United States (Illinois)

Illinois Biometric Information Privacy Act (BIPA)

41 controls. 191 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

41 controls 191 frameworks share controls with it United States (Illinois) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

Illinois BIPA Biometric Information Privacy Act Evidence & Implementation Kit

41 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
BIPA-AUDITPeriodic Audit and Compliance Review0
BIPA-EMPLOYEEEmployee Biometric Programs (Timekeeping, Access)0
BIPA-EXEMPTStatutory Exemptions0
BIPA-INCIDENTIncident Response for Biometric Compromise0
BIPA-IRRECOVIrreversible Harm and Special Risk Recognition0
BIPA-MINORSMinors and Authorised Representatives0
BIPA-PRAPrivate Right of Action and Statutory Damages0
BIPA-SEC10-DEFBiometric Identifier and Information Definitions0
BIPA-SEC15A-DESTROYDestruction When Purpose Satisfied or Three Years Inactive0
BIPA-SEC15A-POLICYWritten Retention and Destruction Policy0
BIPA-SEC15B-CONSENTWritten Release (Informed Consent)0
BIPA-SEC15B-NOTICEWritten Notice Before Collection0
BIPA-SEC15C-PROFITNo Sale, Lease, Trade, or Profit0
BIPA-SEC15D-DISCLOSEDisclosure Restrictions0
BIPA-SEC15E-STOREReasonable Standard of Care and Storage Protections0
BIPA-SEC15aWritten Informed Consent Required0
BIPA-SEC15bDisclosure and Profit Prohibition0
BIPA-SEC15cDisclosure Restriction0
BIPA-SEC15dRetention and Destruction Policy0
BIPA-SEC15eStorage and Protection Requirements0
BIPA-SEC5-1Biometric Identifier Definition192
BIPA-SEC5-2Biometric Information Definition83
BIPA-SEC5-3Private Entity Definition0
BIPA-TRAINWorkforce Training0
BIPA-VENDORVendor and Processor Contracts0
1Short title and effective date (sections 1, 30, 99)0
10Definitions (as amended 2024)0
15Section 15: retention, collection, disclosure and destruction0
15(a)Written, public retention schedule and destruction guidelines, applied0
15(b)Notice and written release before collection0
15(b)(1)Written notice that a biometric identifier or information is being collected or stored0
15(b)(2)Written notice of the specific purpose and length of term of collection, storage and use0
15(b)(3)Written release executed by the subject or representative before collection0
15(c)No sale, lease, trade or other profit from biometric identifiers or information0
15(d)No disclosure, redisclosure or dissemination except on four grounds0
15(e)Storage, transmission and protection0
15(e)(1)Reasonable standard of care within the entity's industry0
15(e)(2)Protection at least equal to the entity's other confidential and sensitive information0
20Right of action and damages (as amended 2024)0
25Construction and exemptions0
5Legislative findings and intent0

Tell me when Illinois Biometric Information Privacy Act (BIPA) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • System security plans
  • Standard operating procedures
  • Current-as-at dates and approval records
  • Revenue analysis
  • Exemption documentation
  • Annual applicability review
  • Annual review
  • Supplier inventory + classification
  • Risk assessments per supplier
  • Contractual cyber clauses

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for Illinois Biometric Information Privacy Act (BIPA), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition