Is Your Customer Service Call a Biometric Event? Lowe’s Voiceprint Lawsuit Signals a New BIPA Risk for AI

Table of Contents

A routine call to customer service may be becoming something very different under Illinois privacy law.

A proposed class action filed against Lowe’s accuses the home improvement retailer of using its customer-service telephone systems to collect biometric “voiceprints” from Illinois callers without providing the written disclosures or obtaining the consent required by the Illinois Biometric Information Privacy Act.

The September 10 lawsuit, filed in Cook County Circuit Court, is still at the allegation stage. Lowe’s has not been found liable, and one of the most important factual questions remains unresolved: whether Lowe’s merely records customer-service calls, which by itself is not necessarily biometric processing, or whether its systems actually analyze callers’ voices in a way that creates biometric identifiers capable of distinguishing or identifying individual speakers.

That distinction could decide much of the case.

But the lawsuit matters even before a court answers it.

It follows similar 2026 litigation accusing Walmart of creating customer voiceprints from telephone calls and arrives almost simultaneously with a separate lawsuit accusing Meta of deriving faceprints from Facebook and Instagram photographs for artificial intelligence and an unreleased facial-recognition system.

Taken together, the cases show how Illinois’ 2008 biometric privacy law is colliding with AI systems that can turn ordinary human characteristics into mathematical data without the person ever realizing biometric processing occurred.

The Lowe’s Lawsuit

The case is Perkins v. Lowe’s Companies, Inc., Case No. 2026CH08748, filed September 10 in the Circuit Court of Cook County, Illinois.

Lead plaintiff Rosemarie Perkins alleges she called Lowe’s corporate customer-service line from Illinois in May 2026 concerning purchases and orders.

According to the complaint, she interacted with an automated telephone system but did not reach a live representative.

The complaint alleges that Lowe’s recorded her voice and, “upon information and belief,” subjected at least some customer calls to speaker-recognition or voice-analysis technology capable of generating voiceprints from distinctive vocal characteristics.

The plaintiff says she was never given the BIPA-specific written notice describing the collection, its purpose and its retention period, and never executed a written release authorizing Lowe’s to collect biometric information from her voice.

She also alleges that voice-derived biometric information was shared with technology vendors or service providers without the consent BIPA requires.

The proposed class covers Illinois residents whose voiceprints or voice-derived biometric information allegedly were processed through Lowe’s customer-service telephone systems without written consent.

Those are allegations. They have not yet been proven.

Lowe’s Publicly Says It Records Customer-Service Calls

Lowe’s current U.S. privacy statement, last updated March 11, 2026, expressly tells consumers that calls may be recorded.

The notice says:

“Calls may be recorded or monitored for training and quality purposes.”

It also describes MyLow as an AI-powered assistant and says information shared with its AI chatbots may be processed by service providers that help operate the system.

The lawsuit does not dispute that Lowe’s discloses ordinary call recording.

Instead, it argues that telling a customer a telephone conversation may be recorded for quality and training is not the same thing as telling that customer that the company allegedly creates a biometric voiceprint from the recording.

That is a critical distinction under BIPA.

A Voice Recording Is Not Automatically a Voiceprint

This may become the central technical issue in the case.

Illinois law expressly lists a “voiceprint” as a biometric identifier, alongside fingerprints, iris scans and scans of face or hand geometry.

But BIPA does not say that every recording containing someone’s voice is a biometric identifier.

The Illinois Attorney General has previously made that distinction explicit.

In a 2017 opinion discussing BIPA, the Attorney General explained that a voiceprint generally involves a mechanical measurement of vocal characteristics used to identify a speaker, and contrasted that with simply recording someone’s voice. The opinion cited federal precedent observing that someone who merely records a voice without generating a voiceprint is not doing the same thing.

The Lowe’s complaint itself recognizes this distinction.

It alleges that an ordinary recording simply preserves the sounds and words spoken during a call, while speaker-recognition technology goes further by analyzing vocal characteristics and converting them into a mathematical representation or template that can be used to recognize, distinguish or authenticate a person.

That difference is enormously important.

If Lowe’s merely records calls for quality assurance, the BIPA voiceprint theory becomes much more difficult.

