July 20, 2026
illinois-biometric-information-privacy-act-amendments-and-judicial-rulings-reshape-liability-landscape-for-employers-and-corporate-compliance

The legal framework surrounding the Illinois Biometric Information Privacy Act (BIPA) has undergone a transformative shift following recent legislative amendments and a landmark appellate court ruling. Since its inception in 2008, BIPA has stood as one of the most stringent privacy laws in the United States, regulating how private entities collect, use, and store biometric identifiers such as fingerprints, facial geometry, and iris scans. For years, Illinois employers faced the prospect of "annihilative liability" due to judicial interpretations that allowed damages to accrue with every individual scan. However, the landscape has fundamentally changed with the passage of Senate Bill 2979 and the subsequent decision by the Seventh Circuit Court of Appeals in Clay v. Union Pacific, which established that recent liability-limiting amendments apply retroactively to pending litigation.

The Genesis and Evolution of BIPA

The Illinois General Assembly enacted BIPA in 2008 in response to the growing use of biometric technology in the commercial sector. The legislature recognized that unlike social security numbers or passwords, biometric identifiers are unique to the individual and cannot be changed if compromised. To mitigate the risks of identity theft and maintain consumer privacy, BIPA mandated that private entities follow a strict set of protocols.

Under the statute, companies must provide written notice to individuals that their biometric data is being collected, state the specific purpose and length of time for which the data will be used, and obtain a written release from the individual. Furthermore, entities are required to publish a publicly available retention schedule and guidelines for the permanent destruction of the data.

For the first decade of its existence, BIPA remained relatively obscure. This changed in 2019 when the Illinois Supreme Court ruled in Rosenbach v. Six Flags Entertainment Corp. that a plaintiff does not need to prove actual injury or "adverse effects" to sue. The mere technical violation of the statute’s notice and consent requirements was deemed sufficient to grant a private right of action. This opened the floodgates for class-action litigation, particularly against employers using biometric time clocks or security systems.

The Crisis of Annihilative Liability: Cothron v. White Castle

The financial stakes of BIPA compliance reached a boiling point in 2023 with the Illinois Supreme Court’s decision in Cothron v. White Castle System, Inc. In this case, a class of employees alleged that White Castle required them to scan their fingerprints to access pay stubs and computer systems without obtaining the necessary prior consent. The central legal question was whether a violation occurred only the first time a fingerprint was scanned or every time a scan occurred thereafter.

The court ruled that a separate claim accrues under BIPA each time a private entity scans or transmits an individual’s biometric data. Given that employees might scan their fingers multiple times a day over several years, the potential damages were astronomical. In the White Castle case, the projected liability was estimated to be in the hundreds of millions of dollars, a figure the court itself acknowledged could be "annihilative" to a business.

Despite the potential for economic ruin, the court maintained that it was bound by the plain language of the statute. However, the majority opinion included a rare and explicit suggestion that the Illinois General Assembly revisit the law to prevent "harsh" and "unjust" results that were likely unintended by the original drafters.

Legislative Intervention: Senate Bill 2979

Responding to the judiciary’s call for clarity and the mounting pressure from the business community, the Illinois General Assembly passed Senate Bill 2979 (SB 2979), which was signed into law and became effective on August 2, 2024. This amendment serves as the most significant revision to BIPA since its enactment.

The core of SB 2979 is a limitation on how statutory damages are calculated. The amendment specifies that for purposes of Section 15(b) (collection and capture) and Section 15(d) (disclosure and dissemination), an aggrieved person is entitled to only a single recovery of liquidated damages, even if the entity repeatedly violated the requirements with respect to that same person.

Under the revised statute:

Seventh Circuit Addresses Biometric Information Privacy Act (BIPA) Damage Accrual (US)
  • A negligent violation results in a maximum of $1,000 per person.
  • An intentional or reckless violation results in a maximum of $5,000 per person.

This change effectively ended the "per-scan" accrual model, replacing it with a "per-person" model. For a company with 1,000 employees, the difference is profound: under the old interpretation, a year of daily scans could result in billions in liability; under the amendment, the maximum exposure for negligent violations would be capped at $1 million.

