ARTICLE
12 November 2020

Amazon Subject Of Illinois Biometric Information Privacy Act Lawsuit

HB
Hall Booth Smith, P.C.

Contributor

Hall Booth Smith, P.C.
Recently three plaintiffs filed a class-action lawsuit alleging that Amazon violated Illinois' Biometric Information Privacy Act ("BIPA"), by collecting and storing "voiceprints" without the users'...
United States Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

Recently three plaintiffs filed a class-action lawsuit alleging that Amazon violated Illinois' Biometric Information Privacy Act ("BIPA"), by collecting and storing "voiceprints" without the users' consent.

Voiceprints

Amazon has a software product called Amazon Connect that companies use to run call-centers. One company with whom Amazon has partnered Pindrop Security. Pindrop Security has the capability to create a "voiceprint," which is essentially a fingerprint based on your voice. Voiceprints are used to authenticate callers by the unique attributes of their voice.

Class-Action Details

The issue in this case arises from the creation of voiceprints without obtaining callers' consent. Voiceprints are considered "biometric data" under BIPA, and BIPA requires consent of the data subject prior to collection and processing of such biometric data.

Specifically, the plaintiffs all used a call-center provided by financial services company, John Hancock. When the plaintiffs called the John Hancock support line, they were informed that they no longer needed to enter their security PIN, due to Pindrop's ability to authenticate their calls based on their voice.

Ramifications

While this sounds like a convenient feature, it has serious security concerns. The lawsuit hones in on one in particular: the lack of security controls offered to callers in the event of a data breach. When using a PIN, if the business suffers a data breach, the caller can simply change their PIN. When a voiceprint is the only means of authentication, and the hacker obtains the voiceprint, there is nothing a caller can do change their voiceprint. This is certainly a problem when a voiceprint is used to authenticate into an account containing sensitive financial information such as John Hancock, but that could be the tip of the iceberg. Pindrop is in the business of making money. It is possible Pindrop provides voice authentication services for many companies with whom an individual may have accounts. If Pindrop were to suffer a data breach, which leads to the loss of a voiceprint, multiple accounts associated with an individual could be compromised, and the individual would have no means of "resetting a password."

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

ARTICLE
12 November 2020

Amazon Subject Of Illinois Biometric Information Privacy Act Lawsuit

United States Privacy

Contributor

Hall Booth Smith, P.C.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More