The Illinois Biometric Information Privacy Act, more commonly known as BIPA, has long stood as the most stringent biometric data protection statute in the United States, creating a complex legal environment for employers and private entities operating within the state. Enacted in 2008, the law was designed to provide a robust framework for the collection, use, and storage of sensitive biological identifiers, such as fingerprints, facial geometry, iris scans, and voiceprints. However, the interpretation of the law’s penalty provisions has undergone a dramatic transformation over the last several years. Following a period of intense litigation that threatened many businesses with "annihilative liability," recent legislative amendments and a landmark 2026 appellate court ruling have finally provided a measure of clarity and relief for the Illinois business community. This evolution marks a significant pivot from a "per-scan" damage model to a more sustainable "per-person" model, fundamentally altering the risk assessment for any organization handling biometric data in Illinois.
The Foundation of Biometric Protection in Illinois
The inception of BIPA in 2008 was a response to the growing prevalence of biometric technology in everyday commerce. Unlike social security numbers or home addresses, biometric identifiers are unique to the individual and cannot be changed if compromised. The Illinois General Assembly recognized that once a person’s biometric data is leaked, they have no recourse to "change" their fingerprint or retina, leaving them permanently vulnerable to identity theft.
Under the original statute, private entities are prohibited from collecting or capturing biometric data unless they first inform the subject in writing that the information is being collected and stored. Furthermore, the entity must state the specific purpose and length of time for which the data will be used and receive a written release from the individual. The law also mandates that companies develop a publicly available written policy establishing a retention schedule and guidelines for permanently destroying the data once the initial purpose has been served.
The legal landscape shifted significantly in 2019 when the Illinois Supreme Court ruled in Rosenbach v. Six Flags Entertainment Corp. that a plaintiff does not need to prove an actual injury or "adverse effect" beyond a violation of their rights under BIPA to seek liquidated damages. This opened the floodgates for class-action litigation, as any technical failure to provide notice or obtain a signature became a potentially multi-million-dollar liability.
The Crisis of Annihilative Liability: Cothron v. White Castle
The tension between privacy advocates and the business community reached a breaking point with the case of Cothron v. White Castle System, Inc. in 2023. In this case, a class of employees alleged that the fast-food giant required them to scan their fingerprints to access pay stubs and computer systems without obtaining the requisite statutory consent for over a decade.
The central legal question was whether a BIPA violation occurred only the first time a fingerprint was scanned without consent, or whether every subsequent scan constituted a fresh violation. The Illinois Supreme Court, adhering to a strict "plain language" interpretation of the statute, ruled that a separate claim accrued each and every time a private entity scanned or transmitted an individual’s biometric data.
The financial implications of this ruling were staggering. For a company like White Castle, with nearly 10,000 employees scanning their fingers multiple times a day over several years, the theoretical damages were estimated to exceed $17 billion. While the court acknowledged that such "annihilative liability" could potentially bankrupt even the most stable companies, it maintained that it was the role of the legislature, not the judiciary, to adjust the statutory language if the results were deemed too harsh. This case eventually led to a $9.39 million settlement, but it served as a wake-up call to the Illinois General Assembly.
Legislative Intervention: The Passage of Senate Bill 2979
In direct response to the Cothron decision and the outcry from the Illinois Chamber of Commerce and various industry groups, the Illinois General Assembly passed Senate Bill 2979 (SB 2979). Signed into law and effective as of August 2, 2024, this amendment represented the first major legislative overhaul of BIPA since its creation.
The core of SB 2979 is the limitation of liquidated damages. The amendment clarifies that an aggrieved person is entitled to only a single recovery of liquidated damages for a violation of the notice and consent requirements, regardless of how many times the entity scanned or transmitted that person’s biometric identifier. Under the new framework, if an employer fails to get a written release and then scans an employee’s finger 1,000 times over a year, that employee is entitled to one set of damages (either $1,000 for a negligent violation or $5,000 for an intentional/reckless violation), rather than 1,000 sets of damages.
This legislative shift effectively neutralized the threat of "per-scan" accrual, bringing the potential liability for businesses back into the realm of the manageable. However, a major question remained: would this amendment apply only to new cases filed after August 2024, or would it apply retroactively to the thousands of cases already clogging the court system?
Judicial Confirmation and Retroactivity: Clay v. Union Pacific
The final piece of the current BIPA puzzle was placed on April 1, 2026, by the Seventh Circuit Court of Appeals in the case of Clay v. Union Pacific. The court was tasked with determining whether the SB 2979 amendments were substantive changes to the law or merely procedural and remedial clarifications.

The Seventh Circuit ruled that the amendment was indeed remedial and procedural in nature. Because the legislature intended to clarify the original intent of the damages provision and address the unintended consequence of "annihilative liability," the court held that the per-person damage cap applies retroactively. This means that for any BIPA lawsuit that was pending on August 2, 2024, or filed thereafter, the damages must be calculated on a per-person basis, regardless of when the actual data collection occurred.
