An Illinois manufacturer captures employees' fingerprint templates for a timekeeping system and, without telling the workers or obtaining any signed authorisation, sends those templates to a third-party payroll-software vendor that hosts the time clocks. The manufacturer did publish a written retention-and-destruction policy and points to it as proof of compliance. A group of employees sues. Under the Illinois Biometric Information Privacy Act, which failure most directly grounds their claim?
- AThe manufacturer breached the Act by capturing the fingerprint templates without first obtaining a written release and by disclosing them to the vendor without the workers' consent. Correct
- BNone, because the manufacturer satisfied the Act by maintaining a publicly available written retention-and-destruction schedule for the fingerprint templates it collected.
- CThe manufacturer breached the Act by failing to register the fingerprint database with the Illinois Attorney General before deploying the time clocks.
- DThe manufacturer breached the Act only by storing the templates on a vendor's servers rather than on its own systems, which the Act prohibits for biometric identifiers.
Why A is correct: Correct: section 15(b) requires informed written consent before a private entity collects a biometric identifier, and section 15(d) bars disclosure without consent, so collecting and sharing the templates without authorisation grounds the claim even though a retention policy existed.
Why B is wrong: Tempting because section 15(a) does require that written retention policy and the firm published one, but the written-policy duty is only one obligation, and it does not cure the separate failure to obtain consent before collecting and disclosing the templates.
Why C is wrong: Tempting because some state biometric regimes involve a regulator, but BIPA imposes no database-registration requirement, so a missing registration cannot be the basis of the employees' claim.
Why D is wrong: Tempting because outsourcing storage feels risky, but BIPA does not bar using vendors to host biometric data, so location of storage alone is not the violation; the consent and disclosure failures are.