June 11, 2021

A Wave of Class Actions Under the Illinois Biometric Information Privacy Act is Causing Insurers and Policyholders to Consider Novel Coverage Questions Under General Liability Policies

Subscribe to Our Newsletter

Newsletter


Ross Weiner

|

June 11, 2021

Over the past few months, you have probably heard about big dollar settlements in cases brought under the Illinois Biometric Information Privacy Act (“BIPA”).  From the social media world, Facebook and TikTok both had significant settlements, agreeing to pay $650 million and $92 million, respectively.  A variety of other companies are now or soon will be facing similar BIPA class actions. 

BIPA is an Illinois statute regulating the collection and use of biometric data, including fingerprints, retina and iris scans, voiceprints, and scans of hand and face geometry.  (740 Ill. Comp. Stat. 14/1  et seq . (2008)). It prohibits private entities from disclosing a person’s biometric information without that person’s consent.  While a few other states have similar laws, only BIPA provides a private right of action. Accordingly, the plaintiffs’ bar has sought to capitalize.

Under BIPA, plaintiffs can recover $1,000 for each negligent BIPA violation and $5,000 for each intentional or reckless violation, plus attorneys’ fees.  The Illinois Supreme Court has held that when a private entity violates BIPA, any person whose biometric information was wrongfully shared can recover, even in the absence of actual injury.   Thus, BIPA class actions expose companies to tremendous potential liability. As the recent Facebook and TikTok settlements confirm, potential damages can add up quickly.   

The new cottage industry of BIPA class actions has led to a predictable result: defendant companies litigating with their insurers over whether there is coverage for the underlying BIPA case.  One case, in particular, stands out.  

West Bend Mut. Ins. Co. v. Krishna Schaumburg Tan, Inc .

In West Bend Mut. Ins. Co. v. Krishna Schaumburg Tan, Inc . (“ West Bend ”), the court was tasked with deciding whether the insurer was obligated to provide a defense for a tanning salon in a BIPA class action brought by a salon customer.  The customer alleged that the tanning salon violated BIPA by obtaining customer fingerprints and sharing them with a third-party vendor without first obtaining the required written release.  The tanning salon, which was covered by two business owners’ liability policies, sought coverage from its insurer.  In response, the insurer filed a declaratory judgment action seeking a declaration that the policy provided no such coverage.  Both parties both moved for summary judgment.  

The policies provided coverage for a “personal injury” that arises out of an “oral or written publication of material that violates a person’s right of privacy,” but also contained an exclusion for “distribution in violation of statutes.”  The parties disputed whether the salon owner’s sharing of customer biometric information with its vendor was a “publication” that violated the customer’s right to privacy and whether the policy’s exclusion applied to BIPA liabilities.

The trial court ruled for the tanning salon, finding the insurer was obligated to provide a defense in the class action. The Illinois Supreme Court affirmed. 

“Publication” and “Right of Privacy”

The insurance policies at issued stated, in pertinent part, as follows:

  1. Business Liability
    1. We will pay those sums that the insured becomes legally obligated to pay as damages because of ‘bodily injury’, ‘property damage’, ‘personal injury’ or ‘advertising injury’ to which this insurance applies. We will have the right and duty to defend the insured against any ‘suit’ seeking those damages. However, we will have no duty to defend the insured against any ‘suit’ seeking damages for ‘bodily injury’, ‘property damage’, ‘personal injury’, or ‘advertising injury’ to which this insurance does not apply.

* * *

  1. This insurance applies:

  • To ‘bodily injury’ and ‘property damage’ only if:
    • (a) The ‘bodily injury’ or ‘property damage’ is caused by an ‘occurrence’ that takes place in the ‘coverage territory’; and
    • (b) The ‘bodily injury’ or ‘property damage’ occurs during the policy period.
  • (2) To:
    • (a) ‘Personal injury’ caused by an offense arising out of your business, excluding advertising, publishing, broadcasting or telecasting done by or for you;
    • (b) ‘Advertising injury’ caused by an offense committed in the course of advertising your goods, products or services[.]”

