Illinois Biometric Information Privacy Act (BIPA)
Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Assurance
Conduct periodic audits of biometric programmes against BIPA requirements, including notice, consent, retention, destruction, vendor flow-down, and security.
- Annual BIPA audit report
- Findings register with owners
- Management review minutes
- Corrective action closure evidence
- No periodic audit
- Findings not tracked to closure
- No management review
Consent and Notice Requirements
No private entity may collect, capture, purchase, receive through trade, or otherwise obtain a person's biometric identifier or biometric information unless it first: (1) informs the subject in writing of the collection; (2) informs the subject of the specific purpose and length of term for which the data will be collected, stored, and used; and (3) receives a written release from the subject (Section 15(a)).
- Written biometric consent forms
- Retention and destruction schedule
- Biometric data storage security controls
- Disclosure log and prohibition attestation
- Litigation and settlement file
- Written informed consent missing or generic
- Retention schedule exceeds statutory 3-year ceiling
- Disclosure to third parties not logged
- No publicly available biometric data policy
No private entity in possession of a biometric identifier or biometric information may sell, lease, trade, or otherwise profit from a person's biometric identifier or biometric information (Section 15(b)).
- Written biometric consent forms
- Retention and destruction schedule
- Biometric data storage security controls
- Disclosure log and prohibition attestation
- Litigation and settlement file
- Written informed consent missing or generic
- Retention schedule exceeds statutory 3-year ceiling
- Disclosure to third parties not logged
- No publicly available biometric data policy
No private entity in possession of a biometric identifier or biometric information may disclose, redisclose, or otherwise disseminate a person's biometric identifier or biometric information unless: (1) the subject consents; (2) disclosure completes a financial transaction requested by the subject; (3) required by State or federal law; or (4) required by a valid warrant or subpoena (Section 15(c)).
- Written biometric consent forms
- Retention and destruction schedule
- Biometric data storage security controls
- Disclosure log and prohibition attestation
- Litigation and settlement file
- Written informed consent missing or generic
- Retention schedule exceeds statutory 3-year ceiling
- Disclosure to third parties not logged
- No publicly available biometric data policy
Data Handling and Security
A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, establishing a retention schedule and guidelines for permanently destroying biometric data when the initial purpose has been satisfied or within 3 years of the individual's last interaction with the private entity, whichever occurs first (Section 15(d)).
- Written biometric consent forms
- Retention and destruction schedule
- Biometric data storage security controls
- Disclosure log and prohibition attestation
- Litigation and settlement file
- Written informed consent missing or generic
- Retention schedule exceeds statutory 3-year ceiling
- Disclosure to third parties not logged
- No publicly available biometric data policy
A private entity in possession of biometric identifiers or biometric information must store, transmit, and protect from disclosure all biometric identifiers and biometric information using the reasonable standard of care within the private entity's industry. Storage and protection must be at least as protective as the entity's standard for other confidential and sensitive information (Section 15(e)).
- Written biometric consent forms
- Retention and destruction schedule
- Biometric data storage security controls
- Disclosure log and prohibition attestation
- Litigation and settlement file
- Written informed consent missing or generic
- Retention schedule exceeds statutory 3-year ceiling
- Disclosure to third parties not logged
- No publicly available biometric data policy
Definitions and Scope
Defines key terms including adequate security, covered defence information, cyber incident, and covered contractor information system.
- CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
- Data inventory tagged with PA 23-56 consumer health data flags
- Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
- Processor vs controller role determination log
- Applicability re-run not triggered when revenue mix shifts
- Consumer health data not separated from general sensitive data
- Pseudonymous data treated as out of scope without safeguards review
- B2B contact data assumed exempt past PA 23-56 effective date
CDI includes controlled technical information or other information requiring safeguarding marked or identified in the contract.
- CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
- Data inventory tagged with PA 23-56 consumer health data flags
- Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
- Processor vs controller role determination log
- Applicability re-run not triggered when revenue mix shifts
- Consumer health data not separated from general sensitive data
- Pseudonymous data treated as out of scope without safeguards review
- B2B contact data assumed exempt past PA 23-56 effective date
Requirements apply to covered contractor information systems that process, store, or transmit covered defence information.
- CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
- Data inventory tagged with PA 23-56 consumer health data flags
- Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
- Processor vs controller role determination log
- Applicability re-run not triggered when revenue mix shifts
- Consumer health data not separated from general sensitive data
- Pseudonymous data treated as out of scope without safeguards review
- B2B contact data assumed exempt past PA 23-56 effective date
Commercial off-the-shelf items are excluded from the safeguarding requirements of the clause.
- CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
- Data inventory tagged with PA 23-56 consumer health data flags
- Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
- Processor vs controller role determination log
- Applicability re-run not triggered when revenue mix shifts
- Consumer health data not separated from general sensitive data
- Pseudonymous data treated as out of scope without safeguards review
- B2B contact data assumed exempt past PA 23-56 effective date
Biometric identifier means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. Does NOT include writing samples, written signatures, photographs, human biological samples used for valid scientific testing or screening, demographic data, tattoo descriptions, or physical descriptions (Section 10).
- CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
- Data inventory tagged with PA 23-56 consumer health data flags
- Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
- Processor vs controller role determination log
- Applicability re-run not triggered when revenue mix shifts
- Consumer health data not separated from general sensitive data
- Pseudonymous data treated as out of scope without safeguards review
- B2B contact data assumed exempt past PA 23-56 effective date
Biometric information means any information based on an individual's biometric identifier used to identify an individual, regardless of how it is captured, converted, stored, or shared (Section 10).
- CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
- Data inventory tagged with PA 23-56 consumer health data flags
- Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
- Processor vs controller role determination log
- Applicability re-run not triggered when revenue mix shifts
- Consumer health data not separated from general sensitive data
- Pseudonymous data treated as out of scope without safeguards review
- B2B contact data assumed exempt past PA 23-56 effective date
Private entity means any individual, partnership, corporation, limited liability company, association, or other group, however organized. Does not include a State or local government agency, or any court of Illinois (Section 10).
- CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
- Data inventory tagged with PA 23-56 consumer health data flags
- Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
- Processor vs controller role determination log
- Applicability re-run not triggered when revenue mix shifts
- Consumer health data not separated from general sensitive data
- Pseudonymous data treated as out of scope without safeguards review
- B2B contact data assumed exempt past PA 23-56 effective date
Defines consumer, controller, processor, personal data, sensitive data, and other key terms
- Term-by-term mapping of § 42-515 definitions (consumer, controller, processor, sale, targeted advertising, sensitive data)
- Consumer health data definitions log under PA 23-56 § 1 amendments
- Pseudonymous data treatment SOP
- Definitions delta vs CPRA, CPA, VCDPA, UCPA
- Definitions not refreshed after PA 23-56 expanded sensitive data
- Consumer scope misapplied to employees or B2B contacts
- Targeted advertising definition not coded into ad stack
- Sale definition narrowed below statutory threshold in vendor contracts
Applies to entities processing data of 100K consumers or 25K consumers deriving 25% revenue from data sales
- Annual threshold recalculation (100,000 consumers OR 25,000 consumers + 25% gross revenue from sale)
- Entity-level exemption memo (state agency, nonprofit (post-PA 23-56 narrowed), higher ed, GLBA, HIPAA)
- Data-level exemption matrix (HIPAA PHI, GLBA NPI, FCRA, FERPA, Driver's Privacy Protection Act)
- Trigger event log when thresholds change mid-year
- Nonprofit exemption assumed without checking PA 23-56 narrowed scope
- Threshold recomputed only annually, missing mid-year breaches
- Data-level exemptions used to skip CTDPA without record-level segregation
- Group entities not assessed individually
Modern slavery is defined to include trafficking in persons, slavery and slavery-like practices (servitude, forced labour, forced marriage, debt bondage), and the worst forms of child labour (s 5).
- CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
- Data inventory tagged with PA 23-56 consumer health data flags
- Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
- Processor vs controller role determination log
- Applicability re-run not triggered when revenue mix shifts
- Consumer health data not separated from general sensitive data
- Pseudonymous data treated as out of scope without safeguards review
- B2B contact data assumed exempt past PA 23-56 effective date
Non-corporate Commonwealth entities must also comply with modern slavery reporting requirements regardless of revenue.
- CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
- Data inventory tagged with PA 23-56 consumer health data flags
- Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
- Processor vs controller role determination log
- Applicability re-run not triggered when revenue mix shifts
- Consumer health data not separated from general sensitive data
- Pseudonymous data treated as out of scope without safeguards review
- B2B contact data assumed exempt past PA 23-56 effective date
The reporting threshold is A$100 million consolidated revenue for the reporting period. The Minister may reduce this threshold by legislative instrument.
- CTDPA applicability worksheet (100K consumer / 25K + 25% revenue thresholds)
- Data inventory tagged with PA 23-56 consumer health data flags
- Entity-level exemption memo (GLBA, HIPAA, nonprofit, higher ed)
- Processor vs controller role determination log
- Applicability re-run not triggered when revenue mix shifts
- Consumer health data not separated from general sensitive data
- Pseudonymous data treated as out of scope without safeguards review
- B2B contact data assumed exempt past PA 23-56 effective date
Destruction
Permanently destroy biometric data when the initial purpose has been satisfied or within three years of the individual's last interaction, whichever occurs first.
- Last activity timestamp per subject
- Automated destruction job logs
- Destruction certificates from vendors
- Exception tracking
- No last-interaction tracking
- Manual destruction prone to misses
- Vendors retain copies
Disclosure
Do not disclose, redisclose, or otherwise disseminate biometric data without subject consent, except where required by law, valid subpoena, or to complete a financial transaction requested by the subject, per Section 15(d).
- Disclosure log with basis
- Subpoena handling procedure
- Vendor data flow inventory
- Consent records for disclosures
- Disclosures to cloud processors without consent assessment
- No log of legal requests
- Marketing analytics partners unrestricted
Incident response
Maintain an incident response plan addressing suspected biometric data compromise, including investigation, notification considerations, and remediation given the irrevocable nature of biometrics.
