Rules

Illinois BIPA compared with other US state biometric privacy laws

Illinois BIPA is the strictest US biometric privacy law, and it shapes how social apps handle face filters, AR features, consent and retention.

What to take away

  • Illinois BIPA is the anchor US biometric privacy law: it requires written consent before collecting face or voice data and a public retention schedule.
  • Only Illinois and Texas let private individuals sue directly, which is why BIPA drives most biometric class action exposure for social apps.
  • California, Colorado and Washington regulate biometrics through broader privacy or facial recognition statutes with different triggers and remedies.
  • Face filters and AR features can count as biometric collection when they map a face or voice, so consent and deletion rules apply before launch.
  • Compliance costs sit mostly in notices, vendor contracts, retention schedules and record keeping, not in filing fees.
  • BIPA does not reach photos, videos or metadata that are not used to identify a person, so much ordinary social posting stays outside it.

What Illinois BIPA covers and who it applies to

The Illinois Biometric Information Privacy Act, usually shortened to Illinois BIPA, governs how private entities handle biometric identifiers and biometric information in Illinois. It passed in 2008 and remains the reference point for US biometric privacy debates.

The law names two categories. Biometric identifiers include retina or iris scans, fingerprints, voiceprints and scans of hand or face geometry. Biometric information means any data based on those identifiers, whatever format a company stores it in.

Coverage turns on collection, not intent. A company that scans a face to build a filter has collected a biometric identifier under the statute, even if the scan is deleted seconds later.

BIPA applies to private entities, not to state agencies or local government. Social platforms, camera app makers, AR studios and the vendors they hire all fall inside its scope when Illinois residents use their products.

Written consent and retention requirements under BIPA are the core duties. Before collection, a company must tell the person in writing that biometric data is being collected, state the specific purpose and the length of time it will be kept, and obtain a written release.

Retention rules are equally specific. An entity must keep a publicly available retention schedule, destroy biometric data when the initial purpose is satisfied, and destroy it no later than three years after the person's last interaction with the company.

The statute also bans profiting from biometric data. Selling, leasing, trading or otherwise profiting from a person's biometric identifier or information is prohibited, with narrow exceptions for financial institutions and security work.

The private right of action gives the statute its bite. Illinois residents can sue directly, and the law provides for liquidated damages, attorney fees and injunctive relief. A single noncompliant scan can become a class claim.

Federal enforcement runs alongside the state statute. The FTC keeps a privacy and security enforcement hub covering biometrics and platform conduct, which is where federal actions against app makers are tracked.

How BIPA compares with other US biometric privacy laws

No other state has copied BIPA exactly. The closest relatives are Texas and Washington, and the differences matter for product teams deciding where to launch a feature.

Texas passed its biometric law in 2009, one year after Illinois. It covers biometric identifiers for commercial purposes and requires informed consent before collection, but enforcement runs through the state attorney general rather than private plaintiffs.

Washington's law, revised in 2017, requires notice and consent before enrolling a person in a biometric identifier database for a commercial purpose. It also gives the attorney general enforcement power and allows claims under the state consumer protection act.

California approaches biometrics through the California Consumer Privacy Act, as amended by the CPRA. Biometric information counts as sensitive personal information, which brings limits on use, disclosure and retention, plus rights to know, delete and correct. Enforcement runs through the attorney general and the state privacy agency, with a limited private right tied to breaches.

Colorado's Privacy Act treats biometric data as sensitive data and requires consent before processing it. Colorado also has a separate facial recognition law for certain businesses that analyze faces in public places.

Other states regulate narrower slices. New York City's biometric ordinance requires signage where biometric identifiers are collected in commercial establishments. Massachusetts and Florida have older, narrower identification statutes with limited reach.

The federal layer is thinner. The FTC enforces general unfairness and deception authority rather than a dedicated biometric rule, so federal action rests on the statutes the FTC enforces. COPPA adds separate rules for apps aimed at children, and no federal biometric statute matches BIPA.

