top of page

Illinois' Biometric Privacy Act: Lessons Learned

Written by Evan Blonien, Edited by Bret Spielbauer

Vol. 2, Issue 2 – May 2026

Introduction

     The right to privacy, a right deemed by many to be fundamental in the digital age, is the latest topic of debate among consumer rights and civil liberty attorneys. As technologies like facial recognition and artificial intelligence expand, so do the threats towards individual privacy. However, current legislation remains stuck in an era of surveillance and security dawning from the Patriot Act in the early 2000s [1]. Only recently have states begun to address individual privacy, but progress remains slow and narrowly focused. One of the acts leading the movement is Illinois’s groundbreaking privacy act known as the “Biometric Information Privacy Act”, or BIPA for short [2]. BIPA makes it unlawful for a company to “collect, capture, purchase, receive through trade, or otherwise obtain a person’s or a customer’s biometric identifiers and/or biometric information” [3]. While some federal laws restrict the collection of social security information, credit card numbers, and other government identification, no federal restriction exists for the protection of a person's biometric data. Biometric data generally refers to unique biological or genetic information, but BIPA defines it more specifically as a "retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry” [4]. The distinguishing feature between biometric identifiers and sensitive information, such as social security numbers, is the immutable nature. While social security numbers can be changed, all it takes is one breach of privacy to forever compromise specific and sensitive biometric information.​

1. U.S. Patriot Act of 2001, Pub. L. No. 107-56, 115 Stat. 272

2.  See 740 ILCS 14/1–99, 2008.

3.  Id., 14/15(b).

4. Id., 14/1.

BIPA Specifications 

     When BIPA was passed in 2008, the State Legislature established strict rules on lawful collection and usage. BIPA requires corporations to meet three standards. The first standard is to inform users (in writing) about what data is being collected. The second is to state why the corporation needs the data, along with how long it will be collected, stored, and used. The third–and most important–is to acquire the written consent of the person whose data is collected. [5]. All of these measures combined gives BIPA the effectiveness to force companies to change the way they handle sensitive information. What differentiates BIPA from other privacy acts put into place by states like Washington, Texas, and California is enforcement. [6] [7] [8].   

     In the landmark case of a 14 year old boy at an amusement park was required to give his fingerprints to verify his age for his season pass [9]. After his mother learned that his biometric data was collected without informed consent, the mother filed suit and the case made its way to the State Supreme Court. The court–sharing the same concerns over the persistent and permanent nature of biometric data–ruled that a technical violation alone is sufficient harm to sue [10]. Additionally, the case also established the individual private right of action [11]. Private right of action allows private citizens to bring a case without having to wait for state action, which is often a slow, grueling process. Illinois' approach to the right of action is different from other states like Texas and Washington which reserve the right of action for the State Attorney General. While this may seem like a small difference, it has huge implications on the effectiveness and impact. Cases brought by the attorney general are fewer, but can result in higher penalties due to the limited time and resources of the Attorney General's office. Alternatively, allowing private citizens to bring cases was thought to flood the court system with violations (while in reality few cases reach the court as companies responded to the act by stopping their illegal data collection). Texas, Washington, and Illinois were afraid of this possibility, however Illinois stated that “when a private entity fails to comply with one of section 15’s requirements, that violation constitutes an evasion, impairment or denial of the statutory rights of any person or customer whose biometric identifier or biometric information is subject to breach” [12].  Therefore, they are entitled to seek recovery even if that would overburden the courts. 

     The result is shown in cases like Cothron v. White Castle [13]. White Castle was brought to court over its use of finger print scans to track employees clocking in and out of work, and as a result they were faced with hundreds of violations per employee. At a rate of $1000 per negligent violation and $5000 per reckless violation (Where a negligent violation means that the company did not use reasonable care when handling data and a reckless violation refers to a willful disregard for the rules). White Castle faced liability of over $17 billion for only 9500 employees. A similar case, Rogers v. BNSF Railway Co., resulted in preliminary liability of over $228 million after the company had violated the statute 45,600 times [14]. Both of these cases show the effectiveness of private action in action. If it were up to the attorney general, far fewer of these cases would see the light of the courtroom and corporations would be more hesitant to reconsider how they handle biometric data. The private right of action is where BIPA gets the teeth to effectively fight back against corporations in ways that attorney generals and other state privacy legislation cannot do.

5. See 740 ILCS 14/15(b).

6. Wash. My Health My Data Act, Ch. 19.373RCW.

7. Texas Capture Or Use Of Biometric Act, Tex. Bus. & Com. Ann. § 503.001 et seq.

8.  California Privacy Rights Act of 2020, Prop. 24 (2023).

9. Rosenbach v. Six Flags Entertainment Corp., 129 N.E.3d 1197 (Ill. 2019)

10. Id, 1200. 

11. Id, 1203.

12. Id, 1206.

13. Cothron v. White Castle, 20 F. 4th 1156 (7th Cir. 2021).

14.  Rogers v. BNSF Railway Co., 680 F. Supp. 3d 1027 (N.D. Ill. 2023).

BIPA’s Limitations

    The protections of BIPA have–so far–been applied with great effect, but there still remain many limitations that can make enforcement difficult. One of the biggest restrictions comes from the definition of biometric identifiers. BIPA only references physical traits such as finger prints, but disregards some of the behavioral factors that are derivatives of that same sensitive information [15]. For example, some of the behavioral factors left out include typing rhythm, gait, keystroke, signature, behavioral profiling, and voice, as well as anything that can be used to identify people, thus compromising privacy in a very similar manner to protected forms of biometric information. Another key weakness in BIPA protections comes from the 2024 amendment to that law [16]. This amendment redefines the consequences of violation. In the previous examples of White Castle and BNSF, liability was based on the total count of violations, however the amendment shifted the definition to only consider the total number of people rather than the number of infractions. This means that a corporation who collected an individual's fingerprint 500 times would face the same punishment as if they only collected their fingerprint once.       Additionally, the Seventh Circuit recently ruled that limit to damages applies retroactively, which means that cases filed before the creation of this amendment must apply damages on a “per person” rather than a “per violation” basis [17].

