The Illinois Supreme Court recently agreed to hear an appeal of an Appellate Court’s decision addressing whether an employee’s claim for damages under Illinois’s Biometric Information Protection Act (BIPA) is preempted by the exclusivity provisions of the Illinois Workers’ Compensation Act (IWCA).

Over the past few years. there has been a significant number of class action lawsuits under the BIPA. A key defense for employers defending BIPA lawsuits has been that the BIPA is preempted by the IWCA. Back in September, the Illinois Appellate Court for the First Judicial District held that employees’ BIPA claims were not preempted under the IWCA and could go forward. The Illinois Supreme Court will consider whether this defense has merit, and perhaps reign in the significant number of lawsuits, including putative class actions filed under the BIPA.

In their recent blog post, Maya Atrakchi and Jason C. Gavejian, attorneys in Jackson Lewis’ Privacy, Data and Cybersecurity Practice Group, urge companies to “immediately take steps to comply with the statute.”

 

BIPA poses class-wide risks to companies with operations in Illinois or who engage with employees or consumers in the state. However, biometric privacy should be on the radar of companies everywhere, as other biometric laws are in place in other states, and additional legislation has been introduced elsewhere, at both the state and federal levels.
Photo of Jason C. Gavejian Jason C. Gavejian

Jason C. Gavejian is the office managing principal of the Berkeley Heights, New Jersey, office of Jackson Lewis P.C. and a member of the firm’s Board of Directors. He is also a Certified Information Privacy Professional (CIPP/US) with the International Association of Privacy…

Jason C. Gavejian is the office managing principal of the Berkeley Heights, New Jersey, office of Jackson Lewis P.C. and a member of the firm’s Board of Directors. He is also a Certified Information Privacy Professional (CIPP/US) with the International Association of Privacy Professionals.

As a Certified Information Privacy Professional (CIPP/US), Jason focuses on the matrix of laws governing privacy, security, and management of data. Jason is co-editor of, and a regular contributor to, the firm’s Privacy blog.

Jason’s work in the area of privacy and data security includes counseling international, national, and regional companies on the vast array of privacy and security mandates, preventive measures, policies, procedures, and best practices. This includes, but is not limited to, the privacy and security requirements under state, federal, and international law (e.g., HIPAA/HITECH, GDPR, California Consumer Privacy Act (CCPA), FTC Act, ECPA, SCA, GLBA etc.). Jason helps companies in all industries to assess information risk and security as part of the development and implementation of comprehensive data security safeguards including written information security programs (WISP). Additionally, Jason assists companies in analyzing issues related to: electronic communications, social media, electronic signatures (ESIGN/UETA), monitoring and recording (GPS, video, audio, etc.), biometrics, and bring your own device (BYOD) and company owned personally enabled device (COPE) programs, including policies and procedures to address same. He regularly advises clients on compliance issues under the Telephone Consumer Protection Act (TCPA) and has represented clients in suits, including class actions, brought in various jurisdictions throughout the country under the TCPA.