Skip to content

Evidence request lists

Illinois Biometric Information Privacy Act (BIPA)

Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Assurance

BIPA-AUDIT
Periodic Audit and Compliance Review

Conduct periodic audits of biometric programmes against BIPA requirements, including notice, consent, retention, destruction, vendor flow-down, and security.

Artefacts an auditor will ask for
  • Annual BIPA audit report
  • Findings register with owners
  • Management review minutes
  • Corrective action closure evidence
Where this commonly fails
  • No periodic audit
  • Findings not tracked to closure
  • No management review

Consent and Notice Requirements

BIPA-SEC15a
Written Informed Consent Required

No private entity may collect, capture, purchase, receive through trade, or otherwise obtain a person's biometric identifier or biometric information unless it first: (1) informs the subject in writing of the collection; (2) informs the subject of the specific purpose and length of term for which the data will be collected, stored, and used; and (3) receives a written release from the subject (Section 15(a)).

Artefacts an auditor will ask for
  • Written biometric consent forms
  • Retention and destruction schedule
  • Biometric data storage security controls
  • Disclosure log and prohibition attestation
  • Litigation and settlement file
Where this commonly fails
  • Written informed consent missing or generic
  • Retention schedule exceeds statutory 3-year ceiling
  • Disclosure to third parties not logged
  • No publicly available biometric data policy
BIPA-SEC15b
Disclosure and Profit Prohibition

No private entity in possession of a biometric identifier or biometric information may sell, lease, trade, or otherwise profit from a person's biometric identifier or biometric information (Section 15(b)).

Artefacts an auditor will ask for
  • Written biometric consent forms
  • Retention and destruction schedule
  • Biometric data storage security controls
  • Disclosure log and prohibition attestation
  • Litigation and settlement file
Where this commonly fails
  • Written informed consent missing or generic
  • Retention schedule exceeds statutory 3-year ceiling
  • Disclosure to third parties not logged
  • No publicly available biometric data policy
BIPA-SEC15c
Disclosure Restriction

No private entity in possession of a biometric identifier or biometric information may disclose, redisclose, or otherwise disseminate a person's biometric identifier or biometric information unless: (1) the subject consents; (2) disclosure completes a financial transaction requested by the subject; (3) required by State or federal law; or (4) required by a valid warrant or subpoena (Section 15(c)).

Artefacts an auditor will ask for
  • Written biometric consent forms
  • Retention and destruction schedule
  • Biometric data storage security controls
  • Disclosure log and prohibition attestation
  • Litigation and settlement file
Where this commonly fails
  • Written informed consent missing or generic
  • Retention schedule exceeds statutory 3-year ceiling
  • Disclosure to third parties not logged
  • No publicly available biometric data policy

Data Handling and Security

BIPA-SEC15d
Retention and Destruction Policy

A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, establishing a retention schedule and guidelines for permanently destroying biometric data when the initial purpose has been satisfied or within 3 years of the individual's last interaction with the private entity, whichever occurs first (Section 15(d)).

Artefacts an auditor will ask for
  • Written biometric consent forms
  • Retention and destruction schedule
  • Biometric data storage security controls
  • Disclosure log and prohibition attestation
  • Litigation and settlement file
Where this commonly fails
  • Written informed consent missing or generic
  • Retention schedule exceeds statutory 3-year ceiling
  • Disclosure to third parties not logged
  • No publicly available biometric data policy
BIPA-SEC15e
Storage and Protection Requirements

A private entity in possession of biometric identifiers or biometric information must store, transmit, and protect from disclosure all biometric identifiers and biometric information using the reasonable standard of care within the private entity's industry. Storage and protection must be at least as protective as the entity's standard for other confidential and sensitive information (Section 15(e)).

Artefacts an auditor will ask for
  • Written biometric consent forms
  • Retention and destruction schedule
  • Biometric data storage security controls
  • Disclosure log and prohibition attestation
  • Litigation and settlement file
Where this commonly fails
  • Written informed consent missing or generic
  • Retention schedule exceeds statutory 3-year ceiling
  • Disclosure to third parties not logged
  • No publicly available biometric data policy

Definitions and Scope

7012(a)
Definitions

Defines key terms including adequate security, covered defence information, cyber incident, and covered contractor information system.

