ATLAS/BRIEFINGLaw, organized for consequential decisions.

PRIV-02 Privacy, Cyber & AI Data Under Duty State law (varies)

Biometric Privacy Laws: Consent, Retention, Security, and Litigation Exposure

Biometric rules are state law, and only Illinois gives private plaintiffs a broad right to sue. This brief maps what is regulated, what consent must look like, and where the money risk concentrates.

Technical diagram marking this brief's subject

Briefing in 60 seconds

  1. Illinois BIPA is the only major biometric statute with a broad private right of action, which is why class filings concentrate there.
  2. Rosenbach v. Six Flags (Ill. 2019) held that a plaintiff need not prove actual injury beyond the statutory violation itself.
  3. Cothron v. White Castle (Ill. 2023) made claims accrue per scan; an August 2024 amendment limits repeated scans to one recovery.
  4. Texas CUBI and Washington's 2017 biometric law are enforced by attorneys general only, but Texas settlements have reached enormous figures.

Controlling variables

Jurisdiction
Whether any affected person is in Illinois decides if private class exposure exists at all; other states channel the same conduct through an attorney general.
Documents
Whether a written, publicly available retention and destruction schedule existed before collection, and whether signed releases predate the very first scan.
Facts
Whether the system derives and stores a mathematical template, since the statutory exclusions turn on the difference between a photo and a faceprint.
Timing
When each collection occurred relative to the August 2024 Illinois amendment, which changed how repeated scans of the same person are counted.
Contract terms
Whether the scanner vendor or the business is treated as the collecting party, and which one carries indemnity for the other's statutory failures.

General legal information about United States law. Not legal advice, not representation, and no attorney–client relationship is created by reading it. Rules differ by jurisdiction and change — verify against the official sources listed below.

No federal statute regulates biometric data across the board. What exists is a patchwork of state law, and one piece of it — Illinois's Biometric Information Privacy Act, 740 ILCS 14 — carries a broad private right of action with liquidated damages and fee shifting. That single design choice explains why nearly all biometric class litigation in the United States traces back to Illinois, while Texas and Washington claims arrive as attorney-general enforcement instead.

Compliance therefore runs on two tracks. One is a national baseline of notice, consent, retention limits, and security for any system that captures a fingerprint, faceprint, voiceprint, or hand-geometry scan. The other is a hardened Illinois layer that assumes a class-action plaintiff will read your paperwork line by line.

What counts as regulated biometric data

The statutes do not regulate "biometrics" in the marketing sense. They regulate a defined list. Under BIPA, a biometric identifier means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. "Biometric information" is any information derived from an identifier and used to identify a person. Everything outside that list — a physical description, a signature, a written sample, a demographic record — sits outside the statute even if it feels sensitive.

The exclusions matter as much as the list. BIPA expressly carves out photographs, writing samples, written signatures, human biological samples used for valid scientific testing, X-rays and similar images, and information collected in a health care setting under federal health-privacy rules. There is also an exemption for financial institutions subject to the federal Gramm-Leach-Bliley regime, which is why many banks and their service providers analyze the question differently than retailers do.

The photograph exclusion is the most misread provision in the field. Illinois federal courts have repeatedly allowed claims to proceed where a company ran face-geometry analysis on uploaded photographs, reasoning that the exclusion covers the photograph itself and not the mathematical template extracted from it. If your system converts an image into a vector that can later match a person, assume you are inside the statute regardless of where the image came from.

State biometric regimes compared on the features that actually drive exposure
RegimeWho can bring a claimConsent standardMoney at stake
Illinois BIPA (740 ILCS 14) Private plaintiffs and classes; no separate injury required Informed written release before collection, plus a published retention and destruction schedule Liquidated damages of $1,000 for negligent and $5,000 for intentional or reckless violations, or actual damages, plus attorney's fees
Texas CUBI (Bus. & Com. Code ch. 503) Attorney General only Notice and consent before capturing an identifier for a commercial purpose Civil penalty of up to $25,000 per violation
Washington biometric statute (2017 HB 1493, ch. 19.375 RCW) Attorney General under the Consumer Protection Act Notice, consent, or a mechanism preventing use for an unrelated purpose, before enrollment in a database Consumer Protection Act remedies; the statute itself creates no private right of action
Comprehensive state privacy acts State regulators; private suits generally unavailable Opt-in consent because biometric data is classed as sensitive data Per-violation civil penalties, often after a statutory cure period

Why Illinois carries the litigation

BIPA imposes four obligations that generate claims. A private entity must publish a written policy with a retention schedule and destruction guidelines. It must give notice and obtain a written release before collecting. It may not sell or otherwise profit from biometric data. And it must store the data using the reasonable standard of care for its industry, at least as protectively as it handles other confidential information.

