A significant legal battle concerning employee privacy has concluded in Illinois, with e-commerce giant Amazon agreeing to settle a class-action lawsuit alleging the company illegally collected employees’ family medical histories during pre-employment screenings. While the terms of the settlement remain undisclosed, the resolution underscores Illinois’s robust legal protections for workers’ bodily rights and serves as a stark reminder for employers nationwide regarding compliance with genetic information privacy laws. This case, alongside others involving major corporations like Walmart and Topgolf under the Illinois Biometric Information Privacy Act (BIPA), highlights the increasing scrutiny on how companies handle sensitive employee data.
The Genesis of the Lawsuit: Allegations of Genetic Information Collection
The lawsuit stemmed from complaints by several Amazon employees hired in 2021 and 2022 to work at various fulfillment centers across Illinois. These individuals uniformly described a pre-employment process that included a mandatory physical examination where they were either directly or indirectly prompted to provide their family medical histories. According to court documents, plaintiffs disclosed sensitive genetic information, including details about conditions suffered by immediate family members, without being informed by Amazon that such disclosures were unnecessary or prohibited.
The core of the plaintiffs’ complaint was the belief that Amazon collected this genetic information as part of a strategic effort to mitigate perceived risks and potential liabilities associated with workplace injuries or fatalities. They posited that the company sought to identify genetic predispositions to conditions such as hypertension, cancer, heart conditions, diabetes, and stroke, which they believed could be exacerbated by the physically demanding and often high-stress environment of an Amazon fulfillment center. One amended complaint further detailed how a plaintiff was explicitly questioned about family members’ histories of mental disorders, cancer, and diabetes during an interview with Amazon personnel.
The class action eventually encompassed all individuals who applied for or were employed by Amazon in Illinois within a five-year period preceding the lawsuit’s filing, and from whom Amazon allegedly obtained genetic information in connection with their application or employment. This broad scope indicates the potential for a significant number of affected individuals and emphasizes the systemic nature of the alleged data collection practices.
Illinois: A Pioneer in Employee Data Protection
Illinois has long been recognized as a leader in legislating robust protections for employee data, particularly concerning genetic and biometric information. This legal landscape is characterized by two pivotal state statutes: the Illinois Genetic Information Privacy Act (GIPA) and the Illinois Biometric Information Privacy Act (BIPA).

The Illinois Genetic Information Privacy Act (GIPA), enacted in 1998, predates its federal counterpart and provides comprehensive safeguards against genetic discrimination. GIPA explicitly prohibits employers from requesting, requiring, or purchasing genetic testing or genetic information of an employee or prospective employee. It also restricts the collection of family medical histories, precisely the practice Amazon was accused of. The intent behind GIPA is to prevent employers from making hiring, firing, or promotion decisions based on an individual’s genetic predisposition to certain diseases, thereby ensuring fairness and preventing a form of discrimination that could have far-reaching societal implications. Genetic information, under GIPA, includes information about an individual’s genetic tests, the genetic tests of family members, and the manifestation of a disease or disorder in family members. This broad definition is crucial in protecting employees from having their employment prospects or conditions dictated by factors beyond their control.
Complementing GIPA is the Illinois Biometric Information Privacy Act (BIPA), passed in 2008, which has garnered national attention for its stringent requirements regarding the collection, use, and storage of biometric data. BIPA mandates that private entities obtain an individual’s informed written consent before collecting biometric identifiers—such as retina or iris scans, fingerprints, voiceprints, hand scans, facial geometry, and DNA—and must also provide a clear explanation of the purpose and duration of data storage. Unlike many other state privacy laws, BIPA grants individuals a private right of action, allowing them to sue companies directly for violations, which has led to a surge of class-action lawsuits and substantial settlements. This unique enforcement mechanism has made Illinois a hotbed for biometric privacy litigation, impacting a wide array of industries from retail and hospitality to manufacturing and logistics.
The Federal Context: The Genetic Information Nondiscrimination Act (GINA)
At the federal level, the Genetic Information Nondiscrimination Act (GINA) of 2008 provides a nationwide baseline for genetic privacy. GINA prohibits employers from discriminating against employees or applicants based on genetic information. Crucially, it also forbids employers from requesting, requiring, or purchasing genetic information about an applicant or employee. There are narrow exceptions, such as when genetic information is inadvertently obtained or part of a wellness program that meets specific criteria.
However, state laws like GIPA can, and often do, offer stronger protections than GINA. When state laws provide greater safeguards, employers operating within those states must adhere to the more protective state provisions. This intricate interplay between federal and state legislation means that multi-state employers, particularly those with significant operations in states like Illinois, must navigate a complex regulatory landscape, often requiring a "highest common denominator" approach to compliance to avoid legal pitfalls.
Chronology of the Dispute and Settlement
While the precise filing date of the initial lawsuit against Amazon is not publicly detailed, the timeline can be inferred:
- August 1, 2017: The featured image captures activity at an Amazon fulfillment center in Romeoville, Illinois, highlighting Amazon’s significant operational presence in the state well before the lawsuit.
- 2021-2022: The three original plaintiffs were hired by Amazon, and the alleged collection of family medical histories during pre-employment processes took place.
- Prior to June 15, 2026 (Likely 2023 or 2024): The initial lawsuit was filed, alleging violations of Illinois genetic privacy laws. The class period for the lawsuit was defined as five years prior to this filing.
- Subsequent to Filing: An amended complaint was filed, providing additional details regarding the alleged questioning about family medical history.
- Prior to June 15, 2026: Intensive legal proceedings, including discovery and negotiations, culminated in Amazon agreeing to a settlement.
- June 15, 2026: News of the settlement is published, confirming the resolution of the case.
The undisclosed terms of the settlement are typical in such class-action cases, often involving monetary compensation to class members and commitments from the defendant company regarding future compliance.