State or law Consent standard Private right of action Retention duty
Illinois BIPA Written release before collection Yes, with liquidated damages Public schedule, destroy at purpose end or within three years
Texas CUBI Informed consent before collection No, attorney general only Destroy within a reasonable time
Washington HB 1493 Notice and consent before enrollment No, attorney general plus consumer act Not specified in the statute
California CCPA and CPRA Purpose limits and consent for sensitive data Limited, breach-linked Purpose limitation and deletion rights
Colorado Privacy Act Consent for sensitive data processing No, attorney general and district attorneys Purpose limitation and deletion rights

Face filters and AR features under BIPA consent rules

Face filters and AR features are the most common way social app users meet biometric processing. A filter that tracks facial landmarks, a lens that maps a face for a mask or a voice changer that models a voiceprint all involve the data BIPA names.

That is why face filters biometric consent is not a cosmetic legal question. If the app is used in Illinois, consent has to happen before the camera pipeline starts building a face template, not after the filter loads.

A compliant flow looks like this:

  1. Show a plain-language notice that names the biometric data being collected and the specific purpose, such as real-time face tracking for filters.
  2. State the retention period, including when the template is deleted and whether any copy is kept.
  3. Collect an affirmative written release, such as a signed in-app consent screen with a timestamped record.
  4. Log the consent record and link it to the user account so the company can prove it later.
  5. Delete the biometric data when the purpose ends or within three years of last interaction, whichever comes first.

A worked example shows the gap. Suppose a photo app adds a face swap lens. If the lens processes frames on the device and never stores a template, the company still collects a face geometry scan while the lens is active. Under BIPA, the notice and written release should appear before the lens is enabled for an Illinois user.

If the same app sends frames to a server for rendering, the exposure grows. The vendor receiving the frames is also a private entity handling biometric data, so contracts need to pass through consent, retention and deletion duties.

AR features privacy also depends on what the feature does with the data. Filters that apply color overlays without deriving face geometry sit closer to ordinary photo editing, while filters that measure facial structure sit squarely inside BIPA.

Voice effects raise the same issue. A voiceprint is a named biometric identifier in Illinois, so a voice changer that models a user's voice should follow the same consent and retention path as a face filter.

Age matters too. When a filter is likely to attract children, the California Age-Appropriate Design Code adds design duties that overlap with biometric consent work, so the two regimes can be mapped in one review.

Litigation and compliance costs for social app operators

The private right of action is the reason BIPA dominates compliance planning. Plaintiffs do not need to show actual harm, and the statute provides liquidated damages per violation, which turns a large user base into a large claimed class.

Because of that structure, most BIPA claims against app makers settle rather than go to trial. The practical cost is a mix of defense fees, settlement funds, notice programs and engineering time to rebuild data flows.

Litigation exposure is not limited to the platform. Vendors that supply face tracking, liveness checks or AR rendering can be named as co-defendants, and platforms can face claims over a vendor's collection.

Regulators watch the same conduct. The FTC publishes technology and privacy analysis on its Office of Technology blog, and its cases and proceedings record covers platform design and privacy disputes. A state lawsuit can draw federal attention.

Compliance costs are mostly fixed and predictable. A team needs a retention schedule published on the site, consent screens with version control, vendor contract clauses, deletion jobs and audit logs. None of these require a large budget, but each needs an owner.

There is a broader cost to getting this wrong. Debates about how platforms handle personal data shape public trust, and the arguments on both sides are documented in critiques of social media that trace platform incentives.

Why Illinois became the strictest biometric regime

Illinois acted before most states had a privacy agency or a comprehensive consumer privacy law. Lawmakers wrote a narrow statute aimed at private collection of face, finger and voice data, which is why it reads differently from later omnibus laws.

The statute's design choices explain its strength. Written consent, a public retention schedule, a ban on profiting from biometric data and a private right of action work together rather than as separate duties.

Federal inaction left room for state leadership. There is no national biometric statute, and the FTC's privacy authority rests on unfairness and deception rather than a dedicated biometric rule, which leaves states to set the terms.

Illinois also has a dense technology and university economy, so face and voice processing reached consumers there early. That gave courts a steady stream of cases to interpret the statute.

Other states moved in different directions. Some prefer attorney general enforcement, some fold biometrics into omnibus privacy laws, and some regulate only facial recognition in public places. That patchwork is now the norm across US state biometric privacy laws.

Comparisons with other countries help product teams. The Quebec privacy law imposes consent and purpose limits on biometric data through its own enforcement model, and the differences show up in how features get built.

What BIPA does not reach in social app design

BIPA is narrower than it looks. It does not cover every image a user uploads, and it does not regulate photographs, videos or metadata unless the data is used to identify a person through a biometric identifier.

A profile photo is not biometric data on its own. A face recognition feature that builds a template from that photo is. The line is the derivation of an identifier, not the presence of a face.

BIPA also does not apply to government agencies, and it does not create a general right to delete any personal data. Deletion rights come from other laws, such as the CCPA in California and comparable state statutes.

Design choices about status, presence and identity raise privacy questions that BIPA does not answer. The tension between visibility and privacy in online status and identity platforms is a signal versus noise problem as much as a legal one, and it deserves separate review before launch.

Advertising identifiers and device fingerprints sit outside BIPA too, even though other privacy laws may reach them. That distinction matters when a team scopes a compliance project and needs to know which data flows to review.

Platform structure adds another limit. Section 230 of the Communications Decency Act shields platforms from liability for much third-party content, but it does not shield a company from its own biometric collection or its own filter design.

Ranking, notifications and moderation rules are not biometric processing, even when they rely on behavioral signals. A team can rebuild a feed without touching the consent, retention and deletion work that BIPA requires.

Expectations also shift across age groups. Research on generational digital culture shows that comfort with sharing differs by cohort, which affects how consent screens should be written and when they should appear for younger users.

Common questions

Does BIPA apply to a face filter that runs only on the phone? Yes, if the filter derives face geometry or a voiceprint. On-device processing does not remove the collection, so the notice and written release duties still apply to Illinois users.

Can a social app rely on its general privacy policy for BIPA consent? No. BIPA requires a written release that states the specific purpose and retention period before collection, which a general policy does not provide.

Which states besides Illinois allow private lawsuits over biometric data? Texas and Washington allow enforcement by the attorney general, and California has a limited private right tied to breaches. Illinois remains the state with the broadest private right of action.

How long can a company keep a face template under BIPA? Until the initial purpose is satisfied, and no later than three years after the person's last interaction with the company. The retention schedule must be public.

Do AR features that never store face data still need consent? They need consent if they collect a biometric identifier, even briefly. Storage length affects the retention duty, not the consent duty.

What is the first step for an app team reviewing biometric features? Map every data flow that derives face, voice or hand geometry, then attach a consent record, retention period and deletion job to each one before launch.

More in Rules

Rules

How COPPA and California's design code change social apps for US teens

COPPA sets the federal baseline for kids' data, while California's Age-Appropriate Design Code adds design duties that reshape teen social apps across the US.

Rules

What does the FCC actually regulate on US social platforms?

FCC social platforms sit mostly outside the agency's reach, but robocalls, texts and licensed spectrum bring parts of platform conduct under its rules.

Rules

Section 230 and state speech laws, what US platforms must remove

Section 230 shields platforms from liability for user posts, but state speech laws and federal rules like COPPA still force removals and design changes.

Latest from Method Desk

Guides

The Wayback Machine and US copyright, archiving memes without a takedown

Wayback Machine copyright rules shape how US archivists capture memes, answer DMCA takedowns and cite frozen pages without republishing them.