TwinEthosRequest access

Law

Illinois Biometric Information Privacy Act (740 ILCS 14)

Illinois (private right of action) · Illinois (US-IL) · 3 provisions encoded · verified against the official source as of 2026-09-30.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

AI-adjacent law General privacy or biometric law, included only where AI data flows trigger it; reported apart from AI-specific law.

Official text: www.ilga.gov.

Binding law — in force AI-adjacent law

Inform in writing and obtain a written release before collecting face or voice biometrics (Illinois BIPA)

740 ILCS 14/15(b) · official text · In force: applies since 3 Oct 2008 · Illinois (US-IL)

Before a private entity collects, captures or otherwise obtains a person's biometric identifier (such as a scan of face geometry or a voiceprint) or biometric information, it must inform the person in writing that the data is being collected or stored, inform them in writing of the specific purpose and how long it will be collected, stored and used, and receive a written release (informed written consent or an electronic signature). Detect a face- or voice-recognition path that computes or enrolls a template with no recorded written release first.

Who it applies to

  • Duty falls on: organization
  • Private entities that collect or capture biometric identifiers or information of people in Illinois, for example through face matching, selfie verification or voice login. In force since 2008-10-03.
  • Not covered:
    • State or local government agencies and Illinois courts, clerks and judges (not a 'private entity', 740 ILCS 14/10)
    • Information captured from a patient in a health care setting, or collected, used or stored for treatment, payment or operations under HIPAA (excluded from 'biometric identifier', 14/10)
    • Photographs, written signatures and physical descriptions are not themselves biometric identifiers (14/10); whether a face-geometry template computed from a photograph is covered is a question for counsel (review flag)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Check a recorded, purpose-specific biometric notice and consent before any code computes, enrolls, or matches a face or voice template.

A consent gate placed immediately before the call that turns an image, video frame, or voice sample into a template or identity match (face_encodings, DeepFace.represent, rekognition.index_faces, voice embedding). The gate reads a stored consent record for this person and purpose (what is collected, why, and how long it is kept), refuses to compute the template without it, and the template is stored with a reference to that record. The notice copy shown at enrollment lives in the capture UI.

Where it goes: 1 application source code, 2 data models, 6 API calls and integrations, 14 user-facing text.

What this provision adds:

  • The notice is in writing and states the specific purpose and how long the data is collected, stored and used; the gate checks a written release (informed written consent or e-signature).

Example (Python face_recognition), before:

def enroll(user_id, image):
    encoding = face_recognition.face_encodings(image)[0]
    db.templates.insert(user_id=user_id, encoding=encoding)

After:

def enroll(user_id, image):
    consent = db.biometric_consents.get(user_id=user_id, purpose='face_login')
    if consent is None or consent.withdrawn_at:
        raise ConsentRequired('biometric notice and consent needed before enrollment')
    encoding = face_recognition.face_encodings(image)[0]
    db.templates.insert(user_id=user_id, encoding=encoding, consent_id=consent.id)

Control: Face or voice biometric template computed without prior notice and consent. The same guard addresses 4 items with binding law in 4 jurisdictions. Engineering guidance, not legal advice.

Rule id il-bipa.biometric-notice-and-written-release · review status: primary source derived

Binding law — in force AI-adjacent law

Publish a biometric retention schedule and destroy face and voice templates on time (Illinois BIPA)

740 ILCS 14/15(a) · official text · In force: applies since 3 Oct 2008 · Illinois (US-IL)

A private entity that possesses biometric identifiers or information must have a written, publicly available policy with a retention schedule and destruction guidelines, destroying the data when the initial purpose is satisfied or within three years of the person's last interaction, whichever comes first, and must follow it. Detect stored face or voice templates (for example a Rekognition collection or face embeddings in a database) with no deletion path, and the absence of a published biometric retention policy.

Who it applies to

  • Duty falls on: organization
  • Private entities in possession of biometric identifiers or information of people in Illinois. In force since 2008-10-03.
  • Not covered:
    • State or local government agencies and Illinois courts, clerks and judges (not a 'private entity', 740 ILCS 14/10)
    • Information captured from a patient in a health care setting, or collected, used or stored for treatment, payment or operations under HIPAA (excluded from 'biometric identifier', 14/10)
    • Photographs, written signatures and physical descriptions are not themselves biometric identifiers (14/10); whether a face-geometry template computed from a photograph is covered is a question for counsel (review flag)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Store each face or voice template with its purpose and an expiry, and run a scheduled job that deletes it from every store when the purpose ends or retention lapses.

Each template row or collection entry carries its purpose, last_interaction_at, and an expires_at computed from the written retention schedule. A scheduled deletion job (cron, Celery beat, EventBridge schedule) removes expired templates from every place they live, including the Rekognition collection (delete_faces with the FaceIds) and any vector index, and account closure or the end of the purpose triggers deletion right away. The retention schedule is published (privacy policy or biometric policy page in the site source) and kept in the repo so code and policy match; deletions are logged.

Where it goes: 1 application source code, 2 data models, 4 infrastructure-as-code, 14 user-facing text.

What this provision adds:

  • Destroy the data when the initial purpose is satisfied or within three years of the person's last interaction, whichever comes first.
  • Keep a written, publicly available policy with the retention schedule and destruction guidelines, and follow it.

Example (AWS Rekognition (boto3)), before:

resp = rekognition.index_faces(CollectionId='members', Image={'Bytes': img}, ExternalImageId=user_id)
db.faces.insert(user_id=user_id, face_id=resp['FaceRecords'][0]['Face']['FaceId'])

After:

resp = rekognition.index_faces(CollectionId='members', Image={'Bytes': img}, ExternalImageId=user_id)
db.faces.insert(user_id=user_id, face_id=resp['FaceRecords'][0]['Face']['FaceId'],
                purpose='door_access', expires_at=retention.expiry_for('door_access', now()))

def purge_expired_faces():   # scheduled daily
    expired = db.faces.expired(before=now())
    for batch in chunks(expired, 1000):
        rekognition.delete_faces(CollectionId='members', FaceIds=[f.face_id for f in batch])
        db.faces.delete_ids([f.id for f in batch])
        deletion_log.record(len(batch), reason='retention_expired')

Control: Biometric templates stored with no retention limit or destruction path. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Rule id il-bipa.biometric-retention-and-destruction · review status: primary source derived