The policies contain the following pertinent definitions:

“F. Liability And Medical Expenses Definitions

  1. ‘Advertising injury’ means injury arising out of one or more of the following offenses:

* * *

b. Oral or written publication of material that violates a person’s right of privacy;

* * *

  1. ‘Bodily injury’ means bodily injury, sickness or disease sustained by a person, including death resulting from any of these at any time.

* * *

  1. ‘Personal injury’ means injury, other than ‘bodily injury’, arising out of one or more of the following offenses:

* * *

e. Oral or written publication of material that violates a person’s right of privacy.”

The insurer argued that the customer’s BIPA complaint did not trigger the policies’ coverage for “personal injury” or “advertising injury” because the complaint did not allege a “publication” of material that violates a person’s “right of privacy.” The insurer first contended that “publication,” as used in business liability policies, means “communication to the public at large,” and because the tanning salon disclosed the biometric information at issue to only a single entity, there was no “publication.”  The Illinois Supreme Court rejected the insurer’s position, relying on publication’s dictionary definition: “the term means both communication to a single party and communication to the public at large.” Accordingly, the tanning salon’s decision to share the biometric information with its vendor was a “publication.”  

The parties also disputed what “right of privacy” means under the policy.  Looking again to the dictionary definition, the court found that the right to privacy includes two primary privacy interests: seclusion and secrecy.  As a result, the court defined the right to secrecy as the right to keep certain information confidential.   Applying this definition, the court found that BIPA protects a secrecy interest—the right of an individual to keep his or her personal identifying information, like fingerprints, secret. Thus, the court found that the customer’s allegation that the tanning salon shared the customer’s biometric information with a third-party sufficiently alleged a potential violation of the customer’s “right to privacy” within the purview of the insurance policies. 

Violation of Statutes Exclusion 

The policies contained the following pertinent exclusions:

B. Exclusions

  1. Applicable To Business Liability Coverage

This insurance does not apply to:

* * *

      p. Personal Or Advertising Injury

         ‘Personal injury’ or ‘advertising injury’:

* * *

      (2) Arising out of oral or written publication of material whose first publication took place before the beginning of the policy period;

      (3) Arising out of the willful violation of a penal statute or ordinance committed by or with the consent of the insured.

Additionally, an endorsement to the policies added the following exclusion:

This insurance does not apply to:

DISTRIBUTION OF MATERIAL IN VIOLATION OF STATUTES

‘Bodily injury’, ‘property damage’, ‘personal injury’ or ‘advertising injury’ arising directly or indirectly out of any action or omission that violates or is alleged to violate:

(1) The Telephone Consumer Protection Act (TCPA) [(47 U.S.C. § 227 (2018))], including any amendment of or addition to such law; or

(2) The CAN-SPAM Act of 2003 [(15 U.S.C. § 7701 (Supp. III 2004))], including any amendment of or addition to such law; or

(3) Any statute, ordinance or regulation, other than the TCPA or CAN-SPAM Act of 2003, that prohibits or limits the sending, transmitting, communicating or distribution of material or information.”

The insurer argued that that the policies’ exclusions expressly ruled out claims stemming from BIPA violations. According to the insurer, the policies barred coverage for violations of statutes that “prohibit the communicating of information,” which, according to the insurers, BIPA does. In response, the tanning salon emphasized the title of the exclusion and argued that the “other than” language in the exclusion bars coverage only for violations of statutes that regulate methods of communication like telephone calls, faxes, and e-mails. The court agreed with the tanning salon. 

The court began its analysis by pointing out that the exclusion is titled “Violation of Statutes that Govern E-Mails, Fax, Phone Calls or Other Methods of Sending Material or Information.”  The court noted that all the items listed in the title are methods of communication. Next, the court referenced how the exclusion explicitly lists two statutes that regulate methods of communication: the TCPA (telephone calls and faxes) and the CAN-SPAM Act (e-mails).  Accordingly, the court construed the words “other than” in the exclusion to mean other statutes of the same general kind that regulate methods of communication like the TCPA and the CAN-SPAM Act. Because BIPA does not regulate methods of communication, the court held that the statutory violation exclusion does not apply. Furthermore, to the extent that the “other than” language in the policies could be viewed as ambiguous, the court noted that it must be construed against the insurer.  

Different Allegations, Different Policies

In West Bend , the Illinois Supreme Court focused on the specific allegations in the underling class action complaint and its holding relied heavily on the policy language.Different facts underlying an alleged BIPA violation could lead to a different result on issues such as “publication” or “right to privacy.” And of course, not all general liability policies contain definitions and exclusions that are identical to the policy provisions considered by the court. Careful review of the underlying BIPA allegations as well as all pertinent policy language is essential to determine the scope of possible coverage for claims under BIPA.

The case was part of a growing trend of similar actions brought by insurers seeking to avoid coverage in the context of Illinois BIPA class actions. Even beyond the Illinois statute, companies need to recognize the increasing concern regarding privacy and protecting biometric information. Insurers will continue to challenge coverage in this area, and some may even seek to introduce changes to policy language to limit coverage. Policyholders need to scrutinize past, present, and future policies and carefully evaluate whether they are covered for possible BIPA violations. And companies without existing general business liability coverage for such claims may need to pursue other insurance options if faced with a potentially damaging class action.  

Ross Weiner is the Legal Director at Risk Settlements, a team of highly experienced legal, insurance and risk specialists. He helps companies assess legal and financial risk and create optimal settlement designs and risk transfer options. Prior to joining Risk Settlements, he was a litigator at Kirkland & Ellis LLP and focused on class actions among other matters .

Certum Group Can Help

Get in touch to start discussing options.

Recent Content

By Patrick Dempsey September 1, 2026
This is the first post in Certum Group's seven-part series bringing our Trade Secret Litigation Playbook to the blog. It draws on Part I of the Playbook, Why Trade Secret Claims Matter Now. Read or download the full Playbook here . In 2025, federal trade secret filings reached an all-time high — roughly 1,551 new cases in U.S. district courts, up from 1,203 just two years earlier. 1 That is not a blip, and it is not a quirk of the docket. It is the visible edge of a structural shift in how companies create value and how easily that value now walks out the door. Trade secrets used to be the quiet cousin of the intellectual property family — patents got the valuation multiples, trademarks got the brand meetings. That era is over. For a lot of growth-stage companies, the trade secret portfolio can be worth more than the patents, copyrights, and trademarks combined. It rarely shows up on the balance sheet, and it is almost never insured against the risk it actually faces — which is not that someone will design around it, but that someone will take it. So it is worth understanding why the numbers are climbing, because each driver points to a specific exposure that a business owner can do something about. Employees move more, and faster The single largest source of trade secret disputes is not corporate espionage. It is ordinary talent mobility. Roughly 60% of misappropriation cases involve a departing employee, typically heading to a direct competitor. Tenure has shortened, remote work has normalized discreet cross-company job searches, and the volume of departures that touch sensitive information has grown accordingly. The prototypical case a decade ago was a sales rep leaving with a customer list. Today it is a design lead, a data scientist, or a process engineer carrying the company's hardest-won know-how — sometimes in a file, more often in their head. The cost of taking information has collapsed A USB drive, a personal cloud folder, an auto-forwarded email rule, a screenshot script — what once required filing cabinets and a truck now takes a few minutes. The technical friction that used to deter casual misappropriation is largely gone. That has two consequences. It makes the taking easier, and it makes the forensic trail richer: badge records, git commit histories, egress logs, and download timestamps now tell a story that is often more persuasive to a judge than any witness. The evidence exists. The question is whether the claim holder preserves it before it rolls off a ninety-day retention setting. AI has raised the stakes Machine-learning models are trained on data, code, and process knowledge that is frequently proprietary. Competitors racing to ship an equivalent product have a powerful incentive to shortcut the long, expensive path of independent development — and in software, life sciences, financial services, and advanced manufacturing, a six-to-twelve-month head start can be worth hundreds of millions of dollars. When the crown jewels are unpatented know-how, misappropriation is not a nuisance. It is an existential competitive event. Apple's 2026 trade secret suit against OpenAI — built around aggressive hiring from Apple's hardware teams — is only the most visible example of a pattern now playing out across the economy. A single, credible venue Finally, the law itself has changed the calculus. Since 2016, the federal Defend Trade Secrets Act has given claim holders a nationwide cause of action, federal discovery tools, and remedies strong enough to matter — including an extraordinary ex parte seizure procedure. 2 Enforcement is more predictable than it was under a patchwork of state statutes, and predictability attracts plaintiffs. It also attracts capital, which is where a firm like ours enters the picture. What it means for you From the underwriter's chair, the trend line is unambiguous: more valuable secrets, more mobile employees, cheaper theft, and a legal framework that rewards claim holders who move deliberately. The companies that fare worst are the ones that treated their secrecy program as a compliance checkbox and discover, only in a complaint, that it was the strategy all along. The companies that fare best have thought about identification, preservation, and enforcement economics before they ever need them. If your business runs on information other people would love to have, the record filing numbers are not abstract. They are a forecast. Go deeper with the Playbook. This post covers one piece of a much larger picture. For the full framework — what the law requires, what a strong pre-filing case looks like, how damages experts value these matters, how counsel fee structures change your economics, and how litigation finance fits in — read Certum Group's Trade Secret Litigation Playbook , our field guide for business owners and the counsel who advise them: certumgroup.com/the-trade-secret-playbook . And if you are evaluating a live dispute — or simply want to pressure-test what a matter is worth and how it might be funded — get in touch. A confidential conversation with Certum is free and carries no obligation, whether or not you ultimately seek funding. Reach us at certumgroup.com/contact-us . Sources 1. Lex Machina, Trade Secret Litigation Report (2026), reporting an all-time high in federal trade secret case filings in 2025; see also Lex Machina, Trade Secret Litigation Report (2024) (1,203 federal filings in 2023). 2. Defend Trade Secrets Act of 2016, Pub. L. No. 114-153, 18 U.S.C. Section 1836 et seq.
By Certum Group Team August 31, 2026
Certum’s William Marra was recently quoted in an article by MLex, a LexisNexis publication, on the widening debate over third-party litigation funding disclosure. “Litigation finance is the capital markets come to law,” Marra told the publication, emphasizing that funders are one of the few sources of capital available to an individual or small business facing a far larger opponent.  Responding to claims that litigation funding is a vehicle for foreign influence, Marra observed that “there’s just no evidence [of foreign influence] in the third-party funding space,” emphasizing that any real threat should be addressed through regulation covering foreign influence in litigation “in all of its forms.” The article also referenced Marra’s forthcoming New York University Law Review article on the third-party funding disclosure debate, which argues that any court-made disclosure rule should apply evenhandedly to all outside financing, and should not target only one form of third-party finance. “If you want to genuinely have a third-party litigation funding disclosure rule, then disclose all forms of third-party funding. Don’t just disclose the type of non-recourse litigation funding seeking money damages that is disproportionately used by poor individuals and small businesses.” The full article, Patent Litigation Drawn into Broader Third-Party Funding Disclosure Debate, is available here .
By Patrick Dempsey August 18, 2026
On July 10, 2026, the most valuable company in the world accused the most talked-about company in the world of theft. Apple sued OpenAI in the U.S. District Court for the Northern District of California, alleging that OpenAI built its hardware ambitions on a foundation of Apple’s misappropriated trade secrets.¹ Few disputes touch as much of Certum’s Trade Secret Litigation Playbook at once: reasonable measures to guard a secret, identifying with particularity what was taken, and the human-centered points — recruiting and employee departures — where secrets actually walk out the door. Nearly every core theme in Certum Group’s Trade Secret Guide is in this case. And the lesson beneath it is worth sitting with: for the companies with the most to protect, trade secret litigation is not a last resort. It’s a front-line instrument of competitive strategy. Background The dispute sits at the intersection of two of the most closely watched storylines in technology. In 2025, OpenAI acquired io, the hardware venture founded by former Apple design chief Jony Ive and a group of other Apple alumni, for a reported $6.5 billion, and set out to build its first consumer hardware device, widely expected to compete directly with the iPhone.² To staff that effort, OpenAI hired aggressively from Apple. According to the complaint, more than 400 former Apple employees now work at OpenAI.³ Two of those hires anchor Apple’s allegations. Tang Yew Tan spent roughly 24 years at Apple, where he served as a vice president of product design responsible for the iPhone and Apple Watch, before becoming OpenAI’s chief hardware officer. Chang Liu spent about eight years at Apple as a senior systems electrical engineer before departing for OpenAI in 2026.⁴ Apple’s theory is not that a single rogue employee walked out the door with a file. It is that the movement of talent was accompanied by a coordinated effort, one Apple describes as operating “at every level," to extract and exploit the confidential information those employees carried in their heads and on their devices.⁵ The Allegations The complaint reads less like a garden-variety departure dispute and more like a catalog of the exact conduct the Trade Secret Guide warns companies to watch for. Among Apple’s central allegations: Apple claims OpenAI’s hardware leadership directed recruiters to use Apple’s confidential project code names during the hiring process, and instructed job candidates to bring “actual parts” and “CAD/design artifacts” to their interviews.⁶ It alleges that OpenAI circulated internal Apple documents marked “Need to Know” that coached departing employees on how to evade Apple’s exit-security procedures, including the “dreaded walkout,” and to alert OpenAI before signing their exit agreements.⁷ The specifics attributed to individual employees are what give the complaint its texture. Apple alleges that Chang Liu exploited an authentication bug to reach internal network storage after his access should have been cut off, messaging a colleague, “LOL, I found out I can access the [network storage], so funny,” and noting within hours of his departure that he “still ha[d] another computer.”⁸ And Apple alleges that io “exploited and used Apple’s secret, proprietary industrial design techniques,” misleading one of Apple’s own manufacturing partners about whether it was authorized to use a confidential metal-finishing technique.⁹ The trade secrets Apple says are at risk span the full arc of its product-development process: technical specifications for unreleased technologies, engineering presentations and prototype data, component and vendor selection processes, and the proprietary manufacturing techniques that turn a design into a shippable product.¹⁰ Notably, Apple’s opening ask is not a damages windfall. It is protection. Apple seeks to bar OpenAI from using or disclosing the information at issue, to compel the return of its confidential materials, and to preserve the evidence.¹¹ In other words, Apple is using the courthouse to do what its NDAs and exit interviews were supposed to do: keep its edge inside the building. OpenAI’s Response OpenAI has pushed back hard, and its answer is a preview of the fault lines any trade secret plaintiff should expect to fight over. On August 6, 2026, OpenAI moved to dismiss, characterizing the alleged conduct as “benign, lawful conduct” that Apple has mischaracterized, and arguing that its hardware executives simply followed standard industry recruiting practices.¹² As to Chang Liu, OpenAI contends he was “trying to help Apple” by assisting former colleagues who asked him to locate work information, not stealing anything.¹³ More pointed, and more instructive, is OpenAI’s argument that Apple’s own conduct undermines its case. OpenAI asserts that Apple allowed employees to use personal iCloud accounts for work and failed to properly revoke access when they left — noting that an Apple manager remained logged into Chang Liu’s personal iCloud account after his departure in order to transfer files.¹⁴ From that, OpenAI argues that Apple’s offboarding lapses created “confusion and unwanted access issues that Apple now characterizes as theft.” OpenAI also contends that Apple has not identified its trade secrets with adequate specificity, pointing instead to “generic categories of the product-development process.”¹⁵ OpenAI must file its full response by August 17, 2026, with oral argument on the motion set for October 1, 2026.¹⁶ Whatever the merits, OpenAI’s playbook is worth studying precisely because it is so conventional. Reasonable secrecy measures and identification of the trade secret with particularity are two of the elements every misappropriation claim rises or falls on, and they are exactly where a well-resourced defendant will apply pressure first. What This Means It is easy to read a case like this as celebrity litigation between two of the most valuable enterprises on earth. The more useful reading is that trade secret law has become core infrastructure for how modern companies protect competitive advantage. Apple did not respond to a $6.5 billion competitive threat with a press release or a patent portfolio. It responded with a trade secret complaint, because in a business where the crown jewels are unpatented know-how — manufacturing techniques, vendor relationships, unreleased designs — the Defend Trade Secrets Act and its state-law counterparts are the sharpest tools available. The case also throws the Trade Secret Guide’s central lessons into relief. The value of a trade secret program is only as good as the “reasonable measures” behind it; OpenAI’s opening move is to argue that Apple’s own iCloud and offboarding practices were not reasonable at all. The ability to describe what was taken, with specificity, is not a formality. It is frequently the whole ballgame at the pleading stage. And the human element — recruiting, exit procedures, the “dreaded walkout” — is where secrets actually leak, long before anyone reaches a courtroom. Companies that treat these as compliance checkboxes learn the hard way, in a complaint, that they were the strategy all along. For those of us who evaluate disputes for a living, Apple v. OpenAI is also a reminder of why high-stakes trade secret matters are among the most compelling on the plaintiff’s side. The conduct is often concrete and documentable, the competitive stakes are enormous, and, as the Federal Circuit’s recent decision in Versata Software v. Ford underscored, the damages framework can reach the full value of what the misappropriation delivered to the wrongdoer, not merely a discounted license fee. That combination is exactly what makes these cases worth pursuing, and worth backing. Apple’s complaint will be tested, as it should be, and the allegations remain just that — allegations. But the strategic signal is already unmistakable. When the most valuable company in the world wants to defend its future, it reaches for trade secret law. Certum Group’s Trade Secret Guide is built to help plaintiffs and their counsel do the same, whatever their size, and this case is a live illustration of why that playbook matters now more than ever. Certum Group can help. If you are evaluating a trade secret dispute or want to talk through options for funding or de-risking one, get in touch . Footnotes ¹ Complaint, Apple Inc. v. OpenAI, Inc. , No. 5:26-cv-07078 (N.D. Cal. filed July 10, 2026); see Apple sues OpenAI over alleged trade secret theft , TechCrunch (July 10, 2026). ² The wildest allegations in Apple's trade secrets lawsuit against OpenAI , TechCrunch (July 13, 2026). ³ Id. ⁴ Apple sues OpenAI over alleged trade secret theft , TechCrunch (July 10, 2026). ⁵ Apple sues OpenAI alleging trade secret theft, says scheme was "at every level," CNBC (July 10, 2026). ⁶ The wildest allegations in Apple's trade secrets lawsuit against OpenAI , TechCrunch (July 13, 2026). ⁷ Id. ⁸ Id. ⁹ Id. ¹⁰ Apple sues OpenAI over alleged trade secret theft , TechCrunch (July 10, 2026). ¹¹ Id. ¹² OpenAI Asks Judge to Toss Apple's Trade Secrets Lawsuit , Claims Journal (Aug. 7, 2026). ¹³ Id. ¹⁴ OpenAI says Apple's own security practices undermine its trade secrets case , TechCrunch (Aug. 6, 2026). ¹⁵ Id. ¹⁶ OpenAI Asks Judge to Toss Apple's Trade Secrets Lawsuit , Claims Journal (Aug. 7, 2026).