Gids voor de samenleving

Illinois BIPA, Biometric Privacy and AI

The Illinois Biometric Information Privacy Act (BIPA), passed in 2008, requires private companies to give written notice and get a written release before they collect biometric identifiers such as face geometry, fingerprints or voiceprints.

  • 4 minuten lezen
  • Laatst bijgewerkt
Op deze pagina4 minuten lezen
  1. Overzicht
  2. Diepe duik
  3. Strategische impact
  4. The Future of Illinois BIPA, Biometric Privacy and AI
  5. Implementatie in de echte wereld
  6. Risico's en vangrails
  7. Implementatie routekaart
  8. Blijf verkennen
  9. Veelgestelde vragen

Overzicht

It also lets individuals sue directly for violations. That private right of action, with fixed damages per violation, has made BIPA the most litigated biometric privacy law in the United States and a real limit on how face and voice AI can be deployed.

Diepe duik

BIPA covers "biometric identifiers", which it lists as retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry, plus "biometric information" derived from them. A private entity has five core duties. It must tell the person in writing that biometric data is being collected, why, and for how long. It must get a written release. It must publish a retention and destruction policy and destroy the data once the purpose is satisfied or within three years of the person's last interaction, whichever comes first. It must not sell, lease, trade or otherwise profit from the data. And it must limit disclosure and store the data with reasonable care. What sets BIPA apart is its private right of action. Any "aggrieved" person can sue for liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation (or actual damages if higher), plus attorneys' fees. In Rosenbach v. Six Flags (2019), the Illinois Supreme Court held that a plaintiff need not show harm beyond the violation itself. In Cothron v. White Castle (2023), it held that a new claim arises with each scan, pointing to potentially enormous damages. The legislature responded in 2024 by limiting recovery to one violation per person for each method of collection. Tims v. Black Horse Carriers (2023) set a five-year limitations period. Major resolutions include Facebook's $650 million settlement, Google's $100 million settlement over Google Photos, and TikTok's $92 million settlement. ACLU v. Clearview AI settled in 2022, with Clearview agreeing to a nationwide ban on selling its faceprint database to most private companies. The statute excludes photographs, but courts have treated face geometry extracted from photos as a biometric identifier. Texas and Washington also have biometric laws, but only their attorneys general can enforce them. Texas used its law to reach a $1.4 billion settlement with Meta in 2024.

Strategische impact

Risico en veiligheid

Catastrofale en alledaagse schade door AI hangt af van wie de risico's begrijpt en wie kan handelen.

Duidelijkere beslissingen

Publieke en professionele geletterdheid bepalen of een krachtig veiligheidsbeleid politiek mogelijk is.

Door de hype heen snijden

Duidelijke verklaringen verminderen de kans op hypes, laboratorium-PR en vaag ethisch theater.

The Future of Illinois BIPA, Biometric Privacy and AI

The 2024 amendment reduced the per-scan damages exposure that drove some of the largest claims, but damages per person are still substantial, so litigation is likely to continue. Other states have proposed BIPA-style bills with private rights of action, and most have not passed. The newer comprehensive state privacy laws usually classify biometrics as sensitive data but leave enforcement to regulators. Courts are still working through open questions, such as whether training AI on scraped face images, or detecting faces without identifying anyone, triggers the statute. Companies deploying face and voice AI in the US are likely to keep treating Illinois as the strictest baseline.

Implementatie in de echte wereld

A retail chain testing facial recognition cameras to flag suspected shoplifters would need written notice and a written release from every shopper scanned in its Illinois stores. That is so impractical that many companies simply turn such features off in Illinois.

An employer using fingerprint or hand-scan time clocks must publish a retention schedule and get written consent from workers. Missing those steps has been the basis of many workplace class actions, including Cothron v. White Castle.

A photo service that automatically groups pictures by face creates face templates. Facebook's Tag Suggestions feature, which worked this way, led to a $650 million class settlement approved in 2021.

A company adding speaker verification or voice cloning for Illinois users has to treat voiceprints as biometric identifiers, get consent before enrollment, and delete the voice data on a published schedule.

Risico's en vangrails

  • Existentieel risico behandelen als sciencefiction, terwijl capaciteiten zich vermenigvuldigen.

  • De veiligheid van oppervlakteproducten verwarren met uitlijning onder hoge autonomie.

  • Hierdoor blijven niet-Engelstalige en niet-deskundige doelgroepen alleen bronnen van lage kwaliteit over.

Implementatie routekaart

  1. Afzonderlijke risico's voor productschade, misbruik en verlies van controle/verkeerde uitlijning.

  2. Vraag welk bewijs uw kijk op tijdlijnen en ernst zou veranderen.

  3. Geef de voorkeur aan primaire bronnen en concrete evaluaties boven marketingclaims.

  4. Identificeer één actiepad: carrière, beleid, financiering of vaardigheden – niet alleen bewustwording.

Blijf verkennen

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the Illinois BIPA, Biometric Privacy and AI quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Quiz starten

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Veelgestelde vragen

What is Illinois BIPA, Biometric Privacy and AI?

The Illinois Biometric Information Privacy Act (BIPA), passed in 2008, requires private companies to give written notice and get a written release before they collect biometric identifiers such as face geometry, fingerprints or voiceprints. It also lets individuals sue directly for violations. That private right of action, with fixed damages per violation, has made BIPA the most litigated biometric privacy law in the United States and a real limit on how face and voice AI can be deployed.

What liquidated damages can a plaintiff recover for each intentional or reckless BIPA violation?

BIPA provides $1,000 per negligent violation and $5,000 per intentional or reckless violation, or actual damages if those are greater, plus attorneys' fees.

What did the Illinois Supreme Court hold in Rosenbach v. Six Flags (2019)?

Rosenbach held that a person whose BIPA rights were violated counts as aggrieved without showing extra injury. That made class actions much easier to bring.

The 2024 amendment limiting recovery to one violation per person per collection method was a response to which ruling?

Cothron held that a claim arises with each scan, which pointed to potentially enormous damages. The legislature amended BIPA in 2024 to limit recovery to one violation per person for each collection method.

Under BIPA, when must biometric data be destroyed?

The retention policy must provide for destruction when the original purpose is satisfied or within three years of the individual's last interaction with the entity, whichever comes first.

How do the Texas and Washington biometric laws differ most from BIPA?

Texas and Washington do not let individuals sue under their biometric laws. Enforcement belongs to the attorney general, as in Texas's $1.4 billion settlement with Meta in 2024.