FB pixel

Lawyer recommends that companies consult biometric privacy experts to avoid lawsuits

 

In light of several class action lawsuits from employees accusing companies of illegally collecting and storing their biometric data, a Chicago attorney has recommended companies to be conscious of the litigation threat stemming from an increasing number of state laws protecting biometric privacy, according to a report by Cook County Record.

“Companies should consult with their lawyers and… adopt policies and procedures to comply with these [and other] requirements,” said Steve Gold, an attorney with McguireWoods. “It is also important for a company to work with its lawyers and its information technology personnel to take steps to maintain the security and privacy of private information including biometrics so as to reduce any possible harm to the individuals whose information is collected.”

There have been two recent cases in the Chicago area highlighting the legal risk. First, employees of the Intercontinental Hotel Group filed a class action lawsuit against the hotel chain over claims that it wrongly collected and used their fingerprints and other biometric information.

The second case involves multiple lawsuits against supermarket chain Mariano’s which allege that the company violated the Illinois Biometric Information Privacy Act (BIPA) by requiring employees to submit their biometrics data without consent.

BIPA was enacted in 2008 protect the security of Illinois residents’ biometric data, including fingerprints and retinal data.

Mariano’s timekeeping system allegedly required the company to scan and store each employee’s unique fingerprint, however, Mariano’s never obtained the written consent of its employees before storing the data, the lawsuit said.

“In Illinois [and a few other states], there is a specific statute addressing biometric information, such [as] a fingerprint,” Gold said. “That law provides that no private entity may collect such information unless it first follows certain guidelines.”

Gold said the company must inform the employee in writing that it is collecting the biometric data; the purpose and length of time for which it is collecting the data; and obtain an informed written consent (which must be signed as a condition of employment).

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

Canada regulator backs privacy-preserving age assurance

The Office of the Privacy Commissioner of Canada (OPC) has published a policy note and guidance documents pertaining to age…

 

FCC seeks comment on KYC revision for commercial phone calls

The U.S. Federal Communications Commission (FCC) has proposed stronger KYC requirements for voice service providers to prevent scams and illegal…

 

Deepfake detection upgrade for Sumsub highlights continuous self-improvement

Sumsub has launched an upgrade to its deepfake detection product with instant online self-learning updates to address rapidly evolving fraud…

 

Metalenz debuts under-display camera for payment-grade face authentication

Unlocking a smartphone with your face used to require a camera placed in a notch or a punch hole in…

 

UK regulators pan patchwork policy for law enforcement facial recognition

The UK’s two Biometrics Commissioners shared cautionary observations about the use of facial recognition in law enforcement over the weekend…

 

IDV spending to hit $29B by 2030 as DPI projects scale: Juniper Research

Spending on digital identity verification (IDV) technology is projected to reach a 55 percent growth rate between now and 2030,…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events