US Privacy Law Illinois, USA

Illinois BIPA: Biometric Privacy Law and Litigation Guide

The Biometric Information Privacy Act: consent and retention duties, $1,000/$5,000 statutory damages, Rosenbach, White Castle, the 2024 amendment, and defense strategy.

Regulation

Biometric Information Privacy Act (740 ILCS 14), enacted 2008

Max Penalty

Liquidated damages of $1,000 per negligent violation or $5,000 per intentional/reckless violation, plus fees; class settlements have reached $650M

Enforcing Authority

Private right of action in Illinois courts (no regulator)

Official Source

www.ilga.gov

Executive Summary

  • BIPA (2008) is the only US biometric law with a private right of action, and it built the largest privacy-litigation docket in the country: thousands of class actions over fingerprints, face scans, and voiceprints.
  • Core duties: written notice and release (consent) before collecting biometric identifiers, a public retention-and-destruction schedule, no selling or profiting, restricted disclosure, and reasonable security.
  • Rosenbach v. Six Flags (Ill. 2019) held that a bare statutory violation, no actual harm, makes a person 'aggrieved' and able to sue; Cothron v. White Castle (Ill. 2023) held claims accrue with every scan, producing astronomical theoretical damages.
  • The 2024 amendment (SB 2979) responded to White Castle: multiple collections of the same biometric from the same person by the same method now constitute a single violation for damages, and electronic signatures qualify as written releases.
  • The price history: Facebook settled for $650M, Google for $100M, and hundreds of employer timeclock cases settle in the millions; damages are liquidated at $1,000/$5,000 per violation.

BIPA is a 2008 statute that reads like a modest notice-and-consent law and functions like the most dangerous privacy statute in America: liquidated damages, class actions, no regulator to negotiate with, and an Illinois Supreme Court that resolved every structural question in plaintiffs’ favor, no-harm standing (Rosenbach), a five-year limitations period (Tims), and per-scan accrual (White Castle) until the legislature stepped in. The compliance program it demands is cheap; the litigation it produces when skipped is not.

LawBIPA, 740 ILCS 14
Damages$1,000 negligent / $5,000 intentional-reckless, per violation
EnforcementPrivate right of action (class actions)
LandmarksRosenbach (2019), Tims (2023), White Castle (2023), SB 2979 (2024)
Record settlementsFacebook $650M; Google $100M

The compliance program

Inventory biometric touchpoints. Timeclocks, door access, photo face-grouping, voice authentication and voice AI, camera analytics, virtual try-on, identity verification vendors. Include third-party SDKs and processors, deploying someone else’s face-matching still collects.

Paper the flow. Written notice with purpose and retention period, signed (or e-signed) release before first collection, and a published retention-and-destruction schedule with the 3-year outer limit. For employees, fold it into onboarding; for consumers, a distinct consent (not buried in ToS, which courts have found inadequate when inconspicuous).

Enforce destruction and no-sale. Automate deletion at purpose-completion or 3 years post-interaction, contractually bind vendors to the same, and never monetize the identifiers. Disclosure requires consent or narrow exceptions.

Extend to the sibling statutes. The same program satisfies Texas CUBI (add AG-facing documentation), Washington, and Colorado’s 2025 biometric rules, and covers the biometric slices of CCPA sensitive personal information and the state laws’ sensitive-data consent duties.

Watch the frontier. Voice AI assistants, retail camera analytics, and AI training on face data are the active case pipeline; new features touching measurable biology deserve a BIPA review before launch, the assessment framework is the natural vehicle.

If your site or app embeds identity-verification, camera, or voice features, check what they collect and transmit with a free scan, the notice-and-consent gap is visible from the outside.

Frequently Asked Questions

What data does BIPA cover, and what does it exclude?

Biometric identifiers: retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry, plus 'biometric information' derived from them. Excluded: photographs themselves (though face geometry extracted from photos is covered, the Facebook theory), writing samples, physical descriptions, and HIPAA-covered health data. The dividing line is measurable biology used for identification, not images or demographics.

What must we do before collecting?

Three things, in writing: (1) inform the subject that a biometric is being collected or stored; (2) disclose the specific purpose and retention period; (3) obtain a written release (electronic signatures suffice post-2024). Plus: publish a retention schedule providing destruction when the purpose is satisfied or within 3 years of the last interaction, never sell or profit from biometrics, and protect them with the reasonable standard of care. Most defendants lose on the paperwork, not the technology.

How did White Castle and the 2024 amendment change damages math?

Cothron held that each fingerprint scan is a separate violation, White Castle's own estimate ran to $17 billion for one employer's timeclocks, while inviting legislative correction. SB 2979 (August 2024) delivered it: repeated collection of the same biometric from the same person via the same method is one violation for liquidated damages. Exposure dropped from per-scan to per-person, still $1,000-$5,000 per employee or user, which keeps class actions economically viable.

Who gets sued under BIPA in practice?

Two dockets: employers using biometric timeclocks or access systems without notice-and-release paperwork (the volume docket, hundreds of cases, typically settling $500 to $2,000 per class member), and technology companies deriving face or voice geometry at scale (the headline docket: Facebook $650M, Google Photos $100M, Clearview AI's injunctive settlement, ongoing suits over voice AI and virtual try-on features). Vendors can be liable alongside the deployers.

How does BIPA compare with other biometric laws?

Texas CUBI (2009) has similar duties but AG-only enforcement, dormant until the $1.4B Meta settlement (2024). Washington's HB 1493 (2017) is enforced by its AG under consumer-protection law. Colorado's 2024 CPA amendments add biometric duties with AG enforcement from July 2025. BIPA remains unique in private enforcement with liquidated damages, which is why 'BIPA compliance' effectively sets the national biometric standard for any company with Illinois users or employees.

Regulatory Crosswalk

Texas CUBIWashington HB 1493Colorado biometric amendmentsCCPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.