Artefacts an auditor will ask for
  • CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
  • Data inventory tagged with PA 23-56 consumer health data flags
  • Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
  • Processor vs controller role determination log
Where this commonly fails
  • Applicability re-run not triggered when revenue mix shifts
  • Consumer health data not separated from general sensitive data
  • Pseudonymous data treated as out of scope without safeguards review
  • B2B contact data assumed exempt past PA 23-56 effective date
7012(b)(1)
Covered Defence Information Identification

CDI includes controlled technical information or other information requiring safeguarding marked or identified in the contract.

Artefacts an auditor will ask for
  • CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
  • Data inventory tagged with PA 23-56 consumer health data flags
  • Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
  • Processor vs controller role determination log
Where this commonly fails
  • Applicability re-run not triggered when revenue mix shifts
  • Consumer health data not separated from general sensitive data
  • Pseudonymous data treated as out of scope without safeguards review
  • B2B contact data assumed exempt past PA 23-56 effective date
7012(b)(2)
Scope of Protected Systems

Requirements apply to covered contractor information systems that process, store, or transmit covered defence information.

Artefacts an auditor will ask for
  • CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
  • Data inventory tagged with PA 23-56 consumer health data flags
  • Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
  • Processor vs controller role determination log
Where this commonly fails
  • Applicability re-run not triggered when revenue mix shifts
  • Consumer health data not separated from general sensitive data
  • Pseudonymous data treated as out of scope without safeguards review
  • B2B contact data assumed exempt past PA 23-56 effective date
7012(b)(3)
COTS Exclusion

Commercial off-the-shelf items are excluded from the safeguarding requirements of the clause.

Artefacts an auditor will ask for
  • CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
  • Data inventory tagged with PA 23-56 consumer health data flags
  • Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
  • Processor vs controller role determination log
Where this commonly fails
  • Applicability re-run not triggered when revenue mix shifts
  • Consumer health data not separated from general sensitive data
  • Pseudonymous data treated as out of scope without safeguards review
  • B2B contact data assumed exempt past PA 23-56 effective date
BIPA-SEC5-1
Biometric Identifier Definition

Biometric identifier means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. Does NOT include writing samples, written signatures, photographs, human biological samples used for valid scientific testing or screening, demographic data, tattoo descriptions, or physical descriptions (Section 10).

Artefacts an auditor will ask for
  • CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
  • Data inventory tagged with PA 23-56 consumer health data flags
  • Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
  • Processor vs controller role determination log
Where this commonly fails
  • Applicability re-run not triggered when revenue mix shifts
  • Consumer health data not separated from general sensitive data
  • Pseudonymous data treated as out of scope without safeguards review
  • B2B contact data assumed exempt past PA 23-56 effective date
BIPA-SEC5-2
Biometric Information Definition

Biometric information means any information based on an individual's biometric identifier used to identify an individual, regardless of how it is captured, converted, stored, or shared (Section 10).

Artefacts an auditor will ask for
  • CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
  • Data inventory tagged with PA 23-56 consumer health data flags
  • Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
  • Processor vs controller role determination log
Where this commonly fails
  • Applicability re-run not triggered when revenue mix shifts
  • Consumer health data not separated from general sensitive data
  • Pseudonymous data treated as out of scope without safeguards review
  • B2B contact data assumed exempt past PA 23-56 effective date
BIPA-SEC5-3
Private Entity Definition

Private entity means any individual, partnership, corporation, limited liability company, association, or other group, however organized. Does not include a State or local government agency, or any court of Illinois (Section 10).

