PRŮVODCE společností

Illinois BIPA, Biometric Privacy and AI

The Illinois Biometric Information Privacy Act (BIPA), passed in 2008, requires private companies to give written notice and get a written release before they collect biometric identifiers such as face geometry, fingerprints or voiceprints.

  • 4 min čtení
  • Naposledy aktualizováno
Na této stránce4 min čtení
  1. Přehled
  2. Hluboký ponor
  3. Strategický dopad
  4. The Future of Illinois BIPA, Biometric Privacy and AI
  5. Real-World Implementace
  6. Rizika a zábradlí
  7. Plán implementace
  8. Pokračujte v objevování
  9. Často kladené otázky

Přehled

It also lets individuals sue directly for violations. That private right of action, with fixed damages per violation, has made BIPA the most litigated biometric privacy law in the United States and a real limit on how face and voice AI can be deployed.

Hluboký ponor

BIPA covers "biometric identifiers", which it lists as retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry, plus "biometric information" derived from them. A private entity has five core duties. It must tell the person in writing that biometric data is being collected, why, and for how long. It must get a written release. It must publish a retention and destruction policy and destroy the data once the purpose is satisfied or within three years of the person's last interaction, whichever comes first. It must not sell, lease, trade or otherwise profit from the data. And it must limit disclosure and store the data with reasonable care. What sets BIPA apart is its private right of action. Any "aggrieved" person can sue for liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation (or actual damages if higher), plus attorneys' fees. In Rosenbach v. Six Flags (2019), the Illinois Supreme Court held that a plaintiff need not show harm beyond the violation itself. In Cothron v. White Castle (2023), it held that a new claim arises with each scan, pointing to potentially enormous damages. The legislature responded in 2024 by limiting recovery to one violation per person for each method of collection. Tims v. Black Horse Carriers (2023) set a five-year limitations period. Major resolutions include Facebook's $650 million settlement, Google's $100 million settlement over Google Photos, and TikTok's $92 million settlement. ACLU v. Clearview AI settled in 2022, with Clearview agreeing to a nationwide ban on selling its faceprint database to most private companies. The statute excludes photographs, but courts have treated face geometry extracted from photos as a biometric identifier. Texas and Washington also have biometric laws, but only their attorneys general can enforce them. Texas used its law to reach a $1.4 billion settlement with Meta in 2024.

Strategický dopad

Riziko a bezpečnost

Katastrofické a každodenní škody AI závisí na tom, kdo rozumí rizikům a kdo může jednat.

Jasnější rozhodnutí

Veřejná a odborná gramotnost určuje, zda je silná bezpečnostní politika politicky možná.

Prorážením humbuku

Jasná vysvětlení snižují zachytávání humbukem, PR v laboratoři a vágní etické divadlo.

The Future of Illinois BIPA, Biometric Privacy and AI

The 2024 amendment reduced the per-scan damages exposure that drove some of the largest claims, but damages per person are still substantial, so litigation is likely to continue. Other states have proposed BIPA-style bills with private rights of action, and most have not passed. The newer comprehensive state privacy laws usually classify biometrics as sensitive data but leave enforcement to regulators. Courts are still working through open questions, such as whether training AI on scraped face images, or detecting faces without identifying anyone, triggers the statute. Companies deploying face and voice AI in the US are likely to keep treating Illinois as the strictest baseline.

Real-World Implementace

A retail chain testing facial recognition cameras to flag suspected shoplifters would need written notice and a written release from every shopper scanned in its Illinois stores. That is so impractical that many companies simply turn such features off in Illinois.

An employer using fingerprint or hand-scan time clocks must publish a retention schedule and get written consent from workers. Missing those steps has been the basis of many workplace class actions, including Cothron v. White Castle.

A photo service that automatically groups pictures by face creates face templates. Facebook's Tag Suggestions feature, which worked this way, led to a $650 million class settlement approved in 2021.

A company adding speaker verification or voice cloning for Illinois users has to treat voiceprints as biometric identifiers, get consent before enrollment, and delete the voice data on a published schedule.

Rizika a zábradlí

  • Zacházení s existenčním rizikem jako sci-fi, zatímco schopnosti kombinují.

  • Matoucí bezpečnost povrchových produktů se zarovnáním pod vysokou autonomií.

  • Neanglické a neodborné publikum ponechává pouze nekvalitní zdroje.

Plán implementace

  1. Oddělte rizika poškození produktu, nesprávného použití a ztráty kontroly/nesouladu.

  2. Zeptejte se, jaké důkazy by změnily váš pohled na časové osy a závažnost.

  3. Upřednostňujte primární zdroje a konkrétní hodnocení před marketingovými tvrzeními.

  4. Identifikujte jednu akční cestu: kariéru, politiku, financování nebo dovednosti – nejen povědomí.

Pokračujte v objevování

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the Illinois BIPA, Biometric Privacy and AI quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Spustit kvíz

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Často kladené otázky

What is Illinois BIPA, Biometric Privacy and AI?

The Illinois Biometric Information Privacy Act (BIPA), passed in 2008, requires private companies to give written notice and get a written release before they collect biometric identifiers such as face geometry, fingerprints or voiceprints. It also lets individuals sue directly for violations. That private right of action, with fixed damages per violation, has made BIPA the most litigated biometric privacy law in the United States and a real limit on how face and voice AI can be deployed.

What liquidated damages can a plaintiff recover for each intentional or reckless BIPA violation?

BIPA provides $1,000 per negligent violation and $5,000 per intentional or reckless violation, or actual damages if those are greater, plus attorneys' fees.

What did the Illinois Supreme Court hold in Rosenbach v. Six Flags (2019)?

Rosenbach held that a person whose BIPA rights were violated counts as aggrieved without showing extra injury. That made class actions much easier to bring.

The 2024 amendment limiting recovery to one violation per person per collection method was a response to which ruling?

Cothron held that a claim arises with each scan, which pointed to potentially enormous damages. The legislature amended BIPA in 2024 to limit recovery to one violation per person for each collection method.

Under BIPA, when must biometric data be destroyed?

The retention policy must provide for destruction when the original purpose is satisfied or within three years of the individual's last interaction with the entity, whichever comes first.

How do the Texas and Washington biometric laws differ most from BIPA?

Texas and Washington do not let individuals sue under their biometric laws. Enforcement belongs to the attorney general, as in Texas's $1.4 billion settlement with Meta in 2024.