Privacy

BIPA and the Price of Getting Biometrics Wrong

Illinois' Biometric Information Privacy Act has made face, fingerprint and voice data a major litigation risk. Its influence now reaches far beyond the state, even as US biometric rules remain fragmented.

BIPA and the Price of Getting Biometrics Wrong

A fingerprint used to open a time clock or a face scan used to enter a venue can feel less consequential than a password. Illinois law treats those identifiers differently. Unlike a password, a biometric identifier is closely tied to a person and cannot simply be changed after misuse or exposure.

That premise sits behind Illinois' Biometric Information Privacy Act, known as BIPA. Enacted in 2008, it has become the most consequential US biometric privacy statute because it gives affected people a direct path to court. The law has produced large settlements involving workplace systems, consumer applications and face-related services, while also influencing product design and contracting well outside Illinois.

What BIPA requires

BIPA applies to private entities that collect, capture, purchase, receive through trade, or otherwise obtain covered biometric identifiers or biometric information from Illinois residents, subject to statutory exemptions and fact-specific questions about scope. Covered identifiers include scans of a retina or iris, fingerprints, voiceprints, and scans of hand or face geometry. Biometric information is information based on such an identifier that can be used to identify someone.

The central obligation is informed, written permission before collection. Before obtaining a covered biometric identifier or information, an entity must give written notice that explains what is being collected, why it is being collected, and how long it will be kept and used. It must then obtain a written release. Illinois law permits electronic signatures, but a preselected box or a buried privacy statement may not establish the clear, documented authorization a company needs.

  • Give written notice before collecting covered biometric data, identifying the purpose and retention period.
  • Obtain a written release from the individual before collection. For a minor, additional rules and parental consent issues may apply.
  • Develop and publicly make available a written retention schedule and destruction guidelines. BIPA generally requires destruction when the initial purpose is satisfied or within three years of the person's last interaction with the entity, whichever occurs first.
  • Do not sell, lease, trade or otherwise profit from biometric identifiers or biometric information.
  • Limit disclosures, obtain required consent for disclosures, and store data using a reasonable standard of care.

Why Illinois litigation has national effects

BIPA's defining feature is its private right of action. Individuals, rather than only a regulator, can sue over alleged violations. The statute authorizes liquidated damages of $1,000 for a negligent violation and $5,000 for an intentional or reckless violation, or actual damages if greater, along with attorney fees, costs and possible injunctive relief. The amount ultimately at issue depends on the claims, proof, applicable limitations rules and the statute's damages provisions as amended by Illinois lawmakers.

For employers and technology providers, the risk is amplified by scale. A timekeeping system may scan many workers repeatedly; a consumer service may process a large user base. Class actions have therefore become a central enforcement mechanism. Companies have resolved BIPA cases for substantial sums without necessarily admitting wrongdoing, and defendants have also contested whether their technology, practices or users fall within the law.

The practical result is national. A vendor that serves customers in Illinois often builds one consent flow, retention control and vendor-contract standard for its whole US operation rather than maintaining a separate Illinois-only system. Face comparison tools, fingerprint attendance terminals and voice authentication products increasingly arrive with BIPA questionnaires, data-processing terms and deletion features because customers expect them.

A patchwork beyond Illinois

Illinois is not the only state to regulate biometrics, but its enforcement model is unusual. Texas' Capture or Use of Biometric Identifier Act requires notice and consent for certain commercial captures, restricts sale and requires destruction within a reasonable time, but enforcement is principally through the state attorney general. Washington has a biometric identifier law focused on enrollment for a commercial purpose and notice and consent, with state enforcement rather than BIPA-style individual damages claims.

Comprehensive state privacy laws also matter. California treats biometric information as sensitive personal information under the California Consumer Privacy Act, while Colorado, Virginia and other states regulate biometric data within broader privacy frameworks. Their duties can include consent, data minimization, security, deletion or consumer rights, but their definitions, exemptions and enforcement routes differ. A California private lawsuit provision for certain data breaches, for example, is not a general BIPA-equivalent right to sue over biometric collection.

No single federal baseline

The United States still has no comprehensive federal biometric privacy law that sets one consent, retention and remedies standard across sectors. Federal agencies can use existing consumer-protection authority in appropriate cases, and sector-specific rules may apply to particular organizations, but those tools do not replace a uniform biometric statute. For organizations operating in the US and EU, the result is a layered compliance task: BIPA and other state laws may apply alongside the EU General Data Protection Regulation, which generally classifies biometric data used for unique identification as a special category of personal data.

The operational lesson is not that every image or audio recording is automatically regulated biometric data. Context, processing purpose and jurisdiction matter. But businesses that convert faces, fingerprints or voices into identity-linked templates should identify where collection occurs, document the legal basis before deployment, set deletion controls, and test vendor practices. This article is general information, not legal advice; obligations should be assessed under the law of each relevant jurisdiction.

More in Privacy