If its technology extracts measurable vocal characteristics and creates an identifying biometric template, the analysis changes substantially.

What Exactly Is a Voiceprint?

Modern voice biometrics can analyze characteristics of speech that are difficult for another person to reproduce exactly.

Depending on the system, relevant signals can include:

  • pitch;
  • cadence;
  • frequency characteristics;
  • vocal tract properties;
  • rhythm;
  • pronunciation patterns;
  • spectral characteristics; and
  • other physical or behavioral characteristics of speech.

Those measurements can be converted into a numerical representation sometimes called a template, embedding or voiceprint.

The system does not necessarily need to save a conventional audio file saying, “This is Jane Smith.”

A mathematical representation can potentially be used to compare one call with another and determine whether the same person is speaking.

That is fundamentally different from storing an MP3 or WAV file for a supervisor to review later.

Voice AI Can Be Doing Several Different Things

The rapid adoption of AI in contact centers makes this issue harder because companies increasingly use audio for functions that sit on a spectrum between simple recording and biometric identification.

A telephone system might perform speech-to-text transcription.

It might identify the language being spoken.

It might determine whether the caller sounds frustrated.

It might summarize the call.

It might detect keywords associated with fraud.

It might distinguish the customer from background voices.

It might authenticate the caller based on vocal characteristics.

Or it might create a persistent voice template that allows the caller to be recognized on future calls.

Those are not necessarily the same legally.

The word “AI” tells a privacy team very little about what actually happens to the customer’s voice.

Why BIPA Is Different From Most U.S. Privacy Laws

The Illinois Biometric Information Privacy Act has been one of the most consequential state privacy laws in the United States because it gives individuals a private right of action.

Unlike many privacy laws that depend primarily on government enforcement, BIPA allows an aggrieved individual to sue a private company directly.

For covered biometric collection, Section 15(b) generally requires the company to do three things before collecting or otherwise obtaining the biometric identifier:

  • inform the person in writing that biometric information is being collected or stored;
  • explain in writing the specific purpose and length of time for which the information will be collected, stored and used; and
  • receive a written release from the individual.

Section 15(d) separately restricts disclosure of biometric information to third parties without consent or another statutory exception.

Section 15(a) also requires companies possessing biometric data to maintain a publicly available retention and destruction policy.

That policy generally requires permanent destruction when the original purpose has been satisfied or within three years of the person’s last interaction with the company, whichever occurs first.

A General Privacy Policy May Not Solve the Problem

This is another reason the Lowe’s lawsuit matters.

Many companies have extensive privacy policies describing recordings, AI, vendors and personal-information processing.

BIPA’s requirements are more specific.

The plaintiff argues that Lowe’s general disclosure that calls may be recorded for quality and training does not tell callers that a biometric voiceprint is allegedly being created.

The complaint also argues that the public privacy statement does not constitute the written release executed by the caller that Section 15(b) requires.

If biometric voice processing is occurring, a general “this call may be recorded” message may therefore be addressing the wrong activity entirely.

The company would be disclosing recording while failing to disclose biometric extraction.

The Written-Consent Requirement Creates a Practical Problem for Call Centers

BIPA becomes particularly awkward in a telephone environment because the law requires a written release.

Illinois amended the law in 2024 to clarify that an electronic signature can satisfy the definition of a written release.

But that still leaves an operational question.

How does a company obtain a written or electronically signed release from someone who simply dials an 800 number?

If a contact center truly uses voice biometrics on Illinois consumers, it may need a workflow different from the familiar recorded announcement that says a call “may be monitored for quality assurance.”

Possible architectures might involve directing customers through an online enrollment process, obtaining electronic consent through an authenticated account, sending a consent request to a mobile device, or designing a non-biometric fallback for callers who do not consent.

The specific solution will depend on the technology and legal advice.

The larger point is that deploying biometric functionality inside an existing voice channel can create compliance requirements the original call-center workflow was never designed to handle.

The Third-Party Vendor Allegation May Be Equally Important

The Lowe’s lawsuit also alleges that biometric information was disclosed to technology vendors or service providers.

The complaint does not identify a specific recipient in the portions describing those allegations. It pleads the disclosure theory “upon information and belief.”

Discovery may therefore become important.

If outside technology providers process the calls, the parties may need to determine:

  • which vendor receives the audio;
  • whether the vendor receives raw recordings or extracted features;
  • whether a voice template is created;
  • where that template is generated;
  • who possesses it;
  • whether it is retained after the call;
  • whether it is associated with a customer account;
  • whether it can be reused to identify the caller;
  • whether Lowe’s can access the resulting biometric representation; and
  • whether information is transmitted to additional subprocessors.

These questions illustrate why vendor inventories that simply say “AI customer service provider” are often inadequate for privacy compliance.

Walmart Is Facing a Nearly Identical Fight

Lowe’s is not alone.

Similar proposed class actions filed against Walmart in Illinois during the summer of 2026 accuse the retailer of turning customer-service calls into biometric voiceprints.

One August federal complaint brought by Illinois residents Carol Krupke and Jeanne Thomas alleges Walmart records calls, analyzes distinguishing vocal characteristics and creates mathematical templates that could be used to identify callers later.

Walmart’s own privacy policy expressly refers to collecting biometrics such as voiceprints when customers contact the company, according to Courthouse News reporting on the litigation.

The plaintiffs nevertheless argue that the company’s disclosures and consent process do not satisfy BIPA.

Those allegations also remain unproven.

But the Walmart and Lowe’s lawsuits arriving within weeks of one another suggest plaintiffs’ lawyers are paying close attention to enterprise voice technology.

Customer Service Could Become the Next Major BIPA Battleground

Historically, many of the best-known BIPA cases involved fingerprint scanners used for employee timekeeping.

That made compliance relatively easy to visualize.

An employee puts a finger on a scanner.

The scanner creates a biometric template.

The employer needs BIPA disclosures and consent.

Voice processing is much less visible.

A customer simply calls a retailer.

There is no special scanner.

There may be no enrollment ceremony.

The customer may have no reason to think biometrics are involved at all.

AI can perform the biometric transformation silently inside the telephone infrastructure.

That invisibility is precisely what creates the litigation risk.

BIPA Does Not Require Traditional Identity Verification for Risk to Exist

Another important question will be what the technology is actually used to do.

A traditional voice-biometric system is easy to classify when it answers:

“Is this really Richard calling?”

The system compares current speech against a previously enrolled template and authenticates the speaker.

Newer AI systems complicate that model.

They may extract voice characteristics for fraud detection, caller differentiation, personalization or analytics without displaying a feature labeled “voice authentication.”

BIPA defines biometric information as information based on a biometric identifier that is used to identify an individual.

So privacy teams need to understand both the mathematical processing and its use.

Merely knowing that a vendor “analyzes audio” is not enough.

Meta Shows the Same Problem Emerging With Faces

The voiceprint lawsuits are part of a much wider debate over AI and biometrics.

On September 4, parents and children from Illinois and California filed a proposed federal class action against Meta accusing the company of using Facebook and Instagram photographs to derive biometric information for AI models and an unreleased facial-recognition system called NameTag.

According to WIRED, the plaintiffs allege that Meta used photographs to develop faceprints without the notice and consent required by Illinois law. Meta disputes the allegations and says the lawsuit misrepresents its work.

NameTag is particularly interesting because the technology was designed for Meta’s smart glasses.

WIRED previously found inactive but functional NameTag code inside Meta’s AI companion application. The system was reportedly designed to turn faces viewed through smart glasses into biometric signatures and compare them with stored faceprints.

Meta removed the code after WIRED reported on it and has said no final decision has been made to launch the feature.

The new lawsuit alleges the underlying face data may have been derived from social-media photographs, an allegation Meta contests.

Three Different Cases, One Common Question

Lowe’s, Walmart and Meta involve very different technology.

But they converge on the same privacy question:

When does ordinary data become biometric data?

A telephone recording is ordinary audio.

Analyze the caller’s physical vocal characteristics and build an identifying template, and it may become a voiceprint.

A Facebook photograph is an image.

Measure facial geometry and generate an identifying face template, and BIPA may be implicated.

The regulatory event can therefore occur not when the information is originally collected but when software transforms it.

That is particularly important in AI systems because the transformation may happen far downstream from the original collection.

AI Training Creates an Even Harder Version of the Problem

The Meta litigation pushes the theory one step further.

Traditionally, biometric systems create a template because they intend to recognize someone.

AI training involves enormous datasets processed for much broader purposes.

The plaintiffs claim Meta’s image-training process itself extracted biometric information from people appearing in photographs.

Meta disputes that characterization.

If courts begin accepting biometric theories based on intermediate processing used during AI development, compliance could become substantially more complicated.

Companies would need to understand not simply which personal information goes into an AI model, but whether preprocessing pipelines derive face geometry, vocal characteristics or other protected biometric representations along the way.

Why BIPA Has Produced So Much Litigation

BIPA combines several features that make it unusually consequential.

It creates a private right of action.

A plaintiff does not necessarily need to prove traditional financial harm merely to establish that statutory privacy rights were violated.

In Rosenbach v. Six Flags, the Illinois Supreme Court held that a person can be “aggrieved” under BIPA based on a violation of the statute’s requirements without separately proving some additional adverse consequence.

The statute also provides liquidated damages.

A negligent violation can support $1,000 or actual damages, whichever is greater.

An intentional or reckless violation can support $5,000 or actual damages, whichever is greater, along with attorneys’ fees, litigation costs and potential injunctive relief.

Illinois Changed the Damages Rules in 2024

Those numbers once produced potentially extraordinary exposure because of another Illinois Supreme Court decision.

In Cothron v. White Castle, the court held in 2023 that a separate BIPA claim could accrue each time a biometric identifier was collected or transmitted without proper consent.

For an employee scanning a fingerprint several times every workday, that interpretation created the possibility of enormous aggregate statutory damages.

The Illinois legislature responded in 2024.

Public Act 103-769 amended BIPA so repeated collection of the same person’s biometric information through the same method generally constitutes a single Section 15(b) violation for damages purposes.

Repeated disclosure of the same biometric data to the same recipient through the same method similarly results in at most one recovery under Section 15(d).

That significantly reduces the catastrophic per-scan damages scenarios that once dominated BIPA discussions.

It does not eliminate class-action exposure.

If thousands or millions of Illinois consumers were affected, per-person statutory damages can still become significant.

The Lowe’s Case Will Probably Turn on Evidence, Not the Word “AI”

The complaint repeatedly references artificial intelligence, automated systems and voice analysis.

But those labels do not establish a BIPA violation.

The important evidence will concern what the technology actually does.

A court may eventually need to know whether Lowe’s or one of its providers:

  • extracts distinctive vocal characteristics;
  • creates a mathematical template;
  • uses that template to identify or distinguish callers;
  • retains the template;
  • associates the template with customer records;
  • compares the template across calls; or
  • transmits the template to another entity.

If none of that occurs, the allegation that ordinary call recording creates a BIPA voiceprint may fail.

If it does occur, the questions shift toward notice, consent, retention and disclosure.

This Is Why Privacy Teams Need to Talk to the Engineers

A privacy questionnaire asking a vendor “Do you collect biometric data?” may not be sufficient anymore.

A vendor could sincerely answer no because it does not market its software as biometric authentication.

Meanwhile, the underlying model might still extract speaker embeddings or facial representations as part of its technical operation.

More useful questions include:

  • Does the system derive mathematical representations from a person’s voice or face?
  • Are those representations persistent or temporary?
  • Can they distinguish one individual from another?
  • Can they be reused across sessions?
  • Are they associated with an account or identifier?
  • Who can access them?
  • Are they transmitted to subprocessors?
  • Are they used for authentication, fraud prevention, analytics, training or personalization?
  • How long are they retained?
  • Can the functionality be disabled for Illinois users?

Those questions move the conversation from marketing language to architecture.

Companies Should Audit Voice Systems Before the Lawsuit Arrives

The Lowe’s and Walmart cases provide a practical reason for retailers, banks, insurers, healthcare organizations and other large contact-center operators to review their voice stacks now.

That inventory may include:

  • interactive voice response systems;
  • call-recording platforms;
  • contact-center-as-a-service providers;
  • fraud-detection products;
  • speaker-authentication tools;
  • speech-to-text services;
  • sentiment-analysis tools;
  • AI call summaries;
  • customer-service copilots; and
  • data warehouses receiving call analytics.

The company should understand exactly which of those systems touch audio and what transformations they perform.

Retention Is Often the Forgotten Requirement

Companies that intentionally deploy biometric authentication often know they need consent.

Retention is easier to miss.

BIPA requires a public retention-and-destruction policy for covered biometric data and generally requires destruction once the purpose for collection has been satisfied or within three years after the person’s last interaction with the company, whichever comes first.

For AI systems, that can become complicated quickly.

The raw recording might be deleted after 30 days.

The transcript might be retained for a year.

An embedding might remain inside a vendor platform.

A fraud model might preserve derived features.

A training dataset might contain another copy.

Deleting the original audio does not necessarily answer what happened to biometric information derived from it.

Sharing With Vendors Needs the Same Attention

Modern AI rarely operates inside one company’s infrastructure.

A retailer may use one vendor to handle telephony, another to transcribe the call, another to detect fraud, another to provide generative AI and a cloud provider underneath all of them.

BIPA’s disclosure restrictions make those relationships important.

Section 15(d) generally prohibits disclosure, redisclosure or dissemination of biometric information without the person’s consent unless a statutory exception applies.

A standard data-processing agreement therefore does not necessarily answer the underlying BIPA question.

The privacy team needs to know whether biometric information is being disclosed in the first place.

The Most Dangerous Compliance Assumption Is “We Don’t Use Biometrics”

The new wave of litigation demonstrates how that statement can become outdated without anyone intentionally deploying a biometric system.

A company buys an AI contact-center product.

The vendor releases a fraud-detection update.

The update introduces speaker recognition.

Another model generates persistent voice embeddings.

The business team sees only that call handling has improved.

The privacy team still believes the company merely records telephone calls.

That gap between product functionality and privacy governance is where lawsuits can begin.

Biometric Compliance Is Becoming an AI Governance Problem

BIPA was enacted in 2008.

Its core concepts predate today’s generative AI boom by more than a decade.

Yet the law maps surprisingly well onto one of AI governance’s biggest problems.

AI systems can derive new information from old information.

A photo can become a faceprint.

A voice recording can become a speaker template.

Behavioral activity can become an inference.

Raw data that seemed relatively ordinary when collected can become highly sensitive after a model processes it.

That means privacy inventories based entirely on the category of information originally collected are increasingly inadequate.

Companies also need to understand what their technology derives.

The Lowe’s Lawsuit Is Still Just a Lawsuit

There is an important caution here.

The complaint against Lowe’s is not a judicial finding that the retailer creates biometric voiceprints.

The complaint expressly relies on allegations made “upon information and belief” regarding speaker-recognition processing and third-party disclosure.

Lowe’s public privacy statement confirms call recording and AI-assisted customer-service functionality, but that alone does not prove that a BIPA-regulated voiceprint is being created.

The same principle applies to the Walmart and Meta cases.

Complaints contain allegations.

The defendants can dispute the facts, the legal theories or both.

The important development for privacy professionals is not that plaintiffs have already won.

It is where plaintiffs are looking next.

The Next BIPA Case May Be Hiding Inside an AI Feature

For years, biometric compliance could be treated as a specialized exercise.

Does the company have a fingerprint time clock?

Does it perform facial recognition?

Does it use iris scanning?

If the answer was no, many privacy programs moved on.

That is becoming harder to justify.

The technology capable of creating biometric identifiers is increasingly embedded inside ordinary enterprise products.

Telephone systems analyze voices.

Photo applications analyze faces.

Fraud systems model behavior.

AI training pipelines extract features humans never manually requested.

The Lowe’s lawsuit therefore deserves attention even if Lowe’s ultimately defeats it.

Its core question will recur:

At what point does ordinary customer data become a biometric identifier?

Under Illinois law, the answer can carry meaningful legal consequences.

And in the age of AI, the business collecting the original data may not even realize that transformation is happening unless someone has looked closely enough at the technology to ask.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.