HƯỚNG DẪN xã hội

Illinois BIPA, Quyền riêng tư sinh trắc học và AI

The Illinois Biometric Information Privacy Act (BIPA), passed in 2008, requires private companies to give written notice and get a written release before they collect biometric identifiers such as face geometry, fingerprints or voiceprints.

  • đọc 4 phút
  • Cập nhật lần cuối
Trên trang nàyđọc 4 phút
  1. Tổng quan
  2. Lặn sâu
  3. Tác động chiến lược
  4. The Future of Illinois BIPA, Biometric Privacy and AI
  5. Triển khai trong thế giới thực
  6. Rủi ro & lan can
  7. Lộ trình thực hiện
  8. Tiếp tục khám phá
  9. Câu hỏi thường gặp

Tổng quan

It also lets individuals sue directly for violations. That private right of action, with fixed damages per violation, has made BIPA the most litigated biometric privacy law in the United States and a real limit on how face and voice AI can be deployed.

Lặn sâu

BIPA covers "biometric identifiers", which it lists as retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry, plus "biometric information" derived from them. A private entity has five core duties. It must tell the person in writing that biometric data is being collected, why, and for how long. It must get a written release. It must publish a retention and destruction policy and destroy the data once the purpose is satisfied or within three years of the person's last interaction, whichever comes first. It must not sell, lease, trade or otherwise profit from the data. And it must limit disclosure and store the data with reasonable care. What sets BIPA apart is its private right of action. Any "aggrieved" person can sue for liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation (or actual damages if higher), plus attorneys' fees. In Rosenbach v. Six Flags (2019), the Illinois Supreme Court held that a plaintiff need not show harm beyond the violation itself. In Cothron v. White Castle (2023), it held that a new claim arises with each scan, pointing to potentially enormous damages. The legislature responded in 2024 by limiting recovery to one violation per person for each method of collection. Tims v. Black Horse Carriers (2023) set a five-year limitations period. Major resolutions include Facebook's $650 million settlement, Google's $100 million settlement over Google Photos, and TikTok's $92 million settlement. ACLU v. Clearview AI settled in 2022, with Clearview agreeing to a nationwide ban on selling its faceprint database to most private companies. The statute excludes photographs, but courts have treated face geometry extracted from photos as a biometric identifier. Texas and Washington also have biometric laws, but only their attorneys general can enforce them. Texas used its law to reach a $1.4 billion settlement with Meta in 2024.

Tác động chiến lược

Rủi ro và an toàn

Những tác hại thảm khốc và thường ngày của AI đều phụ thuộc vào việc ai hiểu được rủi ro và ai có thể hành động.

Quyết định rõ ràng hơn

Kiến thức công cộng và chuyên môn định hình liệu chính sách an toàn mạnh mẽ có khả thi về mặt chính trị hay không.

Phá vỡ sự thổi phồng

Những lời giải thích rõ ràng làm giảm sự thu hút bởi sự cường điệu, PR trong phòng thí nghiệm và sân khấu đạo đức mơ hồ.

The Future of Illinois BIPA, Biometric Privacy and AI

The 2024 amendment reduced the per-scan damages exposure that drove some of the largest claims, but damages per person are still substantial, so litigation is likely to continue. Other states have proposed BIPA-style bills with private rights of action, and most have not passed. The newer comprehensive state privacy laws usually classify biometrics as sensitive data but leave enforcement to regulators. Courts are still working through open questions, such as whether training AI on scraped face images, or detecting faces without identifying anyone, triggers the statute. Companies deploying face and voice AI in the US are likely to keep treating Illinois as the strictest baseline.

Triển khai trong thế giới thực

A retail chain testing facial recognition cameras to flag suspected shoplifters would need written notice and a written release from every shopper scanned in its Illinois stores. That is so impractical that many companies simply turn such features off in Illinois.

An employer using fingerprint or hand-scan time clocks must publish a retention schedule and get written consent from workers. Missing those steps has been the basis of many workplace class actions, including Cothron v. White Castle.

A photo service that automatically groups pictures by face creates face templates. Facebook's Tag Suggestions feature, which worked this way, led to a $650 million class settlement approved in 2021.

A company adding speaker verification or voice cloning for Illinois users has to treat voiceprints as biometric identifiers, get consent before enrollment, and delete the voice data on a published schedule.

Rủi ro & lan can

  • Xử lý rủi ro hiện hữu như khoa học viễn tưởng trong khi khả năng lại phức tạp.

  • Nhầm lẫn giữa an toàn sản phẩm bề mặt với sự liên kết dưới quyền tự chủ cao.

  • Chỉ để lại những khán giả không phải người Anh và không có chuyên môn với những nguồn chất lượng thấp.

Lộ trình thực hiện

  1. Tách biệt các tác hại của sản phẩm, sử dụng sai và rủi ro mất kiểm soát/sai lệch.

  2. Hỏi bằng chứng nào sẽ thay đổi quan điểm của bạn về thời gian và mức độ nghiêm trọng.

  3. Ưu tiên các nguồn chính và đánh giá cụ thể hơn các tuyên bố tiếp thị.

  4. Xác định một lộ trình hành động: sự nghiệp, chính sách, nguồn tài trợ hoặc kỹ năng - không chỉ là nhận thức.

Tiếp tục khám phá

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the Illinois BIPA, Biometric Privacy and AI quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Bắt đầu bài kiểm tra

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Câu hỏi thường gặp

What is Illinois BIPA, Biometric Privacy and AI?

The Illinois Biometric Information Privacy Act (BIPA), passed in 2008, requires private companies to give written notice and get a written release before they collect biometric identifiers such as face geometry, fingerprints or voiceprints. It also lets individuals sue directly for violations. That private right of action, with fixed damages per violation, has made BIPA the most litigated biometric privacy law in the United States and a real limit on how face and voice AI can be deployed.

What liquidated damages can a plaintiff recover for each intentional or reckless BIPA violation?

BIPA provides $1,000 per negligent violation and $5,000 per intentional or reckless violation, or actual damages if those are greater, plus attorneys' fees.

What did the Illinois Supreme Court hold in Rosenbach v. Six Flags (2019)?

Rosenbach held that a person whose BIPA rights were violated counts as aggrieved without showing extra injury. That made class actions much easier to bring.

The 2024 amendment limiting recovery to one violation per person per collection method was a response to which ruling?

Cothron held that a claim arises with each scan, which pointed to potentially enormous damages. The legislature amended BIPA in 2024 to limit recovery to one violation per person for each collection method.

Under BIPA, when must biometric data be destroyed?

The retention policy must provide for destruction when the original purpose is satisfied or within three years of the individual's last interaction with the entity, whichever comes first.

How do the Texas and Washington biometric laws differ most from BIPA?

Texas and Washington do not let individuals sue under their biometric laws. Enforcement belongs to the attorney general, as in Texas's $1.4 billion settlement with Meta in 2024.