     Along with the Public Act, another limitation of BIPA–although actually quite generous compared to other torts–is the five year statute of limitations imposed by the State Supreme Court case Tims v. Black Horse Carriers, Inc. [18]. The case decided whether the biometric privacy statute of limitations fell under the general five year ‘catch-all’ for all civil cases or the one year statute which is exclusive to claims involving “actions for slander, libel or for publication of matter involving the right of privacy” [19]. Ultimately the court ruled in favor of the five year statute, which although is a limitation to the effectiveness of BIPA, is the maximum cap that is placed on all civil cases and is a far more favorable outcome [20].

     Beyond the restrictions on statute of limitations and damages, one big issue for BIPA are the holes that are carved out to avoid stepping into the territory of federal statutes such as HIPAA [21]. Though there are many small exceptions, some of the major ones are the health care workers, financial institutions, and state contractors. The first major exception on healthcare was created because of the existing protections outlined in HIPAA. However, one area under debate is how this exemption applies to health care workers. In the case Mosby v. Ingalls Memorial Hospital, a nurse filed suit because their biometric information was used as a part of an automated medical dispensary [22]. The court ruled that healthcare worker data is a part of a HIPAA-defined health care activity and therefore falls under the exception even though health worker information is not automatically protected under HIPAA and leaves a grey area around unlawful collection [23]. Two smaller exemptions are unions and financial institutions. Though both of these exemptions are a requirement under the Supremacy Clause of the U.S. Constitution, it can sometimes give corporations a lifeline to an otherwise unforgiving act. 

15. See 740 ILCS 14/10. 

16. See Pub. Act 103-0769.

17. Clay v. Union Pacific RR Co., Case No. 25-2185 (7th Cir. Apr. 1 2026).

18. Tims v. Black Horse Carriers, Inc., 216 N.E.3d. 845 (Ill. 2023). 

19. See 735 ILCS 5/13-205.

20. Id. 847.

21. Health Insurance Portability and Accountability Act of 1996, Pub. Law 104-191.

22. Mosby v. Ingalls Memorial Hospital, 234 N.E.3d 110 (Ill. 2023).

23. Id. 120.

Contentious Issues Within BIPA

     Along with the holes that were created in the state statutory exceptions, the most glaring exemption in BIPA is its limitation in scope for only private entities. This is particularly contentious because it leaves out law enforcement and other state affiliates. Law enforcement can use facial recognition cameras, store body camera footage indefinitely, and record all other forms of biometric information without the consent or knowledge of the affected party. Especially given the current outrage against state collaboration with immigration enforcement, the limitless and secretive usage of biometric information has been described as part of the government’s “evolution into cyber-surveillance states . . . to target the digital data associated with suspicious individuals” [24]. Combined with the exemption carved out for government contractors, this means that any company that has facial recognition cameras or any biometric collection device can partner with the government to be exempt from BIPA enforcement despite bypassing the non-consensual collection that BIPA aims to protect. One of the specific threats that is posed by everything being recorded and at the hands of law enforcement is the ability to cross-reference. An example of the potential threat to privacy comes from the scenario where an individual may agree to have his photo taken or used for facial recognition in one instance, but then his face scan is used to identify him in countless other photos even though he did not give consent. The fact that BIPA does not extend to the government is a big shortcoming that will only worsen as technologies like flock cameras continue to develop. Although much has been done towards digital privacy in the past 20 years, the government exemption shows that there is much more work to be done to fully achieve the right of privacy.

24. Donald L. Buresh, The Illinois’ Biometric Information Privacy Act What Every Illinois Attorney Should Know, (Apr. 26, 2026) https://www.dcba.org/mpage/v35-Donald-L-Buresh

Conclusion

       The purpose of a privacy right should be to redistribute the power to individuals to allow them to regain control as to how their data is used and manipulated. In a paper by Prosser, he outlined the four categories of infringement to the right of privacy as (1) intrusion on personal affairs, (2) undesired disclosure of personal information, (3) false light in the public eye, and (4) unauthorized commercial appropriation of personal information [25]. While it is important to celebrate the successes of BIPA such as its trailblazing qualities of private right of action and strict liability or its impact on changing the way businesses protect information, it is equally important to realize that without an equal application of BIPA to both corporate and government entities, BIPA is only able to protect the fourth category of privacy, which is unauthorized commercial appropriation. Until we are able to create a general privacy act that protects all forms of privacy infringement including those by the government, we will remain a long way from a right to privacy and security in the digital age.

25. W.L Prosser, Privacy, 48 Cal. L. Rev. 383 (1960).

bottom of page