What Is BIPA and Why It Matters

The Illinois Biometric Information Privacy Act (BIPA) is one of the most stringent privacy laws in the United States. It governs how organizations collect, use, store, share, and destroy biometric identifiers and biometric information (740 ILCS 14).

Unlike most privacy laws, BIPA lets private individuals sue directly, with statutory damages for each violation. That has made it a major source of class-action lawsuits for businesses of all sizes - not just large enterprises.

If your organization collects or uses biometric data in Illinois, or from Illinois residents, BIPA compliance is not optional.

What It Is

BIPA is an Illinois statute that sets conditions on every stage of the biometric data lifecycle: notice before collection, written consent, retention limits, security safeguards, and destruction deadlines.

Its enforcement mechanism is what sets it apart. An aggrieved person can recover $1,000 per negligent violation or $5,000 per intentional or reckless violation - or actual damages, whichever is greater (§20). The Illinois Supreme Court held in Rosenbach v. Six Flags (2019) that a person need not prove actual harm to sue - a violation of the statute's requirements is enough.

An August 2024 amendment (P.A. 103-769) recalibrated the damages math: when the same biometric identifier is collected from the same person by the same method repeatedly, that counts as at most one recoverable violation, not one per scan. The amendment also confirmed that an electronic signature satisfies the written-consent requirement.

The exposure is still serious. Per-person, per-method damages across a workforce or customer base scale quickly - the arithmetic is just per person now, not per scan.

Who It Applies To

BIPA applies to any private entity that collects biometric data from Illinois residents, operates in Illinois, or runs biometric systems involving Illinois employees, customers, or users.

That includes:

  • Employers: using biometric timekeeping or building access - the classic BIPA fact pattern.
  • Healthcare organizations: for employee biometrics; patient data in a health care setting or handled under HIPAA is excluded from BIPA's definitions.
  • Manufacturers and warehouses: where biometric timeclocks are standard equipment.
  • Retailers and hospitality businesses: from access control to customer-facing systems.
  • Technology companies: using facial recognition or voice authentication.
  • SaaS providers: whose products process Illinois users' biometric data have also faced BIPA claims, though how far the statute reaches out-of-state vendors is fact-dependent and litigation-driven.

Company size does not matter. Small and mid-sized businesses are frequent BIPA defendants.

Who is excluded

The statute carves out government agencies and courts, financial institutions subject to the Gramm-Leach-Bliley Act, and contractors working for state and local government (§§10, 25). Patient information captured in a health care setting or governed by HIPAA is excluded from the definitions - but a hospital's employee fingerprint timeclock is still squarely covered.

What Information Is Regulated

BIPA regulates two defined categories (§10).

Biometric identifiers - the statute's exact list:

  • Retina or iris scans
  • Fingerprints
  • Voiceprints
  • Scans of hand geometry
  • Scans of face geometry (the basis of facial recognition)

Biometric information: any information, however captured or stored, based on a biometric identifier and used to identify an individual.

Common real-world examples: fingerprint or hand-geometry time clocks, facial recognition for building access, voice authentication systems, and biometric features embedded in HR, security, or customer-facing applications.

Relation to Other Frameworks

BIPA is the strictest member of a growing family of biometric rules - and its boundaries are drawn by other frameworks.

  • **CCPA/CPRA:** treats biometric data as sensitive personal information in California, with limitation rights instead of a private right of action.
  • **GDPR:** classifies biometric data used for identification as special category data requiring enhanced protection.
  • **HIPAA:** patient data captured in a health care setting or governed by HIPAA sits outside BIPA's definitions - employee biometrics at the same organization do not.
  • **GLBA:** financial institutions subject to GLBA are excluded from BIPA entirely.

If you operate across states, one biometric governance program - notice, consent, retention, security - satisfies the strictest rule and covers the rest.

IT Requirements

From an IT and cybersecurity perspective, BIPA compliance turns on governance, consent, security, and lifecycle management of biometric data. The statute requires private entities to:

1. Provide written notice. Before collection, individuals must be told what is collected, why, and how long it will be kept (§15(b)).

2. Obtain a written release. Explicit written consent before collection. Since the 2024 amendment, an electronic signature satisfies this requirement - which makes properly built digital consent workflows fully defensible.

3. Publish a retention and destruction policy. A written, publicly available schedule. Destruction is due when the initial purpose is satisfied or within 3 years of the individual's last interaction with the entity - whichever comes first (§15(a)). "When no longer needed" is not the standard; the 3-year cap is a hard deadline.

4. Secure biometric data. Using the reasonable standard of care for your industry, and at least as protectively as other confidential information: strong access controls, encryption, secure storage, logging and monitoring, and least-privilege access.

5. Never sell, and rarely disclose. Selling, leasing, trading, or otherwise profiting from biometric data is prohibited outright - no exceptions (§15(c)). Disclosure is separately restricted to narrow cases: consent, completing a transaction the person requested, legal requirement, or court order (§15(d)).

