Your Face Got Scanned 2,600 Times. A Court Just Said That's One Violation.
Picture this: your employer has been scanning your fingerprint every morning and every evening for five years. That's roughly 2,600 scans. They never got your proper written consent. Under the old rules, each of those scans could have been a separate legal violation — meaning the company could have owed you damages for every single one. A federal appeals court just slammed the door on that math. One person, one claim. Done.
A federal court ruled that a 2024 Illinois law change — which says repeated face or fingerprint scans count as ONE privacy violation, not thousands — applies backward to old lawsuits, drastically cutting what companies owe workers whose biometric data was mishandled.
The ruling, called Clay v. Union Pacific, came from the Seventh Circuit — a federal appeals court that covers Illinois, Indiana, and Wisconsin. It's not the Supreme Court, but in the world of biometric privacy law, this decision just rewrote the scoreboard. And if you've ever clocked in with your thumb, unlocked a gym locker with your face, or had your eyes scanned at a doctor's office, the story behind this ruling is very much about your life.
First, What Is BIPA — and Why Should You Care?
BIPA stands for the Biometric Information Privacy Act. It's an Illinois law passed in 2008, and for a long time it was the strongest protection regular people had over their biometric data — a fancy term for the physical, one-of-a-kind stuff that identifies you: your fingerprints, your face geometry, the pattern of your iris. Unlike a password, you can't change these if they get stolen. That's why privacy advocates say they deserve extra protection.
BIPA required companies to get your written consent before collecting this data, explain why they were collecting it, and delete it on a set schedule. If they didn't? They could be sued. And here's where it got wild: under an earlier Illinois Supreme Court ruling from 2023 (called Cothron v. White Castle), every individual scan counted as its own violation. So if a fast-food chain scanned 1,000 employees' fingerprints twice a day for five years without proper consent forms, the math became catastrophic fast.
That $2.5 billion figure wasn't hypothetical fear-mongering. Courts were actually working through these cases. One employee scanned twice daily for five years could theoretically claim damages exceeding $2.5 million — just for themselves. Scale that to a warehouse workforce and you get numbers that could genuinely destroy companies. Illinois lawmakers looked at this and said, essentially: that's not what we meant. This article is part of a series — start with Your Face Was Scanned Saturday Nobody Asked If That Was Lega.
So What Changed — and When?
In 2024, the Illinois legislature passed an amendment (called SB 2979) that said repeated collection of the same person's biometric data, using the same method, is just one violation — not one per scan. One company, one person, one type of scan = one claim. That's the "one and done" part of the ruling's nickname.
The big question that landed in court: does this new rule apply to all the old lawsuits already filed? Or only to new cases going forward? Because by the time the amendment passed, there were hundreds of active BIPA class action lawsuits — cases where workers were saying, "We got scanned thousands of times, we want damages for each one."
The Seventh Circuit's answer: yes, the new rule applies to old cases too. The court's reasoning was that the amendment was procedural and remedial — lawyer-speak for "it adjusts how damages are calculated, not whether you have a valid claim at all." According to the detailed legal breakdown from Ogletree Deakins, the ruling in Clay v. Union Pacific marked a significant turning point by substantially reducing the damages exposure that defendants faced in the many cases filed under the earlier, more expansive interpretation.
"The amendments do not eliminate all liabilities for violations under BIPA. Companies still must get consent and handle retention correctly — they just can't face fiscal extinction for doing the work wrong once." — Legal analysis, Jackson Lewis
The effect was immediate. According to Recording Law, BIPA class action filings dropped from 427 in 2024 to roughly 150 in 2025 — a 65% collapse in a single year. Total settlement money fell from over $206 million to $136.6 million. These aren't small shifts. The legal earthquake hit, and a lot of cases either settled cheap or quietly disappeared.
Wait — Does This Mean Companies Can Just Do Whatever They Want?
No. And this is the part the headlines miss. Previously in this series: Your Face Got Scanned At Wegmans Nobody Had To Tell You.
The ruling didn't say biometric data is now fair game. It didn't wipe out BIPA. Companies still have to get your written consent before they scan your face or fingerprints. They still have to tell you why they're collecting it and how long they'll keep it. They still have to delete it. If they don't do all of that, they can still be sued — and those lawsuits can still cost them real money. The court just said the penalty math changed, not the rules themselves.
Think of it like a speeding ticket. You still can't speed. The fine just changed.
Why This Matters for You Right Now
- ⚡ The rules didn't disappear — consent, retention limits, and deletion requirements are still legally required under BIPA. Companies just face lower damages when they mess up.
- 📊 Biometric data is becoming normal infrastructure — gym check-ins, office logins, school access systems, eyewear measurements, and airport boarding are all collecting this data right now, often without most people noticing.
- 🔍 Illinois is still your best legal shield — BIPA remains the strongest biometric privacy law in the U.S. If you live or work in Illinois, it applies to you. Most other states have nothing comparable.
- 🔮 This ruling doesn't bind everyone — State courts in Illinois can still disagree with the Seventh Circuit's logic. Other circuits haven't weighed in. The legal debate isn't over; it just moved.
Plaintiffs' attorneys aren't quietly accepting this outcome, either. Their argument — rejected by the court — was that the original law created a real, separate violation every single time a scan happened without consent. Reframing that as "one violation" isn't just fixing the math, they say; it's rewriting what the violation even was. The Seventh Circuit disagreed. But as WilmerHale noted in its analysis of the retroactivity decision, this tension isn't resolved outside the Seventh Circuit's jurisdiction. Other courts may still see it differently.
The Part Nobody's Talking About: Your Body Is Now a Password
Here's the bigger picture. The legal fight over per-scan damages is actually a proxy war for something much simpler: the slow, quiet normalization of your physical body as login credentials.
Think about how many times in the last month your face, fingerprint, or eyes were used to verify you're you. Your phone unlock. Your work timecard. The gym entrance. TSA PreCheck. An online bank verification. A health portal. Maybe your kid's school. These aren't edge cases anymore — they're Tuesday. Up next: Monroe County Biometric Disclosure Retail Facial Recognition.
Every one of those scans creates a data point. That data lives somewhere. A company owns it. And unlike your bank account password, you cannot reset your fingerprint if something goes wrong.
The BIPA fight was always, at its core, about whether companies would face real consequences for being careless with something irreplaceable. The 2024 amendment and this ruling shifted the answer toward "less severe consequences." That's a business win. Whether it's a privacy win is a genuinely open question.
When any app, employer, gym, or device asks to scan your face or fingerprints, treat that consent screen like you're signing a financial contract — because legally, you are. Read what they're collecting, why, and how long they keep it. In most states, that screen is the only protection you have. Once you say yes, the law's ability to help you is limited — and just got a little more limited.
The one practical thing you can do right now: the next time you're asked to enroll your face or fingerprints somewhere — a new app, a new employer's timekeeping system, a gym — ask for the written privacy policy before you scan. Ask specifically: how long do you keep my biometric data, and how do I request it be deleted? Companies covered by BIPA are legally required to answer those questions. Companies not in Illinois... well, you're mostly asking out of politeness and hope. Which tells you something about where the law still needs to catch up.
The real irony of this ruling? The court said that scanning your face a thousand times without consent is legally no worse than doing it once. But if someone steals your face data from that company's database, they've got a thousand times' worth of the same problem — and you have exactly zero ways to change your face.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore News
Your Boss's AI Can Reject You Until 2027 — and Nobody Has to Prove It's Fair
Starting August 2, AI chatbots and deepfakes in Europe need labels. But the tougher protections — the ones that actually shield you from AI decisions in hiring and immigration — won't arrive until December 2027. That gap is the real story.
privacyYour Kid's Photo Is All These Apps Need to Make a Fake Nude
San Francisco is forcing Apple and Google to pull apps that turn ordinary photos into fake sexual images. The scariest part? Those apps were sitting in the same store as your kids' games.
facial-recognitionYour Face Got Scanned at Wegmans. Nobody Had to Tell You.
A store near you might already be scanning your face at the door. Monroe County wants retailers to say so out loud. Here's why that small ask is a much bigger deal.
