For companies that collect, use, acquire or commercialize genetic information in any capacity, Illinois’ Genetic Information Protection Act should be viewed not as a niche compliance obligation but as the next major front in Illinois privacy litigation, Michael C. McCutcheon and Ruby Borja of Baker McKenzie explain. Companies that ignore GIPA can prepare for lawsuits.
Illinois’ Genetic Information Protection Act (GIPA) has existed for decades, largely outside the spotlight of modern data‑privacy enforcement. That era is ending. As businesses increasingly treat genetic data as a strategic input — whether to train AI models, support research and development or monetize data through licensing and partnership arrangements — GIPA has resurfaced as a powerful and underappreciated source of litigation exposure.
Companies that use genetic information in any capacity, particularly those integrating such data into AI systems or acquiring businesses that possess genetic datasets, now face a materially different risk profile. Lawsuits invoking GIPA have already been pursued, and there is little doubt that additional claims will follow as genetic data becomes more central to enterprise value, M&A strategy and advanced analytics.
A brief history of GIPA
Illinois enacted GIPA in 1998 and amended it in 2008, long before genetic data became a scalable commercial asset. Unlike many modern privacy statutes, GIPA was not framed around cybersecurity safeguards or breach notification. It was built instead on a core principle: Genetic information is uniquely sensitive, immutable and deserving of heightened protection.
At its foundation, GIPA treats genetic information as confidential and privileged. It prohibits the disclosure, redisclosure or transfer of genetic data without specific written authorization from the individual tested. The statute leaves little room for implied consent, generalized disclosures or broad downstream use. Notably, it contains no sweeping research or commercialization exception that might otherwise accommodate modern data‑driven business models.
What it takes to comply with GIPA
GIPA compliance cannot be achieved through boilerplate privacy policies or general healthcare authorizations. At a minimum, compliance requires:
- Specific written consent that clearly identifies permitted uses and recipients of genetic information.
- Careful mapping of data flows, including how genetic data is collected, stored, processed, shared and retained.
- Controls on redisclosure, particularly where data is shared with affiliates, partners or third parties.
- Rigorous retention and destruction practices tied to authorized uses.
- Transaction‑level diligence, especially in mergers and acquisitions involving datasets whose provenance may predate the acquiring company.
Importantly, ongoing possession or use of genetic data without proper authorization can itself constitute a continuing violation. Compliance is not a one‑time event; it is an operational discipline that must evolve as data uses evolve.
Why AI makes GIPA risk more acute
AI fundamentally alters how GIPA exposure manifests.
First, AI challenges traditional purpose‑limitation defenses. Genetic data used to train machine‑learning models is not consumed and discarded; it is embedded into systems that continue to generate outputs and commercial value. That persistent use is difficult to reconcile with limited or one‑time consents originally obtained for clinical, diagnostic or research purposes.
Second, AI undermines assumptions about de‑identification. While companies often rely on HIPAA‑style anonymization frameworks, genetic data is inherently identifying. Advances in re‑identification methods — particularly when genetic data is combined with longitudinal health, imaging or demographic datasets — make true anonymization increasingly difficult. Courts evaluating biometric privacy claims have already expressed skepticism toward de‑identification defenses, and similar reasoning is likely to migrate into the genetic‑privacy context.
Third, AI amplifies remedies. Where genetic data is used to train core AI models, plaintiffs may seek injunctive relief beyond damages, including restrictions on use, retraining or commercialization of those models. For businesses whose valuation depends heavily on proprietary AI assets, this risk strikes at the core of enterprise value.
What Companies Need to Know About the Evolving Youth Privacy Landscape
With numerous state youth data laws passed and more in the works, count on a patchwork adding to compliance requirements
Read moreDetailsLitigation and transactional risk is no longer theoretical
Although historically less common than biometric privacy litigation, genetic‑privacy lawsuits are no longer anomalous. Claims have already been brought asserting improper use, transfer or monetization of genetic information, and the statutory framework invites further testing as business models evolve.
This risk is particularly pronounced in the M&A context. Acquirers that inherit genetic datasets — especially those lacking clear, use‑specific consent — may also inherit latent GIPA exposure. As genetic information increasingly factors into acquisition pricing, diligence failures can translate directly into post‑closing litigation, indemnity disputes or impairment of acquired assets.
