Glossary

DEFINITION

BIPA (Biometric Information Privacy Act)

Illinois' 2008 law requiring informed written consent before collecting biometric data — the most-litigated AI-adjacent privacy statute in the United States, with statutory damages of $1,000–$5,000 per violation.

In depth

The Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14) was enacted in 2008, long before generative AI was mainstream, but has become the dominant litigation vehicle for AI-related privacy claims in the United States. BIPA regulates 'biometric identifiers' — retina or iris scans, fingerprints, voiceprints, hand geometry, facial geometry — and 'biometric information' derived from them. It requires: written notice before collection, written consent from the subject, a publicly available written policy on retention and destruction, prohibition on sale or profit from biometric data, and reasonable security measures. BIPA's most consequential feature is its private right of action with statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation, with no cap and class-action eligibility. The Illinois Supreme Court held in Cothron v. White Castle (2023) that each scan is a separate violation. AI systems that collect face prints (video interview AI, access control with facial recognition), voiceprints (voice authentication, meeting transcription AI), or other biometric data from Illinois residents trigger BIPA regardless of where the company is headquartered. Several states have enacted BIPA-inspired laws (Texas CUBI, Washington My Health My Data Act for biometrics, New York City Local Law 144 for employment AI).

Examples

  • An employer using AI-powered video interview software that scans candidates' facial geometry to assess personality — BIPA requires written consent before any Illinois candidate is scanned.
  • A retail chain using facial-recognition AI at store entrances to identify known shoplifters — each entry of an Illinois resident without consent is a separate BIPA violation.
  • An HR system using voice biometrics to authenticate employee timekeeping — collecting Illinois employees' voiceprints without written consent and a destruction policy.

How Locke handles bipa (biometric information privacy act)

Locke detects attempts to paste biometric-adjacent data — descriptions of biometric systems, voiceprint samples, facial-geometry outputs — into AI prompts before transmission. For organisations building AI workflows around biometric data, keeping biometric identifiers out of AI prompt paths is one component of a BIPA-compliant posture.

See the product