Coinbase cryptocurrency exchange logo on smartphone screen showing biometric data lawsuit in Illinois

Lawsuit Alleges Coinbase Violated Illinois Biometric Data Law

The state of Illinois has a unique law governing biometric data on the books, one that last became a topic of national conversation when it was used to chase facial recognition contractor Clearview AI out of the state and to levy big fines against the likes of Facebook and White Castle. Popular cryptocurrency exchange Coinbase, the largest of its type used in the United States, is now facing a similar legal challenge.

The exchange has been sued for collecting biometric data from the photos of ID cards and the “selfies” that it requires when customers set up an account, and from the fingerprint scans that are used to authenticate mobile app users. The suit alleges that Coinbase fails to inform customers of the purpose of collecting the data, how it is stored, under what conditions it is destroyed and how long they can expect it to be held for.

Lawsuit alleges Coinbase has no public written policy for its biometric data handling

The lawsuit says that Coinbase does not provide the requisite information as required by the Illinois Biometric Information Privacy Act (BIPA). Coinbase allegedly creates a “highly detailed” geometric template of user’s faces from the photo ID and selfies that they are required to upload when creating accounts. Customers that want to use the mobile app must use either a face or fingerprint scan to authenticate when logging in, but even those that log in via a web browser must provide the photos at minimum.

In addition to failing to meet the BIPA requirements for providing data handling guidelines and a retention schedule, the suit alleges that the state law requires Coinbase to destroy the collected biometric data from the photos after the account is verified and activated as it no longer serves a required purpose at that point if the user does not opt to use facial verification as a login method. The plaintiffs claim that the exchange is “wrongfully profiting” from the stored biometric data and that it could be exceptionally damaging to users should it be stolen in a hack or data breach.

BIPA provides for damages of up to $5,000 per intentional violation, which the suit is seeking. The amount could be reduced to as little as $1,000 if the court finds that Coinbase is in violation of the law but that the violations were not willful. Coinbase has yet to make any public comment on the case.

If the case moves forward, one potentially interesting facet is that it may force greater transparency into how Coinbase uses the personal data it collects. The company’s data privacy statement says that it does not sell customer personal information to other parties, but it does “share” it with third party advertisers if the user does not opt out via a toggle switch in the account’s Privacy Rights Dashboard. The suit names a number of third party authentication services and banking platforms as Coinbase partners in biometric data sharing.

BIPA wielded against a variety of businesses as other states eye equivalent rules

While the social media scraping case brought against Clearview AI is likely the incident that brought BIPA to mainstream attention in the rest of the country, the active use of the bill in biometric data lawsuits dates back to a 2017 ruling involving the popular amusement park chain Six Flags. That ruling established that BIPA plaintiffs do not have to show actual harm to bring a case, prompting thousands of BIPA-based lawsuits to be filed since.

One of the most recent of these cases, a decision against restaurant chain White Castle, involved the collection of fingerprint data by an employer and sharing of it with a third party without express employee consent. The decision not only sets a precedent for workplaces, but also establishes that a violator may be fined on a per-incident basis rather than just one time for each subject involved; this has put White Castle in the position of facing a possible maximum $17 billion fine considering its number of employees and times their fingers have been scanned.

Given that BIPA case decisions have tended to expand its terms and potential fines in this way over time, companies that are brought to court generally look to settle as fast as possible. Some simply keep any products that could involve biometric data out of Illinois. That was the case with the Google Arts app, which in 2018 introduced a feature allowing users to take a selfie and have the search engine find a historical portrait subject that most closely matched them. That feature was never introduced in the state due to legal concerns. Sony’s Aibo robotic pets, which use facial recognition technology to identify different people, are also not sold in the state.

Though BIPA has been effective, states have been gun-shy about implementing their own versions, largely due to concerns about a ruinous impact on businesses. Texas and Washington are the only states with comparable laws on the books, but neither has a right to private action; only the state attorney general can initiate a lawsuit. The headwinds seem to have changed in 2023, however, as the year has opened with 11 different states putting forward biometric data privacy law proposals.