Artefacts an auditor will ask for
  • CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
  • Data inventory tagged with PA 23-56 consumer health data flags
  • Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
  • Processor vs controller role determination log
Where this commonly fails
  • Applicability re-run not triggered when revenue mix shifts
  • Consumer health data not separated from general sensitive data
  • Pseudonymous data treated as out of scope without safeguards review
  • B2B contact data assumed exempt past PA 23-56 effective date
CTDPA-1
Definitions

Defines consumer, controller, processor, personal data, sensitive data, and other key terms

Artefacts an auditor will ask for
  • Term-by-term mapping of § 42-515 definitions (consumer, controller, processor, sale, targeted advertising, sensitive data)
  • Consumer health data definitions log under PA 23-56 § 1 amendments
  • Pseudonymous data treatment SOP
  • Definitions delta vs CPRA, CPA, VCDPA, UCPA
Where this commonly fails
  • Definitions not refreshed after PA 23-56 expanded sensitive data
  • Consumer scope misapplied to employees or B2B contacts
  • Targeted advertising definition not coded into ad stack
  • Sale definition narrowed below statutory threshold in vendor contracts
CTDPA-2
Applicability Thresholds

Applies to entities processing data of 100K consumers or 25K consumers deriving 25% revenue from data sales

Artefacts an auditor will ask for
  • Annual threshold recalculation (100,000 consumers OR 25,000 consumers + 25% gross revenue from sale)
  • Entity-level exemption memo (state agency, nonprofit (post-PA 23-56 narrowed), higher ed, GLBA, HIPAA)
  • Data-level exemption matrix (HIPAA PHI, GLBA NPI, FCRA, FERPA, Driver's Privacy Protection Act)
  • Trigger event log when thresholds change mid-year
Where this commonly fails
  • Nonprofit exemption assumed without checking PA 23-56 narrowed scope
  • Threshold recomputed only annually, missing mid-year breaches
  • Data-level exemptions used to skip CTDPA without record-level segregation
  • Group entities not assessed individually
MSA-5
Definition of Modern Slavery

Modern slavery is defined to include trafficking in persons, slavery and slavery-like practices (servitude, forced labour, forced marriage, debt bondage), and the worst forms of child labour (s 5).

Artefacts an auditor will ask for
  • CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
  • Data inventory tagged with PA 23-56 consumer health data flags
  • Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
  • Processor vs controller role determination log
Where this commonly fails
  • Applicability re-run not triggered when revenue mix shifts
  • Consumer health data not separated from general sensitive data
  • Pseudonymous data treated as out of scope without safeguards review
  • B2B contact data assumed exempt past PA 23-56 effective date
MSA-Commonwealth
Commonwealth Entities

Non-corporate Commonwealth entities must also comply with modern slavery reporting requirements regardless of revenue.

Artefacts an auditor will ask for
  • CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
  • Data inventory tagged with PA 23-56 consumer health data flags
  • Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
  • Processor vs controller role determination log
Where this commonly fails
  • Applicability re-run not triggered when revenue mix shifts
  • Consumer health data not separated from general sensitive data
  • Pseudonymous data treated as out of scope without safeguards review
  • B2B contact data assumed exempt past PA 23-56 effective date
MSA-Threshold
Revenue Threshold

The reporting threshold is A$100 million consolidated revenue for the reporting period. The Minister may reduce this threshold by legislative instrument.

Artefacts an auditor will ask for
  • CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
  • Data inventory tagged with PA 23-56 consumer health data flags
  • Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
  • Processor vs controller role determination log
Where this commonly fails
  • Applicability re-run not triggered when revenue mix shifts
  • Consumer health data not separated from general sensitive data
  • Pseudonymous data treated as out of scope without safeguards review
  • B2B contact data assumed exempt past PA 23-56 effective date

Destruction

BIPA-SEC15A-DESTROY
Destruction When Purpose Satisfied or Three Years Inactive

Permanently destroy biometric data when the initial purpose has been satisfied or within three years of the individual's last interaction, whichever occurs first.

