Illinois Biometric Information Privacy Act: What Lawyers Should Know
The Illinois Biometric Information Privacy Act, known as BIPA, sets strict rules for how companies collect and use biometric data. Illinois lawyers may not consider BIPA directly relevant to their practice. The rise of AI note-taking and transcription tools is changing that. These tools are increasingly common in depositions, client meetings, and virtual hearings. Many of them analyze a speaker's voice to distinguish participants, thereby creating a voiceprint. Voiceprints fall squarely within BIPA's definition of biometric information.
A law firm using these tools, even through a third-party vendor, could face compliance obligations it never anticipated. BIPA requires written notice, a stated purpose, and written consent before any biometric data is collected. Violations carry real financial exposure, since the law allows individuals to sue directly and assesses damages per violation. Illinois lawmakers are also currently weighing several bills that could change how the law applies going forward. Understanding these requirements matters for any lawyer whose firm now relies on AI-powered tools.
What the Illinois Biometric Information Privacy Act Requires
The Illinois Biometric Information Privacy Act, commonly referred to as BIPA, regulates biometric identifiers and biometric information. The statute defines biometric identifiers as a retina or iris scan, a fingerprint, a voiceprint, or a scan of hand or face geometry. It excludes items like photographs, physical descriptions, and certain health care data. Before a private entity can collect this data, BIPA requires several steps to be taken. The entity must inform the person in writing that it is collecting biometric data. It must also disclose the specific purpose and length of time the data will be stored. Finally, it must obtain a written release from the person before collecting anything.
Private entities must also publish a retention schedule. They must destroy biometric data once its purpose has been fulfilled, or within three years of the person's last interaction, whichever comes first. As mentioned by the ACLU of Illinois, “BIPA continues to stand as the most protective biometric privacy law in the nation, with the only one of its kind to offer consumers protection by allowing them to take a company who violates the law to court.”
Under the statute, a person harmed by a negligent violation can recover $1,000 or actual damages, whichever is greater. Reckless or intentional violations carry damages of $5,000 or actual damages, whichever is greater. Courts can also award reasonable fees, costs, and injunctive relief. These remedies apply per violation, which can make total exposure significant for organizations handling large volumes of biometric data.
AI Notetaking Tools & Compliance Risks for Illinois Law Firms
AI note-taking and transcription tools have become common across many workplaces, including law firms. Particularly, firms use them to document virtual meetings, client intake calls, and internal reviews. Many of these tools analyze voice characteristics to distinguish speakers. That process can create a voiceprint, which brings the tool squarely under BIPA. Employees and meeting participants may not realize that their voices are being captured and analyzed this way. This poses a risk to organizations that enable these tools, even when a third-party vendor built the software.
Worth noting, liability can extend to employers who permit the use of a tool, regardless of who developed it. However, there are several recurring practices organizations use to manage this risk, such as conducting a risk assessment before adopting a tool, drafting written policies on approved use, and building consent into meeting workflows.
Other commonly cited practices include limiting or disabling speaker-identification features, vetting vendors, and setting clear data retention and destruction timelines. Separately, Illinois lawmakers are currently considering several bills that would change BIPA's scope. Some proposed bills would create exceptions for security purposes, shorten the statute of limitations, or add a cure period before liability attaches. Whether any of these proposals become law remains to be seen. The current version of BIPA remains in full effect.
Illinois Biometric Information Privacy Act Compliance Moving Forward
The Illinois Biometric Information Privacy Act remains one of the strictest data privacy laws in the country. Its reach extends further than many lawyers might expect. AI tools are becoming a routine part of legal practice, from transcription apps to virtual meeting assistants.
The odds of unknowingly collecting biometric data continue to rise as a result. Law firms are not exempt simply because the technology comes from a third-party vendor. The statute's private right of action means that even a single unintentional violation can carry real financial consequences. At the same time, the legislative landscape around BIPA continues to shift. Several bills are currently under consideration that could reshape its requirements.
Illinois lawyers who want to stay ahead of this issue should watch both fronts. That means tracking the current law and any subsequent legislative changes. Understanding how BIPA applies to everyday tools is an important part of managing risk. This includes AI note-taking software and other tools used in a modern law practice. For lawyers looking to strengthen their firm's overall risk management approach, including how new technology fits into that picture, contact the professional liability specialists at ISBA Mutual Insurance Company.