For companies that are frequent acquisition targets or that position themselves for strategic investment or exit, unresolved GIPA compliance issues can become material deal obstacles.
Lessons from the continuing wave of BIPA litigation
Any assessment of GIPA risk should be informed by the parallel — and still unfolding — experience under Illinois’s Biometric Information Privacy Act (BIPA). Enacted in 2008, BIPA regulates the collection, use, storage and disclosure of biometric identifiers like fingerprints, facial geometry, voiceprints and retina scans. Like GIPA, BIPA is a consent‑centric statute that treats covered data as uniquely sensitive and imposes strict requirements for written authorization, purpose limitation, retention and destruction.
Over the past decade, BIPA has generated a sustained wave of class‑action litigation across industries, including technology, healthcare, retail, employment and consumer services. Courts have repeatedly made clear that BIPA creates a private right of action untethered from traditional notions of actual harm. Statutory damages — $1,000 per negligent violation and $5,000 per reckless or intentional violation, plus attorneys’ fees — have compounded exposure at scale, fueling numerous eight‑ and nine‑figure settlements and creating bet‑the‑company risk for businesses that built biometric functionality into everyday operations.
GIPA shares many of the same structural features that made BIPA so potent. Both statutes:
- Regulate immutable, uniquely identifying biological data.
- Require specific written consent, rather than generalized notice.
- Impose liability for collection, possession, use and disclosure, not merely breach.
- Provide statutory damages untethered from proof of actual injury.
- Apply per‑violation damages, enabling exponential exposure at scale.
If anything, GIPA may present even greater long‑term risk. Genetic information is not merely identifying; it is predictive, inheritable and permanent. Unlike biometric identifiers used for authentication or access control, genetic data can reveal future health conditions, familial relationships and population‑level insights that persist indefinitely. When deployed in AI systems, genetic data is transformed into enduring computational value.
BIPA litigation demonstrated how a statute initially viewed as niche can become an engine of systemic liability once enforcement momentum builds and judicial doctrines mature. GIPA appears poised to follow a similar trajectory, particularly as courts confront disputes involving AI training, dataset monetization and post‑acquisition use of genetic information. As with BIPA, early cases will likely define the contours of consent, accrual and damages in ways that materially reshape compliance expectations.
The broader lesson is clear. BIPA taught that statutory privacy regimes governing biological data can create existential risk when companies scale first and rationalize compliance later. GIPA carries many of the same features — combined with the amplifying effects of AI and data‑driven valuation — that made BIPA so disruptive. Companies that ignore those lessons do so at their peril.
Risk mitigation strategies
Companies operating in healthcare, life sciences, AI and data analytics should treat genetic data as a high‑risk asset. Practical steps to reduce exposure include:
- Segregating AI training datasets based on data provenance and consent scope.
- Obtaining new consents where feasible and defensible.
- Embedding litigation and privacy counsel into AI governance and product‑development workflows.
- Conducting heightened diligence for acquisitions involving genetic or genomic data.
- Modeling worst‑case statutory exposure, rather than assuming regulatory penalties represent the outer bound of risk.
Conclusion
When the Biometric Information Privacy Act was enacted, it was widely viewed as narrow, technical and unlikely to disrupt mainstream business practices. That assumption proved wrong. BIPA evolved into one of the most consequential privacy statutes in the country, generating a sustained wave of class‑action litigation, reshaping compliance expectations across industries and creating existential risk for companies that integrated biometric technology without strict adherence to its consent requirements.
GIPA appears poised to follow a similar path — only with potentially higher stakes. Genetic information is broader, more persistent and more commercially valuable than biometrics. When embedded into AI systems, licensing strategies or acquired datasets, genetic data can become inseparable from the core value of a business.
The lesson of BIPA was not simply that Illinois courts enforce statutory privacy rights rigorously. It was that statutes governing biological data can transform routine operational decisions into enterprise‑level litigation risk once enforcement momentum builds. The history of BIPA suggests that waiting for definitive guidance, widespread enforcement or appellate clarity may come too late. Businesses that treat GIPA the way many once treated BIPA risk learning the same lesson — only at a higher cost and with fewer off‑ramps.


Michael McCutcheon
Ruby Borja







