BIPA and the US biometric statutes

Lesson 3 of 5 in Biometric Surveillance, Law Enforcement AI, and Protecting Children.

In 2008, reacting to the bankruptcy of a fingerprint-payment startup called Pay By Touch — which left thousands of Illinoisans’ fingerprints as assets in a bankruptcy estate — Illinois passed the Biometric Information Privacy Act (BIPA). For a decade almost nobody noticed. Then the plaintiffs’ bar did, and BIPA became the single most consequential biometric law in the United States: thousands of class actions, nine- and ten-figure settlements, and the reason many face-recognition features simply are not offered in Illinois.

The statute is short. A private entity that collects a biometric identifier (retina/iris scan, fingerprint, voiceprint, face geometry) must first provide written notice of what is collected, why, and for how long, and obtain a written release; it may not sell or profit from biometric data; it must publish a retention-and-destruction schedule (destroy within three years of last interaction); and it must protect the data with reasonable care. What makes it a machine is the enforcement design: a private right of action with liquidated damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation, plus fees.

Three Illinois Supreme Court decisions turned those numbers into existential exposure:

  • Rosenbach v. Six Flags (2019) — a person is “aggrieved” by the bare statutory violation; no actual harm required. A teenager fingerprinted for a season pass without written consent could sue.
  • Tims v. Black Horse Carriers (2023) — a five-year limitations period applies.
  • Cothron v. White Castle (2023) — claims accrue per scan, not per person. White Castle calculated its theoretical exposure at up to $17 billion for employee fingerprint timeclocks. The court noted damages are discretionary and invited the legislature to act — which it did: a 2024 amendment (SB 2979) limits recovery to one violation per person per collection method and lets an electronic signature satisfy the written release.

The case law wrote the ceiling for settlements: Patel v. Facebook — face-tagging templates — settled for $650 million; Google Photos, Snapchat, TikTok, and Clearview all paid. BIPA is also the closest thing the US has to an AI-training-data biometrics rule: classes have sued over faceprints created to train models, not just to identify users.

The US biometric-statute landscape (private-sector collection)
StatuteCitationEnforcementConsent modelWhy it matters

Illinois BIPA (2008)

740 ILCS 14

Private right of action; $1,000/$5,000 liquidated damages per violation

Written notice + written release before collection

The litigation engine: Rosenbach (no harm needed), Cothron (per-scan accrual, capped by 2024 amendment), Patel ($650M)

Texas CUBI (2009)

Bus. & Com. Code §503.001

Attorney General only; up to $25,000 per violation

Notice + consent before capture

Slept until 2022 — then Texas v. Meta settled for $1.4B (2024), the largest single-state privacy recovery, followed by a $1.375B Google settlement (2025)

Washington HB 1493 (2017)

RCW 19.375

AG only (Consumer Protection Act)

Notice/consent for enrollment for commercial use

Narrower “biometric identifier” definition; largely untested — but the 2023 My Health My Data Act added a private right of action covering biometric data as “consumer health data”

Colorado (2024 amendment)

HB 24-1130 amending the Colorado Privacy Act, effective July 2025

AG/district attorneys

Consent required; employer collection limited to specified purposes

First comprehensive-privacy-law state to bolt on BIPA-style biometric duties — the likely template for others

Key terms: bipa, biometric data, private right of action, liquidated damages, consent

Walk a BIPA exposure analysis

Interactive decision tree — outcomes:

  • Likely outside BIPA

    No biometric identifier, no BIPA — but beware: the moment a model derives face geometry from those stored photos (including to train a model), you cross the line. Document that no templates are computed.

  • Exemption — verify it precisely

    BIPA exemptions are construed narrowly and litigated constantly (the healthcare exemption reached the Illinois Supreme Court). Get a written legal analysis, not a hallway conclusion.

  • Baseline compliance posture

    Consent, notice, retention schedule, no selling, reasonable security — the five pillars. Keep signed releases retrievable; in litigation, the release is the defence.

  • Material class-action exposure

    Statutory damages of $1,000–$5,000 per person (per collection method, post-2024 amendment), five-year lookback, no need to prove harm (Rosenbach). This is a board-level disclosure item. Remediate consent now — it does not erase past exposure, but it stops accrual.

  • Contained — remediate immediately

    Small class, but Rosenbach means each person can sue without harm. Pause collection, implement notice-and-release, destroy unlawfully collected templates, and document destruction.

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.