No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

Illinois Genetic Information Protection Act Comes of Age

Illinois’ experience with biometric privacy offers a cautionary tale for companies that keep genetic information in the AI era

by Michael C. McCutcheon and Ruby Borja
August 17, 2026
in Data Privacy
double helix of lego

For companies that collect, use, acquire or commercialize genetic information in any capacity, Illinois’ Genetic Information Protection Act should be viewed not as a niche compliance obligation but as the next major front in Illinois privacy litigation, Michael C. McCutcheon and Ruby Borja of Baker McKenzie explain. Companies that ignore GIPA can prepare for lawsuits.

Illinois’ Genetic Information Protection Act (GIPA) has existed for decades, largely outside the spotlight of modern data‑privacy enforcement. That era is ending. As businesses increasingly treat genetic data as a strategic input — whether to train AI models, support research and development or monetize data through licensing and partnership arrangements — GIPA has resurfaced as a powerful and underappreciated source of litigation exposure.

Companies that use genetic information in any capacity, particularly those integrating such data into AI systems or acquiring businesses that possess genetic datasets, now face a materially different risk profile. Lawsuits invoking GIPA have already been pursued, and there is little doubt that additional claims will follow as genetic data becomes more central to enterprise value, M&A strategy and advanced analytics.

A brief history of GIPA

Illinois enacted GIPA in 1998 and amended it in 2008, long before genetic data became a scalable commercial asset. Unlike many modern privacy statutes, GIPA was not framed around cybersecurity safeguards or breach notification. It was built instead on a core principle: Genetic information is uniquely sensitive, immutable and deserving of heightened protection.

At its foundation, GIPA treats genetic information as confidential and privileged. It prohibits the disclosure, redisclosure or transfer of genetic data without specific written authorization from the individual tested. The statute leaves little room for implied consent, generalized disclosures or broad downstream use. Notably, it contains no sweeping research or commercialization exception that might otherwise accommodate modern data‑driven business models.

What it takes to comply with GIPA

GIPA compliance cannot be achieved through boilerplate privacy policies or general healthcare authorizations. At a minimum, compliance requires:

  • Specific written consent that clearly identifies permitted uses and recipients of genetic information.
  • Careful mapping of data flows, including how genetic data is collected, stored, processed, shared and retained.
  • Controls on redisclosure, particularly where data is shared with affiliates, partners or third parties.
  • Rigorous retention and destruction practices tied to authorized uses.
  • Transaction‑level diligence, especially in mergers and acquisitions involving datasets whose provenance may predate the acquiring company.

Importantly, ongoing possession or use of genetic data without proper authorization can itself constitute a continuing violation. Compliance is not a one‑time event; it is an operational discipline that must evolve as data uses evolve.

Why AI makes GIPA risk more acute

AI fundamentally alters how GIPA exposure manifests.

First, AI challenges traditional purpose‑limitation defenses. Genetic data used to train machine‑learning models is not consumed and discarded; it is embedded into systems that continue to generate outputs and commercial value. That persistent use is difficult to reconcile with limited or one‑time consents originally obtained for clinical, diagnostic or research purposes.

Second, AI undermines assumptions about de‑identification. While companies often rely on HIPAA‑style anonymization frameworks, genetic data is inherently identifying. Advances in re‑identification methods — particularly when genetic data is combined with longitudinal health, imaging or demographic datasets — make true anonymization increasingly difficult. Courts evaluating biometric privacy claims have already expressed skepticism toward de‑identification defenses, and similar reasoning is likely to migrate into the genetic‑privacy context.

Third, AI amplifies remedies. Where genetic data is used to train core AI models, plaintiffs may seek injunctive relief beyond damages, including restrictions on use, retraining or commercialization of those models. For businesses whose valuation depends heavily on proprietary AI assets, this risk strikes at the core of enterprise value.

user data privacy notice in app
Data Privacy

What Companies Need to Know About the Evolving Youth Privacy Landscape

by Greg Szewczyk and Madison Etherington
August 10, 2026

With numerous state youth data laws passed and more in the works, count on a patchwork adding to compliance requirements

Read moreDetails

Litigation and transactional risk is no longer theoretical

Although historically less common than biometric privacy litigation, genetic‑privacy lawsuits are no longer anomalous. Claims have already been brought asserting improper use, transfer or monetization of genetic information, and the statutory framework invites further testing as business models evolve.

This risk is particularly pronounced in the M&A context. Acquirers that inherit genetic datasets — especially those lacking clear, use‑specific consent — may also inherit latent GIPA exposure. As genetic information increasingly factors into acquisition pricing, diligence failures can translate directly into post‑closing litigation, indemnity disputes or impairment of acquired assets.

For companies that are frequent acquisition targets or that position themselves for strategic investment or exit, unresolved GIPA compliance issues can become material deal obstacles.

Lessons from the continuing wave of BIPA litigation

Any assessment of GIPA risk should be informed by the parallel — and still unfolding — experience under Illinois’s Biometric Information Privacy Act (BIPA). Enacted in 2008, BIPA regulates the collection, use, storage and disclosure of biometric identifiers like fingerprints, facial geometry, voiceprints and retina scans. Like GIPA, BIPA is a consent‑centric statute that treats covered data as uniquely sensitive and imposes strict requirements for written authorization, purpose limitation, retention and destruction.

