Federal Case Could Define Biometric Identifier Scope Under Illinois BIPA
A Chicago federal court case may set a precedent on biometric identifier definitions under BIPA.
Why it matters: The decision could influence numerous pending BIPA lawsuits and help legal teams assess claim viability, shaping risk and compliance approaches for companies handling biometric data.
- Illinois' BIPA defines biometric identifiers as retina, iris, fingerprints, voiceprints, or scans of hand or face geometry.
- A federal court in Zellmer v. Facebook ruled face geometry scans aren't BIPA-covered if they can't identify individuals.
- The Illinois legislature amended BIPA effective August 2, 2024, clarifying repeated identical biometric data collections count as one violation.
- The Seventh Circuit says BIPA doesn't apply when biometric data stays on a user's device or when companies only supply software that processes data locally.
The Illinois Biometric Information Privacy Act (BIPA) has emerged as a cornerstone of privacy law, imposing strict rules on the collection and storage of biometric data such as retina scans, fingerprints, and face geometry.
A crucial issue currently before a federal court in Chicago is whether a biometric identifier must be capable of identifying a specific person for a plaintiff to have a valid BIPA claim. This case could provide definitive guidance on how broadly or narrowly BIPA is applied.
In a notable earlier ruling in Zellmer v. Facebook, the court held that face geometry scans do not qualify as biometric identifiers under BIPA if they cannot identify individuals. This decision limits BIPA’s reach concerning certain biometric technologies.
Moreover, the Illinois legislature recently amended BIPA effective August 2, 2024, specifying that multiple collections or disclosures of the same biometric identifier via the same method are treated as a single violation, potentially reducing litigation exposure for repeat uses of the same data point.
The Seventh Circuit has also weighed in, holding that BIPA does not apply to biometric data that remains solely on a user’s device. Thus, companies supplying software that processes biometric data locally do not “possess” or “collect” such data under the statute, further narrowing liability.
As the volume of BIPA litigation remains high, this pending Chicago federal court ruling is closely watched. Its outcome will help litigators determine which claims can proceed and inform companies’ compliance strategies under Illinois’ biometric privacy regime.
By the numbers:
- $1,000 — statutory damages for each negligent BIPA violation
- $5,000 — statutory damages for intentional or reckless BIPA violations
- August 2, 2024 — effective date of Illinois' BIPA amendment clarifying single violation treatment
Yes, but: While BIPA is powerful, courts have limited its scope in key ways, such as excluding non-identifying biometric data and data that remains on user devices.
What's next: The pending federal court decision in Chicago is expected soon; it may establish new precedent on biometric identifier definitions under BIPA, affecting pending and future lawsuits.