Illinois Biometric Information Privacy Act (BIPA) - 2026 Guide
Table of Contents
The Illinois Biometric Information Privacy Act (BIPA) is a state law that protects biometric data: fingerprints, face scans, voiceprints, and eye scans. Before a company collects any of it, BIPA requires written notice and signed consent.
The law covers any private business that collects biometric data from someone in Illinois. There is no revenue floor, no employee minimum, and no exception for companies based in other states.
Unlike most privacy laws, which are enforced by a regulator, BIPA is enforced by the people it protects. Anyone whose data was collected without consent can sue directly, and damages start at $1,000 per person with no proof of harm needed.
Most state privacy laws are enforced by an attorney general, apply only above a size threshold, and give you a window to fix mistakes. BIPA has none of that. Any person whose fingerprint or face scan you captured without consent can take you to court, and the smallest company is as exposed as the largest.
That design has made a 2008 law the most heavily litigated biometric law in the country: Facebook alone paid $650 million to settle claims over its photo-tagging feature.
This guide covers what BIPA actually protects, whether it reaches your business, what your consent flow has to look like, and what the 2024 amendment did and didn't change.
What is the Illinois Biometric Information Privacy Act?
The Illinois Biometric Information Privacy Act, or BIPA (740 ILCS 14), regulates how private businesses collect, store, share, and destroy biometric data. It took effect on October 3, 2008, making Illinois the first state to regulate biometrics, and it remains one of the strictest in U.S. state privacy laws.
The lawmakers' reasoning still holds up. A stolen password can be changed. A stolen fingerprint can't. Because biometric data is permanent, the statute treats collecting it as something that needs permission first, not forgiveness later.
The statute's own findings show what legislators were worried about in 2008: finger-scan payments at grocery stores, gas stations, and school cafeterias (740 ILCS 14/5). The technology moved on to face recognition and voice analysis, but the consent-first mechanics were written broadly enough to follow it.
A 2024 amendment (Public Act 103-769) made repeated scans of the same person by the same method count as one violation.

What counts as biometric data under BIPA?
BIPA protects exactly five biometric identifiers: a retina or iris scan, a fingerprint, a voiceprint, a scan of hand geometry, and a scan of face geometry. That list is closed. It also protects biometric information, meaning any data based on one of those identifiers that's used to identify a person, however it's stored or shared.
The closed list matters because many folks get it wrong. DNA isn't on it: Illinois covers genetic data under a separate law, the Genetic Information Privacy Act. On palm veins, gait, keystroke patterns, and scent, the statute is simply silent: they're not listed, and they're not excluded either.
The statute also excludes a specific set of items: writing samples, written signatures, photographs, demographic data, physical descriptions, donated organs, materials covered by the Genetic Information Privacy Act, health information covered by HIPAA, and medical imaging.
The photograph exclusion deserves a closer look, because the statute pulls in two directions on it. The photo itself is excluded, and so is information derived from excluded items. But biometric information covers data based on a face scan regardless of how it's captured, and a face-geometry map extracted from a photo is exactly what the biggest BIPA cases have targeted.
That tension has never been settled on the statute's text. What the record shows is the risk: Facebook paid $650 million over face templates built from users' photos rather than test the exclusion at trial.

Does BIPA apply to your business?
BIPA applies to any private entity that collects or holds biometric data from a person in Illinois. A private entity means any individual, partnership, corporation, LLC, or association, however organized. There's no revenue threshold, no headcount minimum, and no floor on how many records you hold: one person's fingerprint is enough.
In practice, the law follows the Illinois person, not your address. The statute itself draws no geographic line; courts look at where the collection from an Illinois person happened. So a company with no Illinois office still takes on BIPA exposure through a remote employee in Chicago who clocks in by fingerprint, an Illinois job applicant put through voice screening, or Illinois users of a face-filter app.
Notice what's missing here compared to laws like the Virginia VCDPA: there's no consumer-count math to do. If you collect covered data from anyone in Illinois, you're in.
Who is exempt from BIPA?
