News
Litigator David Morrison is quoted in "Liability Reduced for Companies Facing Biometric Data Privacy Violations," published in the Aug. 22, 2024, edition of Legal Dive.
The article concerns the amendment to the Illinois Biometric Information Privacy Act that was signed by Illinois Gov. J.B. Pritzker on August 2, 2024. As a result, the author writes: "Illinois employers facing big penalties for improperly collecting biometric data on employees and consumers can relax some now that aggressively sought changes to the state’s biometric privacy law have been enacted, reducing companies’ liability risk."
The Illinois biometric privacy statute, enacted in 2008, is considered a pioneering law for its effort to protect consumers and employees from company misuse of data taken from people’s faces, fingerprints, voiceprints, retina scans and other types of personally identifiable imaging.
The law came under fire after companies were hit with large fines. For example, in 2021 Meta paid $650 million to settle a class action lawsuit alleging its Facebook app violated the law. In similar lawsuits around that time, Google agreed to pay $100 million, TikTok $92 million and Snapchat $35 million.
At the core of the fines was language calling for $1,000 per violation for each negligent violation and $5,000 for each reckless or intentional violation. That language became even more crucial following a 2023 court ruling in Cothron v. White Castle Systems that interpreted the statute in a way that drastically increased potential penalties. The company ended up settling the case for $9.4 million.
According to David Morrison, that case was the first time the state’s Supreme Court interpreted the law to permit an individual to claim a damages award for every time that a scanner collected their biometric data.
BIPA's new language makes clear that a private entity that more than once collects or discloses a person’s biometric identifier or biometric information without consent isn’t liable for each incident. Rather, it’s liable for each person, so it’s considered a single violation and the aggrieved person is entitled to, at most, one recovery. That change is effective immediately.
In another change, BIPA’s definition of “written release” is amended to include electronic signatures. This is considered another consequential change because it reduces the chance a company will fail to get the consent it needs to collect the data lawfully.
Despite the improvements, David said that more could be done to protect companies. Since non-compliance with the statute imposes strict liability, it would be helpful to have a safe harbor enacted for companies that have collected biometric information but failed to get the proper release, he said.
The safe harbor would protect those who haven’t experienced a breach and for which there has been no harm to consumers and employees.
Such a measure would be supportive of the business community and protect small businesses, said David. The measure would also protect businesses where the timing and capture of the permission is off by a day or so.
CLICK HERE to read the full article.

