BIPA

Illinois BIPA: What the Biometric Information Privacy Act Requires

Key Takeaways

  • BIPA requires written notice and a written release before a private entity collects a biometric identifier
  • The statute sets damages of $1,000 for negligent violations and $5,000 for intentional or reckless ones, per violation
  • Rosenbach v. Six Flags held that a person need not allege actual injury beyond the statutory violation to sue
  • Cothron v. White Castle held that a separate claim accrues each time a biometric identifier is collected or disclosed
  • Illinois is the only state whose biometric statute carries a broad private right of action; elsewhere enforcement runs through the attorney general

What BIPA Covers

The Biometric Information Privacy Act, 740 ILCS 14, was enacted in Illinois in 2008. It regulates how private entities handle two defined categories of data. A biometric identifier means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. Biometric information means any information, however captured, converted, stored or shared, that is based on a biometric identifier and used to identify an individual.

The statute lists exclusions from the definition of biometric identifier, including writing samples, written signatures, photographs, human biological samples used for valid scientific testing or screening, demographic data, and physical descriptions such as height, weight, hair color or eye color. Information captured from a patient in a health care setting, and information collected for purposes covered by the federal Health Insurance Portability and Accountability Act, are also carved out.

BIPA applies to private entities: individuals, partnerships, corporations, limited liability companies, associations and other groups. It does not apply to state or local government agencies, and it does not apply to contractors, subcontractors or agents of a state agency or local unit of government when working on that entity's behalf.

The Core Obligations

BIPA imposes four distinct duties, and litigation has arisen under each. They operate independently, so compliance with one does not satisfy the others.

Notice and written release before collection

A private entity may not collect, capture, purchase, receive through trade or otherwise obtain a person's biometric identifier or biometric information unless it first informs the subject in writing that the data is being collected or stored, informs the subject in writing of the specific purpose and the length of term for which it is being collected, stored and used, and receives a written release executed by the subject. In the employment context the statute contemplates a release executed as a condition of employment.

The sequencing matters. The notice and release must precede collection, which is why claims frequently turn on when a timekeeping or access-control system was first used rather than on whether a consent form eventually existed.

A published retention and destruction schedule

A private entity in possession of biometric data must develop a written policy, made available to the public, establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information. The destruction trigger is the earlier of two events: when the initial purpose for collecting or obtaining the data has been satisfied, or within three years of the individual's last interaction with the entity.

The public-availability element distinguishes this duty from an internal data-retention policy. A schedule that exists only in an internal handbook does not meet the terms of the section.

The duty is framed around possession rather than collection, which gives it wider reach than the consent provision. An entity that receives biometric data from another party, and therefore never had a collection event of its own to attach notice to, still holds the data and still owes the retention and destruction obligations. Courts have considered what possession means in this context, generally looking to whether the entity exercised dominion or control over the data rather than to where it was physically stored.

No sale or profit from biometric data

A private entity in possession of biometric identifiers or biometric information may not sell, lease, trade or otherwise profit from a person's data. Unlike the disclosure provision below, this prohibition is not subject to a consent exception.

Limits on disclosure

Disclosure, redisclosure or other dissemination is prohibited unless one of four conditions is met: the subject consents; the disclosure completes a financial transaction requested or authorized by the subject; the disclosure is required by state or federal law or municipal ordinance; or the disclosure is required by a valid warrant or subpoena.

A reasonable standard of care

Entities must store, transmit and protect biometric data using the reasonable standard of care within the industry, and in a manner at least as protective as the manner in which they store other confidential and sensitive information.

Remedies and Damages

Section 20 gives any person aggrieved by a violation a right of action against the offending party. Recovery is set at liquidated damages of $1,000 or actual damages, whichever is greater, for a negligent violation, and $5,000 or actual damages, whichever is greater, for an intentional or reckless violation. A prevailing party may also recover reasonable attorneys' fees and costs, expert witness fees and other litigation expenses, and may obtain injunctive relief.

The combination of per-violation liquidated damages and a fee-shifting provision is what produces settlement figures out of proportion to the size of the state. The statute does not cap aggregate recovery.

The Two Rulings That Shaped the Exposure

Two decisions of the Illinois Supreme Court define the practical scope of BIPA liability more than the statutory text alone does.

Rosenbach v. Six Flags Entertainment Corp. (2019)

The question was what it means to be a person “aggrieved” under section 20. The court held that an individual need not plead or prove an injury or adverse effect beyond the violation of the rights conferred by the statute. A violation of the notice and consent provisions is itself the injury the legislature identified. The ruling foreclosed the argument that a plaintiff had to show data misuse or a resulting harm.

Cothron v. White Castle System, Inc. (2023)

The question, certified from the Seventh Circuit, was whether a claim accrues only on the first scan and first transmission of biometric data, or on each one. The court held that a separate claim accrues each time an entity scans or transmits a person's biometric identifier without the required consent. The court also observed that the statute's damages provisions are discretionary rather than mandatory, leaving trial courts room on aggregate awards.

Read together, the two decisions mean liability attaches without proof of harm and multiplies with routine repeated use, such as an employee clocking in twice a day over several years.

How Illinois Compares to Other Biometric Regimes

Several states regulate biometric data, but the enforcement mechanism differs sharply, and that difference drives where litigation concentrates.

JurisdictionInstrumentPrivate right of actionEnforcement
IllinoisBIPA, 740 ILCS 14Yes, broadPrivate suits; statutory damages
TexasCUBI, Bus. & Com. Code §503.001NoAttorney General only
WashingtonRCW 19.375NoAttorney General under the Consumer Protection Act
Comprehensive state privacy lawsSensitive-data provisionsGenerally noState Attorney General; consent required for biometrics

Texas and Washington enacted biometric statutes with substantive obligations comparable to Illinois in several respects, but routed enforcement exclusively through the state. The comprehensive consumer privacy laws now in force across many states typically treat biometric data as sensitive personal data requiring opt-in consent, again enforced by the attorney general rather than by individuals.

