No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

Illinois’ Unique Biometric Privacy Law Presents Lessons for Businesses Everywhere

More than a dozen states considering copycat laws

by Laura Balson
November 7, 2023
in Data Privacy, HR Compliance
person using computer fingerprint reader

The Illinois Biometric Information Privacy Act (BIPA) requires private entities to obtain written consent when capturing, transmitting and storing an individual’s biometric information. With the recent rise of technology to streamline processes in the workplace, it is important to consider whether the use of technology runs afoul of BIPA and what obligations the law imposes on employers. Laura Balson breaks down the law’s requirements and offers measures that companies can take to stay compliant and mitigate risks of potential litigation.

The state of Illinois has been making headlines recently because of its unique biometric privacy law. In one example of a recent settlement, Instagram agreed to pay $68.5 million to resolve a class action filed on behalf of Illinois users.

The law at issue, known as BIPA, is the Biometric Information Privacy Act, enacted by the Illinois legislature in 2008. BIPA applies to any entity that uses Illinois residents’ biometric information in its business. Biometric information as defined under the law includes fingerprints, hand scans, retina or iris scans, facial geometry, voice prints, DNA and other unique biological identifiers. 

With advancing technology in workplace time clocks and security measures, many employers utilize biometric information to track employees’ working time, access secure areas in the workplace and log into online applications.

BIPA’s background

Illinois was the first state to pass sweeping biometric information privacy regulations and provide individuals with a private right of action for failure to adhere to the statute. There is no showing of actual damages required under BIPA and, even without proof of actual harm, statutory damages can be $1,000 per violation or $5,000 per violation if the violation is intentional or reckless.

There are multiple requirements under BIPA, but first and foremost, any company looking to gather biometric data must obtain the written consent of the individual before collecting or storing their data. They must also inform the individual in writing of what data is being collected and the specific purpose and length of time in which it will be collected, stored and used.

BIPA not only prevents companies from collecting and storing data without the individual’s advanced written consent, but it also prohibits companies from selling such data. The Illinois law is unique, but there are also comprehensive biometric data laws in Washington, Texas and New York City. And at least 15 states are considering modeling their future biometric privacy-specific laws off the Illinois statute.

accessible parking space
HR Compliance

Long Covid & Invisible Disabilities: Revisiting ADA Compliance for 2024

by Rachel Sweeney
November 1, 2023

Modern workplaces need modern solutions

Read moreDetails

Recent litigation making headlines

In the Instagram class action suit, plaintiffs claimed that parent company Meta violated BIPA by collecting and storing biometric information without its users’ consent. Meta denied any wrongdoing but still agreed to settle. Although the Instagram case does not involve employees, it is based on the use of facial recognition technology that has become common in many workplaces.

Another headline-grabbing case decided in February involved a group of employees at a trucking company who alleged that they were required to scan their fingerprints to clock in and out of work, without their employer obtaining their consent. The employer, Black Horse Carriers, attempted to dismiss the claim, arguing that since the statute does not provide a timeframe for when claims can be brought, the court should apply a one-year statute of limitations. The case made it to the Illinois Supreme Court, which disagreed with the employer’s arguments, ruling that BIPA claims may reach back as far as five years, drastically increasing the potential liability a company faces when it comes to such claims.

One of the most pivotal decisions under BIPA so far relates to the question of whether claims accrue each time a company collects an individual’s biometric identifier and each time the company transmits the scan to a third party, or only upon the first scan and first transmission.

This question was escalated to the Illinois Supreme Court in Cothron v. White Castle. According to the suit, employees of White Castle restaurants in Illinois had to scan their fingerprints to access their computers and paystubs. To authorize access to the system, White Castle had a third-party vendor verify each scan. The lawsuit was based on the allegation that White Castle never obtained its employees’ permission to do so.

In a tight 4-3 decision, the Illinois Supreme Court held that a separate claim accrues each time an individual’s biometric information is scanned or transmitted. This means an individual has grounds to sue for every instance that their finger touched the scanner and for every instance in which that data was transmitted to the third-party vendor. According to a recent Bloomberg Law analysis, the number of lawsuits in Illinois circuit courts alleging BIPA violations after this ruling skyrocketed 65%.

Compliance

There are several steps a company should take to comply with BIPA. To begin with, they must obtain advanced written consent from anyone who will be asked to use biometric technology and develop a written policy. This policy must be made available to the public and codify a retention schedule along with guidelines for permanently destroying the biometric information that is gathered.

The biometric information must be destroyed when the initial purpose for collecting the information has been fulfilled, or within three years of the individuals’ most recent interaction with the company, whichever comes first.

No company may collect, store or transmit biometric data until they inform the individual of such action, specify the purpose and length of term for which the information will be gathered and receive written consent from the individual to proceed.

Companies are not permitted to sell, lease, trade or otherwise profit from an individual’s or customer’s biometric information. Failure to adhere to these guidelines could result in liquidated damages, reasonable attorney fees and costs and other relief, potentially including an injunction.

Additional best practices to consider include:

  • Audit existing technology to pinpoint every area where biometric information is either being collected, stored or transmitted.
  • Ensure the written consent form is up to date and there is an individual responsible for ensuring consent is obtained before new users are enrolled in the technology.
  • Create a record of documentation to prove BIPA compliance.
  • Speak with a labor and employment attorney regarding the newest BIPA litigation to identify potential process gaps.

New technology is emerging daily, which desensitizes people to the number of times that their personal biometric information is captured and transmitted. Nonetheless, it is crucial to keep up with the latest state and federal laws to ensure compliance and reduce the potential for future litigation.


Tags: Employment Law
Previous Post

Navigating the AI Landscape

Next Post

New Challenges Arise as Workers Return to the Office — or Don’t

Laura Balson

Laura Balson

Laura Balson is managing partner of Constangy, Brooks, Smith & Prophete’s Chicago office and co-chairwoman of the firm’s whistleblower and retaliation practice group. Laura is an experienced litigator and has broad experience counseling and advising employers across industries to help them manage and minimize risk.

Related Posts

layoffs woman with carton of items

Beyond Fair WARNing: Regulatory & Reputational Pitfalls of Workforce Reduction

by Nancy Mann Jackson
June 11, 2025

Nearly 700,000 workers have lost jobs this year as companies respond to economic uncertainty, but employment law experts warn that...

elephant vs donkey

MAGA Hats and Pronoun Disputes Test Workplace Speech Boundaries

by Gorev Ahuja
June 10, 2025

Private employers can regulate political expression more freely, but public agencies must navigate a 3-part constitutional test that weighs speech...

documents protected with lock

Trust but Verify: The Power of Audits to Protect Your Competitive Edge

by Jennifer L. Anderson, Adam S. Baldridge and Nicole Berkowitz Riccio
August 21, 2024

Companies using noncompete agreements to safeguard their competitive edge are rightly concerned as the FTC’s noncompete ban remains in limbo...

hand signing criminal background check form

Q&A: Clean-Slate Laws in Hiring

by Kelly Uebel
June 25, 2024

Multiple states have clean-slate laws taking effect this year; are your background check policies updated?

Next Post
man bringing plants to his office

New Challenges Arise as Workers Return to the Office — or Don’t

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights