How Plaintiffs Prove Statutory Damages In Biometric Privacy Cases

Biometric technology is now a regular part of daily life, and many people may not realize how much personal information is being gathered. Employers might use fingerprint or hand scanners for tracking work hours, businesses could use facial recognition, and tech companies often process facial features or other biometric data through their services. Unlike passwords, you cannot change your biometric traits if the data is compromised or kept too long. Still, just showing that biometric data was collected does not guarantee a right to statutory damages.
Factors like state law, the type of biometric data, the defendant’s actions, consent procedures, how the data was collected or shared, and the available evidence all play a role in whether compensation is possible. At Net Law Advocates, we help plaintiffs nationwide with cases involving the unlawful collection, use, storage, or sharing of biometric information and related privacy issues.
Statutory Damages Can Be Different From Actual Damages
A key idea in biometric privacy lawsuits is understanding the difference between actual damages and statutory or liquidated damages. Actual damages usually mean there must be proof of a real loss caused by the defendant. This could include losing money, identity theft, costs from dealing with misuse, or another recognized harm.
Statutory damages operate differently. A legislature may authorize a defined monetary remedy when a defendant violates particular statutory requirements. The plaintiff’s task therefore begins with the statute itself: What conduct does it prohibit? Does it create a private right of action? Who qualifies as an aggrieved person? What damages are authorized? What level of culpability must be established?
These questions matter because biometric privacy laws differ from state to state. For example, a solution available to an Illinois employee whose fingerprint was collected without permission may not apply to someone in another state facing the same issue.
Illinois BIPA Provides An Important Statutory Framework
The Illinois Biometric Information Privacy Act, 740 ILCS 14/1 et seq., commonly called BIPA, provides one of the country’s most significant private causes of action involving biometric information.
Section 15(b), 740 ILCS 14/15(b), generally requires a private entity, before collecting or obtaining a person’s biometric identifier or biometric information, to inform the person in writing that the information is being collected or stored, explain the specific purpose and length of time for which it is being collected, stored, and used, and obtain a written release.
Section 15(d), 740 ILCS 14/15(d), restricts disclosure and dissemination of biometric identifiers and biometric information except under specified circumstances. Section 15(a) separately addresses written retention and destruction policies.
For plaintiffs, these provisions make documentation extremely important. We may examine whether a written disclosure existed, what it actually said, when it was presented, whether a valid written release was obtained, how biometric information was collected, where it was transmitted, who received it, and what policies governed retention and destruction.
How BIPA Statutory Damages Are Established
Under 740 ILCS 14/20(a), a person aggrieved by a BIPA violation has a private right of action. The statute provides that a prevailing party may recover the greater of actual damages or liquidated damages of $1,000 for a negligent violation and $5,000 for an intentional or reckless violation. It also permits recovery of reasonable attorneys’ fees and costs, including litigation expenses, and other relief that a court considers appropriate.
That distinction between negligence and intentional or reckless conduct can significantly affect a damages claim. Evidence concerning the defendant’s knowledge and conduct may therefore become critical.
We may investigate whether a company knew BIPA applied to its practices, received warnings about compliance problems, had previously been advised to obtain consent, consciously continued its collection practices, failed to change deficient policies, or disregarded known requirements. Internal communications, vendor agreements, compliance records, corporate policies, deposition testimony, system configurations, and other evidence can help establish what the defendant knew and how it responded.
Plaintiffs should not assume, however, that proving a BIPA violation automatically guarantees either $1,000 or $5,000. Section 20 states that a prevailing party “may” recover the available remedies, and courts have recognized discretion concerning damages.
Plaintiffs Do Not Necessarily Have To Prove Financial Loss Under BIPA
A biometric privacy case can be fundamentally different from a traditional identity theft lawsuit. In Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186, the Illinois Supreme Court held that a person need not sustain additional actual injury or adverse consequences beyond a violation of BIPA rights to qualify as an “aggrieved” person under the Act.
That principle matters because BIPA was designed to protect an individual’s control over biometric identifiers and information. A plaintiff’s case therefore does not necessarily disappear simply because no money was stolen, no fraudulent account was opened, and no identity thief used the biometric information.
The statutory violation itself may support the cause of action. Whether monetary damages are ultimately awarded and in what amount is a separate question that depends on the statute, evidence, procedural posture, and the court’s determination.
The Rules For Repeated Biometric Scans Have Changed
Biometric cases frequently involve repeated conduct. An employee, for example, might scan a finger every time the employee clocks in or out. That created an important question about whether hundreds or thousands of scans could produce hundreds or thousands of statutory damage awards.
In Cothron v. White Castle System, Inc., 2023 IL 128004, the Illinois Supreme Court held that claims under Sections 15(b) and 15(d) accrue with each unlawful scan or transmission. The Illinois legislature subsequently amended BIPA through Public Act 103-0769, effective August 2, 2024.
Current 740 ILCS 14/20(b) provides that repeated collection of the same person’s same biometric identifier or biometric information using the same method of collection constitutes a single Section 15(b) violation for which the person is entitled to, at most, one recovery. Section 20(c) establishes a comparable rule for repeated disclosure to the same recipient using the same method of collection.
This is a major consideration when evaluating potential damages. Counting every fingerprint scan and simply multiplying that number by $1,000 or $5,000 no longer accurately describes the current damages framework.
The law continued developing in 2026. In consolidated appeals including Clay v. Union Pacific Railroad Co., the U.S. Court of Appeals for the Seventh Circuit held on April 1, 2026, that the 2024 Section 20 amendment applies retroactively to cases that were pending when the amendment became effective. The court characterized the amendment as a remedial change governing available damages.
Evidence Can Determine The Strength Of A Biometric Privacy Claim
Successful biometric litigation requires more than an allegation that a fingerprint scanner or facial recognition system existed. We work to establish exactly what happened to the plaintiff’s information.
Evidence may include consent documents, employee onboarding records, privacy notices, biometric timekeeping records, application permissions, vendor contracts, data-processing agreements, system logs, corporate retention policies, photographs or descriptions of scanning equipment, and communications explaining how the technology operated.
Third-party vendors can be especially important. A company may collect a fingerprint or facial geometry and transmit information to another entity that authenticates, processes, stores, or analyzes it. Determining which organizations received the data can affect the claims available under Section 15(d) and other applicable laws.
Preserving this evidence early can be important because software changes, employee departures, vendor relationships, and corporate retention practices can make records harder to obtain as time passes.
Biometric Privacy Laws Differ Across The United States
Plaintiffs should not assume that every state provides BIPA-style statutory damages or a private lawsuit for every biometric violation. States have adopted different definitions, consent requirements, enforcement systems, exemptions, and remedies.
Texas, for example, regulates the capture and use of biometric identifiers under Texas Business & Commerce Code § 503.001, but enforcement authority rests with the Texas Attorney General rather than creating the same private BIPA cause of action available in Illinois. Washington’s biometric identifier statute, RCW 19.375, likewise regulates enrollment and disclosure of biometric identifiers but does not mirror Illinois BIPA’s private statutory-damages structure.
Other state consumer privacy statutes may regulate sensitive or biometric data under different requirements. Depending on where the plaintiff lives, where the conduct occurred, the nature of the defendant, and how the information was processed, additional privacy, consumer protection, surveillance, or data security laws may need to be considered.
There is also no single federal statute that creates a universal BIPA-equivalent private statutory-damages claim for every unlawful collection of biometric information. Federal laws can apply in particular factual settings, but plaintiffs must establish that the particular statute covers the conduct at issue rather than treating “biometric privacy” as one nationwide cause of action.
Building A Claim For Statutory Biometric Damages
When we assess a potential biometric privacy case, we look beyond whether technology scanned someone’s face, fingerprint, hand, eye, or other physical characteristic. We determine whether the information qualifies for protection under the applicable statute, whether the defendant was subject to that law, whether required notice and consent were obtained, whether information was disclosed, and whether statutory exemptions apply.
For a damages claim, we also examine the defendant’s level of culpability and the current statutory rules governing recovery. That analysis can make the difference between a potentially actionable privacy violation and conduct for which a private plaintiff has no statutory monetary remedy.
Biometric technology changes quickly, but companies do not receive unlimited authority to collect and use deeply personal identifiers simply because the technology is convenient. When the law grants individuals control over their biometric information, we work to enforce those rights.
Contact Our National Cybersecurity Lawyers About A Biometric Privacy Claim
If a company, employer, technology provider, or other organization collected, stored, used, or disclosed your biometric information without complying with applicable privacy law, you may have legal options. At Net Law Advocates, we represent plaintiffs in biometric privacy and cybersecurity matters throughout the United States. We investigate how biometric information was obtained, whether legally required consent was secured, where the information went, and what remedies may be available under the laws governing your claim.
If you believe your fingerprints, facial geometry, voiceprint, or other biometric information was unlawfully collected or used, please fill out our secure web form for a free, confidential consultation. Our cybersecurity lawyers represent plaintiffs nationwide and can review the circumstances to determine whether you may have a claim for statutory damages or other available relief. Please fill out our secure web form or call our firm at 888-913-2318 for your free consultation.