Close Menu

What The Biometric Information Privacy Act (BIPA) Protects And Why It Matters

TheDigitalIdCardConceptWithAManPointingTo

Across the United States, companies increasingly use biometric technology for convenience, security, and tracking. Tools such as fingerprint time clocks, facial recognition systems, voice authentication, retinal scanners, and behavioral measurements are now common in workplaces, retail, healthcare, and digital applications. While these tools improve efficiency, they also raise significant privacy concerns. Biometric identifiers are permanent and, unlike passwords, cannot be changed if compromised. Due to these risks, Illinois enacted the Biometric Information Privacy Act (BIPA), 740 ILCS 14, one of the nation’s strongest privacy laws.

As plaintiff-side cybersecurity lawyers at Net Law Advocates, we represent individuals whose biometric data was collected or stored unlawfully. Many people are unaware of how frequently companies violate these laws or the impact on their families, finances, and long-term security. BIPA was enacted to provide stronger protection for biometric data than for other personal information. Understanding the law helps individuals recognize when their rights have been violated.

What BIPA Protects

BIPA covers two main categories of information: “biometric identifiers” and “biometric information.” These categories include:

  • Fingerprints
  • Voiceprints
  • Retina or iris scans
  • Hand or face geometry
  • Any information derived from these identifiers

Unlike usernames or passwords, these physical traits uniquely identify individuals. If mishandled, the consequences can be lifelong. This is why BIPA’s protections are more rigorous than many other state privacy laws.

The statute prohibits companies from collecting, capturing, purchasing, receiving, storing, or using biometric identifiers without following strict requirements. This includes employers using fingerprint timekeeping systems, retailers using facial recognition, online services using voiceprint technology, and any business storing biometric identifiers for verification or tracking.

Written Notice And Informed Consent Requirements

One of the most important parts of BIPA is its requirement for informed, written consent. Before collecting biometric identifiers, companies must:

  1. Provide written notice explaining what is being collected.
  2. State the purpose of the collection.
  3. Explain how long the information will be stored.
  4. Obtain a written release.

Businesses cannot collect facial scans or fingerprints without clear notice and consent. Consent cannot be hidden in lengthy documents or assumed through continued employment.
Many of the cases we handle arise from employers who use a fingerprint time clock without ever informing workers of their rights or obtaining consent. These failures directly violate BIPA.

Requirements For Storage, Use, And Destruction

BIPA also regulates how companies store and handle biometric data. Under 740 ILCS 14/15(a), businesses must have a publicly available written policy establishing:

  • How biometric identifiers are stored.
  • How long they are retained.
  • When and how they will be permanently destroyed.

Biometric data cannot be kept indefinitely. It must be deleted when the original purpose has been satisfied or within three years of the individual’s last interaction with the company — whichever comes first.

Many companies fail to maintain destruction schedules or allow vendors to store biometric identifiers without proper safeguards. These errors may constitute legal violations.

Restrictions On Disclosure And Profit

BIPA prohibits companies from selling, leasing, trading, or profiting from biometric identifiers. It also forbids sharing biometric data with third parties unless strict conditions are met.
This ensures that individuals maintain control over their most personal information. Without these protections, companies could commodify or transfer biometric identifiers in ways that expose consumers to serious harm.

Security Requirements

Under 740 ILCS 14/15(e), companies must store biometric data using reasonable standards of care within their industry. They must also protect biometric identifiers at least as securely as other sensitive data.

Failing to secure a biometric database is a direct violation of the statute. A breach involving fingerprints or facial recognition templates is far more damaging than exposure of a password because the individual cannot replace the compromised identifier.

Why BIPA Matters For Workers And Consumers

BIPA is one of the only privacy statutes in the United States that gives individuals a private right of action, meaning victims can sue companies directly. Plaintiffs do not have to prove financial harm or identity theft. A violation of the statute itself is enough to bring a claim.

This matters because biometric data misuse often creates long-term risks rather than immediate financial loss. BIPA ensures that individuals have the power to challenge unlawful biometric collection and demand accountability before the damage becomes irreversible.

For workers, BIPA protects them from employers who install fingerprint time clocks or facial recognition systems without proper notice and consent. For consumers, BIPA protects them from businesses that gather facial scans or voiceprints without authorization. For patients, it ensures that healthcare providers follow strict guidelines before using biometric tools.

These protections help restore balance between powerful companies and individuals who depend on them.

How Lawsuits Under BIPA Work

When we evaluate a BIPA case, we look for specific statutory violations, including:

  • Lack of written consent
  • No published retention schedule
  • No destruction policy
  • Improper data sharing
  • Failure to protect biometric identifiers
  • Retaining data longer than permitted
  • Collecting data without disclosure

Each violation may entitle the plaintiff to statutory damages. Depending on the nature of the violation, damages may be awarded per violation or per individual affected.

Because BIPA violations often affect large groups of employees or consumers, many cases qualify for class action status.

Why BIPA Remains One Of The Strongest Privacy Laws In The Country

BIPA was enacted before biometric technology became widespread, yet it remains the gold standard for biometric protections. It holds companies accountable when they fail to respect transparency, consent, and reasonable data security.

Biometric identifiers are permanent. They are tied to a person’s identity and cannot be replaced. This is why BIPA’s protections are essential and why our firm treats violations with the seriousness they deserve.

Biometric Breach Lawsuit Frequently Asked Questions

What Biometric Data Does BIPA Protect?

BIPA protects fingerprints, voiceprints, facial geometry scans, retinal or iris scans, and any information derived from these identifiers. These traits uniquely identify individuals and cannot be changed if exposed, making them extremely sensitive. Companies that collect these identifiers without proper notice or consent violate the statute.

Do Companies Need My Consent To Collect Biometric Data?

Yes. BIPA requires written notice and a written release before collecting biometric identifiers. The notice must explain what is being collected, why it is being collected, and how long it will be kept. Consent must be informed and cannot be assumed through employment or usage. If a company failed to obtain proper consent, you may have a claim.

Can I Sue A Company If My Biometric Data Was Collected Without Permission?

Yes. BIPA provides individuals with the right to file a lawsuit for statutory damages. Proof of financial loss is not required. If a company failed to follow BIPA’s requirements, you can pursue compensation. Many cases involve employers who never informed workers about biometric timekeeping systems.

Does BIPA Require Companies To Delete Biometric Data?

Yes. A company must have a retention and destruction schedule. Biometric data must be destroyed within statutory timeframes, often within three years of the individual’s last interaction. If a company keeps biometric information indefinitely or without a deletion policy, it may be violating BIPA.

Why Are Biometric Violations So Serious?

Unlike passwords, biometric identifiers cannot be replaced. If a fingerprint template, facial scan, or voiceprint is exposed, the damage can follow someone for life. Biometric misuse can also lead to tracking, profiling, and unauthorized monitoring. BIPA exists to prevent these risks and ensure transparency and protection.

Contact Net Law Advocates For A Free, Confidential Consultation

If your biometric identifiers were collected or stored without proper consent, our Cybersecurity lawyers are ready to evaluate your situation. BIPA gives individuals strong legal protections, and companies that violate those protections must be held accountable.

If you believe your data was exposed or used unlawfully, please fill out our secure web form to schedule a free, confidential consultation. We represent plaintiffs across the United States and will review your case carefully to determine how we may help.

author avatar
Net law Advocates
Submit Your Case for an Evaluation
X Get A Consultation With Us
* Required Field By submitting this form I acknowledge that contacting Net Law Advocates through this website does not create an attorney-client relationship, and any information I send is not protected by attorney-client privilege.
protected by reCAPTCHA Privacy - Terms