Illinois BIPA Compliance (740 ILCS 14/)

Biometric DataRequires Protection

Illinois's BIPA has generated billion-dollar verdicts. If you collect fingerprints, facial scans, or voiceprints—even for time clocks—you need compliance now.

500+ Illinois Businesses Protected
Private Right of Action
Class Action Eligible
$0
Per Intentional Violation
Per Person
$0
Per Negligent Violation
Per Person
$0M
Largest Verdict
BNSF Railway (2022)
0 Years
Statute of Limitations
To File Claims
Understanding the Law

What is BIPA?

The Illinois Biometric Information Privacy Act (740 ILCS 14/) is the strictest biometric privacy law in the nation—and the most litigated.

Covered Biometric Identifiers
Fingerprints
Common
Fingerprint scans used for time clocks, access control, or device authentication
Face Geometry
Common
Facial recognition for security, attendance, or photo tagging systems
Retina/Iris Scans
Eye-based identification for high-security access systems
Voiceprints
Common
Voice recognition for call centers, authentication, or AI assistants
Hand Geometry
Hand scanners for time tracking or physical access control
NOT Covered by BIPA
Regular photographs (without facial geometry extraction)
Tattoos or physical descriptions
Demographic data
Writing samples or signatures
Data collected for healthcare treatment
HIPAA-covered information

Note: Even if data seems excluded, the way it's processed may still trigger BIPA. Photo tagging systems that extract facial geometry are covered.

High-Risk Areas

Common BIPA Violations

Most BIPA lawsuits stem from these six compliance failures. Each can result in statutory damages per affected individual.

No Written Policy

Failing to create and make publicly available a written policy for retention and destruction of biometric data

$1,000 - $5,000 per person

No Written Consent

Collecting biometric data without first obtaining written informed consent from the individual

$1,000 - $5,000 per person

Missing Disclosure

Not informing individuals in writing of the specific purpose and length of time data will be stored

$1,000 - $5,000 per person

Retention Violations

Keeping biometric data longer than necessary or failing to destroy it within required timeframes

$1,000 - $5,000 per person

Unauthorized Disclosure

Selling, leasing, trading, or otherwise disclosing biometric data to third parties

$1,000 - $5,000 per person

Inadequate Security

Failing to store and protect biometric data using reasonable security measures

$1,000 - $5,000 per person

2024 BIPA Amendment: What Changed?

In August 2024, Illinois amended BIPA to address the Cothron v. White Castle ruling. Now, multiple collections or disclosures using the same method constitute a single violation per person, rather than a violation per scan. This significantly reduces (but doesn't eliminate) potential damages.

Important: You still need proper consent and policies. The amendment only limits how violations accrue—not whether you're liable.

Real Consequences

Landmark BIPA Cases

These cases demonstrate the massive financial exposure employers face under BIPA.

2023
Potential $17 billion exposure

White Castle

Cothron v. White Castle

Illinois Supreme Court ruled each fingerprint scan was a separate violation

2022
$228 million verdict

BNSF Railway

Rogers v. BNSF Railway

Jury awarded damages for fingerprint collection without proper consent

2021
$650 million settlement

Facebook

Patel v. Facebook

Photo tagging facial recognition without consent

Our Solutions

How We Protect You

Comprehensive BIPA compliance services for Illinois employers using any form of biometric technology.

BIPA Compliance Audit

Comprehensive assessment of all biometric data collection points, policies, and consent processes

Policy Development

Creation of compliant written retention/destruction policies and consent forms tailored to your operations

Employee Training

Training programs for HR, IT, and managers on proper biometric data handling and consent procedures

Retention Management

Systems to track retention periods and automate destruction of biometric data when no longer needed

Simple Process

Get Protected in 4 Steps

Our streamlined process gets you compliant quickly without disrupting your operations.

01

Biometric Inventory

We identify all biometric data collection points—time clocks, security systems, apps, and third-party vendors

02

Gap Analysis

Review existing policies, consent forms, and data handling practices against BIPA requirements

03

Remediation

Develop compliant policies, implement consent workflows, and establish retention schedules

04

Ongoing Compliance

Continuous monitoring, employee training updates, and vendor management to maintain compliance

Complete Illinois Coverage

Illinois Privacy Compliance Bundle

Illinois has the most aggressive privacy laws in the nation. Combine BIPA with GIPA for complete biometric and genetic information protection.

  • BIPA biometric compliance
  • GIPA genetic information compliance
  • Combined consent management
  • Unified policy framework
  • Single compliance dashboard
BIPA Compliance
Biometric Information
GIPA Compliance
Genetic Information

Don't Be the Next Headline

BIPA class actions have resulted in verdicts exceeding $200 million. If you use fingerprint time clocks, facial recognition, or voice authentication—get a free confidential assessment today.