Back to the hub

Illinois BIPA: does it apply to you and what does it require?

Illinois's Biometric Information Privacy Act (BIPA), 740 ILCS 14, applies to any private entity that collects a biometric identifier such as a fingerprint, face or hand scan, or voiceprint. It sets no revenue or size threshold, requires written notice and consent before collection, and lets individuals sue for statutory damages.

Applies to: Any private entity that collects, captures, or obtains a biometric identifier (fingerprint, face or hand scan, iris scan, or voiceprint) or biometric information from an Illinois resident; there is no revenue, consumer-count, or small-business threshold.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Illinois is the state that turned biometric compliance into a board-level worry. Its Biometric Information Privacy Act, known as BIPA, is the oldest and strictest biometric law in the country, and it is the only one that lets ordinary people sue you directly. If you scan a fingerprint, a face, or a voiceprint and touch anyone in Illinois, the size of your company does not get you out of it.

Who does Illinois BIPA cover?

BIPA (740 ILCS 14) applies to any private entity that collects, captures, purchases, or otherwise obtains a person's biometric identifier or biometric information. A biometric identifier means a retina or iris scan, a fingerprint, a voiceprint, or a scan of hand or face geometry, under 740 ILCS 14/10. There is no revenue floor, no consumer-count trigger, and no small-business exemption. State and local government agencies and Illinois courts sit outside the law, but private companies of any size are in scope the moment biometric data passes through their systems. Photographs, writing samples, and health-care information collected under HIPAA are expressly excluded from the definition.

What must you do before collecting biometric data?

Section 15(b) sets a strict front-end rule. Before you collect a biometric identifier you must inform the person in writing that you are collecting or storing it, tell them in writing the specific purpose and the length of term for which you will keep and use it, and obtain a written release. A 2024 amendment, Public Act 103-769, effective August 2, 2024, confirmed that a written release can be an electronic signature. Consent obtained after the fact does not fix a collection that already happened, so the notice and release have to be in place first.

How long can you keep biometric data, and can you share it?

Section 15(a) requires a written, publicly available retention policy. You must destroy biometric identifiers when the initial purpose is satisfied or within three years of the person's last interaction with you, whichever comes first. Section 15(c) bars you from selling, leasing, trading, or otherwise profiting from the data. Section 15(d) bars disclosure without the person's consent, unless the disclosure completes a financial transaction they authorized, is required by law, or is compelled by a valid warrant. Section 15(e) requires you to protect the data with the reasonable standard of care in your industry, at least as protective as the way you treat your other confidential information.

Why BIPA carries more risk than Texas or Washington

The teeth are in Section 20. A person aggrieved by a violation can sue in state court, or as a supplemental claim in federal court, and recover liquidated damages of $1,000 for a negligent violation or $5,000 for an intentional or reckless one, or actual damages if greater, plus reasonable attorneys' fees and costs. That private right of action is what sets Illinois apart. The Texas biometric law and Washington's statute leave enforcement to the attorney general, so individuals there cannot sue. A 2024 amendment added Sections 20(b) and 20(c), which treat repeated collections or disclosures of the same identifier from the same person by the same method as a single violation, but the per-person damages remain significant. Our biometric privacy laws by state page shows how the four dedicated regimes compare.

Next step

If you use fingerprint time clocks, face recognition, or voiceprints and touch anyone in Illinois, the free 2-minute Obligation Scan checks whether BIPA applies and lists the notice, written-release, retention, and destruction steps you owe, so a missing consent form does not turn into a class action. The US state privacy laws hub shows how data-type triggers like BIPA sit alongside the comprehensive state laws.

Compliance checklist

  • Map every point where you collect a biometric identifier (fingerprint, face or hand geometry, iris scan, or voiceprint) from Illinois residents.
  • Before collection, give written notice of the fact, the specific purpose, and the length of term, then obtain a written release; an electronic signature counts after the 2024 amendment.
  • Publish a written retention schedule and destroy biometric data when the purpose is met or within 3 years of the person's last interaction, whichever comes first.
  • Do not sell, lease, trade, or otherwise profit from biometric identifiers, and do not disclose them without consent or another Section 15(d) basis.
  • Store biometric data with the reasonable standard of care in your industry, at least as protective as your other confidential information.

Sources

Last verified: 2026-07-31

Informational, not legal advice.