Seyfarth Synopsis: The Illinois Supreme Court held in its first ever ruling concerning the state's Biometric Information Privacy Act ("BIPA") that a person need not have sustained actual damage beyond technical violations of BIPA in order to pursue claims for damages. The Illinois Supreme Court's ruling will likely greatly increase the potential exposure for companies in actions alleging violations of the Act, and makes strict compliance with the Act significantly important.
For businesses in Illinois (and potentially in states with similar statues), the ruling in Rosenbach v. Six Flags Entertainment Corp., No. 123186, 2019 Ill. Lexis 7 (Ill. Jan. 25, 2019), serves as a loud warning shot that they must immediately take steps to strictly comply with BIPA's requirements, or risk facing costly class action litigation. As determined by the Illinois Supreme Court, "[w]hatever expenses a business might incur to meet the law's requirements are likely to be insignificant," in light of the potential for "liability for failure to comply with [BIPA's] requirements." Id. at *21.
Despite being barely over a decade old, BIPA litigation was rather stagnant for its first ten years, until a flurry of lawsuits were filed under this law in 2018. The BIPA prohibits an entity from collecting, capturing, purchasing or otherwise obtaining a person's "biometric identifier" or "biometric information," unless it satisfies certain notice, consent, and data retention requirements. At the time BIPA was passed into law, the thought of an entity utilizing fingerprint or facial recognition for employee identification was typically reserved for high-net-worth entities or those with dire need for added levels of security. In today's workplace, businesses small and large across nearly every industry are using fingerprint or facial recognition for both employee and customer identification.
The BIPA outlines several requirements for the collection and use of biometric information by private entities. Private entities collecting a person's biometric information musty (1) inform the person in writing that his or her biometric information is being collected; (2) explain the purpose and length of time for which the information will be used; and (3) receive written consent.
The BIPA also creates a limited right of action for "person[s] aggrieved by a violation" of its terms. A "person aggrieved" by a negligent violation of the BIPA may recover "liquidated damages of $1,000 or actual damages, whichever is greater." A "person aggrieved" by an intentional or reckless violation of the BIPA may recover "liquidated damages of $5,000 or actual damages, whichever is greater."
Since 2014, Defendants, operators of an amusement park in Illinois, have used a fingerprinting process when issuing repeat-entry passes to the park. Id. at *2. Plaintiff alleged that this system scans pass holders' fingerprints; collects, records and stores biometric identifiers and information gleaned from the fingerprints; and then stores that data in order to quickly verify customer identities upon subsequent visits by having customers scan their fingerprints to enter the theme park. She further alleged that in 2014, while the fingerprinting system was in operation, her 14-year-old son visited the amusement park on a school field trip, where his thumbprint was used to gain access as a season pass holder.
Plaintiff filed a three count complaint alleging Defendants violated the BIPA by: (1) collecting, capturing, storing, or obtaining biometric identifiers and biometric information from Plaintiff's son and other members of the proposed class without informing them or their legally authorized representatives in writing that the information was being collected or stored; (2) not informing them in writing of the specific purposes for which Defendants were collecting the information or for how long they would keep and use it; and (3) not obtaining a written release executed by Plaintiff, her son, or members of the class before collecting the information. Id. at *6.
Defendants moved to dismiss the complaint, arguing among many things, that plaintiff had suffered no actual or threatened injury and therefore lacked standing to sue. Id. at *6-7. The Circuit Court granted Defendants' motion to dismiss Count III, but denied its motion as to Counts I and II. Defendants thereafter sought interlocutory review of the Circuit Court's ruling, which the Illinois Appellate Court granted.
On December 21, 2017, the Illinois Appellate Court for the Second District became the first to address the issue of whether a plaintiff can recover for technical violations of the BIPA, even if the complaint does not allege that the plaintiff suffered any harm, loss or injury. It held that a plaintiff is not "aggrieved" within the meaning of the Act and may not pursue either damages or injunctive relief under the Act based solely on a defendant's violation of the statute. Additional injury or adverse effect must be alleged. The injury or adverse effect need not be pecuniary, the Appellate Court held, but it must be more than a technical violation of the Act. Plaintiff thereafter petitioned the Illinois Supreme Court for leave to appeal, which was granted.
The Illinois Supreme Court's Decision
On January 25, 2019, in a highly anticipated ruling, the Illinois Supreme Court reversed the Illinois Appellate Court and remanded the case back to the Circuit Court for further proceedings. After summarizing the BIPA, the Illinois Supreme Court began its analysis by zeroing in its statutory construction, noting that Defendants had read the Act as evincing an intention by the legislature to limit a plaintiff's right to bring a cause of action to circumstances where he or she has sustained some actual damage, beyond violation of the rights conferred by the statute, as the result of the defendant's conduct. Id. at *13-14. The Illinois Supreme Court rejected this argument as untenable, noting that when the General Assembly has wanted to impose such a requirement in other situations, it has made that intention clear. Id.
Next, the Illinois Supreme Court held that a person who suffers actual damages as the result of the violation of his or her rights would meet this definition of course, but sustaining such damages is not necessary to qualify as "aggrieved." Id. at *16. Rather, "[a] person is prejudiced or aggrieved, in the legal sense, when a legal right is invaded by the act complained of or his pecuniary interest is directly affected by the decree or judgment." Id. Accordingly, based on this construction, the Illinois Supreme Court held that a when a private entity fails to comply with one of the BIPA's Section 15's requirements, that violation constitutes an invasion, impairment, or denial of the statutory rights of any person or customer whose biometric identifier or biometric information is subject to the breach. Id. at *17-18. Further, it opined that "[n]o additional consequences need be pleaded or proved. The violation, in itself, is sufficient to support the individual's or customer's statutory cause of action." Id. at *18.
Finally, the Illinois Supreme Court explained that the BIPA vests in individuals and customers the right to control their biometric information by requiring notice before collection and giving them the power to say no by withholding consent. Id. It explained that these procedural protections are particularly crucial in our digital world because technology now permits the wholesale collection and storage of an individual's unique biometric identifiers — identifiers that cannot be changed if compromised or misused. Id. at *18-19 (citations and quotation marks omitted). The Illinois Supreme Court further opined that "[w]hen a private entity fails to adhere to the statutory procedures, as [D]efendants are alleged to have done here, the right of the individual to maintain [his or] her biometric privacy vanishes into thin air. The precise harm the Illinois legislature sought to prevent is then realized. This is no mere 'technicality.' The injury is real and significant." Id. at *19 (citations and quotation marks omitted).
The Illinois Supreme Court concluded its opinion by holding that contrary to the Appellate Court's view, an individual need not allege some actual injury or adverse effect beyond violation of his or her rights under the Act in order to qualify as an "aggrieved" person and be entitled to seek liquidated damages and injunctive relief pursuant to BIPA. Id. at *22. Therefore, it reversed the judgment of the Appellate Court and remanded to the Circuit Court for further proceedings.
What This Means For Businesses
The decision will make it significantly easier for individuals to assert causes of action and seek damages for mere non-compliance with the BIPA's requirements – absent any allegations of harm or injury. In that regard, the decision makes it of the utmost importance that companies take strict measures to comply with the BIPA's requirements. As stated by the Illinois Supreme Court, "[w]hatever expenses a business might incur to meet the law's requirements are likely to be insignificant," in light of the potential for the significant "liability for failure to comply with [the BIPA's] requirements." Id. at *21.
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.