regulatory updates
BIPA Requirements: The Five Duties and the Proof for Each
BIPA gives Illinois employers five duties, from a public retention policy to written consent before the first scan. Each duty, and what you would produce.
Key Takeaways
- •BIPA's five duties live in section 15: a public retention policy, written consent before collection, no profiting, no unauthorized disclosure, and reasonable care in storage.
- •The 2024 amendment, Public Act 103-769, capped recovery at one per person per collection method. The Seventh Circuit held it retroactive in April 2026.
- •Every duty has an artifact. If you cannot produce the notice, the release, or the retention schedule, compliance becomes your word against a complaint.
Search for BIPA requirements and the first page you get is a campaign page about defending the law. The second is the statute itself. The current pages are client alerts about the 2024 amendment. Nobody hands you the operational answer: here is what the Illinois Biometric Information Privacy Act makes your organization do, duty by duty.
I went through the statute and the recent cases and wrote that page. One warning before the list: BIPA is the only biometric law in the country that lets the person whose data you took sue you directly. That single design choice is why the settlements you have heard of came out of Illinois and nowhere else: $650 million in In re Facebook Biometric Information Privacy Litigation, No. 15-cv-03747 (N.D. Cal.), and $92 million in In re TikTok Consumer Privacy Litigation, MDL No. 2948 (N.D. Ill.).
The requirements below are not paperwork for its own sake. Each one is a thing a plaintiff's lawyer will ask you to produce, in writing, years after the fact. This is an explainer, not legal advice; have Illinois counsel verify your specific setup.
What BIPA requires, in one page
The Biometric Information Privacy Act, 740 ILCS 14, passed in 2008, regulates how private entities handle biometric identifiers: fingerprints, voiceprints, retina or iris scans, and scans of hand or face geometry. Section 15 carries the five operational duties:
- 15(a): a written retention and destruction policy, available to the public.
- 15(b): written notice and a signed release from each person, before collection.
- 15(c): no selling, leasing, or otherwise profiting from biometric data.
- 15(d): no disclosure to anyone else without consent or a legal trigger.
- 15(e): protect the data with reasonable care, at least as carefully as you protect other confidential information.
Everything else, the definitions, the exemptions, the damages, exists to serve those five. If you want the statute walked section by section, our BIPA guide does that; this page stays on what you have to do.
Who BIPA applies to, and the exemptions people get wrong
BIPA applies to any private entity operating in Illinois that collects or possesses biometric data. Employers with a fingerprint time clock, gyms with a fingerprint entry pad, retailers running face matching. It does not apply to the government itself: state and local agencies are outside the definition of private entity.
The exemptions are narrower than people assume:
- Financial institutions subject to the Gramm-Leach-Bliley Act's privacy rules are exempt, an exemption banks have but their vendors generally do not.
- Health care: information captured from a patient in a treatment setting, and data governed by HIPAA in defined circumstances, sits outside BIPA's definitions. An employee fingerprint clock at a hospital is a separate question from patient data, and the line between the two is exactly where counsel earns their fee.
- Contractors to government agencies face exemption questions of their own. If that is you, put the question to counsel, not a blog.
Being a small business is not an exemption. Neither is using a vendor: if the scanner belongs to your timekeeping provider but your employees' fingerprints flow through it for you, you are in scope.
Section 15(a): the public retention and destruction policy
The first duty exists before you scan anyone. You need a written policy, available to the public, that says how long you keep biometric data and how you destroy it. The statute sets the outer limit: destruction when the purpose for collection is satisfied, or three years after the person's last interaction with you, whichever comes first.
Two operational details get missed. The policy must be public, not an internal PDF on a shared drive; companies post it on their site or hand it out with onboarding paperwork. And the destruction rule keeps running after employees quit: a former employee whose template is still on the clock two years after termination is a live 15(a) question.
What you would produce: the dated policy, proof of where it was published, and a destruction log showing templates actually deleted on schedule. A policy with no deletion record is half a defense.
Section 15(b): informed written consent, before collection
This is the duty that generates most of the litigation, because the sequence is unforgiving. Before the first scan, the person gets written notice of what is collected, the purpose, and the storage period, and signs a written release. The statute says "first":
No private entity may collect, capture, purchase, receive through trade, or otherwise obtain a person's or a customer's biometric identifier or biometric information, unless it first: (1) informs the subject ... in writing that a biometric identifier or biometric information is being collected or stored ...
