Illinois Biometric Information Privacy Act: What the Recent Cothron Decision Means for Per-Scan Claims
In Cothron v. White Castle System, Inc., the Illinois Supreme Court held that certain claims under the Biometric Information Privacy Act accrue each time an entity unlawfully collects or discloses biometric data, not merely the first time. The plaintiff alleged that employees scanned fingerprints to access workplace systems and that the scans were transmitted to a third-party vendor without the disclosures and consent BIPA requires. The ruling rejected the argument that only the first scan or transmission created a claim.
Per-scan accrual differs sharply from a single-injury theory. Under the single-injury approach, an employee who used a biometric timeclock for years might have only one claim arising when the system first captured the identifier. Cothron permits a claim to accrue with each noncompliant collection under Section 15(b) and each noncompliant disclosure under Section 15(d), subject to defenses, proof, limitations rules, and judicial discretion concerning damages.
The potential arithmetic is severe. BIPA authorizes liquidated damages of $1,000 for each negligent violation and $5,000 for each intentional or reckless violation, plus attorney fees, costs, and other relief. Thousands of employees scanning multiple times per shift can generate a theoretical figure far beyond the economic harm alleged. Cothron emphasized that damages are discretionary rather than automatically awarded at the statutory maximum for every violation, but that does not eliminate settlement or litigation risk.
Businesses and lawmakers have pursued reforms addressing repeated-scan exposure, electronic consent, limitation periods, and damage calculation. Because BIPA has been amended and additional proposals may alter how repeated collections are treated, counsel should verify the current statutory text rather than applying Cothron’s original damage model mechanically. Companies should also review insurance notice requirements early; delayed notice can create a separate coverage dispute.
Any entity using fingerprint timeclocks, facial-recognition access controls, voiceprints, retinal scans, or similar technology should identify the data collected, its purpose, every recipient, and the system’s deletion process. It should determine whether the information qualifies as a biometric identifier or biometric information, complete vendor diligence, restrict contractual use and disclosure, implement security controls, and suspend collection when valid consent or a required policy is missing.
Before collection, the entity should give a written notice explaining that biometric data is being collected or stored, state the specific purpose and length of term, and obtain a written release. It must maintain a publicly available retention and destruction policy providing for timely deletion when the initial purpose is satisfied or within the statutory outside limit. Compliance should be documented, audited, and refreshed when technology, vendors, purposes, or workforce practices change.