You Got the Consent. Section 15(c) Still Says No.
Almost every BIPA programme is built around the written release, because that is the subsection the lawsuits made famous. Two subsections further down sit a flat ban on profiting from biometric data and a narrow list of the only four ways it may be disclosed — and modern AI architecture discloses constantly.
The shortest version: consent unlocks 15(b) and part of 15(d). It unlocks nothing in 15(c). If the plan requires biometric data to be the thing someone pays for, the plan needs different data — not a better form.
How the Two Subsections Are Shaped
15(b) is a permission rule. 15(c) is a prohibition.
Section 15(b) tells you how to collect: notice of the fact and the purpose, the retention period, and a written release. Section 15(c) does not give you a procedure to follow. It says a private entity in possession of a biometric identifier or biometric information may not sell, lease, trade or otherwise profit from it. There is no consent carve-out written into that sentence, which means the strongest release you can draft does not unlock the conduct.
15(d) is a permission rule with four exits, and consent is only one
Disclosure, redisclosure and dissemination are barred unless the subject consents to that disclosure, or the disclosure completes a financial transaction the subject requested and authorised, or it is required by state or federal law or municipal ordinance, or it is made under a valid warrant or subpoena. Notice how narrow the middle two are, and notice that the first one is consent to the disclosure — not consent to the collection.
The two operate on possession, not on collection
Both subsections attach to an entity in possession of the data. An organisation that received biometric data from someone else, and never scanned anyone, is squarely inside them. This is how vendors, processors and acquirers end up as defendants in a statute most people read as a rule about fingerprint clocks.
The remedy is private and per person
The Act gives an aggrieved person a right of action with statutory damages — a higher figure for intentional or reckless violations than for negligent ones — plus fees and injunctive relief, and the Illinois courts have held that no separate injury beyond the violation is required. The 2024 amendment addressed repeat-scan accrual; it did not touch what 15(c) and 15(d) prohibit.
Five Disclosures Teams Do Not Count as Disclosures
Each of these moves biometric data out of your possession, and each needs one of the four exits before it happens.
The API call to a cloud model
If your product sends a face template, a voice embedding or a raw capture to a third-party model for matching, verification or enrolment, data left your possession and entered someone else's. That is the textbook 15(d) event, and it happens on every request rather than once at signup. A release that authorised you to collect a fingerprint says nothing about a transfer to a vendor it never named.
The subprocessor behind your vendor
Your vendor's own infrastructure providers, model hosts and offshore labelling contractors are a chain of disclosures your consent language has to reach. Ask for the list. A vendor that will not name its subprocessors is asking you to consent on your users' behalf to recipients you cannot identify, which is not a consent you are able to give.
Training on customer data
A vendor clause permitting use of your data to improve the service is a business term with a statutory shadow: improving a model with biometric data you disclosed is a purpose your users almost certainly were not told about. Turn the setting off where it exists, and get the answer in the contract rather than in a support reply.
Corporate transactions and integrations
Data-room access, post-close migration and an integration that pipes templates into a partner's platform are each disclosures. In a sale of a business, the argument that the data moved as part of an asset transfer rather than as a sale of the data is exactly the argument 15(c) forces you to have, under time pressure, with a buyer who wants a clean rep.
Law enforcement requests that arrive informally
The 15(d) exit is a valid warrant or subpoena, not a request. A cooperative response to an emailed ask from an officer is a disclosure with no exit, made by a person on your team who thought they were being helpful. This belongs in a written escalation rule, because it is decided in minutes by whoever picks up.
What the Profit Ban Actually Catches
'We do not sell data' is not the test
The sentence bans selling, leasing, trading and otherwise profiting. The last clause is the contested one, and the dispute is about how far it reaches — a direct transaction in the data is plainly inside, while revenue earned from a product that performs biometric matching for a paying customer has been argued both ways. Build on the assumption that any arrangement where the biometric data itself is what someone is paying for is unsafe.
Data-sharing dressed as a partnership
Barter is named in the statute — trade is in the list — so an exchange of biometric data for access, analytics, placement or co-marketing value is not made safer by the absence of an invoice. If a deal moves templates and something of value moves the other way, the absence of money is not the defence people assume it is.
Enrichment and identity products built on collected templates
Using templates collected for one purpose, such as access control, as the raw material of a product sold to third parties is the fact pattern the subsection most obviously targets. Where a business model requires it, no consent form rescues it; the model needs synthetic or separately licensed data, or it needs to not exist in Illinois.
The insurer may decline the tail
Many general liability and cyber policies now carry biometric or statutory-violation exclusions, so the entity holding this exposure is frequently holding it alone. Read the exclusion before you price the feature, not after a demand letter arrives.
Five Things to Put in Place
Write down every place biometric data leaves your systems
One table: destination, what is sent, whether it is raw capture or a derived template, retention at the far end, and the consent text that covers it. Most teams discover a destination nobody had mapped — a debugging log, an analytics pipeline, an error tracker holding an image payload.
Make the release name disclosures, not just collection
Consent to the disclosure is the first exit in 15(d), which means the document has to describe recipients and purposes at a level a person can understand. Categories are workable if they are honest; 'third parties' as the whole answer is not.
Audit the contract for a profit-shaped clause
Look specifically for improvement rights, aggregate-data rights, resale, sublicensing and the survival language after termination. A right that lets your vendor monetise what you disclosed is your problem as well as theirs, because your users' data is the subject matter.
Put the warrant rule in writing before you need it
A one-paragraph policy: biometric data is disclosed to law enforcement only on a valid warrant or subpoena, routed to a named owner, logged. This costs nothing and removes the single most likely unconsidered disclosure in the organisation.
Keep the disclosure log
What was disclosed, to whom, under which exit, and when. The subsections are provable from your own records or from nothing, and a defendant with a log is in a different position from one reconstructing transfers from memory during discovery.
Questions Product and Legal Teams Ask
If our users consent, can we sell biometric data?
The profit subsection is written as a flat prohibition on an entity in possession of a biometric identifier or biometric information selling, leasing, trading or otherwise profiting from it, and unlike the disclosure subsection it does not list consent as an exception. That asymmetry is deliberate and it is the single most misunderstood thing about the statute: teams build a strong release, conclude that it unlocks everything downstream, and design a revenue line that no signature makes lawful. If your plan depends on biometric data being the thing a counterparty pays for, the plan needs different inputs — synthetic data, separately licensed data, or derived signals that are not biometric identifiers or biometric information at all. Redesign the data, not the consent form.
Is sending a face image to a cloud AI API a disclosure?
Treat it as one. The subsection reaches disclosing, redisclosing and otherwise disseminating, and data sent to a third party's infrastructure for processing has been disseminated to that third party whatever the contract calls the relationship. The practical consequences are three. First, your consent language has to cover the disclosure and not merely the collection, which means describing recipients. Second, the vendor's own onward transfers — its hosts, its model providers, its contractors — need to be inside the same description, so you have to ask for the subprocessor list. Third, the 'required by law' and 'financial transaction' exits do not apply to routine product processing, so consent is realistically your only exit and it has to be obtained before the first call, not after a redesign.
What counts as 'otherwise profit from' — does charging for a face-recognition feature violate it?
This is the genuinely unsettled edge of the statute and it is worth being honest about the uncertainty. Transactions in the data itself — selling templates, licensing a dataset, trading access to enrolments — are the core of the prohibition and there is no serious argument otherwise. Earning subscription revenue from a product that performs matching on data you hold for the customer who gave it to you is further from that core, and litigants have pressed both readings. Two practical rules survive the uncertainty: the more the revenue depends on the biometric data as an asset rather than on the software as a service, the worse the position; and anything that makes the data available to a party outside the relationship in which it was collected should be assumed to fail. Where the answer matters to a roadmap decision, get Illinois counsel to look at the specific flow rather than the category.
We are a vendor, not the collector. Do these subsections apply to us?
Yes, because both attach to a private entity in possession of the data rather than to the entity that collected it. A processor that receives templates from its customers is in possession, and is therefore subject to the profit ban and to the disclosure limits on its own onward transfers — including to its hosting providers, its model vendors and any contractor that touches the payload. Contractual language that positions you as a mere service provider allocates risk between you and your customer; it does not remove a statutory duty owed to the individuals. The compliance work for a vendor is accordingly its own: a subprocessor inventory, an improvement-rights position you can defend to customers, a warrant-only rule for law enforcement, a retention and destruction schedule, and a disclosure log.
Does an asset sale of our company transfer biometric data lawfully?
It is the fact pattern where the profit ban and the disclosure limits bite hardest, and it arrives with the least time to think. Moving biometric data to a buyer is a disclosure that needs an exit, and the argument that the data moved incidentally as part of a going concern rather than being sold is precisely the argument the subsection invites a plaintiff to test. Diligence-stage access to a data room containing templates is itself a disclosure, before any deal closes. The workable approach is to plan for exclusion: keep biometric data segregated and inventoried so it can be carved out, destroyed pre-close under your published retention schedule, or re-consented on the buyer's terms. Deals where the biometric database is treated as part of the purchased value are the ones that generate claims after the cheque clears.
The Destination Test
Open your own consent text and your own architecture diagram side by side. Count the destinations biometric data reaches in the diagram. Count the recipients named in the text.
If the first number is larger, the gap is not a documentation problem — every request to an unnamed destination is a disclosure with no exit, and the record of how many times it happened is in your own logs.
Related Reading
- Section 15(b) written release — the permission rule these two subsections sit behind.
- Section 15(a) retention schedule — the published policy that makes a pre-close deletion defensible.
- Scanner deployments — where the templates most organisations hold actually came from.
- Coverage exclusions — who pays when a biometric claim lands.