Illinois BIPA Exemption: Biometric Information and Consent

Here's a sentence that should not make sense, but does: the exact same fingerprint, from the exact same person, can be legally protected on a Tuesday and exempt from BIPA's consent rules on a Wednesday. Not because the law changed. Not because the fingerprint changed. Because the reason someone scanned it changed.
Illinois BIPA, formally the Illinois Biometric Information Privacy Act (BIPA), is a state law that governs how private entities collect and store biometric information such as fingerprint data and face scans. It does not automatically protect every biometric identifier gathered in Illinois. Whether a scan is covered depends heavily on why the biometric data was collected and who collected it, as a recent Illinois BIPA exemption ruling for a home care provider just confirmed.
Illinois BIPA sounds like a blanket Illinois biometric privacy law, but a recent Illinois BIPA exemption ruling for a home care provider shows that the purpose behind collecting a fingerprint or face scan can matter just as much as the biometric data itself.
An Illinois appellate panel just refused to revive a lawsuit against a home care provider that had collected its employees' fingerprints for a state-required background check. The employees argued this violated their biometric privacy rights. The panel disagreed. Not because fingerprints don't count as biometric data (they absolutely do), and not because the company was somehow above the law. Nobody disputed that a fingerprint is a biometric identifier or that the scan generated biometric information under the statute. The panel found the company fell under an exemption enacted directly into the statute by the Illinois General Assembly. Same fingerprint. Same worker. Completely different legal outcome than you'd get if that same private entity scanned the same fingerprint for, say, a time clock.
What the Illinois BIPA Statute Actually Protects
Most people, if you asked them, would tell you Illinois has "that biometric law" that protects your face and fingerprints from companies misusing them. That's technically true. Illinois BIPA is one of the strictest biometric information privacy laws in the country, and for over a decade it's forced companies to get written consent before scanning a fingerprint, face, or iris, and to explain in writing why they're collecting it and how long they'll keep it. The General Assembly enacted the statute in 2008, and it reaches biometric identifiers such as fingerprints, voiceprints, retina or iris scans, and scans of hand or face geometry, along with any biometric information derived from them.
But here's the part that trips people up: BIPA was written to protect specific biometric identifiers, like fingerprints and faceprints, not to blanket-protect every situation those identifiers show up in. Almost immediately, courts and lawmakers started carving out exceptions. And the home care ruling shows one of those exceptions in action. Under BIPA, government contractors and agents working on behalf of a state or local government agency can be exempt from the law's consent requirements. Home care providers delivering state-subsidized services can fall into that bucket. So when this company collected fingerprints specifically to run a background check required by the state, the court said: that falls under the exemption. Different purpose, different scan, same fingerprint, different rule. The exemption attaches to that function, not to the biometric data file itself.
The Exemption: Where the Line Actually Gets Drawn
The exemption isn't a free pass for the whole company to do whatever it wants with biometric data forever. It's tied narrowly to the specific function the data was collected for. A related and widely cited case, Mosby v. Ingalls Memorial Hospital, established that healthcare entities can collect and retain biometric information without consent when it's gathered for treatment, payment, or health care operations, according to legal analysis from McGuireWoods. But that exemption doesn't stretch to cover just anything the hospital decides to do with the same fingerprint later. If a hospital worker's fingerprint unlocks a medication cabinet, that's arguably covered by the healthcare operations exemption. If that exact same hospital later wants to use the same fingerprint for an unrelated research project, the exemption doesn't follow it there. Research isn't treatment, payment, or operations. Consent kicks back in, and a person in that position may have grounds for litigation if the company proceeds without it. For the individual whose fingerprint it is, nothing about the scan has changed. For the private entity holding the biometric information, the legal rules have changed completely.
$800M+ This article is part of a series, start with Uk Age Verification 1 400 Vpn Privacy Signup Surge Podcast.
recovered by consumers in BIPA litigation and settlements from Meta, Google, and TikTok alone
Source: recent BIPA litigation reporting
That number matters because it proves the opposite risk is just as real for any business handling biometric information. Companies can't just wave the word "purpose" around and expect a court to buy it. Illinois BIPA exemptions are narrow on purpose (pun fully intended). A private entity has to show the collection genuinely falls within a defined, limited function, like a government-contracted background check or a hospital's core treatment operations. Courts have been perfectly willing to let massive statutory damages stand when a company's justification doesn't hold up, and litigation over these claims has only grown more common. BIPA damages are calculated per violation rather than per company, and before the 2024 BIPA amendment tightened things, each separate scan of the same biometric information could count as its own violation, which is exactly how you get numbers in the hundreds of millions.
The Consent Rule Nobody Reads the Fine Print On
Here's a fact that surprises almost everyone: consent under BIPA isn't a one-time universal "yes" you give once and forget about. According to the ACLU of Illinois, companies must inform you in writing about the specific purpose and how long they'll keep your biometric information before they collect it, and get written consent tied to that specific purpose. That information has to reach the worker before the first scan, not after. Consent for Purpose A doesn't automatically extend to Purpose B, even if it's the literal same fingerprint sitting in the same database.
