By Steve Levine · Updated July 2, 2026 · 8 min read
A biometric data breach is the unauthorized exposure, collection, or disclosure of biometric identifiers — fingerprints, faceprints, voiceprints, iris or retina scans, hand geometry — or the templates derived from them. Unlike a password or card number, a biometric identifier is biologically permanent: it cannot be reset or reissued, so its exposure is a lasting harm. The Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14, is the leading law in this area. It requires informed written consent and public retention-and-destruction schedules, and its private right of action carries liquidated damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation — the engine behind hundreds of biometric class actions, from workplace fingerprint timeclocks to face-scanning apps.
Free settlement alerts
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
Biometric identifiers are measurements of your unique biological traits. The Illinois Biometric Information Privacy Act lists retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry. Biometric information is any data derived from those identifiers that is used to identify a person — for example, the mathematical template a fingerprint timeclock stores instead of the fingerprint image itself. Photographs and writing samples are generally excluded, but a faceprint template generated from a photo can still qualify.
Because biometrics are immutable. If a password, credit card number, or even a Social Security number is exposed, it can be changed, reissued, or monitored. Your fingerprints, face geometry, and iris patterns are biologically permanent — once a usable template is exposed, you cannot get a new fingerprint. That is why courts and legislatures treat biometric exposure as a lasting injury and why statutes like BIPA impose strict consent and destruction requirements.
BIPA gives a prevailing party the greater of actual damages or liquidated (statutory) damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation, plus reasonable attorneys' fees and costs and possible injunctive relief. A 2024 amendment provides that when a company collects the same biometric identifier from the same person by the same method multiple times, that counts as a single violation for damages purposes — limiting the per-scan exposure recognized in Cothron v. White Castle.
No. In Rosenbach v. Six Flags Entertainment Corp. (2019), the Illinois Supreme Court held that a person is "aggrieved" under BIPA — and may sue — when a company violates the statute's notice, consent, or retention requirements, even without proving any additional injury like identity theft. The violation of the biometric privacy right is itself the harm the statute protects against.
Yes, but Illinois is the only state whose standalone biometric statute lets individuals sue directly. Texas's Capture or Use of Biometric Identifier Act (CUBI) and Washington's biometric privacy law (RCW 19.375) both regulate biometric collection, but only the state attorney general can enforce them — there is no private right of action. Some other states cover biometric data through broader data-breach-notification or comprehensive privacy laws, and more states consider BIPA-style bills each year.
HOT