisition of personal information”. Reasonableness within that window is judged against the number of notices the entity must provide and the methods of communication available to it. Section 134.98(5) suspends the clock entirely while a law enforcement agency has asked the entity not to notify.
Does Wisconsin’s breach statute cover DNA and biometric data?
Yes. Section 134.98(1)(b) lists, alongside a Social Security number, driver’s license or state identification number and financial account number, the individual’s deoxyribonucleic acid profile as defined in § 939.74(2d)(a) and the individual’s unique biometric data — including a fingerprint, voice print, retina or iris image, or any other unique physical representation. Each must be combined with the individual’s last name and first name or initial, and must be neither publicly available nor encrypted, redacted or otherwise rendered unreadable.
Can a Wisconsin consumer sue over a data breach under section 134.98?
Not under the section itself. Its published annotation records that § 134.98 does not create a private right of action, citing Fox v. Iowa Health System, 399 F. Supp. 3d 780 (2019). Subsection (4) adds that a failure to comply “is not negligence or a breach of any duty, but may be evidence of negligence or a breach of a legal duty”, which leaves the statute available as proof in a claim founded on some other duty rather than as a claim of its own.
What does Wisconsin’s statutory right of privacy cover?
Section 995.50(2) defines invasion of privacy as four things: intrusion upon another’s privacy of a nature highly offensive to a reasonable person in a place a reasonable person would consider private or in a manner actionable for trespass; use of a living person’s name, portrait or picture for advertising or trade purposes without prior written consent; publicity given to a matter concerning private life that would be highly offensive to a reasonable person, where the defendant acted unreasonably or recklessly as to whether a legitimate public interest existed; and conduct prohibited under §§ 942.09 or 942.095, whether or not a criminal action followed.
Do Wisconsin state and local government bodies have to give breach notice?
Yes. Section 134.98(1)(a)2 writes them into the definition of “entity”: the state and any office, department, independent agency, authority, institution, association, society or other body in state government created or authorized by the constitution or any law — including the legislature and the courts — and any city, village, town or county. Section 134.98(6m) separately bars a city, village, town or county from enacting or enforcing its own ordinance or regulation on breach notice.
Can a Wisconsin employer ask for an employee’s social media password?
Section 995.55 prohibits it. An employer may not request or require an employee or applicant to disclose access information for, or otherwise grant access to, a personal internet account, and may not discharge or otherwise discriminate against a person who refuses. The section applies the same rule to educational institutions with students and prospective students, and to landlords with tenants and prospective tenants. Employers keep the right to request access information for employer-supplied devices and accounts and to investigate an unauthorized transfer of the employer’s proprietary or confidential information on reasonable cause. Violations carry a forfeiture of up to $1,000.
Who must shred records containing personal information in Wisconsin?
Section 134.97(2) applies to a financial institution, a medical business or a tax preparation business, and requires that before disposing of a record containing personal information the business shred it, erase the information, modify the record to make the information unreadable, or take actions it reasonably believes will keep unauthorized persons from the information between disposal and destruction. “Medical business” is defined broadly — any for-profit or not-for-profit organisation holding information about a person’s physical or mental health, medical history or treatment, other than personnel records. Unlike § 134.98, this section does create civil liability: subsection (3) makes the business liable for damages to the person whose information was disposed of in violation.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.