RatedWithAI

RatedWithAI

Accessibility scanner

Biometric Privacy (BIPA)July 24, 2026

BIPA and Airport Facial Recognition 2026: Airline Check-In & TSA Liability

Biometric boarding, self-service bag drop, and facial-recognition kiosks have spread across US airports — and Illinois travelers moving through O'Hare and Midway are protected by the country's strictest biometric privacy law. Here's who's actually on the hook when a face gets scanned at the gate.

$1K–$5K
Statutory damages per BIPA violation, per scan, per person
Private
Airlines and kiosk vendors are NOT covered by BIPA's government exemption
5 Years
Illinois statute of limitations for BIPA claims

Why Airports Are a BIPA Blind Spot

Most BIPA coverage focuses on retail loss prevention, gyms, and workplace time clocks — settings where a single company clearly controls the technology. Airports are messier: a single facial-recognition touchpoint at a boarding gate might involve the airline, the airport authority, a third-party kiosk vendor, and in some cases a federal agency, all operating the same physical hardware for different legal purposes.

That complexity doesn't create a BIPA exemption — it creates ambiguity about who's responsible, which is exactly the kind of gap the plaintiffs' bar has learned to target. Every private entity that "collects, captures, or otherwise obtains" a scan of someone's face at an Illinois airport is a potential BIPA defendant, whether or not they built the underlying model.

Who's Actually Exempt — and Who Isn't

Generally Exempt
  • TSA (federal government agency)
  • US Customs and Border Protection
  • State/local law enforcement biometric use
  • Financial institutions covered by Gramm-Leach-Bliley
Generally NOT Exempt
  • Airlines operating biometric boarding/check-in
  • Airport authority-run kiosks and concessions
  • Third-party biometric kiosk/software vendors
  • Rental car and lounge-access facial recognition

Travelers often assume that because a kiosk is standing inside a federal security checkpoint, the whole interaction is government activity. It isn't. An airline's own biometric boarding system, run on airline-owned hardware for airline business purposes, stays a private-sector activity — and squarely inside BIPA's scope — even a few feet from a TSA agent.

The Three BIPA Requirements That Trip Up Airlines

1

Written, Purpose-Specific Consent

A general terms-of-service checkbox at booking is not sufficient. BIPA requires informed, written consent specific to the biometric collection — typically presented at or near the point of the actual scan, describing what's collected and why.

2

Published Retention and Destruction Policy

Airlines and vendors must maintain a publicly available policy stating how long facial scan data is kept and the schedule for its destruction — generally no later than three years after the traveler's last interaction with the system, or sooner if the purpose is fulfilled.

3

No Sale or Improper Disclosure

Facial recognition data collected for boarding cannot be sold, leased, or disclosed to third parties (including data brokers or unrelated marketing partners) without separate, specific consent — a common gap when airlines share data with codeshare partners or ad-tech vendors.

Compliance Checklist for Airlines & Airport Vendors

Before Deployment

  • Confirm the entity operating the kiosk is not government-exempt
  • Draft purpose-specific written consent for the scan point
  • Publish a retention/destruction policy publicly
  • Offer a clear, low-friction opt-out at every touchpoint
  • Map data flows to any codeshare or ad-tech partners

Ongoing Operations

  • Log consent capture per traveler, not per booking
  • Enforce the published destruction schedule automatically
  • Audit third-party kiosk vendors for their own compliance
  • Train gate staff on the opt-out process
  • Review contracts for BIPA indemnification clauses

Frequently Asked Questions

Does BIPA apply if the flight isn't departing from Illinois but the traveler lives there?

BIPA generally applies based on where the biometric collection occurs, not the traveler's residency. A facial scan taken at an out-of-state airport typically falls under that state's law, not BIPA — though Illinois residents should still check the specific facts, since some claims have proceeded based on where a company processes or stores the data.

Are rental car counters and airport lounges also exposed?

Yes. Any private company using facial recognition for identity verification at an Illinois airport — rental counters, lounge access, even parking facilities — faces the same consent, retention-policy, and no-sale requirements as airlines and kiosk vendors.

What's the realistic financial exposure for a single flagged BIPA violation?

Illinois courts have held that each individual scan can constitute a separate violation, and statutory damages run $1,000 per negligent violation or $5,000 per intentional/reckless violation. For an airline processing thousands of Illinois-origin passengers daily without proper consent, unaggregated exposure can scale into the tens of millions quickly, which is why most BIPA class actions settle rather than go to trial.

Airport Biometrics Are a Growing BIPA Target

As biometric boarding rolls out to more airlines and airports, Illinois plaintiffs' firms have an increasingly obvious target: high-volume, private-sector facial scans with inconsistent consent practices across carriers and vendors.

If your airline, airport authority, or kiosk platform touches Illinois travelers, treat written consent and a public retention policy as non-negotiable before any camera goes live.