Employee Monitoring Law Planner
Sources

Illinois Biometric Information Privacy Act (BIPA)

Law. Placed at Illinois. Read 30 Sep 2026; 5 provisions cited by the planner.

BIPA s 15(a)Written, public retention schedule and destruction guidelines, applied

A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, that establishes a retention schedule and guidelines for permanently destroying the identifiers and information when the initial purpose for collecting or obtaining them has been satisfied or within three years of the individual's last interaction with the entity, whichever comes first. Absent a valid warrant or subpoena issued by a court of competent jurisdiction, the entity must comply with its own established schedule and guidelines. The duty attaches on possession, so an entity that holds biometric data collected by a vendor on its behalf must publish the policy as well.

What a reviewer asks to see: The published retention and destruction policy (web page or posted notice) with its retention schedule and the destruction trigger of purpose satisfied or three years since last interaction; Destruction records showing the schedule is followed, including for departed employees and closed customer accounts; Any warrant or subpoena relied on to retain data past the schedule
Where monitoring plans usually fall short: A retention policy that exists internally but was never made available to the public; No destruction of employee templates after termination, so three-year clocks run out unnoticed; A vendor holding the templates with no policy published by the entity that uses them
Source: Illinois Biometric Information Privacy Act (BIPA), read 30 Sep 2026
BIPA s 15(b)(1)Written notice that a biometric identifier or information is being collected or stored

Before collecting, capturing, purchasing, receiving through trade or otherwise obtaining a person's or customer's biometric identifier or biometric information, the private entity must inform the subject, or the subject's legally authorized representative, in writing that a biometric identifier or biometric information is being collected or stored. The notice must precede the first collection; a notice given after enrolment does not cure the collection already made.

What a reviewer asks to see: The written notice (enrolment screen, form, employee notice) stating that a biometric identifier or information is collected or stored, dated before first collection; Evidence of delivery to each subject or representative before enrolment
Where monitoring plans usually fall short: Biometric timeclocks or access systems rolled out with no written notice to employees; Notice buried in a privacy policy that says nothing about biometrics specifically; Notice given at the first scan rather than before it
Source: Illinois Biometric Information Privacy Act (BIPA), read 30 Sep 2026
BIPA s 15(b)(2)Written notice of the specific purpose and length of term of collection, storage and use

Before obtaining a biometric identifier or biometric information, the private entity must inform the subject or the subject's legally authorized representative in writing of the specific purpose for which, and the length of term for which, the identifier or information is being collected, stored and used. The purpose must be specific to the use (timekeeping, facility access, identity verification for a transaction) and the term must be stated, which in practice ties the notice to the retention schedule of 15(a).

What a reviewer asks to see: The written notice naming the specific purpose and the length of term of collection, storage and use; Consistency between the stated term and the published retention schedule
Where monitoring plans usually fall short: A purpose stated as generally as security or business operations; No length of term stated at all; A stated term that contradicts the published retention policy
Source: Illinois Biometric Information Privacy Act (BIPA), read 30 Sep 2026
BIPA s 15(b)(3)Written release executed by the subject or representative before collection

Before obtaining a biometric identifier or biometric information, the private entity must receive a written release executed by the subject of the identifier or information or by the subject's legally authorized representative. A written release is informed written consent, an electronic signature (a checkbox, click-through or other electronic process executed with intent to sign, confirmed by the 2024 amendment) or, in employment, a release executed by an employee as a condition of employment. For a minor the release comes from the parent or guardian.

What a reviewer asks to see: Executed written releases or electronic signature records for every enrolled subject, retained for the life of the data and the limitations period; Employment releases executed as a condition of employment where that basis is used; Parent or guardian releases for minors
Where monitoring plans usually fall short: Enrolment with no release at all, the most litigated BIPA violation; A release obtained from a vendor's terms rather than executed by the subject; Electronic consent with no record of who signed, when and with what intent
Source: Illinois Biometric Information Privacy Act (BIPA), read 30 Sep 2026
BIPA s 15(d)No disclosure, redisclosure or dissemination except on four grounds

No private entity in possession of a biometric identifier or biometric information may disclose, redisclose or otherwise disseminate a person's or customer's biometric identifier or biometric information unless the subject or the subject's legally authorized representative consents to the disclosure or redisclosure; or the disclosure completes a financial transaction requested or authorized by the subject or representative; or the disclosure is required by State or federal law or municipal ordinance; or the disclosure is required by a valid warrant or subpoena issued by a court of competent jurisdiction. Transfer to a vendor or cloud provider is a disclosure that needs consent. Under section 20(c) as amended in 2024, repeated disclosure of the same identifier from the same person to the same recipient by the same method is a single violation with at most one recovery.

What a reviewer asks to see: Register of every recipient of biometric data (vendors, processors, affiliates, cloud services) with the ground for each disclosure; Consents covering disclosure to named recipients; Legal, warrant or subpoena records for compelled disclosures
Where monitoring plans usually fall short: Templates sent to a timekeeping or access-control vendor with consent covering collection only; Sharing between affiliates treated as internal; No record of who has received biometric data
Source: Illinois Biometric Information Privacy Act (BIPA), read 30 Sep 2026

Open the full text on compliance.theartofservice.com

See the specimen plan run Plan your own list