ARTICLE
15 December 2022

Considering Using Biometric Information? Adopt A Biometric Policy Now

FL
Foley & Lardner

Contributor

Foley & Lardner LLP looks beyond the law to focus on the constantly evolving demands facing our clients and their industries. With over 1,100 lawyers in 24 offices across the United States, Mexico, Europe and Asia, Foley approaches client service by first understanding our clients’ priorities, objectives and challenges. We work hard to understand our clients’ issues and forge long-term relationships with them to help achieve successful outcomes and solve their legal issues through practical business advice and cutting-edge legal insight. Our clients view us as trusted business advisors because we understand that great legal service is only valuable if it is relevant, practical and beneficial to their businesses.
Businesses and organizations operating in Illinois – including any business with an online presence accessible to residents of Illinois – should remain vigilant of the ever-changing...
United States Employment and HR
To print this article, all you need is to be registered or login on Mondaq.com.

Businesses and organizations operating in Illinois – including any business with an online presence accessible to residents of Illinois – should remain vigilant of the ever-changing set of pitfalls stemming from the Illinois Biometric Information Privacy Act (BIPA). As a reminder, BIPA regulates how private entities collect, handle, and use biometric data, and provides a private right of action to any person aggrieved by a violation of the statute.

Those who fail to properly plan, they may sleepwalk into potentially harsh penalties for technical violations of the statute. Moreover, a series of recent court decisions are only increasing the risks created by the statute. In the latest development, one Illinois court handed down a ruling that effectively creates strict liability (meaning that the company's intentions aren't taken into account in determining whether or not the law was violated) for organizations collecting biometric information without having a publicly available written policy in place at the time of the initial collection.

In that case, Mora v. J&M Plating, Inc., the Illinois appellate court determined that as soon as a private entity begins possessing biometric data, BIPA Section 15(a) kicks in, which effectively obligates the entity to have already developed and published a written policy for the handling of biometric information before the organization ever handles the biometric information in the first place.

Such a policy must include a data-retention schedule and guidelines for how and when the biometric data is destroyed. This obligation to develop and publicize a policy, the court emphasized, layers on top of BIPA Section 15(b)'s requirement that the entity obtain informed written consent from those whose biometric information it seeks to gather and possess.

In other words: if an entity has no retention-and-destruction policy in place before it first collects biometric information, the entity opens itself up to potentially significant liability under BIPA's uncapped statutory damages provision, which provides for $1,000 per negligent violation and $5,000 per intentional or reckless violation.

The risk may be even more significant if the entity begins collecting biometric information without the individual's informed written consent. Taking a generous reading of the opinion, the court's holding would leave organizations with no way to mitigate this liability by adopting a written policy at a later date. Either an organization has a policy at the time of the initial collection or it does not, and if it does not, there is no escaping liability under Section 15(a).

In light of the Mora opinion, businesses and organizations with even the remote possibility of collecting biometric information as part of their operations in Illinois should draft and implement a policy – even if such a policy does not currently seem necessary. If your business or organization operates in Illinois but does not currently have a biometric data retention-and-destruction policy in place, think about developing one, in consultation with counsel.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More