Glossary
BIPA (Biometric Information Privacy Act)
BIPA, the Illinois Biometric Information Privacy Act (740 ILCS 14), regulates collecting biometric identifiers like face geometry, fingerprints, and voiceprints: it requires written notice, a published retention policy, and consent before collection, and it gives individuals a private right of action with statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless one. It is the strictest biometric law in the US and the engine behind some of the largest privacy settlements on record.
Why the numbers get enormous
BIPA's private right of action plus per-violation statutory damages built nine-figure outcomes: Facebook settled face-tagging claims for $650M, and TikTok paid $92M over biometric allegations. The Illinois Supreme Court's Cothron v. White Castle decision held claims accrue per scan, a holding so explosive that the legislature amended the statute in 2024 to cap recovery at one per person per method of collection. Even amended, a few thousand Illinois users times statutory damages is existential math for a small business.
How a website triggers it
You don't need a fingerprint reader. Web-facing BIPA exposure comes from features that process face geometry in uploaded photos or camera streams: virtual try-on widgets, photo-tagging or avatar tools, identity-verification flows, and third-party scripts that run face detection client-side. The trap is vendor-shaped: a site embeds a try-on SDK, the SDK computes a face map, and no notice, consent, or retention policy exists because nobody realized biometrics were in play. Texas and Washington have biometric statutes too (AG-enforced), and several state privacy laws classify biometric data as sensitive, but BIPA's private right of action is why Illinois drives the litigation.
How Complidar checks this
Complidar's biometric check looks for the website-visible indicators: camera-permission requests, face-detection and try-on SDKs, identity-verification widgets, and whether the privacy policy contains the BIPA-required notice, consent, and retention language when those features are present.
Related questions
Does BIPA apply if my business isn't in Illinois?
BIPA protects Illinois residents. Courts have applied it to out-of-state companies whose sites collected biometrics from people in Illinois. If your site offers a face-processing feature and Illinois visitors use it, assume exposure and confirm with counsel; geography of your headquarters isn't the test.
Is a face filter or virtual try-on really 'biometrics'?
If the feature computes face geometry (landmarks, measurements, a face map), that's the 'biometric identifier' the statute regulates, regardless of whether you store it. Vendors often argue the processing is ephemeral or on-device; plaintiffs litigate it anyway, and the consent/notice requirements are cheap compared to the argument.
What does BIPA compliance on a website look like?
Before any face-processing feature runs: written notice of what's collected and why, consent captured affirmatively, and a public retention-and-destruction policy. Mechanically, that's a consent gate in front of the feature and specific language in the privacy policy: both visible from outside, both scannable.
22 checks · up to 120 pages · no card
Last updated 2026-06-11 · Informational, not legal advice