Does BIPA require a written biometric data retention policy?
Under 740 ILCS 14/15(a), any private entity holding biometric identifiers or information must develop a written, publicly available policy setting a retention schedule and destruction guidelines. It must destroy the data once the collection purpose is met or within three years of the person's last interaction, whichever comes first.
Applies to: Any private entity in possession of biometric identifiers or biometric information under Illinois's BIPA; the Section 15(a) written-policy and destruction duty applies regardless of company size.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
Most BIPA attention goes to the notice and consent steps before you collect a fingerprint or a face scan. The retention policy is the duty that gets skipped, and it is the one you owe even after you have stopped collecting. Section 15(a) asks for a written policy, out in public, that says how long you keep biometric data and when you destroy it. Not having one is its own problem.
What does Section 15(a) require?
A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, establishing a retention schedule and guidelines for permanently destroying that data. The trigger for destruction is fixed: when the initial purpose for collecting the data has been satisfied, or within three years of the individual's last interaction with the entity, whichever occurs first. This is not a suggestion to keep data "as long as needed." It is a hard outer limit with a public commitment attached.
When must biometric data be destroyed?
Run both clocks and use whichever expires sooner. If you scanned a fingerprint to enroll someone in a time clock and they leave, the purpose ends and the data should go. Even if the purpose somehow persists, three years after the person's last interaction is the ceiling. Absent a valid warrant or subpoena issued by a court of competent jurisdiction, the entity must comply with its own established retention schedule and destruction guidelines, so the policy you publish becomes the standard you are held to.
Is a missing policy its own violation?
Yes. Section 15(a) stands apart from the Section 15(b) consent steps, so a company can satisfy consent and still breach the statute by never publishing a retention policy. Under Section 20 a person aggrieved by a violation has a right of action, and the liquidated-damages figures attach to violations of the Act. Because the duty to keep a public policy is treated as owed to the public, the cleanest position is to have written, posted, and followed the policy before collection begins.
How the policy fits the rest of BIPA
The retention policy is one of three duties that travel together. You need the written notice and release before collection under Section 15(b), the Section 15(a) policy and destruction schedule here, and the storage-and-care duty in Section 15(e). Getting one right and skipping another still leaves exposure, because each is separately enforceable, and per-violation damages are what make BIPA the state law with a real price tag.
Next step
If you capture fingerprints, faces, or voiceprints from anyone in Illinois, the free 2-minute Obligation Scan checks whether BIPA applies and lists the notice, release, retention, and destruction steps you owe, so the policy is written before a demand arrives rather than after. The US state privacy laws hub shows how Illinois's private right of action compares with attorney-general-only states.
Compliance checklist
- Develop a written retention-and-destruction policy for biometric identifiers and biometric information as defined in 740 ILCS 14/10.
- Make the policy available to the public, not just internal to the company.
- Set a retention schedule and destruction guidelines tied to the initial collection purpose or three years from the person's last interaction, whichever comes first.
- Actually destroy the data on that schedule, absent a valid warrant or subpoena, and keep records that you did.
- Pair the policy with the Section 15(b) written-notice and release steps, because the retention duty does not replace the consent duty.
Sources
- 740 ILCS 14/15 (Retention; collection; disclosure; destruction), Biometric Information Privacy Act, Illinois General Assembly
- 740 ILCS 14/20 (Right of action), Biometric Information Privacy Act, Illinois General Assembly
Last verified: 2026-08-11
Informational, not legal advice.