Illinois BIPA & GIPA Compliance Checklist:
Find Your Litigation Exposure in 2 Minutes
- 9 quick questions
- Takes about 2 minutes
- No sign-up to see your result
Your top next moves
Use the interactive risk check below to see where your business actually stands on Illinois biometric and genetic privacy law.
Answer 8 quick questions, 5 on your fingerprint time clocks, cameras, or voice systems (BIPA), plus a shorter 3-question set on genetic information from pre-employment physicals (GIPA), and get your exposure level in about 2 minutes: your risk band, the specific gaps to close, and a printable checklist you can hand to HR, ownership, or your IT provider.
No sign-up to see your result.
Why Illinois BIPA and GIPA are
Different from Other Compliance Rules (the short version)
Most compliance frameworks require someone to prove they were harmed before they can sue. Illinois’s Biometric Information Privacy Act (BIPA) does not.
In Rosenbach v. Six Flags Entertainment Corp. (2019), the Illinois Supreme Court held that a technical violation alone, no breach, no misuse, no proof of injury, is enough to bring a claim. Statutory damages run $1,000 to $5,000 per violation, and Illinois has produced well over $100 million a year in settlements and judgments on that basis.
The Genetic Information Privacy Act (GIPA) works the same way for genetic information, and its damages are structured even higher: the greater of actual damages or $2,500 per negligent violation and $15,000 per willful violation. Ford Motor Company settled a GIPA class action for $17.5 million after job applicants alleged the company’s pre-employment physicals asked for family medical history without the required separate consent.
The checklist below is organized around the specific compliance requirements
The full BIPA + GIPA Checklist
Work through each section below. Anything you can’t confirm is a gap, and in Illinois, an unconfirmed gap is exactly what a plaintiff’s attorney is looking for.
- 1. BIPA, your Biometric Technology in Use:
✓ Every fingerprint time clock, facial-recognition camera system, and voice-authentication system in use is identified and documented, including any run by a third-party vendor.
✓ A written, publicly available biometric data policy existed BEFORE you started collecting fingerprints, faces, or voices, covering what you collect, why, and how long you keep it.
✓ Every employee whose fingerprint, face, or voice you collect signed a specific, informed consent form before their first scan, not a line inside a general handbook.
✓ A retention and destruction schedule is in place and actually followed: biometric data destroyed once its purpose ends, or within 3 years of a person’s last interaction with you, whichever comes first.
✓ Any third-party vendor operating your time clocks or cameras has confirmed in writing how they store, use, and delete that data. - 2. BIPA, Per-Touchpoint Exposure:
✓ You know how many separate locations, systems, and vendors create a biometric touchpoint across your business.
✓ Each touchpoint has been checked against the paperwork above; a scan happening twice a day, every employee, every shift, is not one violation but a running one.
✓ Manufacturing and construction employers: shift-based time clocks at multiple job sites or plants each count as a separate touchpoint to document.
✓ Healthcare employers: badge and biometric access to secure areas (medication rooms, records areas) is inventoried alongside standard time-and-attendance systems. - 3. GIPA, Genetic Information from Pre-Employment Physicals:
✓ Any pre-employment physical, drug screen, or wellness program that could touch family medical history or genetic test results is identified.
✓ A separate, specific written consent for genetic information exists for each of those touchpoints, not folded into a general medical-release signature.
✓ Any genetic information collected is stored apart from the general personnel file, with access limited to people who genuinely need it.
✓ A distinct retention and destruction schedule exists for genetic information, separate from normal employee record retention.
How to read your gaps?
- 0 – 1 Gap and No Missing Critical Items
Strong Shape.
- 2 – 6 Gaps (Or One Missing Item on Written Policy)
Real, findable exposure that a technical violation alone can turn into a claim.
- 7+ Gaps or 2+ Critical Gaps
You likely have multiple live violations right now, with statutory damages running per person and sometimes per scan.
Most of the paperwork above is HR and legal work, but the systems behind it, vendor data-handling confirmation, access restrictions, retention enforcement, are IT work, which is the half of this a good IT partner operates for you.
Illinois BIPA & GIPA Compliance FAQ
BIPA is the Illinois Biometric Information Privacy Act. It applies to any private employer that collects biometric identifiers, fingerprints, facial geometry from cameras, or voiceprints, most commonly through fingerprint time clocks. If you use any of these, BIPA’s written-policy and consent requirements apply, regardless of your company’s size.
Yes. BIPA requires written, informed consent before the first collection, plus a publicly available policy on retention and destruction. A general employee handbook acknowledgment does not satisfy this requirement on its own.
BIPA covers biometric identifiers: fingerprints, face geometry, voiceprints. GIPA covers genetic information: genetic test results and family medical history. They’re separate Illinois statutes, but they hit the same HR audience through the same mechanism, a missing consent form, and the same plaintiffs’-bar litigation dynamic, which is why this check covers both.
BIPA statutory damages run $1,000 to $5,000 per violation. GIPA is structured even higher: the greater of actual damages or $2,500 per negligent violation and $15,000 per willful violation. Neither requires proof that anyone was actually harmed, a technical violation is enough on its own.
A routine pre-employment physical. If the health screener asks about family medical history as part of the exam, and you didn’t get a separate genetic-information consent for that question, it’s a GIPA violation, even though the physical itself was standard practice.
No such certification exists for an IT company, and LeadingIT doesn’t claim one. What we deliver is the compliance-readiness work itself: the policy, the consent process, the retention enforcement, and the vendor and system controls behind it, for manufacturing, construction, and healthcare employers across Illinois.
These three industries run the technology that creates most of the exposure. Manufacturing and construction employers commonly use fingerprint time clocks across shifts and job sites. Healthcare employers add biometric access to secure areas on top of that. All three routinely run pre-employment physicals that touch GIPA. That combination is why this bundle exists as one check instead of two.
Yes. Plaintiffs’ firms are actively sending mass-arbitration demand letters directly to employers over BIPA and GIPA gaps right now, not just filing individual lawsuits. Getting the underlying paperwork right before a demand arrives is the only real defense against this.
Ready to close your gaps?
If your result flagged missing policy, consent, or retention items, most of that starts as HR and legal paperwork, but the systems behind it, vendor confirmations, access controls, retention enforcement, are IT work LeadingIT handles day to day.
As an Illinois-headquartered IT and cybersecurity provider, this is our home-turf compliance area: we work with manufacturing, construction, and healthcare employers across Chicagoland to close BIPA and GIPA gaps before a demand letter shows up, not after.
Email yourself the full result from the tool above, book a free 30-minute gap review, or contact us, and see how we deliver Illinois biometric and genetic-privacy IT compliance as a managed service.