Consent collected in month three for scanning that started in month one does not cure month one. Workers notice the order of events. In one 2025 post on r/antiwork, a worker described being scanned for three months before any release form appeared, then being asked to sign one covering "past, present, and future" collection. That is the fact pattern that files well.
Since the 2024 amendment, an electronic signature counts as a written release, which removes the last excuse for skipping the step.
What you would produce: the notice text, the signed release, and timestamps proving both predate the first scan. The dates are the case.
Sections 15(c) and 15(d): no profit, no disclosure
The quieter duties. You cannot sell, lease, trade, or otherwise profit from biometric data, full stop; there is no consent form that makes a sale lawful. And you cannot disclose it without the person's consent unless a narrow trigger applies: completing a transaction the person requested, a legal requirement, or a valid warrant or subpoena.
The operational trap is vendors. Biometric templates routinely sit with a timekeeping provider, a payroll processor, and a cloud host. Disclosure to a vendor is still disclosure; your notice and release should say where the data goes, and your vendor contracts should mirror the duties you carry.
What you would produce: the data-flow map naming every system that touches a template, and contracts showing each recipient is bound.
Section 15(e): the reasonable standard of care
Store and transmit biometric data using the reasonable standard of care for your industry, and at least as protectively as you treat other confidential and sensitive information. The statute does not name encryption standards; it names a comparison. If customer payment data is encrypted and access-logged while fingerprint templates sit on an unencrypted terminal with a shared admin password, the comparison answers itself.
What you would produce: the security controls applied to biometric data specifically, shown to be at least equal to those on your other sensitive data.
What it costs to get wrong, and what the 2024 amendment changed
BIPA allows $1,000 per negligent violation and $5,000 per intentional or reckless one, plus attorney's fees. For fifteen years the open question was what counted as one violation. In Cothron v. White Castle (2023), the Illinois Supreme Court said every scan could be a separate violation, producing a potential $17 billion exposure for one fast food chain, a number the legislature then legislated away.
Public Act 103-769, effective August 2, 2024, changed the arithmetic: repeated collection from the same person by the same method is now a single violation, with at most one recovery per person. In April 2026 the Seventh Circuit held the amendment applies retroactively to pending cases, Clay v. Union Pacific Railroad Co., No. 25-2185 (7th Cir. Apr. 1, 2026). One plaintiff there had claimed roughly 1,500 scans; under the amendment, that is one recovery, not 1,500.
Read the ruling the way a claims examiner would, not the way a headline does. Per-person damages made the worst case smaller. They did not touch the duties, and a workforce of 500 unconsented enrollments is still 500 claims at up to $5,000 each, plus fees, in a class action. What changed is that your exposure is now countable, which cuts both ways: it is also countable by the plaintiff's lawyer deciding whether your case is worth filing.
Which other states have a BIPA-style law?
None have copied the private right of action, which is the feature that makes BIPA bite. Texas (CUBI) and Washington (RCW 19.375) require notice and consent, enforced by their attorneys general; Texas used CUBI to reach a $1.4 billion settlement with Meta in July 2024, announced by the Texas Attorney General as the largest privacy settlement ever obtained by a single state. Colorado's HB 24-1130 brought employee biometrics under the Colorado Privacy Act effective July 1, 2025. The biometric law tracker in the resources below keeps the current list.
If you operate in several states, building to BIPA's standard generally clears the others' bars on collection and consent.
Requirement by requirement: what you would have to produce
The pattern across all five duties is the same, and it is the reason I built Clavira: the statute is written in terms of records. Not intentions, records.
| Duty | The artifact |
|---|---|
| 15(a) retention policy | Dated public policy plus a destruction log |
| 15(b) consent | Notice text, signed release, timestamps before first scan |
| 15(c) no profit | Nothing to produce; nothing to sell in your contracts |
| 15(d) disclosure | Data-flow map and vendor agreements |
| 15(e) care | Security controls on biometric data, compared to your other sensitive data |
Run the test on your own operation this week: pick one employee enrolled on your biometric time clock and ask whether you could produce their signed release, the notice they received, and the retention schedule that covered them, with dates, by Friday. If the answer is yes, the hardest part of BIPA is behind you. If the answer is no, you now know exactly which of the five duties to start with.