The Illinois Supreme Court recently issued a ruling that exposes the White Castle burger chain to as much as $17 billion in liability because it didn’t get explicit permission from employees to use biometric controls on its time clocks and computers. But don’t blame the courts for the burger joint’s legal costs. The Illinois legislature’s early and aggressive move to regulate technology in the name of privacy ignored time-honored requirements like proportionality. It’s a lesson for other states and for Congress, which should not follow Illinois’ lead.
Statutes of limitations keep stale controversies out of the courts. In defending against the charge that it violated the rights of some 9,500 current and former employees by using biometric controls without their explicit permission, White Castle has argued that the lead plaintiff in the case took more than a decade to complain. If the offense is getting access to her fingerprint data contrary to the rules in the Illinois Biometric Information Privacy Act, it happened too long ago for her to sue. But Latrina Cothron, a Chicago-based White Castle manager, argues that White Castle committed a new offense with each collection of her fingerprint in the absence of the specific agreement the Illinois statute requires.
The court decided that she is right. It reads the statute as creating a new offense every time an employee’s biometric is collected. Every single workday, sometimes multiple times per day.