What It Is

BIPA is an Illinois statute that sets conditions on every stage of the biometric data lifecycle: notice before collection, written consent, retention limits, security safeguards, and destruction deadlines.

Its enforcement mechanism is what sets it apart. An aggrieved person can recover $1,000 per negligent violation or $5,000 per intentional or reckless violation - or actual damages, whichever is greater (§20). The Illinois Supreme Court held in Rosenbach v. Six Flags (2019) that a person need not prove actual harm to sue - a violation of the statute's requirements is enough.

An August 2024 amendment (P.A. 103-769) recalibrated the damages math: when the same biometric identifier is collected from the same person by the same method repeatedly, that counts as at most one recoverable violation, not one per scan. The amendment also confirmed that an electronic signature satisfies the written-consent requirement.

The exposure is still serious. Per-person, per-method damages across a workforce or customer base scale quickly - the arithmetic is just per person now, not per scan.

What Information Is Regulated

BIPA regulates two defined categories (§10).

Biometric identifiers - the statute's exact list:

  • Retina or iris scans
  • Fingerprints
  • Voiceprints
  • Scans of hand geometry
  • Scans of face geometry (the basis of facial recognition)

Biometric information: any information, however captured or stored, based on a biometric identifier and used to identify an individual.

Common real-world examples: fingerprint or hand-geometry time clocks, facial recognition for building access, voice authentication systems, and biometric features embedded in HR, security, or customer-facing applications.

IT Requirements

From an IT and cybersecurity perspective, BIPA compliance turns on governance, consent, security, and lifecycle management of biometric data. The statute requires private entities to:

1. Provide written notice. Before collection, individuals must be told what is collected, why, and how long it will be kept (§15(b)).

2. Obtain a written release. Explicit written consent before collection. Since the 2024 amendment, an electronic signature satisfies this requirement - which makes properly built digital consent workflows fully defensible.

3. Publish a retention and destruction policy. A written, publicly available schedule. Destruction is due when the initial purpose is satisfied or within 3 years of the individual's last interaction with the entity - whichever comes first (§15(a)). "When no longer needed" is not the standard; the 3-year cap is a hard deadline.

4. Secure biometric data. Using the reasonable standard of care for your industry, and at least as protectively as other confidential information: strong access controls, encryption, secure storage, logging and monitoring, and least-privilege access.

5. Never sell, and rarely disclose. Selling, leasing, trading, or otherwise profiting from biometric data is prohibited outright - no exceptions (§15(c)). Disclosure is separately restricted to narrow cases: consent, completing a transaction the person requested, legal requirement, or court order (§15(d)).

Where IT makes or breaks compliance

Most BIPA violations are not caused by hackers. They come from missing documentation, unclear consent, poor retention practices, or unsecured biometric systems. Key IT responsibilities: identifying where biometric data exists across systems, securing biometric databases and integrations, enforcing access control and MFA, monitoring access and usage, supporting audit trails, executing secure deletion on the statutory schedule, and managing every third-party vendor that touches biometric data.

How It Fits Into Cyber Risk Management

BIPA is often misread as a purely legal problem. Compliance actually fails or succeeds in IT systems - which makes it a governance problem with a technical core.

Governance, Risk & Compliance keeps the notice, consent, and retention documentation aligned with what systems actually do - the gap where most BIPA claims are born. Cyber Risk Management secures the biometric systems themselves, and Third-Party Assessments reach the timeclock vendors and biometric platforms processing data on your behalf.

If your environment cannot demonstrate these controls, BIPA exposure rises with every enrolled fingerprint.

How We Help With BIPA Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment locates every system touching biometric data, then tests your notice, consent, retention, and security posture against BIPA's Section 15 requirements.

How to Prepare

  1. Identify biometric data in your environment

    Document the systems collecting biometric data, the data types, where the data is stored, who has access, and which vendors are involved. Timeclocks, door controllers, and authentication features hide in plain sight.

  2. Review consent and policies

    Confirm written (or electronic-signature) consent is properly collected and stored, retention and destruction policies exist and are followed, and the policies match actual system behavior - including the 3-year destruction cap.

  3. Secure biometric systems

    Implement or validate encryption at rest and in transit, role-based access controls, MFA for administrative access, logging and monitoring, and secure deletion that actually executes on schedule.

  4. Assess vendor risk

    Confirm third-party providers meet BIPA's security requirements, never reuse or resell biometric data, and are contractually obligated to comply. The sale prohibition has no exceptions - your vendors need to know that.

  5. Train staff

    Employees handling biometric data should understand the consent requirements, data handling restrictions, security best practices, and incident reporting procedures.

Official source

Official source: Illinois General Assembly - 740 ILCS 14

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25