A few groups sit outside BIPA entirely. State and local government agencies aren't private entities, and neither are Illinois courts. Financial institutions subject to Title V of the Gramm-Leach-Bliley Act, along with their affiliates, are carved out completely (740 ILCS 14/25). Contractors working for a government agency are exempt, but only for that government work, not across their whole business.
Licensed private detectives, security firms, alarm companies, fingerprint vendors, and locksmiths get a narrower accommodation: BIPA is read not to conflict with the Illinois law that already licenses and regulates them.
Some data is exempt even when the business isn't. Patient information captured in a health care setting, or handled under HIPAA for treatment, payment, or operations, falls outside the law. So does material regulated by the Genetic Information Privacy Act.
One exemption businesses keep looking for doesn't exist: there is no small-business carve-out, and nothing pending in the legislature would create one.
What does BIPA require before you collect biometric data?
BIPA requires three mandatory steps before any fingerprint or face scan is collected. And collection doesn't just mean running a scanner: buying biometric data, receiving it through a trade, or obtaining it any other way all count.
- Tell the person in writing that biometric data is being collected or stored (a legally authorized representative, such as a parent or guardian, can receive the notice instead).
- Tell them in writing why, and for how long the data will be collected, stored, and used.
- Get a written release: a signed consent from the person or their legally authorized representative.
The 2024 amendment (Public Act 103-769) added electronic signatures to the definition of a written release. The bar is a signature in the legal sense: an electronic mark or process tied to a stored record, made with the intent to sign it.
A click-through clears that bar when the click plainly signs a specific consent record. For employees, a release signed as a condition of employment also counts.

What are your other duties under BIPA?
BIPA puts four more duties on any business holding biometric data, beyond the consent rules. They apply to possession itself, so a vendor storing someone else's scans carries them too.
Publish a retention and destruction policy. You need a written public policy with a retention schedule and destruction guidelines. Destroy the data when the initial purpose for collecting it is satisfied, or three years after the person's last interaction with you, whichever comes first. And the schedule binds you: failing to follow your own policy is its own violation, one the 2024 amendment's cap doesn't reach.
Never sell or profit from it. BIPA flatly prohibits selling, leasing, trading, or otherwise profiting from biometric data. Unlike the disclosure rule, this one has no consent exception. A person cannot sign away this protection.
Don't share it without a reason the statute names. Disclosure is allowed in four cases only: the person or their representative consents, the disclosure completes a financial transaction the person requested or authorized, a state, federal, or local law requires it, or a valid warrant or subpoena compels it. An informal police request doesn't qualify.
Protect it at least as well as your most sensitive data. The duty covers storing, transmitting, and protecting the data, and the standard has two parts: your industry's reasonable standard of care, and protection at least as strong as what you give account numbers, passwords, and social security numbers.
One thing BIPA doesn't include is a breach-notification duty. If biometric data leaks, your notice obligations come from Illinois' separate breach-notification law, not from BIPA. The lawsuit risk under BIPA comes from how you collected and stored the data, not from the breach itself.
Can your website or app trigger BIPA?
A website or app can absolutely trigger BIPA. In fact, the biggest settlements on record came from consumer software, not factory timeclocks. If a feature builds one of the five identifiers from an Illinois user, the law is in play.
And the risky features look ordinary. A face filter or virtual try-on tool only works by mapping the user's face. Photo apps that group pictures by person build face templates, and that one feature cost Google $100 million in Illinois. Selfie-to-ID identity checks scan face geometry, and voice assistants, call-center authentication, and voice analytics can all create voiceprints.
You don't need to be a tech giant, either. In Bryant v. Compass Group (2020), a fingerprint scan at a vending machine sign-up was enough to land its operator in a federal appeals court. Wow Bao, a restaurant chain, got sued over the face scans its self-service kiosks used to verify orders.
Training data is the newest front. Clearview AI scraped photos from across the web into a face-search database, and the class action that followed covered virtually anyone whose face appeared online. The company couldn't fund a cash settlement, so it paid the class in equity. If you train models on face or voice data from Illinois users, or buy a model built that way, the collection question lands on you.
The fix has to live inside the product: notice and consent before the feature runs, with a record you can pull up later. That's the same architecture Enzuzo's consent management platform uses for cookie and tracking consent today: notice, an affirmative act, and an audit trail.
Do biometric timeclocks violate BIPA?
Biometric timeclocks are legal under BIPA, but they're the most common source of BIPA lawsuits, because the consent steps get skipped at onboarding. Fingerprint and hand-scan clocks, secure-area scanners, and fingerprint-unlocked systems all collect a covered identifier from every employee, every shift.
Getting it right is mostly a matter of sequence. New hires read the written notice and sign the release before their first punch, not somewhere in the first payroll cycle. The retention policy sits somewhere the public can actually find it.
When someone leaves, the purpose you collected the data for usually ends with them, so that's when it gets destroyed. Three years from their last interaction is the hard deadline either way. Document the timeclock vendor's role too; the next section explains why.
Union employers have one extra shield. In Walton v. Roosevelt University (2023), the Illinois Supreme Court held unanimously that federal labor law preempts BIPA claims from employees under a union contract, when the employer invokes the contract's broad management-rights clause. Those disputes go through the grievance process instead of court.
Arbitration clauses with class-action waivers can play a similar role for non-union staff. Neither shield covers workers who never signed one.

Can software vendors be liable under BIPA?
Vendors are directly liable under BIPA, not just the businesses that deploy them. The statute puts its retention, no-profit, disclosure, and security duties on any entity in possession of biometric data (740 ILCS 14/15). There's no controller-versus-processor split like the one in Colorado's CPA: if you hold the data, you have the duties.
A federal court made that concrete early. In Namuwonge v. Kronos (2019), an employee sued the timeclock maker directly, and the court let the claim proceed against the vendor itself because it had no public retention policy. The employer's consent failures were beside the point; Kronos held the data.
Sharing the data creates exposure of its own. In the White Castle case, every fingerprint scan traveled to a third-party vendor for authentication, and that flow is what turned one employee's claims into a per-scan damages fight.
So if you build or buy biometric features, put the roles in the contract: who gives the notice, who collects the release, who holds the data, who destroys it. Both sides carry duties either way. The contract decides who pays when one of them fails.
BIPA violation penalties
BIPA violations cost $1,000 per person for negligent violations and $5,000 for intentional or reckless ones, or actual damages if those run higher, plus attorney fees, expert fees, and costs (740 ILCS 14/20). Those figures are floors, not caps, and courts can add injunctions on top.
Three design choices make the math dangerous at scale. Nobody has to prove harm: in Rosenbach v. Six Flags (2019), the Illinois Supreme Court held the violation itself is the injury, in a case about a teenager's thumbprint scanned for a season pass.
There's no cure period either, so fixing your consent flow after a demand letter doesn't erase what came before. And damages run per person, which turns a workforce or user base into a multiplier.
The biggest BIPA fines
The biggest BIPA settlements all trace to the same failure: a biometric feature shipped without notice and signed consent, multiplied across a class.
| Company | Amount | Year | What triggered it |
|---|---|---|---|
| $650 million | 2021 | Face templates from photo tagging | |
| Google Photos | $100 million | 2022 | Face grouping feature |
| TikTok | $92 million | 2022 | Alleged faceprint harvesting |
| BNSF Railway | $75 million | 2024 | Driver handprint scans (after a $228M verdict was vacated) |
| Instagram (Meta) | $68.5 million | 2023 | Face recognition without consent |
| Clearview AI | ~23% equity stake (~$51.75M) | 2025 | Scraped photos into a face database |
| Snap | $35 million | 2022 | Lenses and filters |
| White Castle | $9.39 million | 2024 | Employee fingerprint timekeeping |
The BNSF row has a story behind it. The first BIPA jury trial ended in a $228 million judgment in 2022. The judge then vacated the award and ordered a new trial on damages, holding that BIPA damages are discretionary, and the parties settled at $75 million instead. Google's $100 million worked out to roughly $95 for each of the 687,484 Illinois residents who filed a claim.
Every one of those figures traces back to skipped notice-and-consent steps, work a small engineering team could have shipped in a sprint or two.
