Illinois Biometric Information Privacy Act (BIPA): AI Compliance Requirements
Illinois BIPA (740 ILCS 14, effective 2008, amended 2024) is the nation's strongest biometric privacy law and directly affects AI systems that collect or analyze facial geometry, voiceprints, fingerprints, hand scans, or iris/retina scans. Any business using AI facial recognition (for hiring, attendance, or identity verification), voice authentication, or biometric time-clocks in Illinois must comply. The 2024 amendment (SB 2979) limits cumulative violations to one per person per recipient. With over 1,000 class actions filed, BIPA has the highest active litigation risk of any US AI privacy law.
Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
Key Facts
October 3, 2008
$1,000 per negligent violation; $5,000 per intentional/reckless violation (private right of action)
What Your Business Must Do
4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
Biometric Data Retention & Destruction Policy
CriticalPublish a written, publicly available policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information. Destruction is due when the initial purpose for collecting or obtaining the identifiers has been satisfied OR within 3 years of the individual's LAST INTERACTION with the private entity, whichever occurs first. [2026-08-25 CORRECTION: this description previously said "no later than 3 years after collection" — the statute's clock runs from the individual's last interaction with the entity, not from the collection date, which is materially longer for ongoing employees/customers. Corrected against the primary text of 740 ILCS 14/15(a) read this session.]
Deadline: October 3, 2008
740 ILCS 14/15(a)Informed Written Consent Before Biometric Collection
CriticalBefore collecting ANY biometric data through AI or automated systems: (1) Notify the individual in writing of what is being collected and stored. (2) State the specific purpose and duration of collection/storage. (3) Obtain a written or electronic release. This applies to employees, job applicants, and customers. No biometric collection without explicit prior consent.
Deadline: October 3, 2008
740 ILCS 14/15(b)No Sale or Profit from Biometric Data
High PriorityNever sell, lease, trade, or profit from any individual's biometric data. Do not disclose or disseminate biometric data to third parties without written consent — except to complete a financial transaction authorized by the individual, or as required by law.
Deadline: October 3, 2008
740 ILCS 14/15(c)-(d)Biometric Data Security — Equivalent to Confidential Financial Data
High PriorityStore, transmit, and protect biometric identifiers and information using the same reasonable standard of care that your industry uses for other confidential and sensitive information. Minimum: data-at-rest encryption, access controls, and separate storage from other personal data.
Deadline: October 3, 2008
740 ILCS 14/15(e)Who Does This Apply To?
Applies to any private entity — not government — that collects, captures, purchases, receives through trade, or otherwise obtains a person's biometric identifier or biometric information. Covered biometrics: retina/iris scans, fingerprints, voiceprints, hand/finger geometry scans, facial geometry (from which an individual can be identified). AI-specific scope: facial recognition (liveness detection, identity matching), voice biometric authentication, fingerprint scanners in HR systems, AI-powered attendance systems. Does NOT cover: photos, videos, or physical descriptions unless processed to extract biometric identifiers. The 2024 SB 2979 amendment limits cumulative per-person statutory damages to one violation per person per defendant — capping class action exposure.
Recent Enforcement Actions
Against: Meta Platforms, Inc. (Facebook)
Landmark BIPA class action settlement. Facebook's "Tag Suggestions" feature used facial recognition to identify people in photos without consent. The $650M settlement remains the largest BIPA settlement and established that cloud-based AI facial recognition used for photo tagging triggers BIPA obligations — even when the AI processing occurs on servers outside Illinois.
SourceAgainst: White Castle System, Inc.
White Castle BIPA settlement following the Illinois Supreme Court's Cothron v. White Castle ruling (17 Feb 2023) that BIPA violations accrue each time biometric data is collected or transmitted — not just once per person. That accrual theory exposed White Castle to a hypothetical ~$17 BILLION liability for roughly 9,500 employees' repeated fingerprint timeclock scans; the case then settled for $9.39 million (final approval 1 Aug 2024, Judge John J. Tharp Jr., N.D. Ill.) — well below the theoretical exposure, before the 2024 SB 2979 amendment capped per-person damages going forward.
SourceAgainst: TikTok (ByteDance)
TikTok settled BIPA class action for $92M over facial geometry collection from videos uploaded by Illinois users. Established that AI processing of user-generated video to extract facial features triggers BIPA regardless of whether the collection was for a "matching" or analytics purpose.
SourceRecent Regulatory Guidance
SB 2979 Amendment — Per-Violation Cap Signed into Law
Illinois Governor signed SB 2979 amending BIPA to limit cumulative statutory damages to one violation per person per defendant — regardless of how many times biometric data was collected or transmitted without consent. This caps class action exposure dramatically (Cothron ruling had created per-transaction liability). However, intentional/reckless violations remain at $5,000 per violation, and negligent violations at $1,000. The amendment is retroactive and applies to pending litigation.
