Illinois BIPA

Compliance The Web Exposure Company

Illinois BIPA

Biometric Information Privacy Act

BIPA regulates the collection of biometric identifiers such as fingerprints, faceprints, and voiceprints, and requires written consent and a public retention policy. Its private right of action and per-violation statutory damages have driven some of the largest privacy settlements in the country. Security teams must ensure that any tool capturing biometric data, including facial-recognition or voice features, obtains consent before collection.

Try for free
Illinois BIPA biometric privacy compliance monitoring

How Reflectiz Meets Every BIPA Requirement

Requirement → Reflectiz Solution
Right to Privacy

Biometric Data Collection Consent

Reflectiz detects any tool capturing biometric identifiers, such as facial-recognition or voice features, and verifies whether written consent was obtained before collection.

Right to Know

Third-Party Biometric Sharing

The data route map reveals which third parties receive biometric data and flags undisclosed or unauthorized transfers before data leaves your environment.

Data Protection

Retention & Behavior Monitoring

Continuous behavioral baselines alert teams when a component’s biometric-related activity changes, supporting retention and destruction obligations.

Right to Know & Data Protection

Audit Evidence

Audit-ready logs document every biometric-data component and its behavior over time, providing litigation-grade evidence in a high-liability, private-right-of-action environment.

Reduces Regulatory Risk & Saves Time

Automated tracker detection dashboard Streamlined compliance operations Unified compliance management dashboard

Illinois BIPA at a Glance

Key Facts
Key facts about the Illinois Biometric Information Privacy Act (BIPA)
Full nameBiometric Information Privacy Act, 740 ILCS 14. In effect since October 3, 2008.
Who it applies toAny private entity that collects, captures, buys, receives, or otherwise obtains biometric data from people in Illinois. There is no revenue or data-volume threshold.
Biometric identifiersRetina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry. Biometric information is any data based on those identifiers that is used to identify a person.
Before collectionInform the person in writing that biometric data is being collected, state the specific purpose and how long it will be kept, and obtain a written release. An electronic signature counts.
Retention and destructionPublish a written retention schedule. Destroy biometric data once the original purpose is met or within three years of the person’s last interaction, whichever comes first.
Sale and sharingNo selling, leasing, trading, or otherwise profiting from biometric data. No disclosure without consent, except in narrow cases such as a transaction the person requested or a legal requirement.
SecurityStore, transmit, and protect biometric data with the reasonable standard of care for your industry, and at least as carefully as your other confidential data.
ExemptionsState and local government agencies (and their contractors when working for them), financial institutions covered by the Gramm-Leach-Bliley Act, and health information governed by HIPAA.
EnforcementPrivate right of action. Any aggrieved person can sue, and no actual harm is required (Rosenbach v. Six Flags, 2019).
Statutory damages$1,000 per negligent violation or $5,000 per intentional or reckless violation, or actual damages if greater, plus attorneys’ fees and costs.
Statute of limitationsFive years for all BIPA claims (Tims v. Black Horse Carriers, 2023).
2024 amendmentSB 2979, signed August 2, 2024, counts repeated collection from the same person by the same method as one violation. In April 2026, the Seventh Circuit held that the change applies to pending cases (Clay v. Union Pacific).

Illinois BIPA FAQ

Common Questions

What is Illinois BIPA?

The Illinois Biometric Information Privacy Act (BIPA) is a 2008 state law, codified at 740 ILCS 14, that regulates how private entities collect, use, store, and share biometric identifiers such as fingerprints, face geometry, voiceprints, and iris scans. It requires written notice, a written release, and a public retention policy, and it lets individuals sue directly for violations.

Does BIPA apply to websites and online tools?

Yes. BIPA covers biometric data collected from people in Illinois through any channel, including websites and apps. Virtual try-on tools, selfie-based identity checks, facial-recognition logins, and voice features can all capture face geometry or voiceprints. If they run before written notice and consent, your company can be liable, even when a third-party vendor supplies the tool.

What counts as biometric data under BIPA?

BIPA covers biometric identifiers, defined as retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry, and biometric information, meaning any data based on those identifiers that is used to identify a person. Photographs, writing samples, and demographic data are excluded, but courts have treated face-geometry scans taken from photos as covered.

What are the penalties for violating BIPA?

An aggrieved person can recover $1,000 per negligent violation or $5,000 per intentional or reckless violation, or actual damages if greater, plus attorneys’ fees, costs, and injunctive relief. No proof of actual harm is required, and claims can be filed up to five years after the violation. Facebook paid $650 million in 2021 to settle BIPA claims over photo face-tagging.

How did the 2024 amendment change BIPA damages?

Senate Bill 2979, signed on August 2, 2024, ended per-scan damages. Collecting the same biometric data from the same person by the same method now counts as a single violation, so each person recovers once. The amendment also confirmed that an electronic signature satisfies the written release requirement. In April 2026, the Seventh Circuit held in Clay v. Union Pacific that the change applies to pending cases.

Can a third-party vendor’s tool create BIPA liability for my company?

Yes. In Theriot v. Louis Vuitton (2022), a federal court rejected the retailer’s argument that its virtual try-on vendor was the responsible party and let most of the BIPA claims proceed. In December 2025, the Seventh Circuit affirmed class certification for Illinois users of Amazon’s virtual try-on feature. If a tool on your site captures biometric data, you need proof that consent came first.

How does Reflectiz support BIPA compliance?

Reflectiz monitors your website remotely, with no code changes, and maps every script, pixel, and third-party tool that runs on it. It detects components that capture biometric identifiers, verifies whether written consent came before collection, shows which third parties receive the data, and keeps audit-ready logs of each component’s behavior. A consent banner records what users agreed to. Reflectiz shows what your site actually collected.

Last reviewed September 2026. This page summarizes Illinois BIPA for general information and is not legal advice. Related: CCPA, Texas TDPSA, GDPR, and the Reflectiz Privacy Hub.

Ready for BIPA? Know Your Web Exposure.

See every script, tag, and tool on your site that can capture biometric data, and whether consent came first, in one continuous, agentless view.

Start Free