Will insurance cover a BIPA lawsuit?
Insurance sometimes covers BIPA claims, but the window has narrowed steadily since insurers started getting hit with claims. In West Bend Mutual v. Krishna Schaumburg Tan (2021), the Illinois Supreme Court made an insurer defend a tanning salon against a BIPA class action under a standard business liability policy. Sharing fingerprint data with even one vendor, the court held, counts as publication of private information.
Insurers have responded with broader exclusions, and courts have begun enforcing them. An Illinois appellate court rejected coverage under a broad data-violation exclusion in late 2023, and the Seventh Circuit upheld an access-or-disclosure exclusion in 2024. Many current policies now carry BIPA-specific exclusions.
How did the 2024 BIPA amendment change the law?
The 2024 amendment (Public Act 103-769) changed how damages add up. Repeated collections of the same identifier from the same person by the same method now count as one violation, with at most one recovery. It also made electronic signatures valid written consent. The amendment rewrote only the statute's definitions and damages sections; the consent duties haven't changed since 2008.
It answered a ruling that had pushed exposure into absurd territory. In Cothron v. White Castle (February 2023), the Illinois Supreme Court held that a separate claim accrues with every single scan, while warning the totals could be ruinous and inviting the legislature to act. White Castle's own worst-case estimate was $17 billion. Eighteen months later, the legislature acted.
The open question was whether the fix reached lawsuits already in progress, and in April 2026 the Seventh Circuit said yes. In Clay v. Union Pacific (No. 25-2185), a truck driver's roughly 1,500 fingerprint scans could have meant about $7.5 million under per-scan accrual.
The court held the amendment changes remedies, not rights, so it applies to cases that were pending when it took effect. The Illinois Supreme Court hasn't weighed in yet, and state courts could still read it differently.
Three limits keep the amendment from being a full reset. The one-violation rule covers collection and disclosure claims only; retention-policy, profit-ban, and security claims sit outside it. And the cap requires everything to match (same identifier, same person, same collection method), so a fingerprint clock plus a face-scan door may still stack.
The disclosure half of the cap adds one more condition: the same recipient. Send the same fingerprint template to three different vendors and that's three violations under the statute's text, so a multi-vendor biometric stack multiplies exposure even after the amendment.
New BIPA filings have reportedly fallen sharply since the amendment took effect, though cases already in the pipeline are still working through the courts.
Springfield isn't done with BIPA either. A bill to make the amendment expressly retroactive (HB 2866) stalled in committee in March 2025. Bills carving out biometric collection for security purposes, and one adding neural data to the covered list, have been introduced without passing.
What is the statute of limitations for BIPA claims?
BIPA claims carry a five-year statute of limitations. The statute itself sets no deadline, so in Tims v. Black Horse Carriers (2023), the Illinois Supreme Court applied Illinois' five-year catchall period to every BIPA claim, rejecting a lower-court split that had given some claims only one year.
Five years is a long tail. An employee who scanned a fingerprint daily through 2022 can still file in 2027, and a class action can sweep in everyone whose data you touched over that window. Cleaning up your consent flow today doesn't close the book; the exposure from past collection ages out slowly. No pending bill shortens the period, so five years is the planning number.
How does BIPA compare to other biometric privacy laws?
BIPA is the only dedicated biometric statute that lets the affected person sue directly, and that single feature explains why Illinois generates the biometric litigation while other states generate compliance memos. Texas and Washington have their own biometric laws (CUBI and RCW 19.375), but only their attorneys general can enforce them.
| Illinois (BIPA) | Texas (CUBI) | Washington | |
|---|---|---|---|
| Who can sue | Any affected person | Attorney general only | Attorney general only |
| Consent before collection | Written release required | Notice and consent | Notice, consent, or commercial-purpose limits |
| Preset damages per person | $1,000 or $5,000, or actual damages if greater | Civil penalties up to $25,000 per violation, AG-enforced | Civil penalties, AG-enforced |
| Cure period | None | Not applicable (AG enforcement) | Not applicable (AG enforcement) |
Newer comprehensive privacy laws also reach biometrics from a different angle. States like Colorado and Connecticut treat biometric data as sensitive data requiring opt-in consent, enforced by their attorneys general with thresholds and cure windows. If you operate in multiple states, BIPA sets the high-water mark. A consent flow built to Illinois' standard asks more of you than any other state's biometric rules do.
