Biometric Information Privacy Act

From HandWiki
Revision as of 18:23, 6 February 2024 by Sherlock (talk | contribs) (url)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Short description: 2008 Illinois state law

Template:Infobox U.S. State legislation

The Biometric Information Privacy Act is a law set forth on October 3, 2008 in the U.S. state of Illinois, in an effort to regulate the collection, use, and handling of biometric identifiers and information by private entities.[1] Notably, the Act does not apply to government entities.[1] While Texas[2] and Washington[3] are the only other states that implemented similar biometric protections, BIPA is the most stringent.[4] The Act prescribes $1,000 per violation, and $5,000 per violation if the violation is intentional or reckless.[1] Because of this damages provision, the BIPA has spawned several class action lawsuits.[5]

Provisions

The BIPA requires companies doing business in Illinois to comply with a number of requirements pertaining to the collection and storage of biometric information. These include a requirement that companies:

  • Obtain consent from individuals if the company intends to collect or disclose their personal biometric identifiers.
  • Destroy biometric identifiers in a timely manner.
  • Securely store biometric identifiers.[6]

A key area of focus is that an entity must use a "reasonable standard of care"[7] in managing biometric information and identifiers.

Standing

BIPA is the only law in the U.S. that provides a private right of action to any individual who is aggrieved by a violation.[1] However, in order to litigate a BIPA action in federal court, the aggrieved person must have federal constitutional standing otherwise known as Article III standing.[4] Generally, Article III standing requires that a plaintiff suffer an injury to a legally protected interest that is causally connected to the defendant's conduct and such injury will likely be addressed by a court's decision.[8]

Legislative history

Senate Bill 2400, which eventually became the Biometric Information Privacy Act, was introduced by State Senator Terry Link on February 14, 2008; it passed both Houses of the Illinois General Assembly on July 10, 2008, and was approved by then-Governor Rod Blagojevich on October 3, 2008.[9] The purpose of the Act was to establish standards of conduct for private entities that collect or possess biometric information.[10] In 2016, Senator Link proposed and later withdrew an amendment to the Act that would have limited the Act's application to biometrics collected in public.[11]

Proposed Federal Regulation

The National Biometric Information Privacy Act

On August 3, 2020, Senator Jeff Merkley introduced the National Biometric Information Privacy Act of 2020 (Senate Bill 4400).[12] While the Act contains provisions similar to BIPA [13] it is more expansive than BIPA.[14] If passed, the Bill would be the first of its kind to regulate biometric information on a national scale.[15]

Notable cases

As biometric technology advances, there have been a number of lawsuits related to data collection methods, as well as various levels of protection over data. Using fingerprints as ways of clocking in and clocking out of work is an example of a technology that fights what is known as "buddy punching" or the practice of using somebody else to clock in for another worker at a job. In Illinois, the Biometric Information Protection Act law allows people to sue employers for mishandling biometric data. According to the Cook County Record, "In Illinois, both the parent company of Mariano's supermarkets and the Intercontinental Hotel Group have been hit with class action lawsuits alleging they improperly collected and stored employee fingerprints and other biometric data."[16]

Federal court cases

In re Facebook Biometric Info. Privacy Litig., 185 F. Supp. 3d 1155 (N.D. Cal. 2016)

  • Illinois Facebook users alleged that the social media platform violated the BIPA when it scanned images of their faces, without consent, in order to run its Tag Suggestions feature; a California federal court certified the class in 2018.[17]

Monroy v. Shutterfly, Inc., No. 16 C 10984, 2017 WL 4099846 (N.D. Ill. Sept. 15, 2017)

  • Shutterfly users claimed that the company violated the BIPA when it scanned uploaded digital photos using facial recognition software. On September 15, 2017, Northern Illinois District Court Judge Joan B. Gottschall denied a motion to dismiss the lawsuit.[18]

Rivera v. Google, Inc., 238 F. Supp. 3d 1088 (N.D. Ill. 2017)

  • Google users sued the company for violating the BIPA, alleging that it created and stored scans of users' faces on its Google Photos service, without user consent. On February 27, 2017, Northern Illinois District Court Judge Edmond E. Chang denied a motion to dismiss the lawsuit[19] but on December 29, 2018, the lawsuit was dismissed for lack of standing.[20]

