On October 31, 2023, the U.S. District Court for the Northern District of Illinois issued a decision regarding the way a private entity has to notify data subjects before collecting their biometric data.
The decision comes following a privacy class action known as Wilcosky, et al. v. Amazon.com, Inc., et al., No. 19-CV-5061, where several individuals claimed that Amazon’s AI, Alexa, a digital assistant for Amazon’s services that is voice operated, was not compliant with Illinois’ Biometric Information Privacy Act (BIPA), specifically, points 15 (b), (c), (d) of the law.
According to these points,
(b) No private entity may collect, capture, purchase, receive through trade, or otherwise obtain a person's or a customer's biometric identifier or biometric information, unless it first:
(1) informs the subject or the subject's legally authorized representative in writing that a biometric identifier or biometric information is being collected or stored;
(2) informs the subject or the subject's legally authorized representative in writing of the specific purpose and length of term for which a biometric identifier or biometric information is being collected, stored, and used; and
(3) receives a written release executed by the subject of the biometric identifier or biometric information or the subject's legally authorized representative.
(c) No private entity in possession of a biometric identifier or biometric information may sell, lease, trade, or otherwise profit from a person's or a customer's biometric identifier or biometric information.
(d) No private entity in possession of a biometric identifier or biometric information may disclose, redisclose, or otherwise disseminate a person's or a customer's biometric identifier or biometric information unless:
(1) the subject of the biometric identifier or biometric information or the subject's legally authorized representative consents to the disclosure or redisclosure;
(2) the disclosure or redisclosure completes a financial transaction requested or authorized by the subject of the biometric identifier or the biometric information or the subject's legally authorized representative;
(3) the disclosure or redisclosure is required by State or federal law or municipal ordinance; or
(4) the disclosure is required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction.
In particular, the Court reviewed Amazon’s Voice ID feature, which is something users have to enroll into, or opt in, by navigating to a screen where they are notified that this feature “enables Alexa to learn your voice, recognize you when you speak to any of your Alexa devices, and provide enhanced personalization.” The same screen displays at the bottom a hyperlink to the Terms of Use where users are informed that Voice ID “uses recordings of your voice to create an acoustic model of your voice characteristics.” Before completing this process of opting into the use of the Voice ID feature, a user has to agree to the terms of use and provide their authorization for “the creation, use, improvement, and storage” of his or her Voice ID by tapping an “Agree and Continue” button.
In addition, plaintiffs have claimed that while only one member of a household has gone through the process of onboarding and provided consent for data collection, storage and processing, information of another household member was collected as well, even though they never provided their consent. Amazon argued that those who had enrolled into Voice ID received the required notice and provided their written consent by completing the processes of feature activation and agreeing to terms of data processing.
Additionally, it was alleged that “Amazon disclosed, redisclosed, or disseminated” their biometric data, and as such it is in violation of this Section of BIPA. Same as with the previous point, Amazon moved to have this dismissed as it claimed that the plaintiffs cannot provide the actual details of the third parties with which it has allegedly shared their biometric data.
The Court’s decision on each of the 3 was as follows:
Section 15 (b)
Section 15 (c)
Section 15 (d)
This decision, which is now known as ‘the Wilcosky decision,’ brings a significant change to the way a company must provide notice to individuals in such a way as to be in compliance with BIPA. End users must be provided with a clear language that informs them what is being collected, for how long, and for what purposes, so that they can provide a consent that is informed. Furthermore, BIPA includes as ‘biometric identifier’ “a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry'' and excludes a whole range of other types of identifiers. Companies should consider it a best practice to get themselves acquainted with the BIPA’s definition of biometric data and its classification of biometric identifiers.