Up nextNext guide
Clearview AI and Facial Recognition Privacy Cases
Society
Society GUIDE
The Illinois Biometric Information Privacy Act (BIPA), passed in 2008, requires private companies to give written notice and get a written release before they collect biometric identifiers such as face geometry, fingerprints or voiceprints.
It also lets individuals sue directly for violations. That private right of action, with fixed damages per violation, has made BIPA the most litigated biometric privacy law in the United States and a real limit on how face and voice AI can be deployed.
BIPA covers "biometric identifiers", which it lists as retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry, plus "biometric information" derived from them. A private entity has five core duties. It must tell the person in writing that biometric data is being collected, why, and for how long. It must get a written release. It must publish a retention and destruction policy and destroy the data once the purpose is satisfied or within three years of the person's last interaction, whichever comes first. It must not sell, lease, trade or otherwise profit from the data. And it must limit disclosure and store the data with reasonable care. What sets BIPA apart is its private right of action. Any "aggrieved" person can sue for liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation (or actual damages if higher), plus attorneys' fees. In Rosenbach v. Six Flags (2019), the Illinois Supreme Court held that a plaintiff need not show harm beyond the violation itself. In Cothron v. White Castle (2023), it held that a new claim arises with each scan, pointing to potentially enormous damages. The legislature responded in 2024 by limiting recovery to one violation per person for each method of collection. Tims v. Black Horse Carriers (2023) set a five-year limitations period. Major resolutions include Facebook's $650 million settlement, Google's $100 million settlement over Google Photos, and TikTok's $92 million settlement. ACLU v. Clearview AI settled in 2022, with Clearview agreeing to a nationwide ban on selling its faceprint database to most private companies. The statute excludes photographs, but courts have treated face geometry extracted from photos as a biometric identifier. Texas and Washington also have biometric laws, but only their attorneys general can enforce them. Texas used its law to reach a $1.4 billion settlement with Meta in 2024.
Catastrophic and everyday AI harms both depend on who understands the risks and who can act.
Public and professional literacy shapes whether strong safety policy is politically possible.
Clear explanations reduce capture by hype, lab PR, and vague ethics theater.
The 2024 amendment reduced the per-scan damages exposure that drove some of the largest claims, but damages per person are still substantial, so litigation is likely to continue. Other states have proposed BIPA-style bills with private rights of action, and most have not passed. The newer comprehensive state privacy laws usually classify biometrics as sensitive data but leave enforcement to regulators. Courts are still working through open questions, such as whether training AI on scraped face images, or detecting faces without identifying anyone, triggers the statute. Companies deploying face and voice AI in the US are likely to keep treating Illinois as the strictest baseline.
A retail chain testing facial recognition cameras to flag suspected shoplifters would need written notice and a written release from every shopper scanned in its Illinois stores. That is so impractical that many companies simply turn such features off in Illinois.
An employer using fingerprint or hand-scan time clocks must publish a retention schedule and get written consent from workers. Missing those steps has been the basis of many workplace class actions, including Cothron v. White Castle.
A photo service that automatically groups pictures by face creates face templates. Facebook's Tag Suggestions feature, which worked this way, led to a $650 million class settlement approved in 2021.
A company adding speaker verification or voice cloning for Illinois users has to treat voiceprints as biometric identifiers, get consent before enrollment, and delete the voice data on a published schedule.
Treating existential risk as sci-fi while capability compounds.
Confusing surface product safety with alignment under high autonomy.
Leaving non-English and non-expert audiences with only low-quality sources.
Separate product harms, misuse, and loss-of-control / misalignment risks.
Ask what evidence would change your view on timelines and severity.
Prefer primary sources and concrete evals over marketing claims.
Identify one action path: career, policy, funding, or skills — not only awareness.
Free newsletter
Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.
One email each weekday. Unsubscribe in one click. We never sell or share your address.
Test yourself
Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.
Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation
The Illinois Biometric Information Privacy Act (BIPA), passed in 2008, requires private companies to give written notice and get a written release before they collect biometric identifiers such as face geometry, fingerprints or voiceprints. It also lets individuals sue directly for violations. That private right of action, with fixed damages per violation, has made BIPA the most litigated biometric privacy law in the United States and a real limit on how face and voice AI can be deployed.
BIPA provides $1,000 per negligent violation and $5,000 per intentional or reckless violation, or actual damages if those are greater, plus attorneys' fees.
Rosenbach held that a person whose BIPA rights were violated counts as aggrieved without showing extra injury. That made class actions much easier to bring.
Cothron held that a claim arises with each scan, which pointed to potentially enormous damages. The legislature amended BIPA in 2024 to limit recovery to one violation per person for each collection method.
The retention policy must provide for destruction when the original purpose is satisfied or within three years of the individual's last interaction with the entity, whichever comes first.
Texas and Washington do not let individuals sue under their biometric laws. Enforcement belongs to the attorney general, as in Texas's $1.4 billion settlement with Meta in 2024.
Keep learning
More guides picked for this topic
Up nextNext guide
Clearview AI and Facial Recognition Privacy Cases
Society