Over the past decade, BIPA has generated a sustained wave of class‑action litigation across industries, including technology, healthcare, retail, employment and consumer services. Courts have repeatedly made clear that BIPA creates a private right of action untethered from traditional notions of actual harm. Statutory damages — $1,000 per negligent violation and $5,000 per reckless or intentional violation, plus attorneys’ fees — have compounded exposure at scale, fueling numerous eight‑ and nine‑figure settlements and creating bet‑the‑company risk for businesses that built biometric functionality into everyday operations.

GIPA shares many of the same structural features that made BIPA so potent. Both statutes:

  • Regulate immutable, uniquely identifying biological data.
  • Require specific written consent, rather than generalized notice.
  • Impose liability for collection, possession, use and disclosure, not merely breach.
  • Provide statutory damages untethered from proof of actual injury.
  • Apply per‑violation damages, enabling exponential exposure at scale.

If anything, GIPA may present even greater long‑term risk. Genetic information is not merely identifying; it is predictive, inheritable and permanent. Unlike biometric identifiers used for authentication or access control, genetic data can reveal future health conditions, familial relationships and population‑level insights that persist indefinitely. When deployed in AI systems, genetic data is transformed into enduring computational value.

BIPA litigation demonstrated how a statute initially viewed as niche can become an engine of systemic liability once enforcement momentum builds and judicial doctrines mature. GIPA appears poised to follow a similar trajectory, particularly as courts confront disputes involving AI training, dataset monetization and post‑acquisition use of genetic information. As with BIPA, early cases will likely define the contours of consent, accrual and damages in ways that materially reshape compliance expectations.

The broader lesson is clear. BIPA taught that statutory privacy regimes governing biological data can create existential risk when companies scale first and rationalize compliance later. GIPA carries many of the same features — combined with the amplifying effects of AI and data‑driven valuation — that made BIPA so disruptive. Companies that ignore those lessons do so at their peril.

Risk mitigation strategies

Companies operating in healthcare, life sciences, AI and data analytics should treat genetic data as a high‑risk asset. Practical steps to reduce exposure include:

  • Segregating AI training datasets based on data provenance and consent scope.
  • Obtaining new consents where feasible and defensible.
  • Embedding litigation and privacy counsel into AI governance and product‑development workflows.
  • Conducting heightened diligence for acquisitions involving genetic or genomic data.
  • Modeling worst‑case statutory exposure, rather than assuming regulatory penalties represent the outer bound of risk.

Conclusion

When the Biometric Information Privacy Act was enacted, it was widely viewed as narrow, technical and unlikely to disrupt mainstream business practices. That assumption proved wrong. BIPA evolved into one of the most consequential privacy statutes in the country, generating a sustained wave of class‑action litigation, reshaping compliance expectations across industries and creating existential risk for companies that integrated biometric technology without strict adherence to its consent requirements.

GIPA appears poised to follow a similar path — only with potentially higher stakes. Genetic information is broader, more persistent and more commercially valuable than biometrics. When embedded into AI systems, licensing strategies or acquired datasets, genetic data can become inseparable from the core value of a business.

The lesson of BIPA was not simply that Illinois courts enforce statutory privacy rights rigorously. It was that statutes governing biological data can transform routine operational decisions into enterprise‑level litigation risk once enforcement momentum builds. The history of BIPA suggests that waiting for definitive guidance, widespread enforcement or appellate clarity may come too late. Businesses that treat GIPA the way many once treated BIPA risk learning the same lesson — only at a higher cost and with fewer off‑ramps.

Tags: Artificial Intelligence (AI)Health Care
Previous Post

26% of Execs Say Audit Has Caught Public-Facing AI Mistake

Next Post

You Settled With the FTC; Now Comes a 20-Year Consent Decree

Michael C. McCutcheon and Ruby Borja

Michael C. McCutcheon and Ruby Borja

Michael McCutcheon is a partner in Baker McKenzie’s Chicago and New York offices. His practice focuses on commercial litigation and arbitration, representing domestic and international entities in complex disputes around the world.
Ruby Borja is a litigation associate in Baker McKenzie's Chicago office. Prior to joining the firm, Ruby served as a judicial law clerk to Judge John T. Copenhaver Jr. of the US District Court for the Southern District of West Virginia.

Related Posts

news roundup data grungy

Cybersecurity Pros Name Social Engineering as Top Human Risk

by Staff and Wire Reports
September 4, 2026

Plus: 20-point bump for AI in financial predictions; July sees ransomware peak

uk prime minister andy burnham

Risk & Compliance Implications of New UK Government

by Jonathan Armstrong
August 28, 2026

AI policy-making is already undergoing shake-ups

news roundup data grungy

Only 1 in 10 Can See Through Shell Companies for Sanctioned Parties

by Staff and Wire Reports
August 27, 2026

Plus: Small firms have higher chance of reaching SOC 2 goals; AI-enabled cyber risk ranks as top threat

nist headquarters sign

NIST Is Offering a New AI Evaluation Framework, Not Another Compliance Checklist

by Larry Marks
August 21, 2026

Draft framework TEVV-Athlon is designed for organizational flexibility

Next Post
federal trade commission building front

You Settled With the FTC; Now Comes a 20-Year Consent Decree

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights