Creates the "Enhanced Personal Privacy Act"
HB 3537 creates new rules for private companies handling biometric data like fingerprints, facial scans, or voiceprints. It requires companies to get customer consent (which can be implied through actions like using a service) before collecting or using this data for commercial purposes (not security, employment, or healthcare), store it securely, and destroy it within one year or after the customer's last interaction. The law excludes healthcare data protected by federal HIPAA, financial data under the Gramm-Leach-Bliley Act, and biometric data used for employment or security purposes. Companies must follow reasonable security standards for this data but cannot be sued for violations under this law.
Bill status
in committee
1 of 4 stages cleared
Introduction
Feb 2026
Committee Review
Floor Vote
Governor
Introduced Feb 27, 2026
Last action May 15, 2026
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
3
Key actions
0
Committee
1
May 15, 2026
Committee
Referred: Emerging Issues(H)
lower
Feb 27, 2026
Introduced
Introduced and Read First Time (H)
lower
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Brad Christ
RRepublican
Ask Maddy
·
AI policy assistant
Ask Maddy about HB 3537
Scope: MO
Hi! I can help you understand HB 3537. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline