A recent ruling from the Seventh Circuit Court of Appeals has revived a lawsuit against Gunnar Optiks, LLC, a company known for its computer eyewear. The court found that the company may have violated Illinois' Biometric Information Privacy Act (BIPA) by collecting facial data without proper consent. This ruling could have significant implications for how companies handle biometric data in the future.

The case, William Clements v. Gunnar Optiks, LLC (docket number 25-1890), centers around allegations that Gunnar Optiks collected images of potential customers' faces through a virtual try-on feature. This feature allowed users to see how the glasses would look on them by scanning their faces. William Clements, the plaintiff, argues that this practice violated BIPA, which requires companies to obtain consent before collecting biometric information.

The dispute began when Clements filed a lawsuit against Gunnar Optiks in state court, claiming that the company did not comply with the state's privacy laws. Gunnar Optiks contended that the data collection was exempt under the law because it occurred in a healthcare context. However, the state court rejected this argument. The case was later moved to federal court, where the district court dismissed the complaint, stating that Clements failed to state a claim under the law.

The Seventh Circuit Court of Appeals, led by Judge Frank Easterbrook, reviewed the case and found that the district court had erred in its dismissal. The court acknowledged that Gunnar Optiks did not deny that facial images fall under the scope of BIPA. The law defines biometric identifiers to include “a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry.” Therefore, the court ruled that the collection of facial data without consent could be a violation of the law.

The court noted that Gunnar Optiks argued that the data collection was exempt because it was for health care treatment under the Health Insurance Portability and Accountability Act (HIPAA). However, the court found that the company's assertion that its glasses relieve eye strain was not sufficient to categorize the data collection as a healthcare activity. The court stated, “Even if Gunnar’s glasses reduce digital eye strain, how does collecting data about facial shapes come within the exclusion in the state statute?”

Ultimately, the Seventh Circuit vacated the district court's judgment and sent the case back for further proceedings. The court emphasized that factual defenses, such as Gunnar's claims about the benefits of its eyewear, should be proven through evidence, not assumed at the complaint stage. The ruling highlighted the need for a more thorough examination of whether Gunnar Optiks complied with BIPA and HIPAA.

This ruling is significant for several reasons. First, it reinforces the importance of consent when collecting biometric data. Companies that handle biometric information must ensure they comply with state laws like BIPA, which is designed to protect individuals' privacy rights. The decision also underscores the broader implications for businesses that utilize technology to collect personal data, particularly in the healthcare sector.

The outcome of this case could set a precedent for future lawsuits involving biometric data collection. With growing concerns about privacy and data security, companies may need to reevaluate their practices to avoid potential legal challenges. The ruling serves as a reminder that businesses must be transparent about their data collection methods and obtain explicit consent from consumers.

Looking ahead, it remains to be seen how this case will unfold in the lower court. The Seventh Circuit's decision opens the door for further discovery and examination of Gunnar Optiks' practices regarding data collection and compliance with privacy laws. It is unclear if Gunnar Optiks will appeal the ruling or if there are related cases pending that could influence the outcome.

As this case progresses, it will be essential for consumers and businesses alike to pay attention to the evolving landscape of biometric privacy laws and the implications for data collection practices.