Where IT makes or breaks compliance

Most BIPA violations are not caused by hackers. They come from missing documentation, unclear consent, poor retention practices, or unsecured biometric systems. Key IT responsibilities: identifying where biometric data exists across systems, securing biometric databases and integrations, enforcing access control and MFA, monitoring access and usage, supporting audit trails, executing secure deletion on the statutory schedule, and managing every third-party vendor that touches biometric data.

Why It Matters

BIPA's risk profile is unique among U.S. privacy laws:

  • No proof of harm required. The Illinois Supreme Court has held that a statutory violation alone makes a person "aggrieved" and able to sue (Rosenbach v. Six Flags, 2019).
  • Statutory damages per violation. $1,000 negligent, $5,000 intentional or reckless - or actual damages, whichever is greater.
  • One violation per person, per method. Under the 2024 amendment, repeated scans of the same person by the same method count once for damages. The per-scan multiplier is gone - but do the per-person math: a 100-employee fingerprint timeclock deployed without compliant notice and consent still represents six figures of statutory exposure at the negligent tier alone.
  • Class actions are the norm. Biometric systems touch everyone in a workforce or user base at once, so claims arrive as classes, not individuals.

The failure mode is mundane: a timeclock rolled out without written notice, a consent form that never got signed, a retention policy that exists nowhere. Paperwork failures, priced per person.

How It Fits Into Cyber Risk Management

BIPA is often misread as a purely legal problem. Compliance actually fails or succeeds in IT systems - which makes it a governance problem with a technical core.

Governance, Risk & Compliance keeps the notice, consent, and retention documentation aligned with what systems actually do - the gap where most BIPA claims are born. Cyber Risk Management secures the biometric systems themselves, and Third-Party Assessments reach the timeclock vendors and biometric platforms processing data on your behalf.

If your environment cannot demonstrate these controls, BIPA exposure rises with every enrolled fingerprint.

How We Help With BIPA Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment locates every system touching biometric data, then tests your notice, consent, retention, and security posture against BIPA's Section 15 requirements.

How to Prepare

  1. 01Identify biometric data in your environment

    Document the systems collecting biometric data, the data types, where the data is stored, who has access, and which vendors are involved. Timeclocks, door controllers, and authentication features hide in plain sight.

  2. 02Review consent and policies

    Confirm written (or electronic-signature) consent is properly collected and stored, retention and destruction policies exist and are followed, and the policies match actual system behavior - including the 3-year destruction cap.

  3. 03Secure biometric systems

    Implement or validate encryption at rest and in transit, role-based access controls, MFA for administrative access, logging and monitoring, and secure deletion that actually executes on schedule.

  4. 04Assess vendor risk

    Confirm third-party providers meet BIPA's security requirements, never reuse or resell biometric data, and are contractually obligated to comply. The sale prohibition has no exceptions - your vendors need to know that.

  5. 05Train staff

    Employees handling biometric data should understand the consent requirements, data handling restrictions, security best practices, and incident reporting procedures.

Frequently Asked Questions

Does BIPA apply to my business?

If you are a private entity collecting biometric data from Illinois residents or employees - a fingerprint timeclock, facial-recognition access, voice authentication - BIPA applies regardless of your size or where you are headquartered. Exclusions: government entities, GLBA-covered financial institutions, and patient data handled under HIPAA.

What happens if we're not compliant with BIPA?

Individuals can sue directly for $1,000 per negligent violation or $5,000 per intentional or reckless one, with no proof of actual harm required. Since the 2024 amendment, repeated scans of one person by one method count as a single violation - but claims arrive as class actions, so exposure still scales with every person enrolled in the system.

How long does it take to become BIPA compliant?

Often faster than other frameworks - the core is notice, signed consent, a published retention policy, and secured systems. The assessment runs two to four weeks; organizations with a handful of biometric systems can usually close the documentation and control gaps within a few months.

What does BIPA compliance cost?

It depends on how many systems touch biometric data and what documentation exists today. We publish no pricing - you get a firm quote after the assessment, and the conversation costs nothing.

We already have an IT provider. Do we still need help with BIPA?

Probably. Most BIPA claims stem from missing consent forms and retention policies, not failed servers - a compliance-documentation problem IT providers rarely own. Our co-managed approach adds that governance layer alongside your provider's work, without turf wars.

What's the difference between BIPA and CCPA/CPRA's biometric rules?

BIPA is biometric-specific, requires consent before collection, flatly prohibits selling biometric data, and lets individuals sue directly - no harm required. CCPA/CPRA treats biometrics as one category of sensitive personal information, with opt-out and limitation rights enforced mainly by regulators. BIPA is the stricter standard; build to it and California's biometric rules largely follow.

Can we handle BIPA compliance ourselves?

If your biometric footprint is small, possibly - the requirements are concrete. Our DIY-with-support tier gives you the gap analysis and templates-to-reality checking while your team executes, scoped and quoted after your assessment. The risk in DIY is the mismatch between what policies say and what systems do.

Where do we start with BIPA?

Inventory first: find every system that captures a fingerprint, face, voice, hand, or iris. Our Cyber Risk & Compliance Gap Assessment does exactly that, then tests notice, consent, retention, and security against the statute - before a demand letter does it for you.

Official source

Official source: Illinois General Assembly - 740 ILCS 14

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25