Rosenbach removed the injury filter

In Rosenbach v. Six Flags (Ill. 2019), the Illinois Supreme Court held that a person is "aggrieved" under the statute by the violation itself and need not plead a separate actual injury. That ruling converted paperwork failures into damages claims. A company with flawless security and no data loss can still face a class action because releases were signed a week after the first fingerprint scan rather than before it.

Cothron, then the 2024 correction

In Cothron v. White Castle (Ill. 2023), the court held that a claim accrues each time a biometric identifier is collected or disclosed, not only at first enrollment. For an employee scanning in and out daily for years, the arithmetic became catastrophic, though the court noted that the damages award is discretionary and invited legislative correction. The General Assembly took the invitation: Illinois amended BIPA in August 2024 through SB 2979 so that multiple collections from the same person by the same method count as a single violation with a single recovery, and so that an electronic signature satisfies the written-release requirement.

Two other Illinois decisions shape case value. Tims v. Black Horse Carriers (Ill. 2023) applied a five-year limitations period to all BIPA claims, and McDonald v. Symphony Bronzeville Park (Ill. 2022) held that the state workers' compensation scheme does not preempt employee BIPA claims. Together they mean a workplace timeclock deployment can be examined back five years with no exclusive-remedy defense.

Verify before relying: the August 2024 amendment changed accrual prospectively in practice, but courts continue to sort out how it applies to conduct and filings that predate it. Confirm the current posture before pricing an old exposure.

The attorney-general states and the second layer

Texas and Washington regulate similar conduct with no private right of action. That does not make them low risk. Texas has pursued biometric enforcement aggressively, and the Attorney General's office announced a settlement in 2024 valued at $1.4 billion arising from facial-recognition allegations under state law — a reminder that a single-plaintiff regime with a $25,000 per-violation penalty scales when violations are counted per person.

Underneath the dedicated statutes sits a second layer. Most comprehensive state privacy acts classify biometric data used to identify a person as sensitive data requiring opt-in consent, a data-protection assessment, and honoring deletion requests. Washington's consumer health data statute, enacted in 2023, reaches biometric data connected to health and channels claims through the state consumer protection act, which is why plaintiffs' counsel have been testing it; its scope remains unsettled as of mid-2026. Treat these overlays as independent obligations rather than duplicates of BIPA, because their consent mechanics, deletion duties, and cure periods differ.

Building a defensible collection file

The record that defends a biometric program is assembled before deployment, not after a demand letter. Most losses are sequencing failures: the right documents existed, but they existed too late.

  1. Inventory the templates

    Identify every system that derives a template — timeclocks, door access, device unlock, voice authentication in a call center, photo tagging, age-estimation tools, and any vendor doing it on your behalf. Record where each template lives and how long it persists.

  2. Publish the schedule first

    Adopt and publicly post a written retention policy stating the destruction trigger: the earlier of the purpose being satisfied or a fixed period after the individual's last interaction. A schedule that exists only in an internal wiki does not satisfy the publication requirement.

  3. Collect the release before the first scan

    Use a standalone, biometric-specific disclosure and written release naming the identifier, the purpose, and the retention period. Do not bury it in an onboarding acknowledgment or an omnibus privacy policy acceptance.

  4. Push the terms down to vendors

    Require the vendor to collect only under your notice, to refrain from training or improving models on your users' templates, to delete on schedule, and to indemnify statutory claims. A training-data clause belongs in every recognition contract.

  5. Prove destruction

    Generate deletion logs tied to individuals and dates. In litigation, the ability to show templates were destroyed on schedule is often worth more than the consent forms.