BIPA compliance checklist: how to comply
BIPA compliance comes down to consent and records: know where biometric data enters your business, and be able to prove permission came first.
- Map the entry points. Timeclocks, door scanners, ID verification, face filters, voice features, and any vendor system that touches fingerprints, faces, or voices.
- Put notice and release before collection. Written notice of what, why, and how long, then a signed release. Electronic signatures count; make sure yours produces a stored record per person.
- Publish a retention and destruction policy. Public, written, with the whichever-comes-first destruction trigger built in.
- Fix the vendor contracts. Name who notices, who collects consent, who holds data, who destroys it, and who indemnifies whom.
- Verify destruction actually runs. Departed employees and closed accounts need their data deleted on schedule, and you want a log proving it.
- Keep the consent records. In a lawsuit, the timestamped release is the first thing you'll be asked to produce. A five-year claims window means the records outlive the data.
Consent you can prove is the entire game under BIPA. Enzuzo's consent management platform gives websites that proof layer for tracking consent: geo-targeted banners, consent logs with timestamps, and records you can produce on demand. Book a demo to see how you can avoid BIPA claims.
Frequently asked questions about BIPA
What is BIPA in simple terms?
BIPA is an Illinois law that stops companies from taking your fingerprint, face scan, or voiceprint without asking first. A business has to tell you in writing what it's collecting and why, get your signed permission, and delete the data when it's done. If it skips those steps, you can sue it directly for $1,000 or more.
What is the statute of limitations for BIPA claims?
BIPA claims can be filed up to five years after a violation. The Illinois Supreme Court set that period in Tims v. Black Horse Carriers (2023), applying the state's catchall deadline because BIPA sets none of its own. The window runs per violation, so past collection can stay actionable for years after you fix your process.
Does BIPA apply to companies outside Illinois?
A company with no Illinois presence can still face BIPA claims, because courts focus on where data was collected from an Illinois person, not on where the company is based. A remote Illinois employee clocking in by fingerprint, an Illinois applicant screened by voice analysis, or Illinois users of a face-filter app each create exposure.
What damages can someone recover under BIPA?
A person can recover $1,000 or actual damages for each negligent violation, whichever is greater, and $5,000 or actual damages for intentional or reckless ones, plus attorney fees. Since August 2024, repeated scans of the same person by the same method count as one violation, so recovery runs per person rather than per scan.
Is DNA covered by BIPA?
DNA is not covered by BIPA. The law protects exactly five identifiers: retina or iris scans, fingerprints, voiceprints, hand geometry scans, and face geometry scans. Genetic material falls under a different Illinois law, the Genetic Information Privacy Act. Many summaries list DNA under BIPA, and they're wrong on the statute's text.
Did the 2024 amendment reduce BIPA liability?
The 2024 amendment reduced BIPA exposure substantially by ending per-scan damages: repeated collection of the same biometric identifier from the same person by the same method is now a single violation. In April 2026 the Seventh Circuit held the change applies retroactively in federal court to cases pending when it took effect. Per-person damages, attorney fees, and the five-year window all remain.
Does BIPA have a cure period or a small-business exemption?
BIPA has neither a cure period nor a small-business exemption. Fixing a consent gap after the fact doesn't erase liability for the data already collected, and a five-person shop faces the same statute as a national chain. Nothing pending in the legislature would change either one.
Do photos or face filters trigger BIPA?
Face filters can trigger BIPA even though photographs themselves are excluded, because a filter works by mapping face geometry, and a face-geometry scan is a covered identifier. Face templates built from user photos drove the Facebook, Google, and Instagram settlements, and lens and filter features drove Snap's. Plan on notice and consent before those features run for Illinois users.
Mate Prgin
Mate is the CEO & Founder of Enzuzo. He has an executive MBA from Ivey Business School and is a subject matter expert in data privacy and compliance.

