livelaw

Guides · Georgia

Recording Law for Voiceprints & Biometric Data in Georgia

Georgia has no state biometric-voiceprint law, despite a failed 2025–2026 bill

Georgia currently has no state statute that regulates the extraction, storage, or use of biometric voiceprints from recorded conversations. Unlike Illinois (BIPA) or Texas (CUBI), there is no law requiring consent, notice, or limits on how businesses can collect, store, or use voiceprints. The only backstop is Georgia’s data-breach notification statute (O.C.G.A. § 10-1-912), which imposes a post-breach notice duty but no pre-breach collection, consent, or storage rules. Notably, in the 2025–2026 Regular Session, the Georgia General Assembly introduced SB 111, the "Georgia Consumer Privacy Protection Act," which as introduced would have expressly defined "biometric data" to include voiceprints and required consent/notice for processing such data. However, the enrolled "AS PASSED" version signed into Act 462 in 2026 had that content entirely stripped and replaced with unrelated rural-hospital tax-credit language. Thus, as of enactment in 2026, Georgia still lacks any biometric-specific statute, and businesses extracting voiceprints from recorded conversations face no state-law consent, notice, or retention requirements specific to biometric identifiers.

Georgia’s one-party rule covers recorded conversations, not voiceprints

Georgia is a one-party-consent state for recording conversations. Under O.C.G.A. § 16-11-66(a), it is legal to record a conversation as long as at least one person in the conversation consents. The statute applies uniformly to "wire, oral, or electronic communication" and does not distinguish between in-person and phone/electronic communications. Importantly, this law governs the act of recording the conversation itself, not the extraction or storage of a biometric voiceprint from that recording. So while you can legally record a conversation in Georgia with one-party consent, the state does not regulate what you do with a voiceprint created from that recording. Georgia also has no statute that imposes biometric-specific rules on how voiceprints are handled.

Because Georgia has no biometric-specific statute, there is no legal requirement to get consent or provide notice before extracting a biometric voiceprint from a recorded conversation. The state’s wiretapping statute (O.C.G.A. § 16-11-62) only restricts clandestine recording of private conversations in private places and does not address biometric data extraction. The data-breach notification law (O.C.G.A. § 10-1-912) only requires notice after a breach, not before collecting biometric data. So Georgia businesses using voice-ID features do not need to obtain additional consent or provide notice solely for voiceprint extraction. The 2025–2026 Regular Session bill SB 111 would have created a biometric-consent regime covering voiceprints, but its biometric provisions were stripped out before enactment and never became law.

What happens if a voiceprint is breached in Georgia?

If a biometric voiceprint is compromised, Georgia’s data-breach notification law (O.C.G.A. § 10-1-912) requires the business to notify affected individuals after discovering the breach. This law applies to computerized data that includes personal information, including biometric data, but it does not regulate how the data was collected or stored in the first place. There is no private right of action under this statute, and no specific security requirements for biometric data. So while Georgia does impose a post-breach notice duty, it does not impose pre-breach collection or storage rules for voiceprints. The only adjacent law is the data-breach statute, which functions as a notice mechanism rather than a substantive biometric-privacy rule.

Hypothetical: Using voice-ID in a Georgia business

Imagine a Georgia law firm records client calls for training and quality control. The firm uses a voice-ID feature to extract a biometric voiceprint from each recorded call to authenticate speakers in future interactions. Because Georgia has no biometric-specific law, the firm does not need to get additional consent or provide notice for the voiceprint extraction. The firm must, however, comply with Georgia’s one-party-consent rule for recording the calls themselves (O.C.G.A. § 16-11-66(a)). If the firm later suffers a breach exposing the voiceprints, it must notify affected clients under the state’s data-breach law (O.C.G.A. § 10-1-912). The 2025–2026 Regular Session bill SB 111 would have required consent/notice for processing biometric data including voiceprints, but its biometric provisions were stripped out before enactment and never became law.

Federal and common-law risks to watch in Georgia

Even without a biometric-specific statute, businesses extracting and storing voiceprints in Georgia face risks under federal law and common-law torts. The FTC can challenge practices as unfair or deceptive under the FTC Act if they mislead consumers about how voiceprints are used or stored. Georgia courts recognize invasion-of-privacy claims, so a person could sue if they believe the extraction or storage of their voiceprint was highly offensive or unreasonable. These risks are not unique to Georgia but apply nationwide. Businesses should document their practices and obtain informed consent where possible to reduce legal exposure. The 2025–2026 Regular Session bill SB 111 would have created a biometric-consent regime covering voiceprints, but its biometric provisions were stripped out before enactment and never became law.

Georgia’s 2025–2026 SB 111: what almost became law

In the 2025–2026 Regular Session, the Georgia General Assembly introduced SB 111, titled the "Georgia Consumer Privacy Protection Act." As introduced, the bill would have added new Code Sections 10-1-960 et seq. to Title 10 and expressly defined "biometric data" to include "a fingerprint, voiceprint, eye retina or iris, or other unique biological patterns or characteristics that are used to identify a specific individual." Section 10-1-961(3)(A) of the as-introduced text would have required controllers to provide notice and obtain consent before processing sensitive data, including biometric identifiers. However, the enrolled "AS PASSED" version signed into Act 462 in 2026 had that content entirely stripped and replaced with unrelated rural-hospital tax-credit language. Thus, SB 111’s biometric/privacy content never became law, and Georgia remains without a biometric-specific statute as of enactment in 2026.

Frequently asked questions

Does Georgia law require consent to extract a biometric voiceprint from a recorded conversation?

No. Georgia currently has no biometric-specific statute, so there is no legal requirement to get consent, notice, or any other condition for extracting a biometric voiceprint from a recorded conversation. The state’s one-party-consent rule (O.C.G.A. § 16-11-66(a)) only governs the act of recording the conversation itself, not what you do with the recording afterward. The 2025–2026 Regular Session bill SB 111 would have required consent/notice for processing biometric data including voiceprints, but its biometric provisions were stripped out before enactment and never became law.

What if someone sues over the extraction or storage of their voiceprint in Georgia?

Georgia does not have a biometric-specific statute, so lawsuits would likely rely on general claims like invasion of privacy or unfair/deceptive practices under the FTC Act. These claims depend on the specific facts and are decided case-by-case. There is no statutory private right of action for biometric data in Georgia. Civil remedies in Georgia rest primarily on the common-law invasion-of-privacy tort (Pavesich v. New England Life Ins. Co., 122 Ga. 190 (1905)) and courts recognizing civil suits tied to statutory violations, rather than an express, standalone statutory private-right-of-action clause. The 2025–2026 Regular Session bill SB 111 would have created a biometric-consent regime covering voiceprints, but its biometric provisions were stripped out before enactment and never became law.

Does Georgia’s data-breach law apply to biometric voiceprints?

Yes. Georgia’s data-breach notification law (O.C.G.A. § 10-1-912) requires notice to affected individuals if a breach exposes computerized data containing personal information, including biometric data. It does not impose pre-breach collection, consent, or storage rules for voiceprints. The statute functions as a notice mechanism rather than a substantive biometric-privacy rule.

Is there any legal gray area in Georgia regarding voiceprints?

Yes. While Georgia has no biometric-specific statute, federal and common-law claims could arise depending on how a business collects, stores, or uses voiceprints. Practices that mislead consumers about how their voiceprints are handled could face FTC scrutiny, and highly offensive or unreasonable handling might lead to invasion-of-privacy claims. The safest approach is to obtain informed consent and document your practices. The 2025–2026 Regular Session bill SB 111 would have created a biometric-consent regime covering voiceprints, but its biometric provisions were stripped out before enactment and never became law.

Want a lawyer already lined up before you need one?

live.law connects your smartglasses to a real attorney, live. Join the waitlist to be first in line.

Join the waitlist

live.law is not a law firm and does not provide legal advice. This page is general information, not legal advice for your specific situation — for that, talk to a licensed attorney in your state.