Binding law — in force AI-adjacent law
Do not disclose face or voice biometrics to another party without consent (Illinois BIPA)
A private entity in possession of a biometric identifier or biometric information may not disclose, redisclose or otherwise disseminate it unless the person consents, the disclosure completes a financial transaction the person requested or authorized, it is required by law, or it is required by a valid warrant or subpoena. Detect templates, or the images or voice samples used to identify people, sent to a third-party service or partner with no consent check for that disclosure.
Who it applies to
- Duty falls on: organization
- Private entities in possession of biometric identifiers or information of people in Illinois. Whether a call to a recognition vendor acting for the entity is a 'disclosure' is a question for counsel (review flag). In force since 2008-10-03.
- Not covered:
- State or local government agencies and Illinois courts, clerks and judges (not a 'private entity', 740 ILCS 14/10)
- Information captured from a patient in a health care setting, or collected, used or stored for treatment, payment or operations under HIPAA (excluded from 'biometric identifier', 14/10)
- Photographs, written signatures and physical descriptions are not themselves biometric identifiers (14/10); whether a face-geometry template computed from a photograph is covered is a question for counsel (review flag)
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Check a recorded consent naming the recipient (or a documented exception) before any face or voice template, or identifying image or sample, is sent to a vendor or partner.
A disclosure gate wrapped around every outbound call that carries templates, face images used for identification, or voice samples: vendor recognition APIs, partner webhooks, shared buckets, analytics events. The gate looks up a consent record for this person that names the recipient (or a documented exception such as a transaction the person requested), refuses the call without it, and writes an audit entry of what was sent, to whom, and under which consent or exception. Biometric fields are stripped from analytics and telemetry payloads entirely.
Where it goes: 1 application source code, 6 API calls and integrations, 10 logs and telemetry.
What this provision adds:
- Disclose only with the person's consent, to complete a financial transaction the person requested or authorized, when required by law, or under a valid warrant or subpoena.
- Whether a call to a recognition vendor acting for the entity is a disclosure is a question for counsel, so flag such vendor calls for review.
Example (Python requests to an identity vendor), before:
def verify_with_vendor(user, selfie_bytes):
r = requests.post(VENDOR_URL, files={'image': selfie_bytes}, timeout=10)
return r.json()['match']After:
def verify_with_vendor(user, selfie_bytes):
consent = db.biometric_consents.get(user_id=user.id, recipient='acme-idv', purpose='disclosure')
if consent is None or consent.withdrawn_at:
raise ConsentRequired('no consent to share biometric data with acme-idv')
r = requests.post(VENDOR_URL, files={'image': selfie_bytes}, timeout=10)
disclosure_log.insert(user_id=user.id, recipient='acme-idv', data='face_image', consent_id=consent.id)
return r.json()['match']Control: Biometric data disclosed to another party without consent. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.
Rule id il-bipa.biometric-disclosure-consent · review status: primary source derived