Think of it like a building permit. A permit to demolish a house doesn't give you permission to skip safety codes when you renovate the lot next door. The city cares about what you're doing right now, not just that you once had approval for something related. Biometric consent works the same way. Getting permission to scan a face for a security badge doesn't hand a company blanket permission to use that same face scan for marketing analysis, or to sell it to a third party, or to run it through some new system nobody told you about. The same logic governs biometric data: the paperwork covers one job, not every job that comes later.
Home Care Fingerprint Checks: Why This Case Matters for Employment
Home care providers sit in an unusual spot. Many of them deliver state-subsidized care, which pulls them toward government contractor status. They also run background checks constantly as a condition of employment, because you're sending someone into a client's home, often to care for an elderly or disabled person. That combination, government-adjacent function plus a legally required background check, is exactly the kind of narrow lane the BIPA exemption was built for. It's not that home care biometrics are unregulated. It's that this particular use, fingerprinting for a mandated background check tied to state-subsidized services, lines up with an exemption Illinois already wrote into the statute. For the individual worker, the practical result is blunt: the biometric information taken for a mandated background check sits outside the consent rules, while the same biometric information taken for payroll does not.
What You Just Learned
- 🧠 Purpose matters as much as data typethe same fingerprint can be exempt or protected depending on why the biometric information was collected.
- 🔬 Government contractor exemptions are narrowthey cover the specific function, not the whole organization or every piece of biometric data it holds forever.
- 💡 Consent doesn't transfer between purposessaying yes to one use isn't saying yes to another, even for the same individual.
- ⚖️ Damages can still be massiveover $800 million recovered in other BIPA settlements shows courts don't treat biometric exemptions as a rubber stamp.
People Also Ask: Does Illinois BIPA Cover Every Company?
No. Illinois BIPA covers private entities broadly, but it carves out specific exemptions, including government contractors performing defined functions and healthcare entities collecting biometric information for treatment, payment, or operations. If your fingerprint or face scan falls inside one of those narrow lanes, the private entity may not need your written consent for that specific use, even though the general rule requires it. Federal appeals in these cases run through the Seventh Circuit, which has spent years sorting out when a worker or consumer can bring a BIPA claim in federal court at all. This is also why so much BIPA litigation turns on a single question: what was the biometric identifier actually collected for, and what happens to the biometric information after that.
The practical test is narrow. A company claiming an exemption has to point to the defined function the biometric information was collected for, document that purpose in writing, and stay inside it. Reuse the same biometric data for something new and the exemption stops traveling with the file, because the statute measures protection by purpose rather than by the type of information involved.
| Scenario | BIPA Status | Why | What was collected |
|---|---|---|---|
| Home care worker fingerprinted for state-required background check | Exempt | Falls under government contractor exemption | Fingerprint biometric information for a state mandated check |
| Hospital worker's fingerprint used to access medication cabinet | Likely exempt | Tied to health care operations | Fingerprint biometric information tied to cabinet access |
| That same hospital worker's fingerprint reused for research data | Protected, consent required | Research isn't treatment, payment, or operations | The same biometric information reused for a study |
| Retail employee fingerprinted for a private time clock system | Protected, consent required | No government or healthcare exemption applies | Fingerprint biometric information logged for payroll |
| Bank covered by the Gramm Leach Bliley Act collecting a customer voiceprint | Exempt | BIPA's financial institution exemption applies | Voiceprint biometric information held by the bank |
| State agency collecting fingerprints itself | Outside BIPA | The statute regulates companies, not government bodies | Fingerprint biometric information held by a public agency |
The exemption would not apply to information collected for research purposes because the definition of "health care operations" under HIPAA does not include research. Previously in this series: Online Identity Verification One Id Three Hiring Checks Podc.
legal analysis of the Mosby v. Ingalls Memorial Hospital ruling, McGuireWoods
Why Biometric Privacy Feels Simple But Isn't
People assume biometric privacy works like a light switch. Your face or fingerprint gets scanned, the law flips on, you're protected, done. It's an understandable assumption. Most privacy conversations we hear about, credit card breaches, social media leaks, treat the data itself as the thing being protected. So it feels natural to think the same must be true for a fingerprint or a face scan.
But Illinois BIPA, like a lot of biometric law, was actually written around a mix of the identifier and the entity collecting it, with exemptions layered on top for specific functions. That's a more complicated design than most people expect, and honestly, it's a more complicated design than most privacy laws use. According to a comprehensive overview from Recording Law, BIPA's exemptions are specifically bounded to defined functions and don't broadly extend to every use a covered entity might dream up later. So the misconception isn't dumb. It's just built on a mental model borrowed from the wrong kind of privacy law.
Timing adds another layer. BIPA amendments signed in 2024 changed how violations are counted, so repeated scans of the same individual by the same company now add up differently than they did in the cases that produced the biggest settlements. The underlying duty did not change: tell people what biometric information you are taking, say why, say how long you will keep it, and get that permission in writing.
Consent and the Documents Nobody Reads
If you've ever clicked "I agree" at a workplace kiosk without reading the fine print, you've probably signed a BIPA consent form and had no idea. The form is supposed to spell out the specific purpose and retention period for your biometric information. That specificity is the whole ballgame. It's the difference between a company being able to use your fingerprint for exactly one stated reason, versus being able to quietly repurpose it down the line.
This is the part of biometric information privacy that CaraComp spends a lot of time explaining to people who assume facial recognition and fingerprint systems all get treated the same way under the law. They don't. The rules shift depending on the industry, the collector, and the stated purpose, which is exactly why a home care background check and a retail time clock can land on opposite sides of the same statute.
Illinois BIPA does not treat a fingerprint or face scan as automatically protected everywhere it goes. An Illinois BIPA exemption can apply the moment the purpose behind the scan shifts, which means the safest question to ask isn't "is my biometric information protected," it's "protected for what, and by whom."
What Happens if the Illinois BIPA Exemption Doesn't Apply
Outside the narrow lanes carved out for government contractors and defined healthcare operations, BIPA's default laws are still some of the toughest in the country. Companies must get written consent before collecting biometric information, disclose the exact purpose and retention schedule, and avoid selling or profiting from that data. Break those laws, and the penalties bite. According to legal reporting from Dorsey and Whitney, BIPA allows $1,000 in statutory damages per negligent violation and $5,000 per reckless or intentional one, and because each separate scan used to count as its own violation, that math got enormous fast in court after court. It's why Meta, Google, and TikTok collectively ended up paying out over $800 million.
So the exemption isn't a loophole that swallows the law. It's a specific, narrow door. Walk through the wrong one, and the full weight of BIPA is still waiting on the other side. Up next: Credit Card Age Verification Steam Skips Age Estimation.
Here's the thing that should actually stick with you after all this: the next time someone hands you a form at work and says "just need your fingerprint for the system," the honest response isn't "sure" or "no way." It's "for what, exactly, and does that reason come with an exemption attached." Because in Illinois, that one detail, the reason, not the fingerprint, is what decides whether you and your biometric information are protected at all.
Illinois BIPA: Frequently Asked Questions
What is the Illinois BIPA exemption for home care providers?
The exemption comes from BIPA's government contractor provision, part of the law the Illinois General Assembly wrote into the statute. When a home care provider collects fingerprints for a state-required background check tied to state-subsidized services, courts have found that use falls under an exemption rather than the law's general consent requirements. It applies narrowly to that specific function, not to every fingerprint or piece of biometric information the company ever collects.
Does written consent apply to every fingerprint scan?
Generally yes. Illinois BIPA requires a private entity to disclose the specific purpose and retention period in writing and get signed consent before collecting a fingerprint or face scan. The exceptions are narrow, tied to defined categories like certain government contractors and specific healthcare operations, not a blanket pass for any business that decides consent is inconvenient. That written notice is often the only information a worker ever gets about where the scan ends up.
Can the same fingerprint be protected in one job and exempt in another?
Yes, and that is the core lesson from the home care ruling. The legal status depends on why the biometric identifier was collected and who collected it, not on the biometric itself. A fingerprint scanned for a government-mandated background check can be treated differently under Illinois BIPA than the identical fingerprint scanned for an unrelated purpose, even for the same individual.
How much have companies paid in Illinois BIPA settlements?
Consumers have recovered over $800 million in BIPA settlements and related litigation from companies including Meta, Google, and TikTok. Before a 2024 amendment, each separate biometric scan could be treated as its own violation, with statutory damages of $1,000 for negligent violations and $5,000 for reckless or intentional ones, which pushed some potential damages into the hundreds of millions or more for a single person's claim.
Why does biometric privacy depend on purpose instead of the data type?
Illinois BIPA was written to regulate specific identifiers like fingerprints and faceprints, but lawmakers layered exemptions on top for defined situations, such as certain government contracts and health care operations. That design means biometric information isn't automatically protected everywhere. The purpose behind the collection determines which rules, if any exemption, actually apply to that individual.
Does an exemption cover a company forever once it applies once?
No. Exemptions are tied to the specific function the biometric information was collected for, not to the company as a whole. If a hospital, for example, collects a fingerprint for treatment-related access and later reuses that same fingerprint for an unrelated purpose like research, the earlier exemption does not automatically cover the new use, and consent requirements can kick back in.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
Online Identity Verification: One ID, Three Hiring Checks
A single photo ID can't answer three different hiring questions at once. Here's why understanding the difference between identity, authorization, and credentials protects your personal information.
facial-recognitionBiometric Device Quality: DHS Bets $440M on Cameras
DHS just committed $440 million to better cameras and scanners, not smarter software. Here's why the quality of the original photo decides whether any facial comparison can be trusted at all.
facial-recognitionMeta Smart Glasses Facial Recognition: Code Pulled in 48 Hours
Two Harvard students proved smart glasses could identify strangers on the street in seconds. Here's what that reveals about consent when the camera is invisible.
