Biometric Information Privacy Act: Risk Management Tips for Illinois Lawyers

 
 

Earlier this month, ISBA Mutual discussed how the Biometric Information Privacy Act creates real financial exposure for organizations, including law firms, that mishandle biometric data. AI notetaking and transcription tools have made this risk more relevant to legal practice than ever before. Many of these tools generate a voiceprint when they distinguish between speakers on a call or in a meeting.

A voiceprint counts as biometric information under Illinois law. Firms that adopt these tools without understanding BIPA's requirements can face steep statutory damages, even when a third-party vendor built the software. The law's private right of action means employees, clients, and other meeting participants can bring claims directly against the organizations that use these tools.

Illinois lawmakers are also weighing several bills that could reshape the law's scope in the coming months. Firms benefit from a clear, practical approach to managing BIPA risk as AI adoption continues to grow.

Biometric Information Privacy Act Risk Factors to Watch

The Biometric Information Privacy Act treats biometric identifiers differently from other personal data. Illinois lawmakers explained this reasoning in the statute's own legislative findings. Biometric identifiers cannot be changed once compromised, unlike a password or account number.

That makes biometric data far riskier to mishandle than most information a firm collects. The ACLU of Illinois frames this idea directly.

"A person's biometric information belongs to them, and only them." — ACLU of Illinois

That principle underlies BIPA's strict notice and consent requirements. It also explains why the law lets individuals sue directly. Firms cannot simply rely on government enforcement to catch violations. A negligent violation can trigger $1,000 in damages or actual damages, whichever is greater. A reckless or intentional violation raises that figure to $5,000, with damages assessed per violation. Exposure can grow quickly across a firm with many clients, employees, or meeting participants.

Moving forward, Illinois lawmakers are currently considering several bills that would narrow some of these protections. Proposed changes include shorter statutes of limitation and new exceptions for security purposes. None of these proposals have passed yet.

For now, the current version of BIPA remains fully in effect. This legislative reasoning still guides how courts and regulators approach the law today.

Practical Steps for Managing AI Note-Taking Risk

A recent Illinois Business Journal article outlines a series of practices that organizations commonly use to manage this risk. These practices focus on assessment, consent, and ongoing oversight rather than a single fix.

Commonly cited steps include:

  • Conducting a risk assessment before adopting any AI note-taking tool

  • Drafting written policies that specify which tools are approved for use

  • Building consent into pre-meeting workflows and virtual meeting invitations

  • Limiting or turning off speaker-identification and voice-profiling features where possible

  • Vetting vendors and reviewing their data handling practices before adoption

  • Setting clear retention and destruction timelines for recordings and transcripts

  • Training managers and employees on consent requirements and prohibited uses

  • Auditing usage regularly to catch unauthorized tools before they create liability

Firms that combine several of these steps tend to reduce exposure. That approach works better than relying on just one safeguard because liability can extend to the organization enabling a tool. This is true even when a vendor built the software. Overall, the same underlying question applies across every use case:

Does the tool identify people by their voice?

If so, BIPA is likely in play. Some organizations also designate a single point of contact for tool approvals, helping to ensure every new tool goes through the same review before it reaches a meeting.

Next Steps for Firms Concerning the Biometric Information Privacy Act

The Biometric Information Privacy Act is not going away. Law firms that adopt new technology without checking for biometric data risk exposure they may not expect. The good news is that most of this risk can be managed by implementing fundamental best practices like informed consent, clear policies, and careful vendor selection.

None of this requires avoiding AI tools altogether; it simply requires knowing which tools create a voiceprint. Firms can then build the right safeguards around them. BIPA also continues to evolve through pending legislation. Staying current on the law will matter as much as staying current on the technology itself. Illinois lawyers who want a closer look at their firm's overall risk profile can take that step now. This includes evaluating how new technology fits into the bigger picture.

For firms ready to review their risk management and professional liability coverage, contact the team at ISBA Mutual Insurance Company.

Rick Young

As a Chicago-based digital marketing agency, Rizzo Young Marketing personalizes the experience for each of our clients. All of our efforts are carefully customized and proactively managed to ensure that you're receiving the most out of your budget. Whether you need a digital marketing expert to grow your brand or just someone to take care of everyday maintenance, we can help.

https://www.RizzoYoung.com/
Next
Next

Illinois Biometric Information Privacy Act: What Lawyers Should Know