This ruling provided immediate relief to hundreds of companies facing legacy litigation. By capping the potential payout at a single penalty per individual, the court significantly reduced the settlement value of pending class actions, potentially saving the Illinois economy billions of dollars in projected litigation costs.
Chronology of Key BIPA Milestones
To understand the current state of biometric law in Illinois, it is essential to view the timeline of its evolution:
- October 2008: The Biometric Information Privacy Act (BIPA) is signed into law, establishing the first comprehensive biometric regulatory framework in the U.S.
- January 2019: The Illinois Supreme Court rules in Rosenbach v. Six Flags that "actual harm" is not required to sue; a procedural violation is sufficient.
- February 2023: The Illinois Supreme Court rules in Cothron v. White Castle that claims accrue with every single scan, creating the "per-scan" damage model.
- August 2, 2024: Senate Bill 2979 becomes effective, amending BIPA to limit damages to a "per-person" basis.
- April 1, 2026: The Seventh Circuit Court of Appeals decides Clay v. Union Pacific, confirming that the per-person amendment applies retroactively to pending cases.
Supporting Data and Economic Impact
The impact of BIPA litigation on the Illinois business environment has been profound. Between 2017 and 2023, more than 2,000 BIPA-related class-action lawsuits were filed in Illinois courts. Before the 2024 amendment, the "per-scan" model created a high-stakes environment where even small businesses faced potential bankruptcy.
Data from legal analysts suggests that the average BIPA settlement for a mid-sized company ranged from $1 million to $5 million between 2020 and 2023. With the shift to the "per-person" model, experts project that while the number of filings may remain steady in the short term, the total settlement values will decrease by an estimated 60% to 80% for cases involving frequent daily scans.
For example, a company with 500 employees that would have faced a theoretical $500 million liability under the Cothron interpretation (assuming multiple scans per day over five years) now faces a maximum statutory exposure of $500,000 (at $1,000 per person) or $2.5 million (if the violation is proven to be intentional or reckless).
Stakeholder Perspectives: Privacy vs. Commerce
The legislative and judicial shifts have drawn mixed reactions from various stakeholders.
Privacy Advocates: Groups such as the ACLU of Illinois have expressed concern that the reduction in penalties might diminish the deterrent effect of the law. They argue that biometrics are the most sensitive form of personal data and that the "per-scan" model provided a necessary incentive for companies to prioritize data security. From their perspective, the retroactive application of the amendment unfairly strips away the potential recovery for individuals whose privacy rights were repeatedly violated over many years.
Business Organizations: The Illinois Retail Merchants Association and the Illinois Manufacturers’ Association have lauded the 2024 amendment and the 2026 Clay decision. They argue that the previous "per-scan" interpretation was a "litigation trap" that did nothing to improve actual data security but instead enriched trial lawyers at the expense of local businesses and economic growth. They contend that the per-person model still provides a significant penalty for non-compliance while ensuring that a single administrative error does not result in the destruction of a company.
Compliance Mandates for Illinois Employers
Despite the reduction in potential damages, BIPA remains a high-risk statute. Employers and private entities must still adhere to a strict set of compliance protocols to avoid the $1,000 to $5,000 per-person penalties. Current best practices for compliance include:
- Comprehensive Audits: Companies must identify every point of biometric data collection, including time clocks, security doors, and software logins.
- Written Policies: Organizations must maintain a written, publicly available policy that outlines the retention schedule and the protocol for the permanent destruction of biometric identifiers.
- Informed Consent: Before any data is collected, the entity must provide a clear written notice and obtain a signed "written release" from the individual.
- Vendor Management: If a third-party vendor (such as a payroll provider or security firm) handles the data, the employer must ensure the vendor is also BIPA-compliant, as the employer can often be held liable for the vendor’s failures.
- Prohibition on Profiling: BIPA strictly prohibits the sale, lease, trade, or profiting from an individual’s biometric data under any circumstances.
Broader Impact and Future Implications
The developments in Illinois are being closely watched by legislators in other states. As of 2026, several other states, including Texas and Washington, have implemented biometric privacy laws, though none are as litigious as Illinois due to their lack of a broad private right of action. However, the "Illinois model" of legislative correction—moving from per-scan to per-person—is expected to serve as a blueprint for future biometric regulations at both the state and federal levels.
The 2026 Clay v. Union Pacific decision provides a necessary "reset" for the Illinois judiciary, allowing courts to clear a backlog of cases that were previously stuck in settlement negotiations over astronomical damage figures. While the "gold standard" of biometric privacy remains in place in Illinois, the law has transitioned from a potential "company-killer" to a more standard regulatory framework. For employers, the message is clear: while the threat of "annihilative liability" has receded, the requirement for strict procedural compliance is as mandatory as ever. Organizations that fail to respect the biological boundaries of their employees and consumers will still find themselves facing significant, and now clearly defined, legal consequences.