Artefacts an auditor will ask for
  • Last activity timestamp per subject
  • Automated destruction job logs
  • Destruction certificates from vendors
  • Exception tracking
Where this commonly fails
  • No last-interaction tracking
  • Manual destruction prone to misses
  • Vendors retain copies

Disclosure

BIPA-SEC15D-DISCLOSE
Disclosure Restrictions

Do not disclose, redisclose, or otherwise disseminate biometric data without subject consent, except where required by law, valid subpoena, or to complete a financial transaction requested by the subject, per Section 15(d).

Artefacts an auditor will ask for
  • Disclosure log with basis
  • Subpoena handling procedure
  • Vendor data flow inventory
  • Consent records for disclosures
Where this commonly fails
  • Disclosures to cloud processors without consent assessment
  • No log of legal requests
  • Marketing analytics partners unrestricted

Incident response

BIPA-INCIDENT
Incident Response for Biometric Compromise

Maintain an incident response plan addressing suspected biometric data compromise, including investigation, notification considerations, and remediation given the irrevocable nature of biometrics.

Artefacts an auditor will ask for
  • BIPA-specific IR playbook
  • Tabletop exercise records
  • PIPA breach notification analysis (815 ILCS 530)
  • Post-incident reports
Where this commonly fails
  • No biometric-specific scenario in IR plan
  • PIPA notification not considered
  • No tabletop

Liability

BIPA-PRA
Private Right of Action and Statutory Damages

Recognise individuals' private right of action with statutory damages of USD 1,000 per negligent violation and USD 5,000 per intentional or reckless violation, plus attorneys' fees and injunctive relief, per Section 20.

Artefacts an auditor will ask for
  • Cyber/EPLI insurance schedule covering BIPA
  • Reserve estimates per scan event
  • Litigation hold procedures
  • Class action defence plan
Where this commonly fails
  • No BIPA-specific insurance
  • Per-scan exposure not modelled (Cothron v. White Castle)
  • No litigation hold

Notice and consent

BIPA-SEC15B-CONSENT
Written Release (Informed Consent)

Obtain a written release executed by the subject (or legally authorised representative) before collecting, capturing, purchasing, receiving through trade, or otherwise obtaining biometric data, per Section 15(b)(3).

Artefacts an auditor will ask for
  • Wet or electronic signature records
  • Identity verification at signing
  • Release storage system
  • Audit trail per subject
Where this commonly fails
  • Implied consent only
  • No record of who signed
  • Consent bundled in long employment agreement
BIPA-SEC15B-NOTICE
Written Notice Before Collection

Before collecting biometric identifiers or information, inform the subject in writing that the data is being collected or stored, the specific purpose, and the length of term for collection, storage, and use, per Section 15(b)(1)-(2).

Artefacts an auditor will ask for
  • Notice form or screen
  • Purpose-specific text
  • Term-of-use disclosure
  • Timestamp of notice delivery
Where this commonly fails
  • Notice generic, no specific purpose
  • No term disclosed
  • Notice after collection

Policy

BIPA-SEC15A-POLICY
Written Retention and Destruction Policy

Develop a publicly available written policy establishing a retention schedule and destruction guidelines for biometric identifiers and information, in line with Section 15(a).

Artefacts an auditor will ask for
  • Published BIPA policy on website
  • Retention schedule by data type
  • Destruction procedures
  • Policy version history
Where this commonly fails
  • Policy exists but not public
  • No defined destruction timeline
  • Policy never updated

Prohibited disclosures

BIPA-SEC15C-PROFIT
No Sale, Lease, Trade, or Profit

Do not sell, lease, trade, or otherwise profit from a person's biometric identifier or information, per Section 15(c).

Artefacts an auditor will ask for
  • Revenue source mapping
  • Contracts confirming no biometric monetisation
  • Marketing data flows review
  • Internal policy prohibiting sale
Where this commonly fails
  • Biometric data licensed to analytics partners
  • Data shared in mergers without restriction
  • Indirect monetisation through derived features

Risk recognition

BIPA-IRRECOV
Irreversible Harm and Special Risk Recognition

Acknowledge in policy and risk register that biometric identifiers are biologically unique and, once compromised, cannot be reissued or replaced like a password, justifying heightened protection.