McDonald v. Symphony Bronzeville Park LLC, N.E.3d (Ill. App. Ct. Sept. 18, 2020).[21]

  • A nursing home violated BIPA when it collected an employee's biometric data for time tracking purposes without disclosing or obtaining consent from the employee.[21] The Illinois Supreme Court will determine whether the Worker's Compensation Act provides employers with a defense against BIPA claims by their employees.[22]

State court cases

Rosenbach v. Six Flags Entm't Corp., 2019 IL 123186

  • Six Flags was sued for collecting park-goers thumbprints without informed consent. The Illinois Court of Appeals ruled that a mere technical violation of the BIPA was insufficient to maintain an action, because it did not necessarily mean a party was "aggrieved," as required by the statute.[23] This was reversed by the Illinois Supreme Court which ruled that users do not need to prove an injury (such as identity fraud or physical harm) in order to sue; the mere violation of the act was sufficient to collect damages.[24]

Additionally, an employee of the NorthShore University HealthSystem has sued the company for allegedly collecting worker fingerprints without their consent, in violation of the Illinois Biometric Information Privacy Act. In Cook County Circuit Court, the employee alleged "that the defendant scanned and digitally collected his fingerprints without consent, for use with a biometric employee punch clock."[25]

Settlements

On December 1, 2016, the first settlement involving the BIPA was approved by a judge in Cook County, Illinois.[26] The class action lawsuit was against L.A. Tan Enterprises, Inc. and settled for $1.5 million, which included between $125 and $150 for each class member who filed a claim.[27]

In February 2021, Judge James Donato approved a $650 million settlement in the federal In re Facebook Biometric Info. Privacy Litig. case, praising the settlement as "a major win for consumers in the hotly contested area of digital privacy."[28][29] Two class members have appealed the settlement to the United States Court of Appeals for the Ninth Circuit.[30]

Challenges

There was a bill (SB3053) pending before the Illinois legislature to amend the BIPA. The bill proposed to exempt private entities from the BIPAs requirements under a number of circumstances, including (1) if the biometric information is used "exclusively for employment, human resources, fraud prevention, or security purposes", (2) if the company "does not sell, lease, trade or similarly profit" from the biometric information, or (3) if the company protects biometric information at least as securely as it secures other sensitive information.[31] The bill never got out of committee, and expired 2019.

SB3053 was viewed by privacy advocates as an attempt to entirely gut the BIPA.[32][33][34] It received significant opposition from many groups that advocate for digital privacy rights, including the Electronic Frontier Foundation.[6]

During Facebook founder Mark Zuckerberg's testimony before Congress on April 10, 2018, in the aftermath of Facebook's scandal with Cambridge Analytica, Senator Dick Durbin questioned Zuckerberg about Facebook's support for SB3053.

Related state-level bills and laws

There are a number of similar bills that have been introduced in states across the country.[35] These include:

  • Michigan, 2017 Bill Text MI H.B. 5019
  • New Hampshire, 2017 Bill Text NH H.B. 523 (amended and passed in 2018 as NH H.B. 523)[36]
  • Alaska, 2017 Bill Text AK H.B. 72
  • Montana, 2017 Bill Text MT H.B. 518
  • New York, 2021 Assembly Bill 27[37] & Senate Bill 1933.[38]

Foreign equivalents

On May 25, 2018, the EU effectuated the General Data Protection Regulation (GDPR),[39] one of the world's strongest data protection regulations to date.[40]

