Illinois AI Biometric Law 2026: What Business Owners Must Do

Illinois AI Biometric Law 2026: What Business Owners Must Do

Last Updated: July 2026

Illinois BIPA is a state law. It stands for the Biometric Info Privacy Act. The law sets strict rules for any firm that uses body data through AI tools. This includes fingerprints, facial scans, retina patterns, and voiceprints. You must get written consent before you capture any biometric data. You must also post a clear data policy. It must say how long data is kept and when it is deleted. Each breach of these rules brings a fine.

AI Smart Ventures has helped hundreds of growing businesses with AI compliance. This includes BIPA rules that come up with time-tracking, safety, and HR tools. Many owners only learn about these rules after an audit flags a tool as non-compliant. Acting early protects your money and your workers’ trust.

More AI tools now include biometric features as standard parts. Facial scans for access control are now common. So are fingerprint scanners for time clocks and voice tools for internal systems. Business owners in Illinois face a clear choice. You can audit your tech stack now or risk a class-action suit later. The sections below break down what BIPA requires. They also show how to build a compliant workflow.

Key Takeaways

  1. Written consent is mandatory. BIPA requires you to get signed consent from each person. Get this before you collect any biometric data. A verbal deal or buried clause in a standard contract does not satisfy the law.
  2. Fines apply per incident. Initial violations start at $1,000 each. Intentional or reckless violations rise to $5,000 per incident. Repeated non-compliance is extremely costly.
  3. Third-party tools do not transfer liability. Your vendor may collect biometric data on your behalf. But your business still carries the legal burden for consent and notice.
  4. A written retention policy is required. BIPA requires a posted schedule. It must say how long data is held and when it is deleted for good.
  5. Private lawsuits are allowed. Unlike many privacy laws, BIPA lets people sue directly. They do not need to wait for a government agency. This raises lawsuit risk for business owners.

Many growing businesses assume general IT safety practices satisfy BIPA. They do not. The sections below walk through the specific duties, fines, and steps. Every Illinois business owner should take these in 2026.

What Is Illinois BIPA?

The Illinois Biometric Info Privacy Act is the country’s most enforced biometric privacy law. It governs how private firms handle unique body data. This data cannot be changed if stolen. Fingerprints, facial geometry, iris scans, retina patterns, and voiceprints are all covered.

The law requires three steps before you collect any biometric data. First, give written notice. Second, state why you are collecting data and for how long. Third, get a signed release from each person. Without all three steps, the collection itself is a breach.

BIPA also requires firms to post a written data schedule. It must state when data will be deleted. Data must be removed when the original reason ends. Or it must be deleted within three years of the person’s last contact with your firm. Whichever comes first applies. Courts have found that even automated data capture triggers BIPA rules. Review every system you use. That includes HR tools, time records, and safety checkpoints.

How Does BIPA Apply to AI Tools?

Modern AI tools trigger BIPA when they capture, read, or store body traits. They use those traits to find people. Many features look like simple tools. But auto-attendance and frictionless entry collect biometric data in the background.

A platform does not need to be labeled a biometric system. BIPA still applies. If the software reads a facial scan or maps a fingerprint, BIPA applies. The same is true if it learns a voiceprint. It does not matter how the vendor labels the feature.

Common examples in 2026 include AI time clocks that scan fingerprints or palms. Safety cameras with facial detection also apply. So do voice tools for internal systems and platforms that read facial expressions. When your vendor stores biometric data off-site, confirm their data handling meets BIPA rules. Vendor contracts should name storage locations, access controls, and deletion dates.

Which Businesses Must Follow BIPA?

BIPA applies to any private firm in Illinois. This includes those that collect, buy, receive, or profit from biometric data. The law does not set a minimum worker count or revenue limit. A firm with five workers has the same duty as a large one. Size does not change what the law requires.

The law also covers firms based outside Illinois. It applies if they collect data from Illinois residents or workers. Industries with high risk include construction, healthcare, retail, and logistics. These fields often use fingerprints or facial scans for time tracking and access. But no sector is fully exempt. Law firms, marketing agencies, and service firms also fall under the law. This includes any firm using voice tools or visitor systems with facial detection. The EEOC has issued AI guidance for hiring that applies when AI tools are used in your workforce.

Assume BIPA applies to every tool that touches a person’s body data. Then check vendor documents to confirm compliance.

What Does BIPA Require from Owners?