Artefacts an auditor will ask for
  • BIPA risk in enterprise risk register
  • Policy statement on irrevocability
  • Board briefing slides
  • Privacy impact assessments
Where this commonly fails
  • Biometric risk not in risk register
  • Treated equivalently to passwords
  • No board visibility

Scope

BIPA-EXEMPT
Statutory Exemptions

Confirm whether the entity or specific activity qualifies for exemptions such as financial institutions subject to GLBA, certain healthcare uses, or specific government contractors, per Section 25.

Artefacts an auditor will ask for
  • Exemption memo with legal review
  • Activity-by-activity scoping
  • Annual reconfirmation
  • Carve-out documentation
Where this commonly fails
  • GLBA exemption claimed for non-financial activities
  • Healthcare exemption stretched
  • No annual review
BIPA-SEC10-DEF
Biometric Identifier and Information Definitions

Identify all biometric identifiers (retina/iris scan, fingerprint, voiceprint, scan of hand or face geometry) and biometric information derived from them, as defined in 740 ILCS 14/10.

Artefacts an auditor will ask for
  • Biometric data inventory
  • System list capturing biometrics
  • Exclusion memo (writing samples, signatures, photographs without face geometry)
  • Data flow diagrams
Where this commonly fails
  • Face recognition deployed without classifying it as biometric
  • Voice authentication systems excluded by mistake
  • No inventory

Security

BIPA-SEC15E-STORE
Reasonable Standard of Care and Storage Protections

Store, transmit, and protect biometric data using the reasonable standard of care within the entity's industry, and in a manner the same as or more protective than other confidential and sensitive information, per Section 15(e).

Artefacts an auditor will ask for
  • Encryption at rest and in transit evidence
  • Role-based access control matrix
  • Industry standard benchmark (ISO 27001, NIST)
  • Penetration test reports
Where this commonly fails
  • Biometric templates stored unencrypted
  • Same access as ordinary HR data
  • No industry benchmark

Special subjects

BIPA-MINORS
Minors and Authorised Representatives

Where biometrics are collected from minors, obtain the written release from a legally authorised representative and apply appropriate safeguards.

Artefacts an auditor will ask for
  • Age gating
  • Parental release forms
  • Verification of authority
  • Separate storage for minors' data
Where this commonly fails
  • No age verification
  • Parental release missing
  • Minors' data co-mingled with adults

Third parties

BIPA-VENDOR
Vendor and Processor Contracts

Bind vendors processing biometric data on the entity's behalf to BIPA obligations including notice support, consent capture, retention, destruction, security, and prohibition on resale.

Artefacts an auditor will ask for
  • BIPA addenda with vendors
  • Vendor security questionnaires
  • Data return or destruction certificates
  • Sub-vendor approval records
Where this commonly fails
  • Standard MSA without BIPA terms
  • No destruction certificate at end
  • Sub-vendors not approved

Training

BIPA-TRAIN
Workforce Training

Train staff responsible for biometric systems on BIPA notice, consent, retention, destruction, disclosure, and security obligations.

Artefacts an auditor will ask for
  • BIPA training module
  • Completion records for HR, IT, security, vendors
  • Role-based training matrix
  • Annual refresh schedule
Where this commonly fails
  • No BIPA-specific training
  • Vendor staff not trained
  • No annual refresh

Workforce

BIPA-EMPLOYEE
Employee Biometric Programs (Timekeeping, Access)

Apply BIPA notice, consent, retention, and destruction obligations to employee biometric systems such as fingerprint timeclocks, palm scanners, and facial recognition turnstiles.

Artefacts an auditor will ask for
  • Employee onboarding consent form
  • Vendor BIPA addendum (timeclock provider)
  • Termination-triggered destruction
  • Annual employee re-notice if changes
Where this commonly fails
  • Timeclock vendor retains data after termination
  • No employee consent on file pre-BIPA
  • No vendor flow-down
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Illinois Biometric Information Privacy Act (BIPA) framework page.