Biometric Information Privacy Act
   HOME

TheInfoList



OR:

The Biometric Information Privacy Act (BIPA) is a law set forth on October 3, 2008 in the U.S. state of Illinois, in an effort to regulate the collection, use, and handling of biometric identifiers and information by private entities. Notably, the Act does not apply to government entities. While Texas and Washington are the only other states that implemented similar biometric protections, BIPA is the most stringent. The Act prescribes $1,000 per violation, and $5,000 per violation if the violation is intentional or reckless. Because of this damages provision, the BIPA has spawned several
class action A class action is a form of lawsuit. Class Action may also refer to: * ''Class Action'' (film), 1991, starring Gene Hackman and Mary Elizabeth Mastrantonio * Class Action (band), a garage house band * "Class Action" (''Teenage Robot''), a 2002 e ...
lawsuits.


Provisions

The BIPA requires companies doing business in
Illinois Illinois ( ) is a U.S. state, state in the Midwestern United States, Midwestern United States. It borders on Lake Michigan to its northeast, the Mississippi River to its west, and the Wabash River, Wabash and Ohio River, Ohio rivers to its ...
to comply with a number of requirements pertaining to the collection and storage of biometric information. These include a requirement that companies: * Obtain consent from individuals if the company intends to collect or disclose their
personal Personal may refer to: Aspects of persons' respective individualities * Privacy * Personality * Personal, personal advertisement, variety of classified advertisement used to find romance or friendship Companies * Personal, Inc., a Washington, ...
biometric identifiers. * Destroy biometric identifiers in a timely manner. * Securely store biometric identifiers. A key area of focus is that an entity must use a "reasonable standard of care" in managing biometric information and identifiers.


Standing

BIPA grants a private right of action to any individual aggrieved by a violation. However, in order to litigate a BIPA action in federal court, the aggrieved person must have federal constitutional standing otherwise known as Article III standing. Generally, Article III standing requires that a plaintiff suffer an injury to a legally protected interest that is causally connected to the defendant's conduct and such injury will likely be addressed by a court's decision.


Legislative history

Senate Bill 2400, which eventually became the Biometric Information Privacy Act, was introduced by State Senator
Terry Link Terry Link (born March 20, 1947) is an American politician who represented the 30th district in the Illinois Senate from 1997 until his resignation in 2020. The 30th district includes all or part of the municipalities of Beach Park, Illinois, Bea ...
on February 14, 2008; it passed both Houses of the Illinois General Assembly on July 10, 2008, and was approved by then-Governor
Rod Blagojevich Rod R. Blagojevich ( ; born December 10, 1956), often referred to by his nickname "Blago", is an American politician who served as the 40th governor of Illinois from 2003 to 2009. A member of the Democratic Party, Blagojevich previously worked ...
on October 3, 2008. The purpose of the Act was to establish standards of conduct for private entities that collect or possess biometric information. In 2016, Senator Link proposed and later withdrew an amendment to the Act that would have limited the Act's application to biometrics collected in public.


Proposed Federal Regulation


The National Biometric Information Privacy Act

On August 3, 2020, Senator
Jeff Merkley Jeffrey Alan Merkley (born October 24, 1956) is an American politician who is the junior United States senator from Oregon. He was first elected to the Senate in 2008. A member of the Democratic Party, he served from 1999 to 2009 as the repres ...
introduced the National Biometric Information Privacy Act of 2020 (Senate Bill 4400). While the Act contains provisions similar to BIPA it is more expansive than BIPA. If passed, the Bill would be the first of its kind to regulate biometric information on a national scale.


Notable cases

As biometric technology advances, there have been a number of lawsuits related to data collection methods, as well as various levels of protection over
data Data ( , ) are a collection of discrete or continuous values that convey information, describing the quantity, quality, fact, statistics, other basic units of meaning, or simply sequences of symbols that may be further interpreted for ...
. Using
fingerprint A fingerprint is an impression left by the friction ridges of a human finger. The recovery of partial fingerprints from a crime scene is an important method of forensic science. Moisture and grease on a finger result in fingerprints on surfa ...
s as ways of clocking in and clocking out of work is an example of a technology that fights what is known as "buddy punching" or the practice of using somebody else to clock in for another worker at a job. In Illinois, the Biometric Information Protection Act law allows people to sue employers for mishandling biometric data. According to the ''Cook County Record'', "In Illinois, both the parent company of Mariano's supermarkets and the Intercontinental Hotel Group have been hit with class action lawsuits alleging they improperly collected and stored employee fingerprints and other biometric data."