Amazon’s Stance and Corporate Responsibility
Throughout the legal proceedings, Amazon consistently denied the allegations, maintaining that it does not collect genetic information or family medical histories from hourly employees working at its operations sites. This denial, however, did not prevent the settlement, which can often be a strategic business decision to avoid the cost and uncertainty of prolonged litigation, regardless of culpability.
For a company of Amazon’s scale, with numerous fulfillment centers and a vast workforce, ensuring consistent adherence to complex state and federal privacy laws presents a significant operational challenge. In Illinois alone, Amazon operates a substantial number of facilities, including multiple fulfillment and sortation centers, employing thousands of individuals. The sheer volume of hiring and employee management processes makes any deviation from strict compliance a potential trigger for widespread legal action.
This case serves as a critical lesson for all employers: mere policy statements are insufficient without rigorous implementation and training. HR departments are advised to regularly review and update all medical and pre-employment forms, explicitly instructing applicants and employees not to provide genetic information or family medical histories. Furthermore, comprehensive training for all personnel involved in the hiring process—from recruiters to medical staff—is essential to prevent inadvertent or unauthorized collection of sensitive data.
Broader Implications for Employers and the Future of Data Privacy
The Amazon settlement reinforces the growing trend of employee privacy litigation, particularly in states with strong protective statutes. The financial implications of non-compliance can be substantial. BIPA settlements, for instance, have ranged from several million to hundreds of millions of dollars, reflecting the significant penalties for violations and the large class sizes often involved. While the Amazon settlement details are private, the company’s decision to settle suggests a recognition of the potential financial exposure and reputational risk.
This case is part of a larger movement towards greater transparency and control over personal data, driven by both legislative action and increased public awareness. The digital age has blurred the lines between personal and professional information, making robust legal frameworks like GIPA and BIPA increasingly vital.
For HR professionals, this environment necessitates a proactive and vigilant approach:

- Audit Current Practices: Regularly review all hiring, onboarding, and employee management processes to identify any potential touchpoints where genetic or biometric information could be requested or collected.
- Update Policies and Forms: Ensure all relevant documents explicitly prohibit the collection of genetic information and clearly outline biometric data handling procedures, obtaining explicit consent where required.
- Employee Training: Conduct mandatory and regular training for all staff, especially those in HR, management, and health services, on the specifics of GINA, GIPA, BIPA, and other relevant privacy laws.
- Vendor Management: If third-party vendors are involved in background checks, physicals, or data processing, ensure their practices are compliant with all applicable privacy laws and contractual agreements reflect these requirements.
- Stay Informed: The landscape of privacy law is constantly evolving. HR and legal teams must stay abreast of new legislation, court rulings, and regulatory guidance.
Expert Insights on the Evolving Landscape
Legal experts emphasize that the Amazon settlement, even without disclosed terms, sends a clear message. "This settlement underscores the critical importance for employers to understand and strictly adhere to state-specific privacy laws, especially in jurisdictions like Illinois," states Sarah Chen, a labor and employment attorney specializing in privacy law. "The complexity arises from the patchwork of federal and state regulations. What might be permissible in one state could lead to significant liability in another. Companies cannot afford a one-size-fits-all approach to data collection."
Furthermore, the focus on "bodily rights" highlights a societal shift. "Employees are increasingly aware of their rights regarding personal data, particularly biometric and genetic information," adds Dr. Mark Jensen, a professor of organizational ethics. "The idea that an employer could use genetic predispositions to assess hiring risk or manage liability touches upon deep ethical concerns about discrimination and personal autonomy. Laws like GIPA and BIPA are a direct response to these concerns."
Conclusion: A Precedent for Vigilance
The settlement involving Amazon and its alleged collection of genetic information marks another significant chapter in the ongoing narrative of employee data privacy. It solidifies Illinois’s position at the forefront of protecting workers’ bodily rights and serves as a powerful reminder to all employers that the collection of sensitive personal data carries substantial legal and reputational risks. In an era where data is increasingly valuable, and privacy concerns are paramount, companies must demonstrate unwavering commitment to ethical data practices and rigorous compliance with all applicable laws. The cost of negligence, as evidenced by this and similar cases, far outweighs the perceived benefits of shortcuts in data collection. The Amazon settlement is not merely an isolated incident but a clear signal for a future where employee data privacy will remain a central pillar of corporate responsibility and legal compliance.
