Jose Felgueroso
Abogado | Attorney

  • Home
  • Blog


The Violation of Rights under the Illinois Biometric-Information Law Allows for Remedies even in the Absence of Additional harm

info@josefelgueroso.com

Versión en español

2019-04-30

In a case involving the Illiniois Biometric Information Privacy Act, the Supreme Court of that state held unanimously in January that a plaintiff could obtain compensation and injunctive relief without the need to allege harm beyond the violation of that statute.

Source: Wikimedia Commons

Background

Biometric technology relies on identification methods based on unique biological or physiological characteristics (for example, DNA, fingerprints, and voice). This technology provides benefits, as it can be used to protect data and provide an additional layer of security. But it also generates concerns related to how to limit its use and distribution to those with a legitimate need; in addition, companies and law enforcement can use biometric information to track individuals pervasively and surreptitiously. A characteristic that sets biometric technology apart from other forms of identification is that if biometric information is compromised (for example, as a result of a data breach), the biometric information affected cannot be changed.

The Biometric Information Privacy Act ("BIPA" or "the Act"), enacted by the Illinois General Assembly in 2008, defines biometric information as information based on an individual's biometric identifier used to identify an individual, regardless of how it is collected. BIPA requires a person's informed consent prior to the collection of that person's biometric information, recognizes only a limited right to disclosure, mandates protection obligations and retention guidelines, prohibits profiting from biometric information, and creates a private right of action.

In this case, Stacy Rosenbach sued Six Flags on behalf of her 14-year old son Alexander. Six Flags operates an amusement park in Gurnee, Illinois. Since 2014, Six Flags collected, recorded, and stored the fingerprints of persons who wanted to buy a season pass for the park. Alexander visited the park in 2014, after Rosenbach had bought online a season pass. During the sign-up process at the park's security checkpoint, Alexander was asked to scan his thumb into a biometric-data capture system. Subsequently, at the park's administrative building, Alexander obtained his season pass. The park did not provide Alexander with any paperwork, and did not inform Alexander of the purpose of the fingerprint collection or for how long it would be stored. Neither Alexander nor Rosenbach consented in writing to the collection, storage, use, or dissemination of his thumbprint. Six Flags retained Alexander's thumbprint, but did not disclose any use of the thumbprint or how long it would retain it; in addition, Six Flags did not have a publicly-available written policy that specified the retention schedule.

The parties did not dispute that a thumbprint and its electronic version are biometric identifiers.

Procedural History

Rosenbach sued in an Illinois state court, seeking damages and injunctive relief under BIPA and asserting a claim for the common-law action of unjust enrichment. Ruling on Six Flags's motion to dismiss Rosenbach's claims, the court of first instance dismissed Rosenbach's claim of unjust enrichment, but it denied the motion to dismiss her claims under BIPA. Six Flags filed an interlocutory appeal to the state appellate court, which held that Rosenbach was not an "aggrieved" person under BIPA, because she had not alleged any injury beyond Six Flags's violation of the Act. Rosenbach appealed to the Illinois Supreme Court (the "Court").

The Judgment

The issue before the Court was whether a person who fails to allege actual harm beyond a violation of BIPA may obtain damages and injunctive relief. Rosenbach argued that Alexander could obtain redress based on Six Flags's violation of BIPA, whereas Six Flags argued that one who fails to allege an actual harm may not sue under BIPA.

The dispute centered around the meaning of the term "aggrieved." BIPA does not define this term, so the Court determined that its popular meaning should be used. Under the Court's precedent, to be "aggrieved" means "having a substantial grievance; a denial of some personal or property right." Moreover, dictionaries define the term as "suffering from an infringement or denial of legal rights" (Merriam-Webster's Collegiate Dictionary) and "having legal rights that are adversely affected" (Black's Law Dictionary). In addition, under the Illinois AIDS Confidentiality Act, an aggrieved person does not need to prove actual harm to obtain relief; that statute provides a private right of action for violations, in terms that are similar to those in BIPA.

In BIPA, the Illinois General Assembly noted that the use of biometrics is increasing for business and security purposes. In addition, it stated that biometrics are unlike other unique identifiers, because they are biologically unique, and, once compromised, the individual has no recourse. Based on this risk, BIPA requires notice and consent from individuals before the collection of their biometric information, and it provides for liquidated damages for violations of the Act. In other words, BIPA creates an incentive for parties that collect and store biometric information to prevent problems from arising in the first place; according to the Court, to require a person affected by a biometric-data breach to wait for actual harm to obtain recourse would be contrary to BIPA's preventative goal.

The Court concluded that if a party violates BIPA and the plaintiff does not allege actual injury beyond the violation of the rights recognized in the Act, the plaintiff is an aggrieved party and may recover liquidated damages and injunctive relief.

The Court sent the case back to the court of first instance for additional proceedings.

Significance of the Judgment

The United States lacks a comprehensive federal privacy law, but in recent years several states have enacted privacy laws, such as the California Consumer Privacy Act and other laws addressing privacy-related matters, such as data breaches and identity theft.

The Illinois legislature enacted BIPA to address harms associated with biometric technology, whose use is growing and whose full impact is still unknown. By requiring notice and informed consent from persons before their biometric information is collected, BIPA prevents surreptitious biometric surveillance and allows individuals an opportunity to have full knowledge of the potential risks of sharing their biometric information. By including liquidated damages, BIPA creates an incentive for compliance and a remedy for individuals whose biometric information has been collected, especially taking into account the difficulty of discovering and proving actual harm if the biometric information is compromised, for example as a result of a data breach.