Illinois BIPA
Illinois BIPA
Biometric Information Privacy Act
BIPA regulates the collection of biometric identifiers such as fingerprints, faceprints, and voiceprints, and requires written consent and a public retention policy. Its private right of action and per-violation statutory damages have driven some of the largest privacy settlements in the country. Security teams must ensure that any tool capturing biometric data, including facial-recognition or voice features, obtains consent before collection.
How Reflectiz Meets Every BIPA Requirement
Requirement → Reflectiz SolutionBiometric Data Collection Consent
Reflectiz detects any tool capturing biometric identifiers, such as facial-recognition or voice features, and verifies whether written consent was obtained before collection.
Third-Party Biometric Sharing
The data route map reveals which third parties receive biometric data and flags undisclosed or unauthorized transfers before data leaves your environment.
Retention & Behavior Monitoring
Continuous behavioral baselines alert teams when a component’s biometric-related activity changes, supporting retention and destruction obligations.
Audit Evidence
Audit-ready logs document every biometric-data component and its behavior over time, providing litigation-grade evidence in a high-liability, private-right-of-action environment.
Reduces Regulatory Risk & Saves Time
Illinois BIPA at a Glance
Key Facts| Full name | Biometric Information Privacy Act, 740 ILCS 14. In effect since October 3, 2008. |
|---|---|
| Who it applies to | Any private entity that collects, captures, buys, receives, or otherwise obtains biometric data from people in Illinois. There is no revenue or data-volume threshold. |
| Biometric identifiers | Retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry. Biometric information is any data based on those identifiers that is used to identify a person. |
| Before collection | Inform the person in writing that biometric data is being collected, state the specific purpose and how long it will be kept, and obtain a written release. An electronic signature counts. |
| Retention and destruction | Publish a written retention schedule. Destroy biometric data once the original purpose is met or within three years of the person’s last interaction, whichever comes first. |
| Sale and sharing | No selling, leasing, trading, or otherwise profiting from biometric data. No disclosure without consent, except in narrow cases such as a transaction the person requested or a legal requirement. |
| Security | Store, transmit, and protect biometric data with the reasonable standard of care for your industry, and at least as carefully as your other confidential data. |
| Exemptions | State and local government agencies (and their contractors when working for them), financial institutions covered by the Gramm-Leach-Bliley Act, and health information governed by HIPAA. |
| Enforcement | Private right of action. Any aggrieved person can sue, and no actual harm is required (Rosenbach v. Six Flags, 2019). |
| Statutory damages | $1,000 per negligent violation or $5,000 per intentional or reckless violation, or actual damages if greater, plus attorneys’ fees and costs. |
| Statute of limitations | Five years for all BIPA claims (Tims v. Black Horse Carriers, 2023). |
| 2024 amendment | SB 2979, signed August 2, 2024, counts repeated collection from the same person by the same method as one violation. In April 2026, the Seventh Circuit held that the change applies to pending cases (Clay v. Union Pacific). |
Illinois BIPA FAQ
Common QuestionsWhat is Illinois BIPA?
The Illinois Biometric Information Privacy Act (BIPA) is a 2008 state law, codified at 740 ILCS 14, that regulates how private entities collect, use, store, and share biometric identifiers such as fingerprints, face geometry, voiceprints, and iris scans. It requires written notice, a written release, and a public retention policy, and it lets individuals sue directly for violations.
Does BIPA apply to websites and online tools?
Yes. BIPA covers biometric data collected from people in Illinois through any channel, including websites and apps. Virtual try-on tools, selfie-based identity checks, facial-recognition logins, and voice features can all capture face geometry or voiceprints. If they run before written notice and consent, your company can be liable, even when a third-party vendor supplies the tool.
What counts as biometric data under BIPA?
BIPA covers biometric identifiers, defined as retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry, and biometric information, meaning any data based on those identifiers that is used to identify a person. Photographs, writing samples, and demographic data are excluded, but courts have treated face-geometry scans taken from photos as covered.
What are the penalties for violating BIPA?
An aggrieved person can recover $1,000 per negligent violation or $5,000 per intentional or reckless violation, or actual damages if greater, plus attorneys’ fees, costs, and injunctive relief. No proof of actual harm is required, and claims can be filed up to five years after the violation. Facebook paid $650 million in 2021 to settle BIPA claims over photo face-tagging.
How did the 2024 amendment change BIPA damages?
Senate Bill 2979, signed on August 2, 2024, ended per-scan damages. Collecting the same biometric data from the same person by the same method now counts as a single violation, so each person recovers once. The amendment also confirmed that an electronic signature satisfies the written release requirement. In April 2026, the Seventh Circuit held in Clay v. Union Pacific that the change applies to pending cases.
Can a third-party vendor’s tool create BIPA liability for my company?
Yes. In Theriot v. Louis Vuitton (2022), a federal court rejected the retailer’s argument that its virtual try-on vendor was the responsible party and let most of the BIPA claims proceed. In December 2025, the Seventh Circuit affirmed class certification for Illinois users of Amazon’s virtual try-on feature. If a tool on your site captures biometric data, you need proof that consent came first.
How does Reflectiz support BIPA compliance?
Reflectiz monitors your website remotely, with no code changes, and maps every script, pixel, and third-party tool that runs on it. It detects components that capture biometric identifiers, verifies whether written consent came before collection, shows which third parties receive the data, and keeps audit-ready logs of each component’s behavior. A consent banner records what users agreed to. Reflectiz shows what your site actually collected.
Last reviewed September 2026. This page summarizes Illinois BIPA for general information and is not legal advice. Related: CCPA, Texas TDPSA, GDPR, and the Reflectiz Privacy Hub.
Ready for BIPA? Know Your Web Exposure.
See every script, tag, and tool on your site that can capture biometric data, and whether consent came first, in one continuous, agentless view.