CIPP-US - State Privacy Laws - Section 5.4

Describe state-level biometric privacy laws and AI bias frameworks, including BIPA's written policy and consent requirements and automated decision-making rules.

Describe Illinois BIPA's duty to publish a written retention policy and obtain informed written consent before collecting a biometric identifier or biometric information such as fingerprints or facial recognition data, with strict retention and destruction schedules. Recognise emerging state automated decision-making laws imposing impact assessment, disclosure, and opt-out duties.

BIPABiometric identifierFacial recognitionAutomated decision-making law

Practice question for this objective

Free sampleState Privacy Lawshard

An Illinois manufacturer captures employees' fingerprint templates for a timekeeping system and, without telling the workers or obtaining any signed authorisation, sends those templates to a third-party payroll-software vendor that hosts the time clocks. The manufacturer did publish a written retention-and-destruction policy and points to it as proof of compliance. A group of employees sues. Under the Illinois Biometric Information Privacy Act, which failure most directly grounds their claim?

  • AThe manufacturer breached the Act by capturing the fingerprint templates without first obtaining a written release and by disclosing them to the vendor without the workers' consent. Correct
  • BNone, because the manufacturer satisfied the Act by maintaining a publicly available written retention-and-destruction schedule for the fingerprint templates it collected.
  • CThe manufacturer breached the Act by failing to register the fingerprint database with the Illinois Attorney General before deploying the time clocks.
  • DThe manufacturer breached the Act only by storing the templates on a vendor's servers rather than on its own systems, which the Act prohibits for biometric identifiers.
BIPA requires prior written consent to collect biometric identifiers and consent before disclosing them, duties separate from the written retention-policy requirement. BIPA imposes distinct obligations: section 15(a) mandates a public written retention-and-destruction policy, section 15(b) requires informed written consent before collection, and section 15(d) bars disclosure of biometric data without consent. Publishing a retention policy satisfies only one duty and does not excuse collecting and sharing fingerprint templates without the employees' written authorisation.

Why A is correct: Correct: section 15(b) requires informed written consent before a private entity collects a biometric identifier, and section 15(d) bars disclosure without consent, so collecting and sharing the templates without authorisation grounds the claim even though a retention policy existed.

Why B is wrong: Tempting because section 15(a) does require that written retention policy and the firm published one, but the written-policy duty is only one obligation, and it does not cure the separate failure to obtain consent before collecting and disclosing the templates.

Why C is wrong: Tempting because some state biometric regimes involve a regulator, but BIPA imposes no database-registration requirement, so a missing registration cannot be the basis of the employees' claim.

Why D is wrong: Tempting because outsourcing storage feels risky, but BIPA does not bar using vendors to host biometric data, so location of storage alone is not the violation; the consent and disclosure failures are.

See more CIPP-US practice questions, answers explained.

More in this domain

Back to all State Privacy Laws objectives, or the CIPP-US cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.