us

216.73.217.135

Back
News

Amazon Sued Over Illegal Storage of Employee Biometric Data

Amazon Sued Over Illegal Storage of Employee Biometric Data
R Richard M. NOVEMBER 20, 2019 1 minute read

Lawyers from the firm of McGuire Law P.C. of Chicago filed a class action complaint on November 15, against Amazon Web Services (AWS) accusing AWS of violating the Illinois Biometric Privacy Act (BIPA).  

This lawsuit is the latest in a series of BIPA violation suits filed against major enterprises across the state of Illinois. The act aims to defend the individual from having their biometric data recorded, saved, or used without their signed consent. 

The lawsuit specifically targets the storage provided by AWS on its server network for employers and other “commercial customers” who have scanned and captured so-called biometric data from employees, customers, and others. 

According to the complaint, “Defendant (AWS) stores a myriad of types of data on behalf of a wide range of customers spanning virtually every industry sector.” “Notably, Defendant (AWS) also offers cloud storage services for businesses that handle biometric identifiers and biometric information. For example, some of the Defendant’s customers are commercial businesses that require their employees to provide their biometrics, e.g. fingerprints, to check-in and out of their shifts at work.”

The lawsuit alleges that AWS “converts this information into usable formats and mediums for its customers.”

Over the course of the last few years, the 2008 BIPA law has been used to target giant tech companies like Google and Facebook over facial recognition programs. But it has fundamentally been focused against employers across all spectrum of industries who demand biometric data from their workers. This biometric data can be in the form of fingerprint scans or other biometric modalities in order to verify the identity of the worker when punching a time clock for work shifts or when obtaining sensitive data or secured areas. 

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Share you link

Bring your voice

Bring Your Voice.

The community for every hand that writes and every voice that speaks against fraud.

Join Community

Pitch a piece and get a verified byline in the Media room.

“Industry Partnerships That Create Real Value”

Join Shufti’s partnership network to expand your connections, collaborate with industry leaders, and unlock new opportunities.

Pitch a piece and get a verified byline in the Media room.

Partnership Inquiries?
Email us at [email protected]

iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
Copyright © 2026 Shufti. All rights reserved.