Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
cite 740 ILCS 14/1, 14/5, 14/10, 14/15, 14/25 (P.A. 95-994, eff. 2008-10-03, as amended by P.A. 103-0769, eff. 2024-08-02)
stage In effect
since 2008-10-03
source Illinois Compiled Statutes, official code site (current codified text with per-section source notes)
Requires a private entity to give written notice of the purpose and length of collection, storage and use, and to obtain a written release, before capturing a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry; a 2024 amendment recognizes an electronic signature as a valid release.
Bars selling, leasing, trading, or profiting from biometric data, limits disclosure to consent, a subject-requested transaction, or legal process, and requires a public written retention schedule that destroys the data within 3 years of the individual's last interaction or when the collection purpose is satisfied, whichever is first.
The Act excludes photographs, writing samples, and similar raw items from the definition of biometric identifier, but not an identifier such as a face-geometry scan that is itself enumerated, even when computed from an otherwise excluded item; no controlling appellate holding on that specific application was found in this pass.
What it asks of an app →
Breach notification
cite 815 ILCS 530/1 et seq. (P.A. 94-36, eff. 2006-01-01)
stage In effect
since 2006-01-01
source Illinois Compiled Statutes, official code site (current codified text)
Requires a data collector, government agency or private entity, holding computerized personal information of Illinois residents to notify affected residents of a security breach in the most expedient time possible and without unreasonable delay.
Personal information expressly includes unique biometric data used to authenticate an individual, such as a fingerprint, retina or iris image, or other physical or digital biometric representation, alongside a name paired with a Social Security number, account number, or medical information.
A data collector must notify the Illinois Attorney General once a single breach affects more than 500 Illinois residents, and a State agency must do so above 250 residents; a violation is an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act.
What it asks of an app →
Enforcement supervision
cite 740 ILCS 14/20, as amended by P.A. 103-0769 (SB 2979), eff. 2024-08-02
stage In effect
since 2024-08-02
source Illinois Compiled Statutes official code site and Illinois General Assembly, Public Act 103-0769 (enrolled act)
Arms any person aggrieved by a BIPA violation with a private right of action in state circuit court or as a supplemental federal claim, recovering the greater of $1,000 or actual damages for a negligent violation and the greater of $5,000 or actual damages for an intentional or reckless violation, plus attorneys' fees, costs, and injunctive relief.
The Illinois Supreme Court held a claim accrues with each scan or disclosure (Cothron v. White Castle, 2023) under one uniform five-year limitations period for every Section 15 claim (Tims v. Black Horse Carriers, 2023); a 2024 amendment then capped recovery at one award per person per collection or disclosure method, responding directly to Cothron's invitation to the legislature to revisit the resulting damages exposure.
The Seventh Circuit held in 2026 that the cap is a remedial change to available damages, not a substantive change to BIPA's liability standard, so it applies retroactively to cases already pending when the amendment took effect (Clay v. Union Pacific Railroad Co., 2026).
What it asks of an app →