Nothing Was Stolen. That Is Precisely Why Your Cyber Policy Says No.
A biometric class action is not a breach, not a discrimination claim, and not an advertising injury in any sense a broker would recognise. It lands in the seam between three policies, and the seam is where carriers have been sewing exclusions for six years.
The Structural Problem
Every insurance product a mid-sized company buys was designed around a story. General liability imagines someone slipping in your lobby or your ad copy defaming a competitor. Employment practices liability imagines a manager behaving badly. Cyber imagines an intruder. A BIPA claim tells none of those stories.
The BIPA story is that the system worked. The timeclock read the fingerprint it was installed to read. The camera ran the face-matching it was purchased to run. The vendor stored the templates it was contracted to store. The violation is procedural — no written notice of the specific purpose and length of term, no signed release, no publicly available retention and destruction schedule — and procedural violations are exactly what general-purpose policies were never drafted to price.
How Each Policy Says No
CGL — the exclusion war
The coverage grant is not the obstacle. Illinois authority has accepted that a BIPA suit can allege publication of material violating a right of privacy under Coverage B. Carriers therefore fight on exclusions. The violation-of-statutes exclusion — aimed at TCPA and fax-blasting suits — was read by the Illinois Supreme Court in West Bend v. Krishna Schaumburg Tan as not extending to BIPA. Carriers responded with the access-or-disclosure-of-confidential-or-personal-information exclusion and, on newer forms, recording-and-distribution and express biometric exclusions. Whether you are covered depends on which vintage of form you bought.
EPLI — the wrongful act definition
Intuitively the right home for the employee-timeclock fact pattern, and frequently the wrong one contractually. Many forms enumerate covered wrongful acts around discrimination, harassment, retaliation and wrongful termination, and a privacy statute violation is simply not on the list. Where it is not excluded outright, a broad statutory-violation exclusion often finishes the job. The fix is an endorsement, and it is negotiable at renewal.
Cyber — the security-failure predicate
Cyber forms condition coverage on a security failure or a privacy event involving unauthorized access. BIPA alleges authorized, intentional, functioning collection. Some forms include wrongful-collection or media liability wording capable of reaching it; an increasing number carry an express biometric-information exclusion. Read the insuring agreement's trigger language before you assume the word 'privacy' in the product name means anything here.
The vendor's policy — your best unclaimed asset
If a third-party timeclock, camera-analytics or identity-verification vendor supplied the system, your master services agreement may name you as an additional insured or carry an indemnity. Plaintiffs commonly sue both the deploying employer and the technology vendor, and the vendor's own exclusions may differ from yours. Tender to the vendor and to the vendor's carrier at the same time you tender to your own; a late tender is a waivable right you did not have to waive.
Fight for the Defense, Not the Indemnity
BIPA litigation resolves by settlement with striking consistency. That has a direct consequence for coverage strategy: the indemnity question often never gets decided, while defense costs begin accruing at the first responsive pleading and continue through class certification, which is where the expensive expert work lives.
The duty to defend is broader than the duty to indemnify and is measured against the allegations of the complaint. A complaint that pleads dissemination of templates to a third-party vendor may pull the claim inside a coverage grant even where the eventual facts would not. This is why the first thing to do after service is not to assess the merits but to tender — to every carrier on the tower, in writing, with the complaint attached, under a reservation of your own rights.
- •Tendering within days, to every policy, not just the obvious one
- •A complaint that alleges disclosure to a vendor, not just collection
- •An older CGL form without the access-or-disclosure endorsement
- •A vendor contract naming you as additional insured
- •Defense costs written outside the limit rather than eroding it
- •An express biometric-information exclusion on the current form
- •Claims-made policies where notice landed after the period closed
- •Prior-knowledge language triggered by an internal memo you wrote
- •Assuming the broker's coverage summary is the policy wording
- •Waiting for the carrier to volunteer that a second policy might respond
The Exposure Is Sized Before the Coverage Question
Illinois courts held in Cothron v. White Castle that a claim can accrue on each scan rather than only on the first, and the legislature responded with a 2024 amendment limiting recovery to a single recovery per person per method of collection. Both facts matter to insurance: the amendment compressed the theoretical ceiling, but it did not change the per-person statutory damages figures, and the class sizes in a warehouse or a retail chain are large enough that the number still clears most sublimits. A biometric sublimit that looks generous in the quote can be a rounding error against the demand.