Judicial Confirmation of Retroactivity: Clay v. Union Pacific

While the passage of SB 2979 provided relief for future conduct, a massive question remained: did the amendment apply to the thousands of BIPA lawsuits already working their way through the court system? On April 1, 2026, the Seventh Circuit Court of Appeals addressed this in Clay v. Union Pacific.

The court analyzed whether the per-person damage accrual amendment was "substantive" or "remedial and procedural." In legal terms, substantive changes (which create new rights or duties) generally do not apply retroactively, while procedural or remedial changes (which clarify or modify the enforcement of existing rights) often do.

The Seventh Circuit concluded that SB 2979 was remedial in nature. The court reasoned that the amendment did not take away a person’s right to sue or change the underlying legality of biometric collection; rather, it clarified the intended scope of the penalty. Consequently, the court ruled that the per-person cap applies retroactively to any cases that were pending as of the amendment’s effective date of August 2, 2024. This decision has effectively deflated the settlement value of many ongoing class actions, saving Illinois employers from potentially bankrupting judgments.

Data and Economic Impact of BIPA Litigation

The impact of BIPA on the Illinois economy has been a subject of intense debate. According to legal industry trackers, over 2,000 BIPA-related class actions have been filed in the last five years. The settlements have been substantial:

  • Facebook (Meta): Settled a BIPA class action regarding facial recognition for $650 million in 2020.
  • Google: Settled a similar suit regarding Google Photos for $100 million in 2022.
  • White Castle: Following the Supreme Court ruling, the company eventually settled for $9.39 million, a figure significantly lower than the theoretical "per-scan" maximum but still a heavy burden.

The transition to a per-person damage model is expected to stabilize the insurance market for Illinois businesses. Previously, many insurers began excluding BIPA coverage from General Liability and Employment Practices Liability Insurance (EPLI) policies due to the unpredictable and massive nature of the risk. With liability now capped at a per-person rate, actuarial modeling becomes more feasible, potentially leading to the return of affordable coverage options.

Industry Reactions and Privacy Concerns

The reaction to these legal developments has been divided. Business advocacy groups, such as the Illinois Chamber of Commerce and the Technology Network (TechNet), have lauded the changes as a victory for common sense and economic stability. They argue that the amendment protects small and medium-sized businesses that adopted biometric technology in good faith to improve security and efficiency without realizing they were triggering catastrophic liability.

Conversely, privacy advocates and the plaintiffs’ bar have expressed concern that the reduced penalties may weaken the deterrent effect of the law. Organizations like the ACLU of Illinois have historically argued that biometric data is so sensitive that only the threat of significant financial consequences will ensure that corporations treat it with the necessary care. They contend that a "one-time fee" for violating privacy might become a mere "cost of doing business" for large corporations.

Implications for Future Corporate Compliance

Despite the cap on damages, BIPA remains a potent tool for litigation, and the "per-person" penalties can still aggregate into significant sums. A company with 5,000 employees found to have intentionally violated the law could still face a $25 million judgment ($5,000 x 5,000).

Legal experts recommend that Illinois employers and any private entity operating in the state conduct a comprehensive audit of their data practices. Essential compliance steps include:

  1. Written Policies: Maintaining a public-facing biometric retention and destruction policy.
  2. Informed Consent: Ensuring that every individual (employee or consumer) signs a written release before their biometric data is captured.
  3. Vendor Management: Scrutinizing contracts with third-party vendors (such as payroll providers or security firms) that handle biometric data to ensure they are also BIPA-compliant and provide indemnification.
  4. Data Minimization: Evaluating whether the collection of biometric data is strictly necessary or if alternative, less-regulated methods of identification can be used.

Conclusion

The shift from the "per-scan" interpretation in Cothron to the "per-person" legislative cap in SB 2979, reinforced by the retroactivity ruling in Clay v. Union Pacific, marks the end of an era of extreme legal peril for Illinois businesses. While BIPA remains the most robust biometric privacy law in the nation, the recent recalibration brings the statute’s enforcement mechanism more in line with traditional notions of statutory damages. Moving forward, the focus for Illinois entities must remain on proactive compliance, as the "per-person" liability model still carries enough weight to demand rigorous adherence to privacy protocols.