Somewhere in Illinois right now, a warehouse worker is pressing a thumb to a scanner to clock in for a shift, and that thumbprint is worth more, legally speaking, than the thumb it’s attached to. If her employer collected it without a written notice and a signed release — no injury required, no fraud, no misuse, just the missing paperwork — she has a claim worth $1,000 per violation under state law, and $5,000 if a court decides the company was reckless about it. Drive the same warehouse forty miles east into Indiana, install the same scanner, skip the same paperwork, and the identical thumb is worth nothing at all. Not less. Nothing. The harm is the same; only the legal status of the worker’s biology has changed, somewhere around the state line, at the speed of a truck.
This is the strange geography of biometric privacy in America, and Illinois is its accidental capital. In 2008, years before face recognition became a consumer product, the state passed the Biometric Information Privacy Act — 740 ILCS 14, known everywhere as BIPA — after a fingerprint-scanning company called Pay By Touch went bankrupt and nobody could say what would happen to the fingerprints it had collected. The law requires informed written consent before anyone collects a faceprint, fingerprint or voiceprint, sets rules for retention and deletion, and bans selling the stuff. All sensible. But the clause that made BIPA the most feared statute in Silicon Valley is the enforcement mechanism: a private right of action. Any person “aggrieved” can sue, for statutory damages, without having to prove the data was ever leaked, sold or misused. The violation is the injury.
That one design choice is the entire story. Illinois is not the only state with a biometric law — Texas passed one in 2009, Washington in 2017 — but both left enforcement to their attorneys general, which in practice means enforcement happens when an AG decides it happens, which is to say almost never, with one enormous exception we’ll get to. Illinois handed the enforcement budget to everyone with a face. By early 2020, more than four hundred BIPA suits had been filed in five years, and the law has since become a one-state extraction industry.
The receipts are absurd. Facebook’s photo-tagging feature — the one that helpfully suggested names for the people in your pictures — cost the company $650 million after a judge decided the original $550 million settlement wasn’t enough, with roughly $397 checks eventually going out to eligible Illinois users. TikTok paid $92 million. Google paid $100 million over face groupings in Google Photos. Snap paid $35 million. In the first BIPA case to reach a jury, in 2022, a federal jury found that BNSF Railway had recklessly violated the law 45,600 times — once per truck driver fingerprinted at its automated railyard gates — before the parties ultimately settled after trial. Hundreds of millions of dollars, all told, for a harm that, one state over, does not legally exist.
The border is the policy
It’s tempting to read this as a story about Illinois being unusually far-sighted, and in 2008 it was. But the more uncomfortable reading is that nothing about the underlying protection is special — the consent requirements in Texas’s law are broadly similar — and everything about the outcome turns on who is allowed to walk into court. A right without a private remedy is a press release. A right with statutory damages and no injury requirement is an industry. The face of a Chicagoan and the face of a St. Louisan are made of the same geometry; one is a regulated asset and the other is free for the taking, and the difference is a jurisdictional accident that no one chose and no one can justify on the merits.
The perversity runs deeper, because the identifier at stake is the one credential you can never rotate. If a company loses your password, you change it. If it loses your credit card number, the bank issues a new one and absorbs the fraud. Your face has no reissue process. The entire logic of statutory damages — you don’t have to show harm, because the law presumes the harm of losing control over something irreplaceable — is an admission that by the time misuse is provable, it’s too late to fix. Illinois is the only place that priced this in advance. Everywhere else priced it at zero and called the difference innovation.
The counterargument writes itself, and defendants have written it many times: strict liability for paperwork violations invites shakedowns, punishes employers over fingerprint time-clocks, and enriches plaintiffs’ lawyers more than plaintiffs — $397 is a nice check, but it is not a face. There’s something to it. Illinois lawmakers amended BIPA in 2024 to rein in the per-scan damages math that had produced those astronomical exposure figures. But notice what the amendment debate conceded: the mechanism worked. Companies changed their behavior in Illinois — disabling features, rewriting onboarding flows, geofencing consent — because the threat was credible. The threat was credible because the plaintiffs were real.
The exception that proves the geography
In July 2024, Texas showed what AG-only enforcement looks like when an attorney general actually cares: Ken Paxton’s office extracted $1.4 billion from Meta over face geometry collected without consent — the largest state privacy settlement ever, bigger than the entire Illinois haul. One company, one lawsuit, one politically motivated enforcer. It’s a staggering number that also proves the rule: in a decade and a half, Texas’s biometric law produced essentially one enforcement event, timed to an AG’s priorities, while Illinois’s produced a standing market in which any aggrieved person is a potential plaintiff and every employer with a thumb scanner is a potential defendant. Enforcement as lottery versus enforcement as weather.
The weather may be spreading. Washington’s 2023 My Health My Data Act covers biometric data and includes a private right of action — the first state law since BIPA to copy the mechanism rather than just the vocabulary. New York City’s biometric law lets individuals sue over undisclosed collection in stores and restaurants. California’s landmark privacy act covers biometric information but offers only a narrow private right of action for certain data breaches — which is why California, the supposed capital of tech regulation, is a rounding error in biometric litigation while Illinois is the whole graph.
So: who owns your face? The honest answer is that it depends on the latitude and longitude of the camera. Your faceprint is simultaneously a protected biological asset, a free raw material and a $1.4 billion negotiating chip, and the only variable is which legislature happened to hand you a key to the courthouse. We tend to talk about privacy law as though it were a statement of values — what a society believes about the body and the self. Illinois suggests it’s something cruder and more interesting: a statement of plumbing. Values are everywhere. Standing is rare. The face you’re reading this with is the same face everywhere; it’s the law that keeps changing its mind about what you are.