The Renewal Conversation
- Ask which policy is intended to respond. Put the question to the underwriter in writing. Silence is the answer you will be quoted back later.
- Pull the exclusion schedule for Coverage B. Look specifically for access-or-disclosure, recording-and-distribution, and biometric wording.
- Price an affirmative biometric grant. It exists in the market. Ask for the sublimit and whether defense erodes it.
- Check the EPLI wrongful-act definition. If a privacy statute violation is not enumerated, ask for it to be added.
- Audit your vendor contracts for additional-insured status. Every biometric system you did not build should have someone else's paper behind it.
- Fix the underlying compliance first. Written notice, signed release, published retention schedule. The cheapest claim is the one nobody can plead.
Frequently Asked Questions
Our carrier denied under the access-or-disclosure exclusion. Is that the end?
Not necessarily. That exclusion is drafted around data-breach exposure and its application to intentional, authorized collection has been contested. The stronger response is usually not to argue the exclusion in the abstract but to point at what the complaint actually alleges and at the other policies on your tower. A denial letter is a carrier's opening position, and the volume of BIPA coverage litigation in Illinois exists precisely because those positions are frequently negotiated.
We are a SaaS vendor, not the employer. Does any of this apply to us?
Yes, and often more acutely. Plaintiffs routinely name the technology provider alongside the deploying business, and a vendor's tech E&O policy may exclude statutory privacy violations while its cyber policy requires a security failure that never occurred. If you supply face matching, voice biometrics, keystroke analytics or identity verification into Illinois, the coverage question is a product decision, not just a finance one.
Does it matter that we never sold or profited from the biometric data?
For BIPA liability, only partly — the notice, release and retention-schedule duties attach to collection and possession regardless of profit. For insurance, it can matter more, because some exclusions are drafted around disclosure or distribution. A fact pattern where nothing left your systems can weaken a coverage argument built on publication while also weakening the carrier's disclosure-based exclusion. This cuts both ways and is worth mapping before you tender.
Did the 2024 single-recovery amendment reduce our insurance need?
It reduced the tail-risk arithmetic that made per-scan accrual so alarming, but it left the per-person statutory damages and the fee-shifting provision intact. Class-wide exposure at a few thousand employees still reaches seven figures before fees, and defense costs through class certification are substantially independent of the damages theory. The amendment made the number forecastable, not small.
Are other states' biometric laws covered the same way?
The coverage analysis travels, but the exposure does not. Illinois remains the outlier because of its private right of action; Texas CUBI and Washington's biometric statute are enforced by their attorneys general, and Colorado's employer consent provisions run through its privacy act. If your carrier offers a biometric endorsement, check whether it is written to Illinois specifically or to biometric identifiers generally, because a multi-state footprint deserves the broader wording.
The Coverage Audit Is a One-Hour Job
Most companies deploying biometric systems have never asked which of their policies is supposed to answer for it. The audit is short: list every system that touches a fingerprint, face, voice or gait; pull the exclusion schedules on three policies; and write down, per system, the name of the policy that would respond.
If any row comes back blank, you are self-insured for that system and did not decide to be. That is the finding worth having before a complaint arrives, not after.
This article is general information about insurance coverage and biometric privacy law, not legal advice, and policy wording controls in every case. Coverage outcomes are form-specific and jurisdiction-specific — have coverage counsel read your actual policies before you rely on, or abandon, a tender.