Understanding BIPA Compliance and the Landmark 2024 SB 2979 Legislative Reform
The Illinois Biometric Information Privacy Act (BIPA) has shaped the legal landscape of cybersecurity and data privacy since 2008. Designed to safeguard individual identity in an increasingly digital world, BIPA restricts how private entities gather, utilize, store, share, and destroy biometric identifiers. Biometric identifiers are statutorily defined as fingerprints, voiceprints, iris or retina scans, hand scans, and facial geometry.
The White Castle Crisis and the 'Per-Scan' Multiplier
For over a decade, BIPA's private right of action created a unique and high-stakes risk environment. In 2023, the Illinois Supreme Court issued its landmark ruling in Cothron v. White Castle System, Inc., holding that a separate statutory violation accrued every single time an individual scanned their biometric data in violation of the law.
For a typical employee who scanned their fingerprint clocking in and out four times a day, this meant accumulating hundreds of violations a year. The court's literal interpretation of the statute exposed businesses to astronomical liquidated damages—such as White Castle's estimated class liability of over $17 billion. The court explicitly noted that the legislature held the power to reform the statutory language if the resulting liability was ruinous.
The Solution: 2024 Senate Bill 2979
Responding to intense pressure from the business and legal communities, the Illinois General Assembly passed Senate Bill 2979, which was signed into law and became effective on August 2, 2024. SB 2979 enacted the most sweeping amendments in BIPA's history, establishing that:
- Capped Collection Claims (Section 15(b)): A private entity that collects an individual's biometric data without complying with statutory notice and consent requirements has committed a single, consolidated violation. No multiple recoveries can be obtained for subsequent scans of the same biometric identifier using the same collection method.
- Capped Disclosure Claims (Section 15(d)): A private entity that discloses or disseminates an individual's biometric data without obtaining specific statutory consent has committed a single violation, regardless of how many times the data is transferred or transmitted.
- Electronic Signature Release: The reform explicitly modernized the statutory definition of "written release" to include digital and electronic signatures, matching modern software workflows.
Practical Risk Management & Implementation
While SB 2979 has eliminated the threat of business-bankrupting "per-scan" damages, class-action risk remains high. A class of 500 employees can still seek a baseline of $500,000 for simple negligent collection ($1,000 per person) or up to $2.5 million for reckless violations ($5,000 per person), plus plaintiffs' attorneys' fees.
To manage risk effectively under current 2026 legal standards, corporate counsels and security officers should follow three critical protocols:
- Implement Multi-Factor Written Releases: Ensure that your timekeeping or biometric security systems cannot be activated until the user has actively checked and signed a specific written BIPA release form.
- Enforce Vendor Indemnification: Audit all third-party software and cloud storage APIs that receive biometric templates. Verify that they are legally compliant and that their service level agreements contain robust data privacy indemnification clauses.
- Coordinate with State-level Requirements: Ensure your compliance model accounts for overlapping requirements across jurisdictions, such as Washington's My Health My Data Act and Texas's CUBI regulations.