Courts Define When BIPA Exemptions Apply to Biometric Use in Finance
Federal courts ruled on BIPA exemptions for biometric authentication in financial services.
Why it matters: Financial institutions and biometric vendors must understand when BIPA exemptions apply under GLBA to avoid costly privacy litigation risks.
- Illinois’ BIPA exempts financial institutions subject to the Gramm-Leach-Bliley Act (GLBA) from biometric data rules.
- In June 2026, the Third Circuit ruled in Pindrop Security’s case that voice biometrics used for direct financial authentication qualifies for the exemption.
- In March 2026, the Seventh Circuit affirmed Nuance Communications’ voice authentication under GLBA exemption in financial services.
- In 2025, courts held biometric data collectors like Jumio are not exempt under GLBA and must comply fully with BIPA.
The Illinois Biometric Information Privacy Act (BIPA) broadly regulates biometric data collection but exempts financial institutions regulated under the Gramm-Leach-Bliley Act (GLBA) from its requirements. Recent federal decisions clarify how this exemption applies to biometric authentication vendors in financial services.
In June 2026, the U.S. Court of Appeals for the Third Circuit ruled in Pindrop Security, Inc. v. Amazon.com that Pindrop, which authenticates customer voices for financial transactions, falls within the GLBA exemption. The court labeled this as "core financial infrastructure," meaning Pindrop's direct role in verifying identity for banking activities exempts it from BIPA. Clarissa Cerda, Pindrop’s Chief Legal Officer, said, "The court confirmed that authenticating a voice in a financial transaction is a proper banking activity governed by the federal framework." (ABA Banking Journal, June 2026).
Similarly, in March 2026, the Seventh Circuit ruled in Nuance Communications, Inc. v. Plaintiff that Nuance’s voice authentication used by banks qualifies for the GLBA exemption from BIPA. Liisa M. Thomas, partner at Sheppard Mullin, explained, "The court acknowledged Nuance's identity verification as a proper banking activity exempt from state biometric regulations." (Jenner & Block, March 2026).
Conversely, in 2025, courts found that biometric data collectors like Jumio Corp., who supply identity verification tech to financial institutions but do not directly perform authentication in transactions, are not covered by the GLBA exemption and must comply fully with BIPA. The ruling in Davis v. Jumio Corp. stressed the importance of understanding a vendor’s role: data collectors are subject to state biometric privacy rules.
These rulings sharpen compliance distinctions for financial entities and service providers. Vendors directly performing biometric authentication in financial transactions can claim BIPA exemption under GLBA, while support service vendors without a direct role generally cannot. Legal professionals and compliance officers in financial services should assess vendor roles carefully to manage privacy risks.
By the numbers:
- June 2026 — Third Circuit ruling on Pindrop Security’s BIPA exemption
- March 2026 — Seventh Circuit affirming GLBA exemption for Nuance Communications
- 2025 — Court ruling denying GLBA exemption to biometric data collector Jumio
Yes, but: While these rulings clarify exemption scope, BIPA compliance complexities remain, as state-level privacy laws continue evolving and may differ beyond Illinois.
What's next: Financial institutions should monitor ongoing litigation and regulatory updates, as further cases may refine the scope of biometric privacy exemptions under GLBA.