Illinois — Biometric Privacy

Illinois Privacy Law

Illinois enacted the Biometric Information Privacy Act (BIPA) in 2008, creating the nation's strictest and most comprehensive biometric privacy law. BIPA has become one of the most litigated privacy laws in the United States, with billions of dollars in settlements and ongoing litigation against major technology companies and employers.

What BIPA Regulates

The Biometric Information Privacy Act, enacted in 2008 and codified at 740 ILCS 14, was the first state law of its kind and remains the most consequential. It regulates biometric identifiers, defined as a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry, and biometric information, meaning information based on a biometric identifier and used to identify a person. The statute expressly excludes writing samples, signatures, photographs, physical descriptions, and information collected in a healthcare setting under HIPAA.

The definitional line has carried enormous weight in litigation. Photographs are excluded, but a face geometry scan derived from a photograph has been treated as within the statute, which is how photo-tagging and facial recognition systems came within its reach.

The Obligations the Statute Imposes

A private entity in possession of biometric identifiers must develop a written policy, made available to the public, establishing a retention schedule and guidelines for permanent destruction. The destruction trigger is the earlier of the purpose being satisfied or three years after the individual’s last interaction with the entity.

Before collection, the entity must inform the subject in writing that a biometric identifier is being collected or stored, inform them in writing of the specific purpose and the length of term for which it will be collected, stored and used, and receive a written release executed by the subject. In the employment context the release may be a condition of employment, which is why workplace collection is lawful where the paperwork is right and unlawful where it is missing.

The statute also prohibits selling, leasing, trading or otherwise profiting from a person’s biometric identifiers outright, with no consent exception. Disclosure is permitted only with consent, to complete a transaction the subject requested, where required by law, or under a valid warrant or subpoena. Storage must use the reasonable standard of care within the entity’s industry, and must be at least as protective as how it handles other confidential and sensitive information.

Why BIPA Generates the Litigation It Does

The distinguishing feature is section 20, which gives any person aggrieved by a violation a private right of action, with liquidated damages of 1,000 dollars for a negligent violation and 5,000 dollars for an intentional or reckless one, or actual damages if greater, plus attorney’s fees and injunctive relief. Almost no other biometric statute in the country does this: Texas and Washington regulate similar conduct but reserve enforcement to the state.

Two Illinois Supreme Court decisions set the shape of the exposure. In Rosenbach v. Six Flags the court held that a person need not plead injury beyond the statutory violation itself to be aggrieved, which removed the standing obstacle that would otherwise have limited the statute. In Cothron v. White Castle the court held that a separate claim accrues on each scan or transmission rather than only the first, producing potential damages that scale with the number of interactions rather than the number of people.

The legislature responded in 2024 with an amendment providing that multiple collections by the same method from the same person constitute a single violation for damages purposes, and confirming that an electronic signature satisfies the written release requirement. The amendment materially reduces the accrual exposure identified in Cothron going forward.

Where Violations Arise

The largest category is employment. Fingerprint and hand-geometry timekeeping systems were adopted widely before the statute drew attention, frequently without any written policy, notice or release, and often through a vendor to whom biometric data was disclosed without consent. Those cases are ordinarily straightforward on liability because the required documentation either exists or does not.

The second category is consumer technology: facial recognition in photo services, virtual try-on tools that map facial geometry, voice assistants processing voiceprints, and security or access systems in commercial premises. The third is the vendor layer, where a company supplying biometric technology to another business is itself a private entity in possession of identifiers and carries its own obligations rather than inheriting its customer’s.

The Rest of Illinois Privacy Law

Illinois legislates privacy across several statutes beyond BIPA. The Personal Information Protection Act sets breach notification duties and requires reasonable security for personal information. The Right to Privacy in the Workplace Act restricts employers from requesting social media credentials and regulates certain employment practices. The Artificial Intelligence Video Interview Act requires notice, explanation and consent before AI is used to analyse video interviews, and imposes deletion duties on request. The Genetic Information Privacy Act restricts use and disclosure of genetic testing information and, like BIPA, carries a private right of action.

The Student Online Personal Protection Act governs operators of school-directed online services, and the Mental Health and Developmental Disabilities Confidentiality Act imposes consent requirements for mental health records that are stricter than the federal baseline.

What Compliance Turns On

Because the statute is documentary, disputes are usually resolved on records rather than on intent. What exists in writing decides the case: a public retention and destruction policy, a written notice stating purpose and term given before collection, a signed release, vendor agreements addressing disclosure and destruction, and evidence that destruction actually occurred on schedule. An entity that collected biometric data lawfully but cannot produce the paperwork is in substantially the same position as one that never sought consent.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.