SourceIL Supreme Court — Rosenbach Doctrine Reaffirmed
Illinois Supreme Court reaffirmed the Rosenbach doctrine: plaintiffs do not need to allege actual harm to bring a BIPA claim — technical BIPA violations (consent form missing, policy not published) are sufficient for statutory damages. This keeps the private right of action robust even after SB 2979 per-violation cap. Businesses must ensure formal BIPA compliance, not just avoid data breaches.
SourceKey Case Law & Precedent
Rosenbach v. Six Flags Entertainment Corp.
Illinois Supreme Court · 2019Established that a BIPA plaintiff does not need to plead actual harm — a mere technical violation of BIPA (e.g., failing to publish a biometric retention policy or collecting fingerprints without prior consent) is sufficient for statutory damages of $1,000–$5,000 per person. This ruling is the foundation of all BIPA class action litigation and makes even technically non-harmful AI biometric use high-risk.
Outcome: Plaintiff prevailed. All subsequent BIPA class actions rely on Rosenbach. No actual harm requirement.
Case referenceCothron v. White Castle System, Inc.
Illinois Supreme Court · 2023Held that a BIPA violation accrues each time biometric data is scanned or transmitted without consent — creating per-transaction liability. For White Castle's daily employee fingerprint timeclock scans, this meant potential $17 billion exposure before SB 2979 amendment capped per-person damages. Critical for AI systems with recurring biometric authentication.
Outcome: Per-transaction accrual confirmed. Led directly to SB 2979 legislative fix capping per-person damages.
Case referenceIn re Facebook Biometric Information Privacy Litigation
N.D. Cal. · 2022The $650M Facebook settlement established that cloud-based AI facial recognition for content tagging triggers BIPA even when: (1) the AI computation occurs off-device; (2) the facial data is used for feature improvement rather than identity authentication; (3) the company is headquartered outside Illinois. Applies extraterritorially to any company with Illinois user data.
Outcome: $650M class action settlement. Facebook discontinued "Tag Suggestions" globally.
Case referenceClay v. Union Pacific Railroad Co. (consolidated with Willis v. Universal Intermodal Services and Gregg v. Central Transport LLC)
US Court of Appeals for the Seventh Circuit · 2026Resolved, at the appellate level, whether SB 2979's August 2024 per-person damages cap (already tracked by this entry) applies retroactively to BIPA claims that ACCRUED before the amendment took effect - the single biggest open question left by the Cothron per-scan-accrual ruling. The court held the cap is remedial/procedural (it modifies only the Section 20 damages provision, not the Section 15 liability standard, and sets a maximum rather than a minimum recovery), so it applies to any case pending on 2024-08-02, not just claims arising after that date. Directly changes exposure modeling for any AI vendor (facial-recognition access control, voice-biometric authentication, biometric timeclocks) facing a pre-2024 BIPA claim.
Outcome: Seventh Circuit reversed the lower courts and confirmed retroactive application (No. 25-2185, decided 2026-04-01); per-scan damages theories are no longer viable in Seventh Circuit BIPA cases. Consistent with reporting that Illinois BIPA filings fell sharply, from 427 (2024) to 150 (2025), which multiple secondary sources attribute to SB 2979 plus this ruling.
Case referenceQuarterly Enforcement Digest
Q1 2026: BIPA remains the most actively litigated AI privacy law in the US (1,000+ class actions filed since 2019). SB 2979 amendment (August 2024) capped per-person damages but did not eliminate the private right of action; the Seventh Circuit confirmed retroactive application 2026-04-01 (Clay v. Union Pacific, see caseCitations), and filings fell sharply from 427 (2024) to 150 (2025). Businesses with Illinois employees using biometric time-clocks or facial recognition for access control must maintain: (1) published biometric retention/destruction policy; (2) written individual consents; (3) no third-party data sharing without consent. AI vendors processing Illinois employee biometric data (Veridium, Clear, HireVue voiceprint) must ensure their customer contracts include BIPA-compliant data processing agreements.
Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.
Industry Playbooks covering Illinois Biometric Information Privacy Act (BIPA)
These industry playbooks include jurisdiction-specific checklist items and guidance for Illinois Biometric Information Privacy Act (BIPA).
Frequently Asked Questions
Does Illinois Biometric Information Privacy Act (BIPA) apply to my business?
Illinois BIPA (740 ILCS 14, effective 2008, amended 2024) is the nation's strongest biometric privacy law and directly affects AI systems that collect or analyze facial geometry, voiceprints, fingerprints, hand scans, or iris/retina scans. Any… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under Illinois Biometric Information Privacy Act (BIPA) is: $1,000 per negligent violation; $5,000 per intentional/reckless violation (private right of action). Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with Illinois Biometric Information Privacy Act (BIPA)?
The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.
Official Source
https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004&ChapterID=57Last updated: 2026-08-22 — verify at source before relying on this information.
Don't leave compliance to chance
Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan