
Short answer: the Illinois Biometric Information Privacy Act (BIPA), found in the Illinois Compiled Statutes (the state code) at 740 ILCS 14, is in force as of October 5, 2026. Before a business collects a fingerprint, face scan or similar identifier, it must give written notice and get a written release. It must also keep a public written policy on storing and destroying the data. People can sue. The Act sets $1,000 for a careless (negligent) violation and $5,000 for an intentional or reckless one, plus lawyers' fees. A 2024 amendment gives each person at most one recovery for repeated scans by the same method. This is not legal advice. Confirm the current text before you act on it.
TL;DR
- Status on October 5, 2026: in force since 2008. The latest amendment is Public Act 103-769 (the label for the 2024 law that changed BIPA), effective August 2, 2024.
- Who: any "private entity," which covers almost any business, group or person. Government agencies are out.
- What: written policy, written notice, written release, no selling the data, limits on sharing, and safe storage.
- Enforcement: by individuals who sue. The Act names no state agency to enforce it.
- Deadline to sue: five years, according to the Illinois Supreme Court in 2023.
- Still open: does the 2024 limit apply to lawsuits filed before it took effect? A federal appeals court says yes. The state supreme court has not ruled.
What BIPA is, in one paragraph
BIPA is a statute, meaning a law passed by a legislature. The Illinois General Assembly passed it in 2008. A biometric identifier is a body measurement that can pick out one person, such as a fingerprint. The core idea is consent. A business must tell you in writing what it is collecting and why. You must agree in writing before it takes your fingerprint or face scan. Much of what BIPA means in practice comes from court decisions. Those are primary law, meaning official legal text, just as statutes are. For the types of primary law, see types of primary law in the US.
The dates, in order
Cases with "IL" in the citation are Illinois Supreme Court decisions.
- October 3, 2008: BIPA took effect (Public Act 95-994, the label for a law passed by the Illinois legislature).
- January 25, 2019: Rosenbach v. Six Flags, 2019 IL 123186. A person can sue without showing harm beyond the violation itself.
- February 3, 2022: McDonald v. Symphony Bronzeville Park, 2022 IL 126511. Workers' compensation law does not block a worker's BIPA claim.
- February 2, 2023: Tims v. Black Horse Carriers, 2023 IL 127801. Five-year deadline.
- February 17, 2023: Cothron v. White Castle, 2023 IL 128004. A new claim arises with each scan.
- March 23, 2023: Walton v. Roosevelt University, 2023 IL 128338. Union workers' claims can be sent to the union's own dispute process.
- August 2, 2024: Public Act 103-769 took effect and added the one-recovery rule.
- April 1, 2026: the Seventh Circuit, a federal appeals court, decided Clay v. Union Pacific Railroad (No. 25-2185). It applied the 2024 limit to pending cases.
- Now: several bills to change BIPA were filed in the 2025-2026 session. One example is HB 2984, which would add "neural data." The General Assembly's bill status page shows it stuck in a House committee since March 27, 2026. As of October 5, 2026, no 2025-2026 bill appears to have become law. The official text still lists Public Act 103-769 as the latest change.
What counts as a biometric identifier
Section 10 says: "'Biometric identifier' means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry." It then lists what is left out. Examples are writing samples, signatures, photographs, and plain facts such as height or hair color. Also left out is information captured from a patient in a health care setting. So is information collected for health care treatment, payment or operations under the federal health privacy law (HIPAA). Medical images such as X-rays and MRIs are out too.
"Biometric information" is wider. It means any information "based on an individual's biometric identifier used to identify an individual." That reaches a stored template made from a scan.
A "private entity" is almost any person, firm or group, "however organized." It leaves out government agencies and Illinois courts. The text sets no size limit and no location test. Whether Illinois law reaches a case with out-of-state facts is a question for a court, so ask a lawyer.
What a business must do
| Duty | Section 15 | What the text says |
|---|---|---|
| Public written policy | (a) | Must set a retention schedule and rules for destroying the data when its purpose is met or "within 3 years of the individual's last interaction," whichever comes first. Follow it. |
| Notice and release before collecting | (b) | Tell the person in writing that the data is being collected or stored, and the specific purpose and length of term. Get a written release. |
| No profit from the data | (c) | May not "sell, lease, trade, or otherwise profit" from it. |
| Limits on sharing | (d) | May not disclose it without consent, unless needed to finish a financial transaction the person asked for, required by law, or demanded by a valid warrant or subpoena (a court order or demand for records). |
| Safe storage | (e) | Use "the reasonable standard of care within the private entity's industry," at least as protective as for other sensitive data. |
The Act defines a "written release" in three ways. It can be "informed written consent." It can be an "electronic signature." For staff it can be "a release executed by an employee as a condition of employment." The 2024 amendment added the electronic signature. Section 25 also exempts banks and similar firms covered by a federal law, the Gramm-Leach-Bliley Act. It exempts contractors working for a state or local agency too.
Who can sue and for how much
Section 20 lets "any person aggrieved by a violation" sue in state court, or add the claim to a related federal case. The state supreme court read "aggrieved" in Rosenbach. It said: "No additional consequences need be pleaded or proved. The violation, in itself, is sufficient to support the individual's or customer's statutory cause of action."
A winner "may recover for each violation." The options:
- Negligent (careless) violation: liquidated damages of $1,000 or actual damages, whichever is greater. Liquidated damages are a fixed sum the law sets, so the person need not prove a loss. Actual damages are the person's proven dollar loss.
- Intentional or reckless violation: $5,000 or actual damages, whichever is greater. Reckless means ignoring a known risk.
- Lawyers' fees and costs, including expert witness fees.
- Other relief, including an injunction, which is a court order to stop doing something.
The Act has no state-agency enforcement section. The private lawsuit is its enforcement tool.
Why the 2024 change matters
In Cothron, the state supreme court held that "a claim accrues under the Act with every scan or transmission of biometric identifiers or biometric information without prior informed consent." A worker who scanned a fingerprint twice a day could, in theory, have hundreds of claims. The court noted that damages are discretionary and asked the legislature to "make clear its intent."
The legislature did so in Public Act 103-769. New section 20(b) covers collection. Take a business that collects "the same biometric identifier or biometric information from the same person using the same method of collection" more than once. The law says it "has committed a single violation of subsection (b) of Section 15 for which the aggrieved person is entitled to, at most, one recovery." Section 20(c) does the same for repeated sharing with the same recipient. These subsections speak only to collection and disclosure, which are sections 15(b) and 15(d).
To see the stakes, take the Clay case. The worker said his fingerprint was scanned about 1,500 times. The court wrote that if the railroad were found liable for intentional violations, "that could net Clay alone $7.5 million." Under the amendment, the same worker gets at most one recovery. The cap does not erase the notice, policy, consent, storage or sharing duties.
Does the cap reach older lawsuits?
The amendment says nothing about lawsuits already pending. On April 1, 2026, the Seventh Circuit held that it "applies retroactively to cases pending at the time it was enacted," meaning it reaches lawsuits already under way. The court reasoned that the amendment changes only the remedy. That ruling binds federal trial courts in Illinois, Indiana and Wisconsin. Illinois state courts do not have to follow it. No Illinois Supreme Court ruling on the question was found as of October 5, 2026. This point matters only for a lawsuit filed before August 2, 2024. If you face one, ask a lawyer which court it is in.
The deadline to sue
BIPA has no deadline of its own. In Tims, the state supreme court held "that the five-year limitations period contained in section 13-205 of the Code governs claims under the Act." That covers every part of section 15.
Illinois BIPA checklist before collecting a fingerprint or face scan
- Decide the purpose and how long you will keep the data. Write them down.
- Publish a policy on keeping and destroying the data. Then follow it.
- Give each person a written notice that names the data, the purpose and the length of term.
- Get a signed or electronically signed release before the first scan. For staff, a release can be a condition of employment.
- Never sell or trade the data.
- Get consent before you pass it to a vendor, such as a timekeeping company.
- Store it with at least the care you give your other sensitive records.
- If you have a union workforce, ask a lawyer how the contract affects consent. Walton held that a broad management-rights clause (a contract term giving the employer wide control) can send these claims to the union's dispute process.
A worked example
A gym wants fingerprint door access. Before the first scan, it posts a policy that says it will delete each fingerprint when a membership ends, and no later than 3 years after the member's last visit. It gives each member a written notice naming the fingerprint, the purpose (door entry) and how long it keeps the data. The member signs a release, on paper or on a screen. The gym never sells the data, and it shares it with its door-lock vendor only with the member's consent. If the gym starts scanning before the member signs, a form signed afterward does not fix the first scan.
What goes wrong
The common error is using an article from 2021 or 2022 that describes per-scan damages as current. The second is skipping the written policy because consent forms exist, when section 15(a) is a separate duty. The third is assuming a vendor's software handles consent. The business that collects the data carries the duty.
FAQ
Is BIPA still in effect? Yes. It has been in force since October 3, 2008. The latest amendment took effect August 2, 2024.
Does BIPA cover employees? Yes. The Act's definition of "written release" mentions employment. The state supreme court has also allowed worker claims (McDonald). Union-represented workers face the Walton rule.
How much can a business owe? The Act sets $1,000 for a negligent violation and $5,000 for an intentional or reckless one, or actual damages if higher, plus fees. Since 2024, repeated collection of the same biometric identifier from the same person by the same method gets at most one recovery. Repeated sharing with the same recipient is treated the same way.
Is a photograph covered? The Act's list leaves out "photographs." It covers a "scan of hand or face geometry." If a product turns photos into face templates, ask a lawyer how the Act applies.
Is an electronic signature enough? Yes. The 2024 amendment added it to the definition of a written release.
How long do people have to sue? Five years under Tims.
Where do I read the official text? The Illinois General Assembly publishes the Act. The state supreme court posts Cothron, and the federal appeals court posts Clay. To cite Illinois law, see how to find and cite Illinois law. To place this law in the wider map, read US Law Data: The Complete Guide. For how states handle data after a breach, see state data breach notification laws, and for other privacy laws, state privacy laws and where to read them.
If your product needs current state statute text and its change history, see the US primary law API, a data service that software can call to pull statute text.
New legal AI guides, weekly.
Further Reading
US Law Data: The Complete Guide for Business and Technical Readers
Read postHow Does a Bill Become a Law? From Idea to the US Code
Read postFlorida Attorney General Opinions: How to Find, Read and Cite Them
Read postUSC vs CFR: What the Abbreviations Mean and How They Differ
Read postFederal vs State Law: Which One Applies to You?
Read postWhat Does Codified Mean in Law? A Plain Guide With Real Examples
Read post
Co-Founder & CTO
Priyansh leads engineering and AI at Vaquill AI: the pipelines that pull statutes, regulations and court rules from every US jurisdiction's official publisher, and the REST API, MCP server and open dataset that serve them.