HB3667 would amend the Illinois Biometric Information Privacy Act (BIPA) to narrow and clarify how the law applies to certain biometric uses, especially in security and workplace timekeeping contexts. The bill revises key definitions, including “biometric identifier” and “written release,” and adds new definitions for “biometric lock,” “biometric time clock,” “person,” and “security purpose.” It also provides that when biometric data is collected as part of the same repeated process, a private entity would only need to provide notice and obtain consent during the initial collection, rather than repeatedly for each use.
The bill creates a new exception allowing private entities to collect or use biometric data without the usual BIPA notice-and-consent requirements when the data is used for a “security purpose,” so long as it is used only for that purpose, retained only as long as reasonably necessary, and subject to a documented deletion process. It also states that BIPA does not apply to biometric time clocks or biometric locks that convert biometric data into a mathematical representation that cannot recreate the original identifier. Most significantly, the bill repeals BIPA’s private right of action, which would eliminate the ability of individuals to sue directly under the statute for violations.
Impact
If enacted, HB3667 would substantially reduce the scope and enforceability of BIPA in Illinois. It would limit notice and consent obligations for repeated biometric collection, exempt certain security-related uses, and exclude biometric time clocks and biometric locks that use mathematical templates from the Act’s coverage. The bill would also remove the statute’s private right of action, shifting enforcement away from private lawsuits and likely reducing litigation exposure for employers, retailers, security vendors, and other private entities that use biometric systems. The bill would amend 740 ILCS 14/10, 14/15, and 14/25 and take effect immediately.
Sentiment
No committee transcripts or recorded votes were provided, so there is no documented debate or roll-call history to gauge legislative sentiment. Based on the bill text and caption, the measure appears aimed at easing compliance burdens and limiting liability for private entities using biometric technology for security and timekeeping. The overall framing suggests a pro-business, liability-reduction approach rather than an expansion of privacy protections.
Contention
The main points of contention are likely to be the bill’s broad exemptions and the repeal of the private right of action. Privacy advocates and consumer-rights supporters would likely object to narrowing BIPA, especially because the law has been a major enforcement tool against unauthorized biometric collection. By contrast, employers, retailers, security companies, and other private entities using fingerprint or facial-recognition systems would likely support the bill because it reduces repeated consent requirements, creates security-purpose exceptions, and limits lawsuit exposure. The treatment of biometric time clocks and biometric locks is also likely to be controversial because those devices are common in workplaces and access-control systems.
"New Jersey Disclosure and Accountability Transparency Act (NJ DaTA)"; establishes certain requirements for disclosure and processing of personally identifiable information; establishes Office of Data Protection and Responsible Use in Division of Consumer Affairs.
"New Jersey Disclosure and Accountability Transparency Act (NJ DaTA)"; establishes certain requirements for disclosure and processing of personally identifiable information; establishes Office of Data Protection and Responsible Use in Division of Consumer Affairs.