The same discipline applies when a program ends. When a scanner is decommissioned or a vendor is replaced, destruction must run to completion and be documented, because a preserved backup of templates is a live obligation. If a claim is already foreseeable, that duty collides with a litigation hold, and counsel should resolve the conflict deliberately rather than letting an administrator choose.

Where claims actually originate

  • The vendor collected, but you are the defendant. Plaintiffs typically sue the business the person interacted with and the technology provider together. Without a negotiated indemnification clause covering statutory claims and defense costs, the business funds both defenses.
  • Consent postdates collection. Rollouts start with a pilot and paperwork follows. Every scan in the gap is a separate alleged violation for the individuals involved.
  • No published schedule. The retention-policy count is the easiest claim to plead because the absence of a public document is visible from outside the company.
  • Feature creep into templates. Age estimation, liveness checks, and fraud tools quietly begin deriving face geometry. The product team does not think of this as biometrics; the statute does.
  • Contractors and applicants are forgotten. Consent workflows built for employees often miss staffing-agency workers and visitors, who are covered on the same terms.
  • Insurance mismatch. General liability and cyber policies frequently exclude statutory privacy claims or violations of laws addressing the collection of information. Read the exclusions before assuming coverage.

Governance frameworks help even though they are not law. Organizations deploying face or voice recognition often map controls to the NIST AI Risk Management Framework, which is voluntary but gives structure to accuracy testing, documentation, and monitoring across demographic groups. Federal advertising and data-security expectations run alongside the state statutes; the FTC's privacy and security business guidance is the practical reference for claims about how biometric systems perform.

Questions the desk gets

Does a photograph of a face trigger these laws?

The photograph alone generally does not. The regulated event is deriving a scan of face geometry from it. Illinois courts have allowed claims where companies ran face-template analysis on stored photos, holding that the statutory exclusion protects the image and not the template. If your pipeline produces a numeric representation capable of matching a person later, treat it as covered.

Do these laws apply to employees or only to consumers?

Illinois reaches both. Employee fingerprint and hand-geometry timeclocks generated the first large wave of BIPA litigation, and the Illinois Supreme Court has held that workers' compensation exclusivity does not bar those claims. Employers running biometric attendance systems should treat the workforce as the highest-count population and should also review adjacent screening paperwork, discussed in our brief on FCRA employment background checks.

Can consent be obtained through a website privacy policy?

Not in Illinois. The statute requires informed written consent tied to a specific disclosure of what is collected, why, and for how long it is kept. Acceptance of general terms of service is regularly rejected as insufficient. Other states set a lower bar, but designing to the Illinois standard produces one workflow instead of several.

Does an out-of-state company escape BIPA?

Location of incorporation is not the test. What matters is where the individual was when the identifier was collected, and courts examine whether the relevant conduct occurred primarily in Illinois. National consumer applications and multistate employers usually cannot segregate Illinois users cleanly, which is why many organizations apply the Illinois standard everywhere.

Where the risk actually sits

The exposure is not in the technology. It is in the two weeks between switching on a scanner and completing the paperwork, in a retention schedule nobody published, and in a vendor contract that never mentioned statutory claims. Start with an honest template inventory, because most organizations underestimate it by half once age-estimation and fraud tools are counted.

Then sequence the fixes: publish the schedule, replace the consent artifact, paper the vendors, and build deletion evidence. If templates have already been stored without releases, treat the question as a potential incident and involve counsel early, using the posture described in our brief on data-breach response, privilege, and notification. Where the same vendor also supplies models or analytics, fold the biometric terms into the broader negotiation covered in contracting with AI vendors, and if any users may be minors, check the separate consent architecture in children's online privacy. Related work across this area sits on the Privacy, Cyber & AI desk.

Sources

  1. Illinois General Assembly — Illinois Compiled Statutes (search 740 ILCS 14, Biometric Information Privacy Act)
  2. Federal Trade Commission — Privacy and Security business guidance
  3. Office of the Attorney General of Texas — enforcement of the Capture or Use of Biometric Identifier Act
  4. Washington State Office of the Attorney General — consumer protection enforcement
  5. NIST — AI Risk Management Framework (governance for recognition systems)

Atlas Research Desk

ATLAS briefs are researched and edited by the Research Desk, an editorial organization — not attorneys acting for you. Method and limits: editorial method · source standards · corrections.