References

  1. 1.0 1.1 1.2 1.3 "740 ILCS 14/20 Biometric Information Privacy Act.". October 3, 2008. https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004&ChapterID=57. 
  2. "BUSINESS AND COMMERCE CODE CHAPTER 503. BIOMETRIC IDENTIFIERS". https://statutes.capitol.texas.gov/Docs/BC/htm/BC.503.HTM. 
  3. "RCW 19.375.020: Enrollment, disclosure, and retention of biometric identifiers.". https://app.leg.wa.gov/RCW/default.aspx?cite=19.375.020. 
  4. 4.0 4.1 Neace, Gabrielle (2020). "Biometric Privacy: Blending Employment Law with the Growth of Technology". UIC J. Marshall L. Rev. 73: 75. https://repository.law.uic.edu/cgi/viewcontent.cgi?article=2811&context=lawreview. 
  5. "Biometric Privacy Litigation: The Next Class Action Battleground" (in en-US). https://biglawbusiness.com/biometric-privacy-litigation-the-next-class-action-battleground/. 
  6. 6.0 6.1 Schwartz, Adam (2018-04-10). "New Attack on the Illinois Biometric Privacy Act" (in en). Electronic Frontier Foundation. https://www.eff.org/deeplinks/2018/04/new-attack-illinois-biometric-privacy-act. 
  7. "ILGA". https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004&ChapterID=57. 
  8. "Lujan v. Defs. of Wildlife, 504 U.S. 555, 560 (1992)". https://www.law.cornell.edu/supremecourt/text/504/555. 
  9. "LRB Digest Indices". ftp://12.43.67.2/Digest/95thFinalDigest.pdf. 
  10. "Westlaw Sign In | Thomson Reuters" (in en). https://1.next.westlaw.com/Document/I529e8f60e6bd11e7af08dbc2fa7f734f/View/FullText.html?navigationPath=Search/v1/results/navigation/i0ad74037000001638ae7f171a8076a11?Nav=CASE&fragmentIdentifier=I529e8f60e6bd11e7af08dbc2fa7f734f&startIndex=1&contextData=%2528sc.Search%2529&transitionType=SearchItem&listSource=Search&listPageSource=a5bb3070c63f72f3abe7ab54c41662c1&list=ALL&rank=1&sessionScopeId=a50d2df8ce1e0f30112d6b6c94e836843a8d087bcb22d6ae04d275ca4432e8b5&originationContext=Search%20Result&transitionType=SearchItem&contextData=(sc.Search). 
  11. "Facebook-backed lawmakers are pushing to gut privacy law". The Verge. https://www.theverge.com/2018/4/10/17218756/facebook-biometric-privacy-lobbying-bipa-illinois. 
  12. Merkley, Jeff (2020-08-03). "Text - S.4400 - 116th Congress (2019-2020): National Biometric Information Privacy Act of 2020". https://www.congress.gov/bill/116th-congress/senate-bill/4400/text. 
  13. Shifrin, Dmitry (May 28, 2021). "Past, Present and Future: What's Happening with Illinois' and Other Biometric Privacy Laws". https://www.natlawreview.com/article/past-present-and-future-what-s-happening-illinois-and-other-biometric-privacy-laws. 
  14. "The Evolution of Biometric Data Privacy Laws" (in en-US). August 4, 2021. https://pro.bloomberglaw.com/brief/biometric-data-privacy-laws-and-lawsuits/. 
  15. Ibadi, Mona (December 7, 2020). "Protecting our Fingerprints and Retinas: A Call for Biometric Data Privacy Legislation". http://ipjournal.law.wfu.edu/2020/12/protecting-our-fingerprints-and-retinas-a-call-for-biometric-data-privacy-legislation/. 
  16. Minnis, Glenn (2018-03-02). "Employers facing surge in class action suits over storage, use of employee fingerprints, other biometrics" (in en). Cook County Record. https://cookcountyrecord.com/stories/511172229-employers-facing-surge-in-class-action-suits-over-storage-use-of-employee-fingerprints-other-biometrics. 
  17. "Facebook Users Win Class Cert. In Face Scan Privacy Row" (in en). April 16, 2018. https://www.law360.com/articles/1034143/facebook-users-win-class-cert-in-face-scan-privacy-row. 
  18. "Monroy v. Shutterfly, Inc., No. 1:2016cv10984 - Document 39 (N.D. Ill. 2017)" (in en). https://law.justia.com/cases/federal/district-courts/illinois/ilndce/1:2016cv10984/334068/39/. 
  19. Bilyk, Jonathan. "Judge won't short-circuit class action accusing Google Photos of breaking IL biometric privacy law" (in en). https://cookcountyrecord.com/stories/511086238-judge-won-t-short-circuit-class-action-accusing-google-photos-of-breaking-il-biometric-privacy-law. 
  20. "Rivera et al v. Google LLC., No. 1:2016cv02714 - Document 207 (N.D. Ill. 2018)" (in en). https://law.justia.com/cases/federal/district-courts/illinois/ilndce/1:2016cv02714/323329/207/. 
  21. 21.0 21.1 "McDonald v. Symphony Bronzeville Park LLC, N.E.3d (Ill. App. Ct. Sept. 18, 2020)" (in en). https://cases.justia.com/illinois/court-of-appeals-first-appellate-district/2020-1-19-2398.pdf?ts=1600474173. 
  22. Callow, Clingen; Molho, McLean LLC-Ross I.; Eikram, Iman (2021-05-21). "Perhaps Some Relief Under Illinois' Biometric Information Privacy Act." (in en). https://www.lexology.com/library/detail.aspx?g=b2316cc1-32a3-43f2-94f2-a716587ca255. 
  23. "Recent Illinois Appellate Court Ruling Could End The Recent Flood Of Class Action Lawsuits Against Employers Under Illinois' Biometric Information Privacy Act" (in en). Littler Mendelson P.C.. 2018-01-09. https://www.littler.com/publication-press/publication/recent-illinois-appellate-court-ruling-could-end-recent-flood-class. 
  24. Schwartz, Jennifer Lynch and Adam (2019-01-25). "Victory! Illinois Supreme Court Protects Biometric Privacy" (in en). https://www.eff.org/deeplinks/2019/01/victory-illinois-supreme-court-protects-biometric-privacy. 
  25. Torres, Louie. "NorthShore University HealthSystem allegedly collected worker fingerprints without consent" (in en). https://cookcountyrecord.com/stories/511371893-law-courts-northshore-university-healthsystem-allegedly-collected-worker-fingerprints-without-consent. 
  26. "First Settlement Reached Under Illinois Biometric Law" (in en-US). https://biglawbusiness.com/first-settlement-reached-under-illinois-biometric-law/. 
  27. "Winston & Strawn" (in en). https://www.winston.com/en/thought-leadership/biometric-privacy-litigation-the-next-class-action-battleground-1.html. 
  28. "In re Facebook Biometric Info. Privacy Litig.". https://casetext.com/case/in-re-facebook-biometric-info-privacy-litig-5. 
  29. "Judge Approves Facebook's $650M Privacy Settlement as 'Major Win for Consumers'". Law.com. February 26, 2021. https://www.law.com/therecorder/2021/02/26/judge-approves-facebooks-650m-privacy-settlement-as-major-win-for-consumers/?slreturn=20220125044045. 
  30. "Facebook Biometric Information Privacy Litigation". https://www.facebookbipaclassaction.com/. 
  31. "Illinois SB3053 | 2017-2018 | 100th General Assembly" (in en). LegiScan. https://legiscan.com/IL/text/SB3053/id/1731625. 
  32. "Facebook-backed lawmakers are pushing to gut privacy law". The Verge. https://www.theverge.com/2018/4/10/17218756/facebook-biometric-privacy-lobbying-bipa-illinois. 
  33. Marotti, Ally. "Proposed changes to Illinois' biometric law concern privacy advocates" (in en-US). chicagotribune.com. http://www.chicagotribune.com/business/ct-biz-illinois-biometrics-bills-20180409-story.html. 
  34. "Biometric Information Privacy" (in en-US). Technology Safety. https://www.techsafety.org/blog/2018/3/15/biometric-information-privacy. 
  35. "Biometric Information Protection: The Stage is Set for Expansion of Claims" (in en). https://www.lexisnexis.com/lexis-practice-advisor/the-journal/b/lpa/archive/2018/02/28/biometric-information-protection-the-stage-is-set-for-expansion-of-claims.aspx. 
  36. "Establishing a committee to study the use and regulation of biometric information". Act of May 17, 2018. New Hampshire State Legislature. https://legiscan.com/NH/bill/HB523/2018. 
  37. "Bill Search and Legislative Information | New York State Assembly". https://nyassembly.gov/leg/?default_fld=&leg_video=&bn=A00027&term=&Summary=Y&Text=Y. 
  38. "NY State Senate Bill S1933" (in en). 2021-01-16. https://www.nysenate.gov/legislation/bills/2021/s1933. 
  39. "General Data Protection Regulation.". April 27, 2016. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02016R0679-20160504&qid=1532348683434. 
  40. Fisher, Sandra L.; Bondarouk, Tanya (2020). "Encyclopedia of Electronic HRM". https://ris.utwente.nl/ws/files/221637852/Encyclopedia_of_Electronic_HRM_Frontmatter.pdf. 

External links