Where BIPA Claims Have Concentrated

Filing patterns have clustered in a few recurring settings rather than spreading evenly across the economy.

  • Workplace timekeeping. Fingerprint and hand-geometry time clocks, where collection is repeated daily and predates any consent form
  • Access control. Building and equipment entry systems using fingerprint or facial recognition
  • Vendor relationships. Claims against the technology provider as well as the employer, since the statute reaches any private entity that obtains the data
  • Consumer-facing features. Photo tagging, virtual try-on tools and voice assistants that analyze face or voice data
  • Retail loss prevention. Facial recognition deployed in stores without posted notice or written release

Vendors and Technology Providers

The statute's obligations attach to any private entity that collects, captures, purchases, receives through trade or otherwise obtains biometric data. Nothing limits them to the entity with the direct relationship to the individual. A vendor supplying a fingerprint time clock, a facial recognition platform or a voice authentication service can itself obtain biometric identifiers within the meaning of the Act.

That structure produces claims against both the deploying organization and its technology supplier arising from the same collection. It has also generated disputes over allocation between them, since indemnification provisions in supply agreements were frequently drafted without this statute in view. Courts have addressed whether a vendor that never interacts with the individual can satisfy the notice and release requirements at all, given that the statute directs those duties at the entity collecting the data.

The Health Care Exclusion

The Act excludes from the definition of biometric identifier “information captured from a patient in a health care setting” and information collected, used or stored for health care treatment, payment or operations under HIPAA. The exclusion is written in terms of the patient relationship.

Litigation has tested its edges. A recurring question is whether biometric data collected from health care workers, such as nurses using fingerprint scanners to access medication dispensing cabinets, falls within an exclusion framed around patients. Courts have reached differing conclusions, some reading the treatment, payment and operations language broadly enough to reach workforce systems integral to patient care, others confining the exclusion to data captured from patients themselves. The distinction determines whether a large category of hospital employment claims proceeds.

The 2024 Amendment

The Illinois legislature responded to Cothron directly. An amendment enacted in 2024 provides that a private entity that more than once collects or discloses a person's biometric identifier or biometric information from the same person using the same method of collection commits, for purposes of the damages provisions, a single violation, and that the aggrieved person is entitled to at most one recovery for that single violation.

The amendment also addressed the form of consent, providing that a written release may include an electronic signature, defined as an electronic sound, symbol or process attached to or logically associated with a record and executed or adopted with intent to sign the record.

Two questions followed from the amendment. The first is temporal: whether it applies to conduct predating its effective date or only prospectively, an issue that determines the exposure in a substantial volume of pending cases. The second is scope: the single-violation rule is tied to the same method of collection, so an entity using more than one collection method may face separate accrual for each.

Limitations Period

Because BIPA contains no limitations provision of its own, courts had applied several different periods to different subsections, producing a fragmented result in which the same set of facts could be timely under one section and barred under another. In Tims v. Black Horse Carriers, Inc. (2023), the Illinois Supreme Court held that the state's five-year catch-all limitations period applies to all claims under the Act.

The decision resolved the fragmentation in favor of the longer period. Combined with the accrual rule then in force, it substantially expanded the window of conduct that could be reached in a single action, which is part of the context for the legislature's subsequent amendment.

Insurance Coverage Disputes

A parallel body of litigation concerns whether commercial general liability and related policies cover BIPA claims. Insurers have relied on exclusions for violation of statutes concerning the recording and distribution of material or information, and on employment-related practices exclusions where the claim arises from workplace timekeeping.

Outcomes have turned on specific policy language rather than on a general rule, and courts have reached different conclusions on similar exclusions. The result is that the availability of coverage for a BIPA claim is frequently litigated separately from the underlying claim itself.

Open Questions

Several issues continue to divide courts and shape how claims are litigated. The scope of the health care exclusion, and how far it extends to data collected from health care workers rather than patients, has produced conflicting outcomes. The interaction between BIPA and the exclusivity provisions of the Illinois Workers' Compensation Act has been litigated in the employment context. Questions about which statute of limitations applies, and about whether and when insurance policies cover BIPA claims, have generated their own body of decisions.

The Illinois legislature has also amended the statute since enactment. Anyone relying on this guide for a specific matter should confirm the current text of 740 ILCS 14 and the state of the case law, both of which continue to move.

Background

For the underlying law rather than this development: Illinois privacy law, HR & Employment privacy law, Technology & SaaS privacy law.

Frequently Asked Questions

Does BIPA apply to companies based outside Illinois?
The statute regulates private entities that collect biometric identifiers from individuals, and claims have been brought against out-of-state companies whose systems collected data from Illinois residents. Whether Illinois law reaches a given defendant is a jurisdictional question that turns on the facts of the relationship and the location of the collection.
Is a photograph a biometric identifier under BIPA?
The statute expressly excludes photographs from the definition of biometric identifier. Courts have nonetheless considered whether a scan of face geometry derived from a photograph falls within the definition, since the scan itself is listed as a covered identifier.
What is the difference between a biometric identifier and biometric information?
A biometric identifier is the enumerated measurement itself: a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. Biometric information is any information based on such an identifier that is used to identify a person, regardless of how it is captured or stored. Both are covered by the statute's obligations.
Does consent obtained after collection cure a BIPA violation?
The statute requires the written notice and release before collection. Under Cothron, a claim accrues at each collection or transmission without consent, so consent obtained later does not retroactively authorize earlier collections.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.