RoutineMetric

Biometric Privacy (BIPA) Statutory Liability & Compliance Calculator

Analyze compliance posture and model class-action risk exposure under the Illinois Biometric Information Privacy Act (BIPA) SB 2979 Standards.

BIPA Statutory Self-Audit Checklist

Complete this 7-point diagnostic based on your organization's biometric data handling.

Section 15(a)

Do you have a written, publicly available biometric retention policy and permanent destruction guidelines?

Guidelines must mandate destroying biometric data when the initial collection purpose is satisfied, or within 3 years of the individual's last interaction, whichever occurs first.

Section 15(b)(1)

Do you provide written notice to individuals BEFORE collecting or capturing their biometric data?

Notice must be provided in writing before any fingerprint, hand, facial, or voice scanning occurs.

Section 15(b)(2)

Does your written notice explicitly specify the purpose and length of term for which data is stored?

The disclosure template must clearly state why you are collecting the biometric data and how long it will be stored.

Section 15(b)(3)

Do you obtain an active, signed 'written release' (consent) from each individual BEFORE collection?

A signed written release (paper or digital) is a non-negotiable requirement under Illinois law.

Section 15(c)

Can you confirm that you NEVER sell, lease, trade, or otherwise profit from biometric data?

BIPA imposes an absolute statutory ban on the sale or commercial monetization of biometric data. Yes means you NEVER sell it.

Section 15(d)

Do you obtain written consent before disclosing or disseminating biometric data to third parties (vendors)?

This covers sharing biometric templates with cloud-based timeclock providers, hosting servers, or software vendors.

Section 15(e)

Do you protect biometric data using a standard of care equal to or stronger than other highly sensitive data?

Encryption in transit and at rest is required. The security level must match or exceed your standard for other sensitive identifiers like SSNs or passwords.

Your Compliance Posture

0%Score
Rating: High Risk

Your score is weighted by the statutory legal risk of each BIPA requirement. Review recommendations below.

Statutory Action Items

Section 15(a)Mandatory

Draft and publish a biometric retention schedule. Guidelines must mandate permanent deletion upon satisfaction of purpose or within 3 years of the individual's last contact.

Section 15(b)(1)Mandatory

Implement written disclosures that are presented to employees/customers prior to any fingerprint, hand, facial, or voice scanning.

Section 15(b)(2)Mandatory

Update your disclosure templates to state the precise collection purpose and the exact storage duration (matching your retention policy).

Section 15(b)(3)Mandatory

Implement a mandatory signing workflow (paper or electronic) to obtain a legally binding 'written release' from individuals prior to scan enrollment.

Section 15(c)Mandatory

Cease any activities involving the selling, leasing, trading, or monetization of biometric data. This is an absolute statutory ban.

Section 15(d)Mandatory

Audit vendor integrations. Ensure explicit consent is obtained from individuals before sharing or disclosing biometric data to any third-party processor.

Section 15(e)Mandatory

Verify that biometric templates are encrypted in transit and at rest, and that your security measures are at least as protective as those for other highly sensitive data.

Advertisement
Bottom Banner Ad (728x90)

Understanding BIPA Compliance and the Landmark 2024 SB 2979 Legislative Reform

The Illinois Biometric Information Privacy Act (BIPA) has shaped the legal landscape of cybersecurity and data privacy since 2008. Designed to safeguard individual identity in an increasingly digital world, BIPA restricts how private entities gather, utilize, store, share, and destroy biometric identifiers. Biometric identifiers are statutorily defined as fingerprints, voiceprints, iris or retina scans, hand scans, and facial geometry.

The White Castle Crisis and the 'Per-Scan' Multiplier

For over a decade, BIPA's private right of action created a unique and high-stakes risk environment. In 2023, the Illinois Supreme Court issued its landmark ruling in Cothron v. White Castle System, Inc., holding that a separate statutory violation accrued every single time an individual scanned their biometric data in violation of the law.

For a typical employee who scanned their fingerprint clocking in and out four times a day, this meant accumulating hundreds of violations a year. The court's literal interpretation of the statute exposed businesses to astronomical liquidated damages—such as White Castle's estimated class liability of over $17 billion. The court explicitly noted that the legislature held the power to reform the statutory language if the resulting liability was ruinous.

The Solution: 2024 Senate Bill 2979

Responding to intense pressure from the business and legal communities, the Illinois General Assembly passed Senate Bill 2979, which was signed into law and became effective on August 2, 2024. SB 2979 enacted the most sweeping amendments in BIPA's history, establishing that:

  • Capped Collection Claims (Section 15(b)): A private entity that collects an individual's biometric data without complying with statutory notice and consent requirements has committed a single, consolidated violation. No multiple recoveries can be obtained for subsequent scans of the same biometric identifier using the same collection method.
  • Capped Disclosure Claims (Section 15(d)): A private entity that discloses or disseminates an individual's biometric data without obtaining specific statutory consent has committed a single violation, regardless of how many times the data is transferred or transmitted.
  • Electronic Signature Release: The reform explicitly modernized the statutory definition of "written release" to include digital and electronic signatures, matching modern software workflows.

Practical Risk Management & Implementation

While SB 2979 has eliminated the threat of business-bankrupting "per-scan" damages, class-action risk remains high. A class of 500 employees can still seek a baseline of $500,000 for simple negligent collection ($1,000 per person) or up to $2.5 million for reckless violations ($5,000 per person), plus plaintiffs' attorneys' fees.

To manage risk effectively under current 2026 legal standards, corporate counsels and security officers should follow three critical protocols:

  1. Implement Multi-Factor Written Releases: Ensure that your timekeeping or biometric security systems cannot be activated until the user has actively checked and signed a specific written BIPA release form.
  2. Enforce Vendor Indemnification: Audit all third-party software and cloud storage APIs that receive biometric templates. Verify that they are legally compliant and that their service level agreements contain robust data privacy indemnification clauses.
  3. Coordinate with State-level Requirements: Ensure your compliance model accounts for overlapping requirements across jurisdictions, such as Washington's My Health My Data Act and Texas's CUBI regulations.
Advertisement