The Illinois Biometric Information Privacy Act (BIPA) has ignited a wave of lawsuits, creating significant legal risks for businesses utilizing biometric data for everything from time clocks to access systems. Companies must proactively assess and manage compliance as the legal landscape evolves and other states consider similar privacy laws.

The quiet hum of a time clock, the swift scan of a fingerprint to unlock a door, or even the seemingly benign facial recognition in a new app – these everyday interactions, designed for convenience and security, have unexpectedly ignited a legal powder keg in Illinois, sending shockwaves through businesses far beyond the state’s borders.
Welcome to the world of the Illinois Biometric Information Privacy Act (BIPA), a 17-year-old statute that, like a dormant volcano, has erupted into a torrent of litigation, transforming routine technological adoptions into perilous legal gambles.
This isn’t just about big tech firms.
From local businesses using biometric timekeeping systems to healthcare facilities employing advanced access controls, BIPA has become a formidable force.
As legal experts Damon Silver and Joe Lazzarotti of Jackson Lewis, joined by Chicago-based BIPA litigation specialists Jody Mason and Jason Selvey, recently discussed, the central question for organizations today is stark: How do we harness the power of data and new technologies without crashing headfirst into a wall of legal risk, and how can we manage that risk without needlessly stifling innovation?
The story of BIPA’s ascent to prominence is one of serendipity for the plaintiff’s bar and a looming threat for businesses.
For years, the act lay relatively undisturbed.
Then, about seven years ago, “some enterprising plaintiff’s attorneys all of a sudden looked at the statutes and said, this looks like a good statute to use, since it’s amenable to class actions,” recounts Jason Selvey.
The result? A “tidal wave of class actions” – thousands of them – making Illinois the “envy of the nation” for its litigious landscape surrounding biometric data.
At the heart of this legal storm is the very definition of “you.”
BIPA regulates two distinct but often conflated categories: “biometric identifiers” and “biometric information.” The former refers to physical characteristics like retina or iris scans, fingerprints, voice prints, or scans of hand or face geometry.
The latter, “biometric information,” is data derived from these identifiers, crucial for its ability to identify an individual.
This distinction, however, is far from clear-cut in practice.
Courts are still grappling with what constitutes a “voice print” or a “scan of hand or face geometry.” For instance, while photographs are explicitly exempted, the line blurs when a financial service company compares a photo ID against a live selfie – is that merely a photo, or is it a “facial geometry scan” ripe for litigation?
The ongoing legal battles underscore the inherent ambiguities, leaving businesses navigating a minefield without a perfectly clear map.
The sheer breadth of technologies now targeted by BIPA litigation is, frankly, astonishing.
While timekeeping systems, where employees clock in and out with a finger or face scan, remain the most prevalent target, the plaintiff’s bar has demonstrated remarkable creativity.
Jody Mason points to cases involving dash cam technology, point-of-sale systems, and security access systems where a scan grants entry to a building or a medication cabinet.
But the reach extends even further, encompassing video game avatars, online photo storage, theme park entry, vending machines, and test-taking software.
“The plaintiffs’ bar has really tried to be creative and push the envelope in terms of the types of technology that they target,” Mason observes, noting that as these technologies become more ubiquitous, so too does the litigation.
What, then, are companies doing “wrong” to trigger these lawsuits?
Selvey outlines “the big three” core elements of BIPA claims.
First, Section 15A mandates a retention and destruction policy for biometric data, requiring its deletion when no longer needed or within three years, whichever comes first. Many businesses simply don’t have this in place.
Second, and perhaps the most common, is Section 15B: the “consent and information disclosure claim.” Companies must obtain “knowing and written consent” before collecting or disclosing biometric data and make specific disclosures about how the data will be used.
Historically, many defendants had no consent at all, or their consent was vague and easily challenged.
Finally, the third major claim involves the disclosure of biometric data to third parties, such as vendors. If a company shares this data without explicit consent for that specific disclosure, it’s another potential violation.
While other claims exist, such as failing to safeguard data, these “big three” form the backbone of most lawsuits.
The primary motivator for this litigation isn’t actual harm; it’s the statutory damages. As Selvey explains, “we’re not aware of a single case under the belt where there has been any harm, like someone had their identity stolen or anything like that.” Instead, the statute allows for $5,000 per reckless or intentional violation and $1,000 per negligent violation, plus attorney’s fees and costs.
In a class action context, where each “scan” or “collection” could theoretically constitute a separate violation, these figures quickly escalate into astronomical sums, making BIPA an incredibly lucrative avenue for plaintiffs’ attorneys.
The issue of consent itself is a complex dance.
While more companies are now attempting compliance, the devil is in the details. “When this first came down, back then, it was very common for someone to say, what are you talking about?” Selvey notes.
Now, consent forms are more common, but their specificity and timing are critical. The concept of “post-use consent” – obtaining consent after data has already been collected – is a thorny issue currently working its way through the courts.
Moreover, the very act of a company trying to become compliant can inadvertently trigger claims, as it draws attention to past non-compliance.
The legal landscape is far from settled.
Major appellate battles are ongoing, promising to redefine BIPA’s scope.
One key issue is the healthcare exemption: the Illinois Supreme Court recently ruled in Mosby v. Ingalls Memorial Hospital that data from a medication dispensing cabinet used by healthcare workers was exempt.
Now, courts are asking if this exemption extends to timekeeping systems used by healthcare personnel.
Another critical development is a 2024 clarification to the statute, enacted in response to the Cothron v. White Castle decision. This amendment states that if the “same entity collects the same biometric identifier information from the same individual using the same mechanism of collection,” it constitutes, at most, a single violation.
The crucial question currently before the Seventh Circuit is whether this clarification applies retroactively to pending cases, a decision that could significantly impact “per-scan damages” and reduce potential liabilities.
While Illinois remains the epicenter, other states are beginning to take note.
Texas and Washington have similar, albeit weaker, biometric privacy laws, notably lacking a private right of action, which prevents the kind of class-action explosion seen in Illinois.
Colorado, however, enacted a new law on July 1st, allowing for the mandatory use of biometrics for employment purposes like timekeeping, but with its own set of compliance requirements, including a crisis response plan.
New York has also been “toying” with similar legislation.
For companies, the message is clear: proactive defense is paramount.
Jody Mason advises, “The first thing…that I would recommend that companies do is really just take stock of the technologies that they’re using.” This includes identifying any technology that might implicate BIPA or similar statutes.
Regular, periodic reviews of policies and consents with legal counsel are essential, given the rapid evolution of case law and new legislation.
Beyond policies, implementation is key: “You can have the greatest policies in the world in place, but if you’re not following them, you could still have a potential issue.” The “big one,” Mason stresses, is having a process for legal review of new technologies before they are implemented.
This proactive approach, ideally involving both internal and external counsel, allows companies to assess risks and ensure compliance before a system goes live.
In a world increasingly reliant on biometric data for everything from security to convenience, BIPA stands as a potent reminder of the unforeseen legal consequences that can arise from technological advancement.
It underscores the delicate balance between innovation, privacy protection, and the ever-present threat of litigation.
For businesses, the “explosion” in BIPA cases is a wake-up call, demanding vigilance, proactive legal strategy, and a deep understanding of the subtle ways in which our digital footprints can become legal liabilities.
The battle for biometric privacy is far from over; it’s just getting started.