- BIPA-specific IR playbook
- Tabletop exercise records
- PIPA breach notification analysis (815 ILCS 530)
- Post-incident reports
- No biometric-specific scenario in IR plan
- PIPA notification not considered
- No tabletop
Liability
Recognise individuals' private right of action with statutory damages of USD 1,000 per negligent violation and USD 5,000 per intentional or reckless violation, plus attorneys' fees and injunctive relief, per Section 20.
- Cyber/EPLI insurance schedule covering BIPA
- Reserve estimates per scan event
- Litigation hold procedures
- Class action defence plan
- No BIPA-specific insurance
- Per-scan exposure not modelled (Cothron v. White Castle)
- No litigation hold
Notice and consent
Obtain a written release executed by the subject (or legally authorised representative) before collecting, capturing, purchasing, receiving through trade, or otherwise obtaining biometric data, per Section 15(b)(3).
- Wet or electronic signature records
- Identity verification at signing
- Release storage system
- Audit trail per subject
- Implied consent only
- No record of who signed
- Consent bundled in long employment agreement
Before collecting biometric identifiers or information, inform the subject in writing that the data is being collected or stored, the specific purpose, and the length of term for collection, storage, and use, per Section 15(b)(1)-(2).
- Notice form or screen
- Purpose-specific text
- Term-of-use disclosure
- Timestamp of notice delivery
- Notice generic, no specific purpose
- No term disclosed
- Notice after collection
Policy
Develop a publicly available written policy establishing a retention schedule and destruction guidelines for biometric identifiers and information, in line with Section 15(a).
- Published BIPA policy on website
- Retention schedule by data type
- Destruction procedures
- Policy version history
- Policy exists but not public
- No defined destruction timeline
- Policy never updated
Prohibited disclosures
Do not sell, lease, trade, or otherwise profit from a person's biometric identifier or information, per Section 15(c).
- Revenue source mapping
- Contracts confirming no biometric monetisation
- Marketing data flows review
- Internal policy prohibiting sale
- Biometric data licensed to analytics partners
- Data shared in mergers without restriction
- Indirect monetisation through derived features
Risk recognition
Acknowledge in policy and risk register that biometric identifiers are biologically unique and, once compromised, cannot be reissued or replaced like a password, justifying heightened protection.
- BIPA risk in enterprise risk register
- Policy statement on irrevocability
- Board briefing slides
- Privacy impact assessments
- Biometric risk not in risk register
- Treated equivalently to passwords
- No board visibility
Scope
Confirm whether the entity or specific activity qualifies for exemptions such as financial institutions subject to GLBA, certain healthcare uses, or specific government contractors, per Section 25.
- Exemption memo with legal review
- Activity-by-activity scoping
- Annual reconfirmation
- Carve-out documentation
- GLBA exemption claimed for non-financial activities
- Healthcare exemption stretched
- No annual review
Identify all biometric identifiers (retina/iris scan, fingerprint, voiceprint, scan of hand or face geometry) and biometric information derived from them, as defined in 740 ILCS 14/10.
- Biometric data inventory
- System list capturing biometrics
- Exclusion memo (writing samples, signatures, photographs without face geometry)
- Data flow diagrams
- Face recognition deployed without classifying it as biometric
- Voice authentication systems excluded by mistake
- No inventory
Security
Store, transmit, and protect biometric data using the reasonable standard of care within the entity's industry, and in a manner the same as or more protective than other confidential and sensitive information, per Section 15(e).
- Encryption at rest and in transit evidence
- Role-based access control matrix
- Industry standard benchmark (ISO 27001, NIST)
- Penetration test reports
- Biometric templates stored unencrypted
- Same access as ordinary HR data
- No industry benchmark
Special subjects
Where biometrics are collected from minors, obtain the written release from a legally authorised representative and apply appropriate safeguards.
- Age gating
- Parental release forms
- Verification of authority
- Separate storage for minors' data
- No age verification
- Parental release missing
- Minors' data co-mingled with adults
Third parties
Bind vendors processing biometric data on the entity's behalf to BIPA obligations including notice support, consent capture, retention, destruction, security, and prohibition on resale.
- BIPA addenda with vendors
- Vendor security questionnaires
- Data return or destruction certificates
- Sub-vendor approval records
- Standard MSA without BIPA terms
- No destruction certificate at end
- Sub-vendors not approved
Training
Train staff responsible for biometric systems on BIPA notice, consent, retention, destruction, disclosure, and security obligations.
- BIPA training module
- Completion records for HR, IT, security, vendors
- Role-based training matrix
- Annual refresh schedule
- No BIPA-specific training
- Vendor staff not trained
- No annual refresh
Workforce
Apply BIPA notice, consent, retention, and destruction obligations to employee biometric systems such as fingerprint timeclocks, palm scanners, and facial recognition turnstiles.
- Employee onboarding consent form
- Vendor BIPA addendum (timeclock provider)
- Termination-triggered destruction
- Annual employee re-notice if changes
- Timeclock vendor retains data after termination
- No employee consent on file pre-BIPA
- No vendor flow-down
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Illinois Biometric Information Privacy Act (BIPA) framework page.