Back to the hub

Does each biometric scan count as a separate BIPA violation?

Yes. In Cothron v. White Castle (2023 IL 128004) the Illinois Supreme Court held that a separate BIPA claim accrues each time a private entity scans or transmits a person's biometric identifier without consent, rather than only at the first scan. A 2024 amendment later limited repeated same-method collection to a single recovery.

Applies to: Private entities that collect biometric identifiers such as fingerprints, face or hand geometry, retina or iris scans, or voiceprints from people in Illinois, and anyone assessing BIPA class-action exposure from repeated scans.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

The Illinois Biometric Information Privacy Act carries the harshest damages of any US biometric law, and a 2023 decision made the math far worse for companies that scan fingerprints or faces. The question was simple to ask and expensive to answer: when you scan the same employee's fingerprint every shift without consent, is that one violation or thousands?

What did the Illinois Supreme Court hold in Cothron?

In Cothron v. White Castle System, Inc., 2023 IL 128004, the court answered a question certified by the Seventh Circuit. White Castle required employees to scan a fingerprint to reach their pay stubs and workstations and had not obtained consent for years. The court held, 4 to 3, that a separate claim accrues under the Act each time a private entity scans or transmits a person's biometric identifier in violation of Section 15(b) or 15(d). A claim is not limited to the first scan. Because BIPA sets damages per violation, repeated scans can compound into very large exposure, a point the majority acknowledged while leaving any change to the legislature.

How the 2024 amendment changed the damages math

The legislature responded. Public Act 103-769, effective August 2, 2024, added subsections (b) and (c) to Section 20 of BIPA. Under the amendment, when a private entity more than once collects or discloses the same biometric identifier from the same person using the same method, that counts as a single violation, and the person is entitled to at most one recovery. The amendment narrows the multiplier that Cothron created, but only for that specific repeated, same-method pattern. It does not erase per-scan accrual for distinct methods or distinct identifiers, and the underlying damages figures are unchanged.

What per-scan liability means for your business

The damages are set by Section 20 of BIPA: $1,000 or actual damages for a negligent violation, and $5,000 or actual damages for an intentional or reckless one, plus attorneys' fees. Multiply even the lower figure across a workforce scanning in daily and the number climbs quickly, which is why consent before the first scan matters so much. The biometric laws by state overview shows how Illinois compares with Texas and Washington, and the statute of limitations page explains the five-year window for bringing a claim.

Next step

If your business captures fingerprints, face geometry, or other biometrics from people in Illinois, the free 2-minute Obligation Scan flags whether your consent, notice, and retention practices meet BIPA before a class action tests them. The US state privacy laws hub covers the wider set of obligations.

Compliance checklist

  • Get written consent before the first biometric scan, because BIPA Section 15(b) requires written notice and a signed release before you collect.
  • Assume liability can attach to every scan, since Cothron holds a separate claim accrues each time you scan or transmit without consent.
  • Do not treat the 2024 cap as a fix: Public Act 103-769 limits repeated same-method collection to one recovery, but a negligent violation is still $1,000 and an intentional or reckless one $5,000.
  • Publish a written retention and destruction policy and delete biometric data by the statutory deadline, because gaps here drive class actions.
  • Track your limitations exposure, as BIPA claims carry a five-year statute of limitations under Tims v. Black Horse Carriers.

Sources

Last verified: 2026-08-06

Informational, not legal advice.