HB2838 amends the Illinois Biometric Information Privacy Act (BIPA) to create new definitions and carve-outs for certain biometric uses tied to security and access control. The bill defines terms such as “biometric lock,” “biometric time clock,” “person,” and “security purpose,” and it narrows the scope of the Act by excluding information captured by biometric locks and time clocks that convert biometric data into a mathematical representation that cannot be used to recreate the original biometric identifier. It also expands the definition of “biometric identifier” to clarify what is and is not covered, while preserving existing exclusions for items such as photographs, medical imaging, and certain health care and financial information.
The bill also changes the enforcement framework under BIPA. It keeps a private right of action in state or federal court, but requires an aggrieved person to give a private entity 30 days’ written notice identifying the alleged violation before filing suit, and allows the entity to cure the violation within that period to avoid damages. It further limits recovery by treating repeated collection or disclosure of the same biometric data from the same person by the same method as a single violation in certain circumstances. In addition, the bill exempts private entities whose employees are covered by a collective bargaining agreement that sets different biometric retention and use policies.
Impact
HB2838 would materially narrow the reach of BIPA for employers and private entities using biometric systems for security, access control, and timekeeping. It would create statutory exceptions for biometric locks and biometric time clocks that convert biometric data into non-reversible mathematical representations, and it would allow certain biometric collection without the usual written notice and release requirements when used solely for a defined security purpose. The bill would also add a mandatory pre-suit notice-and-cure process and limit multiple recoveries for repeated violations involving the same person and same method, reducing litigation exposure under the Act. These changes would affect the rights and obligations of businesses, employees, customers, and litigants under 740 ILCS 14/10, 14/15, 14/20, and 14/25.
Sentiment
Based on the bill text and the absence of recorded committee debate or votes in the provided materials, the overall posture appears pro-business and pro-employer, with an emphasis on clarifying and narrowing biometric privacy liability rather than expanding it. The bill title and structure suggest support for using biometric technology for security purposes while preserving some privacy protections. Because there are no transcripts or vote records included, no formal legislative sentiment can be inferred beyond the bill’s apparent policy direction.
Contention
The main points of contention are likely to be the bill’s new exceptions and liability limits. Privacy advocates may object that the security-purpose carve-out and the exclusion for biometric locks and time clocks weaken existing BIPA protections and create broader room for collection and retention of biometric data. Employers, security vendors, and other private entities are likely to support the measure because it reduces compliance burdens, adds a cure period, and limits class-action exposure. The collective bargaining agreement exemption may also be debated because it treats unionized workplaces differently from non-union workplaces, and the narrowed recovery rules may be seen as reducing deterrence for repeated violations.