BIPA: The Illinois Biometric Information Privacy Act
Illinois’ Biometric Information Privacy Act, or BIPA, is a 2008 privacy law that requires notice and consent for many uses of biometric identifiers and allows affected people to sue. Its litigation history has made it a national compliance benchmark for facial biometrics.
The Illinois Biometric Information Privacy Act, commonly called BIPA, has been in force since October 3, 2008. It regulates private entities that collect, use, store or disclose biometric identifiers and biometric information of people in Illinois. It is among the most consequential US biometric privacy laws because it combines detailed duties with a private right of action.
BIPA covers identifiers such as a retina or iris scan, fingerprint, voiceprint, and a scan of hand or face geometry. It also covers biometric information derived from an identifier and used to identify a person. Ordinary photographs, video recordings and physical descriptions are generally excluded, but a photograph can fall within the law when software extracts a face-geometry template from it.
Notice, consent and data-governance duties
Before collecting or obtaining a person’s biometric identifier or biometric information, a private entity generally must provide written notice that biometric data is being collected or stored, state the specific purpose and length of time for which it will be collected, stored and used, and obtain a written release. A release is informed written consent, including consent executed electronically under a 2024 amendment.
- Maintain a publicly available written retention schedule and destruction policy. Data generally must be destroyed when the original purpose has been satisfied or within three years of the person’s last interaction with the entity, whichever comes first.
- Do not sell, lease, trade or otherwise profit from biometric identifiers or biometric information.
- Do not disclose biometric data without consent unless a listed exception applies, such as a legal requirement or warrant.
- Store, transmit and protect biometric data using a reasonable standard of care, at least as protective as the standard used for other confidential and sensitive information.
The statute includes important exemptions, including for certain government activities, financial institutions and data governed by specified federal health privacy rules. Those exemptions are fact-specific. BIPA does not contain a broad exemption for employers, which is why timekeeping systems using fingerprints have been a major source of cases.
Private lawsuits and the litigation record
Unlike most state privacy laws, BIPA allows an aggrieved person to bring an individual or class action. Available remedies include actual damages or statutory damages of $1,000 for a negligent violation and $5,000 for an intentional or reckless violation, plus reasonable attorneys’ fees, litigation costs and injunctive relief. These amounts can make large class actions financially significant.
Illinois Supreme Court decisions have broadly shaped the law. In Rosenbach v. Six Flags Entertainment Corp. in 2019, the court held that a person need not show additional harm, such as identity theft, beyond a violation of BIPA’s procedural protections. In Cothron v. White Castle System, Inc. in 2023, the court held that claims could accrue with each unlawful collection or transmission. A 2024 statutory amendment limited certain repeated collection and disclosure claims involving the same person, biometric data and method to a single violation, reducing the per-scan exposure at issue in Cothron. Litigation over particular practices, exemptions, limitations periods and the amendment’s application continues.
Facial recognition and liveness checks
BIPA does not ban facial recognition or biometric liveness detection. Liveness detection is a technique intended to distinguish a live person from a photo, video, mask or synthetic presentation during verification. But a system that creates or uses a face template can trigger BIPA, whether it is used for building access, identity verification, fraud prevention, workplace attendance or consumer authentication.
A business should not assume that a short-lived face scan, a vendor-hosted workflow or a fraud-prevention purpose removes BIPA obligations. Compliance analysis commonly focuses on who collects the template, what notices and releases are presented, whether data is shared with a vendor, the retention period, and contractual and security controls. BIPA prescribes no particular liveness technology or accuracy threshold.
Other state laws and national relevance
Texas and Washington have biometric privacy statutes, but their enforcement models differ and generally rely on government enforcement rather than a BIPA-style private damages action. California’s consumer privacy law treats biometric information as sensitive personal information, while its private lawsuit provision is limited largely to certain data breaches. Several comprehensive state privacy laws also impose consent or sensitive-data duties that can cover biometrics, but their scope and remedies vary.
BIPA matters beyond Illinois because national employers, retailers, platforms and identity providers may interact with Illinois residents or deploy the same biometric system across multiple states. Its class-action record has influenced product design, vendor contracting, retention policies and consent flows nationally. There is still no single federal biometric privacy statute that replaces this patchwork, so organizations must assess BIPA alongside other applicable state, sectoral and consumer-protection rules.