Federal court cases

''In re Facebook Biometric Info. Privacy Litig.'', 185 F. Supp. 3d 1155 (N.D. Cal. 2016) * Illinois
Facebook Facebook is a social media and social networking service owned by the American technology conglomerate Meta Platforms, Meta. Created in 2004 by Mark Zuckerberg with four other Harvard College students and roommates, Eduardo Saverin, Andre ...
users alleged that the social media platform violated the BIPA when it scanned images of their faces, without consent, in order to run its Tag Suggestions feature; a California federal court certified the class in 2018. ''Monroy v. Shutterfly, Inc.'', No. 16 C 10984, 2017 WL 4099846 (N.D. Ill. Sept. 15, 2017) *
Shutterfly Shutterfly, LLC. is an American photography, photography products, and image sharing company, headquartered in San Jose, California. The company is mainly known for custom photo printing services, including books featuring user-provided images, ...
users claimed that the company violated the BIPA when it scanned uploaded digital photos using
facial recognition software A facial recognition system is a technology potentially capable of matching a human face from a digital image or a video frame against a database of faces. Such a system is typically employed to authenticate users through ID verification ser ...
. On September 15, 2017, Northern Illinois District Court Judge Joan B. Gottschall denied a
motion to dismiss In United States law, a motion is a procedural device to bring a limited, contested issue before a court for decision. It is a request to the judge (or judges) to make a decision about the case. Motions may be made at any point in administrativ ...
the lawsuit. ''Rivera v. Google, Inc.'', 238 F. Supp. 3d 1088 (N.D. Ill. 2017) *
Google Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
users sued the company for violating the BIPA, alleging that it created and stored scans of users' faces on its
Google Photos Google Photos is a photo sharing and Cloud storage, storage service developed by Google. It was announced in May 2015 and spun off from Google+, the company's former Social networking service, social network. Google Photos shares the 15 gigab ...
service, without user consent. On February 27, 2017, Northern Illinois District Court Judge Edmond E. Chang denied a motion to dismiss the lawsuit but on December 29, 2018, the lawsuit was dismissed for lack of
standing Standing, also referred to as orthostasis, is a position in which the body is held in an upright (orthostatic) position and supported only by the feet. Although seemingly static, the body rocks slightly back and forth from the ankle in the ...
. ''McDonald v. Symphony Bronzeville Park LLC'', N.E.3d (Ill. App. Ct. Sept. 18, 2020). * A nursing home violated BIPA when it collected an employee's biometric data for time tracking purposes without disclosing or obtaining consent from the employee. The Illinois Supreme Court will determine whether the Worker's Compensation Act provides employers with a defense against BIPA claims by their employees.


State court cases

''Rosenbach v. Six Flags Entm't Corp.'', 2019 IL 123186 *
Six Flags Six Flags Entertainment Corporation is an American amusement park company headquartered in Charlotte, North Carolina, United States. It was formed on July 2, 2024, following a merger between longtime rivals Cedar Fair and the former Six Flags ...
was sued for collecting park-goers thumbprints without informed consent. The Illinois Court of Appeals ruled that a mere technical violation of the BIPA was insufficient to maintain an action, because it did not necessarily mean a party was "aggrieved," as required by the statute. This was reversed by the
Illinois Supreme Court The Supreme Court of Illinois is the state supreme court, the highest court of the judiciary of Illinois. The court's authority is granted in Article VI of the current Illinois Constitution, which provides for seven justices elected from the fiv ...
which ruled that users do not need to prove an injury (such as identity fraud or physical harm) in order to sue; the mere violation of the act was sufficient to collect damages. Additionally, an employee of the
NorthShore University HealthSystem NorthShore University HealthSystem (formerly Evanston Northwestern Healthcare or ENH) is an integrated Hospital system, healthcare delivery system serving patients throughout the Chicago metropolitan area. As of late 2021, NorthShore encompasse ...
has sued the company for allegedly collecting worker fingerprints without their consent, in violation of the Illinois Biometric Information Privacy Act. In
Cook County Circuit Court The Circuit Court of Cook County is the largest of the 25 Illinois circuit courts, circuit courts (trial courts of original jurisdiction, original and general jurisdiction) in the judiciary of Illinois as well as one of the largest unified cour ...
, the employee alleged "that the defendant scanned and digitally collected his fingerprints without consent, for use with a biometric employee punch clock."