BIPA gives business owners four clear duties. All must be done before you collect any biometric data. First, give each person written notice. Explain what data will be collected and why. Second, state how long the data will be stored and when it will be deleted. Third, get a written or electronic signature as proof of consent. Fourth, post a biometric data schedule. It must match the timelines you shared with each person.

These steps must happen before data collection starts. Doing them after the fact does not fix a breach under BIPA case law. Firms must also make sure biometric data is never sold, leased, or traded. Sharing data with a third party needs separate written consent from each person. Limited exceptions exist for financial transactions or when the law requires it. Keep organized records of all consent forms. Good records help defend any future claim.

Building a BIPA plan takes clear policies and trained staff. You also need the right legal documents. Have all of this ready before you launch any new AI tool. If your current setup is missing these pieces, a workflow review can help. It will find the gaps and stop costly exposure before it starts.

If you need support building a compliance-ready AI strategy, AI Smart Ventures gives AI Consulting for growing businesses facing rules like BIPA. Schedule a consultation to review your current tools and create a defensible compliance plan.

What Are the Penalties for Violations?

BIPA fines apply per person, per violation. This makes the money risk high, even for small teams. Courts treat each act as a separate violation. That includes each capture, storage, or transfer of biometric data without consent. For careless violations, the law allows a $1,000 fine per incident or actual damages, whichever is greater. For violations done on purpose or recklessly, that amount rises to $5,000 per incident, plus attorney fees.

The real risk booster is the private right of action. BIPA lets any Illinois resident file a lawsuit. They can do this alone or as part of a class action. They do not need to prove actual harm. Showing that a firm collected biometric data without consent is enough to sue. Class-action settlements in major BIPA cases have reached hundreds of millions of dollars. One bad time-clock setup can create huge legal risk. This can happen if it collected data from many workers for months without consent forms.

The FTC has issued guidance on AI and deceptive practices that matters when AI tools make false claims about how they use data. Business owners should review both sets of rules when checking new tools.

How Do You Build a BIPA Compliance Plan?

A BIPA compliance plan starts with a full audit of your tech tools. Find every tool that touches biometric data. List all systems used for time tracking, door access, and hiring. Include visitor and safety systems too. For each tool, get vendor documents. Confirm whether the system collects biometric data. If it does, check the vendor’s data handling. Look at storage locations, encryption, and deletion steps.

Next, create or update your compliance documents. Draft a written notice explaining what data is collected and why. Also state when it will be deleted. Build a consent form for workers and other data subjects. They must sign it before their data is captured. Post a storage schedule on your internal hub or website. Train all staff who use biometric systems on the consent step. Set automated workflows to delete data on your posted schedule. Review every vendor contract that involves biometric data. Make sure it includes data protection clauses.

As global rules expand, the EU AI Act shows where biometric rules are heading worldwide. Building strong BIPA practices now puts you ahead of future rules.

How Do You Vet AI Vendors for BIPA?

Vetting AI vendors for BIPA starts with asking direct questions before signing any contract. Request a written statement from the vendor. Ask whether their platform collects, stores, or sends any biometric data. Ask for their data storage and deletion policy. Make sure the timelines match what BIPA requires. Verify that they use encryption for stored biometric data. Check that they have access controls to stop not-allowed viewing or sharing.

Review the vendor’s sub-vendor list. Find any third parties that also handle biometric data on their behalf. Each link in that chain must meet BIPA standards. Insist on contract language that bars the sale or transfer of biometric data. No sharing should happen without proper sign-off. Vendors who will not give written answers to these questions are a risk. Choose vendors who publish BIPA compliance documents. This cuts work for your team. It also strengthens your legal position if a claim is filed.

A vertical compliance checklist titled "BIPA Compliance Steps for Business Owners" with seven numbered rows, each showing a checkbox icon and a short action label: 1. Find all AI tools that collect biometric data; 2. Draft written notice describing what is collected and why; 3. Obtain signed consent before any data collection begins; 4. Publish a written retention and destruction policy; 5. Review vendor contracts for biometric data clauses; 6. Set automated deletion triggers matching BIPA timelines; 7. Train staff on consent procedures and data handling rules. Design uses navy blue headers, teal checkbox icons, white card background, and clean sans-serif typography in an expert enterprise style.

Frequently Asked Questions

Does BIPA apply to out-of-state businesses?

Yes. BIPA applies to any firm that collects biometric data from Illinois residents or workers. It does not matter where the firm is based. If your business employs Illinois residents or serves Illinois customers using biometric tools, the law covers you. Where your office is located does not create an exception. Many out-of-state firms have faced BIPA lawsuits. Their tools captured data from Illinois residents without proper notice or consent.

What counts as a biometric identifier under BIPA?

BIPA defines biometric identifiers as fingerprints, voiceprints, retina scans, iris scans, and facial geometry. Biometric info includes any data from these identifiers that can be used to find a specific person. Photos, writing samples, and general basic info are typically excluded. The exception is when they are processed to extract a biometric identifier. The key test is simple. Can the data find a person by a body trait that cannot be reissued if stolen?

Does written consent have to be on paper?

No. BIPA allows electronic consent in addition to paper signatures. Consent must be a separate, informed, and intentional act. It must happen before any data collection begins. Courts have found buried consent clauses in standard agreements are not enough. The consent form must clearly describe what data will be collected and why. It must also say how long data will be stored and when it will be deleted.

Are healthcare providers exempt from BIPA?

Partially. BIPA exempts biometric data collected for healthcare treatment, payment, and operations under HIPAA. But this exception is narrow. It applies only to that specific healthcare context. A healthcare employer using a fingerprint time clock for payroll is not exempt. Being a healthcare provider does not mean every data use is exempt. What matters is the purpose of the data collection. Your industry does not decide whether the HIPAA carve-out applies.

Can an employee waive BIPA rights for good?

No. BIPA consent cannot be waived for good or indefinitely. Each data collection event tied to a new purpose needs separate consent. If your business changes how it uses biometric data, you need fresh consent. The same applies if you hire a new vendor or use data for a new purpose. A one-time signature during hiring does not cover all future uses. New collection purposes need new consent.

What happens if we delete data but lacked consent at collection?

Deleting data after the fact does not remove BIPA risk for past breaches. Courts have found that the breach occurs at the moment of collection without proper consent. Deleting data later can help limit ongoing harm. But it does not remove the right to sue for the original breach. If you find past consent gaps, talk to a lawyer right away. Assess your risk and build a fix plan before any claim is filed.

How long must biometric data be retained under BIPA?

BIPA does not set a minimum storage period. It sets a maximum. Biometric data must be deleted within the earlier of two events. The first trigger is when the initial reason for collection ends. The second is three years after the person’s last contact with the firm. A written storage schedule must document these timelines and be made public. Many businesses set up automated deletion triggers in their HR or safety platforms to meet these deadlines.

How can I get help navigating BIPA for my business?

AI Smart Ventures supports growing businesses in auditing their AI tools and building compliance-ready workflows. The first step is finding which tools trigger BIPA rules. Then we create the documents, consent steps, and vendor protocols to meet the law. Schedule a consultation to get a clear picture of your current compliance status and a step-by-step plan to close any gaps before they become costly violations.

Executive Summary

Illinois BIPA is the country’s most litigated biometric privacy law. It covers growing businesses of every size. This includes any that use AI tools for time tracking, safety, or HR. The law requires written notice and signed consent before you collect any data. You also need a posted storage schedule with clear deletion dates. Fines reach $5,000 per intentional violation. The private right of action allows class-action suits without proof of actual harm. Business owners must audit every AI tool, vet vendors, and build formal consent steps. Do all of this before those tools go live.

What Should You Do Next?

Start by listing every AI tool your business uses. Include tools for door access, worker time records, or identity checks. For each tool, confirm whether it collects biometric data. Then compare your current consent forms against BIPA’s written notice rules. Build a written storage and deletion plan for each system. Do this before you add any new tools.

AI Smart Ventures offers AI Consulting for growing businesses that need a clear approach to AI compliance. Schedule a consultation to get a compliance-focused review of your current AI tools and a clear roadmap for meeting BIPA needs.

People Also Read

About the Author

Nicole A. Donnelly is the Founder of AI Smart Ventures and an AI Adoption Specialist with 20 years of history as a founder and CEO and over a decade leading AI adoption plans. She helps businesses connect AI with clarity and confidence, driving innovation and lasting growth. Nicole has trained over 20,217 experts in Applied AI, delivered 624 workshops, and worked with close to 1,000 businesses across diverse industries.

Expertise: AI Transformation, AI Strategy, AI Rollout, AI Adoption, Applied AI, Marketing, Business Operations

Connect: LinkedIn | Website

Disclaimer: This content is for informational purposes only and does not constitute expert business or tech advice. Results vary based on industry, current systems and rollout commitment. Contact AI Smart Ventures for a consultation about your specific situation.