Settlements

On December 1, 2016, the first settlement involving the BIPA was approved by a judge in
Cook County Cook County is the most populous county in the U.S. state of Illinois and the second-most-populous county in the United States, after Los Angeles County, California. More than 40 percent of all residents of Illinois live within Cook County. ...
, Illinois. The class action lawsuit was against L.A. Tan Enterprises, Inc. and settled for $1.5 million, which included between $125 and $150 for each class member who filed a claim. In February 2021, Judge James Donato approved a $650 million settlement in the federal ''In re Facebook Biometric Info. Privacy Litig.'' case, praising the settlement as "a major win for consumers in the hotly contested area of digital privacy." Two class members have appealed the settlement to the
United States Court of Appeals for the Ninth Circuit The United States Court of Appeals for the Ninth Circuit (in case citations, 9th Cir.) is the U.S. federal court of appeals that has appellate jurisdiction over the U.S. district courts for the following federal judicial districts: * Distric ...
.


Challenges

There was a bill (SB3053) pending before the Illinois legislature to amend the BIPA. The bill proposed to exempt private entities from the BIPAs requirements under a number of circumstances, including (1) if the biometric information is used "exclusively for employment, human resources, fraud prevention, or security purposes", (2) if the company "does not sell, lease, trade or similarly profit" from the biometric information, or (3) if the company protects biometric information at least as securely as it secures other sensitive information. The bill never got out of committee, and expired 2019. SB3053 was viewed by privacy advocates as an attempt to entirely gut the BIPA. It received significant opposition from many groups that advocate for digital privacy rights, including the
Electronic Frontier Foundation The Electronic Frontier Foundation (EFF) is an American international non-profit digital rights group based in San Francisco, California. It was founded in 1990 to promote Internet civil liberties. It provides funds for legal defense in court, ...
. During
Facebook Facebook is a social media and social networking service owned by the American technology conglomerate Meta Platforms, Meta. Created in 2004 by Mark Zuckerberg with four other Harvard College students and roommates, Eduardo Saverin, Andre ...
founder
Mark Zuckerberg Mark Elliot Zuckerberg (; born May 14, 1984) is an American businessman who co-founded the social media service Facebook and its parent company Meta Platforms, of which he is the chairman, chief executive officer, and controlling sharehold ...
's testimony before
Congress A congress is a formal meeting of the representatives of different countries, constituent states, organizations, trade unions, political parties, or other groups. The term originated in Late Middle English to denote an encounter (meeting of ...
on April 10, 2018, in the aftermath of Facebook's
scandal A scandal can be broadly defined as the strong social reactions of outrage, anger, or surprise, when accusations or rumours circulate or appear for some reason, regarding a person or persons who are perceived to have transgressed in some way a ...
with
Cambridge Analytica Cambridge Analytica Ltd. (CA), previously known as SCL USA, was a British political consulting firm that came to prominence through the Facebook–Cambridge Analytica data scandal. It was started in 2013, as a subsidiary of the private intell ...
, Senator
Dick Durbin Richard Joseph Durbin (born November 21, 1944) is an American lawyer and politician serving as the Seniority in the United States Senate, senior United States senator from the state of Illinois, a seat he has held since 1997. A member of the Dem ...
questioned Zuckerberg about Facebook's support for SB3053.


Related state-level bills and laws

There are a number of similar bills that have been introduced in states across the country. These include: * Michigan, 2017 Bill Text MI H.B. 5019 * New Hampshire, 2017 Bill Text NH H.B. 523 (amended and passed in 2018 as NH H.B. 523) * Alaska, 2017 Bill Text AK H.B. 72 * Montana, 2017 Bill Text MT H.B. 518 *New York, 2021 Assembly Bill 27 & Senate Bill 1933.


Foreign equivalents

On May 25, 2018, the EU effectuated the General Data Protection Regulation (
GDPR The General Data Protection Regulation (Regulation (EU) 2016/679), abbreviated GDPR, is a European Union regulation on information privacy in the European Union (EU) and the European Economic Area (EEA). The GDPR is an important component of ...
), one of the world's strongest data protection regulations to date.


References


External links

* {{ILCS, 740, 14, title=Biometric Information Privacy Act Computing legislation Illinois statutes 2008 in American law