A routine call to Walmart about a missing package or a disputed charge may have captured far more than a customer complaint. According to a new proposed class action, an AI system on the other end was allegedly measuring pitch, cadence, tone, and vocal frequency to build a permanent biometric template — a voiceprint. Unlike a stolen password, a voice cannot be reset. Two Illinois residents say Walmart never disclosed any of this was happening, at least not in any way that counts under the law. This pattern of secretly tracking users without meaningful disclosure has surfaced across multiple industries.
What the Lawsuit Actually Claims
Two Illinois consumers allege Walmart’s AI phone system captures biometric data without the legally required consent or disclosure.
Carol Krupke and Jeanne Thomas filed the suit, according to Bloomberg Law. They allege Walmart’s AI-powered interactive voice system generates voiceprints for fraud prevention and possibly “emotion tracking” — meaning the AI gauges how frustrated or urgent a caller sounds by analyzing vocal traits in real time. This practice echoes the methods used in a surveillance app built to covertly collect data without user knowledge. Walmart’s privacy policy does mention collecting “biometric information including voiceprints,” but the plaintiffs argue that buried language falls well short of what Illinois’ Biometric Information Privacy Act demands. A Walmart spokesperson reportedly did not respond to requests for comment, according to Bloomberg Law. No liability has been found; the case remains at the proposed class action stage.
BIPA sets specific thresholds before any company can touch biometric data:
- Written notice that a biometric identifier is being collected
- Written disclosure of the purpose and how long data will be stored
- Written consent from the individual before collection begins
- A publicly available retention and destruction schedule — which the complaint alleges Walmart lacks
- Statutory damages of $1,000 to $5,000 per violation
“The complaint’s bet is that a buried policy line doesn’t meet BIPA’s actual notice and consent requirements,” according to a privacy analysis of the case published by Osano.
This is not Walmart’s first BIPA dispute. The company previously settled a $10 million claim over palm-scanner timekeeping systems for employees, according to IDTechWire. A separate suit over voice-recognition headsets used by warehouse workers for inventory tracking — Barton v. Walmart — survived a motion to dismiss, according to Lexology. At a certain point, the pattern resembles a series that keeps getting renewed rather than a string of unrelated incidents.
Illinois Changed the Rules – But the Stakes Remain High
A 2024 amendment caps per-person damages, though Illinois remains the country’s fiercest biometric privacy battleground.
BIPA drove the $650 million Facebook settlement and has made Illinois what legal commentators describe as “a hotbed of biometric class actions” against major tech and retail companies, according to NBC Chicago reporting. The Illinois Supreme Court ruled in 2023 that a new BIPA claim accrues each time a biometric scan occurs — dramatically expanding potential exposure. Illinois then amended BIPA in 2024 via Senate Bill 2979, capping damages to a single violation per claimant rather than per scan, a change the Seventh Circuit has applied retroactively to pending cases, according to IDTechWire.
The case reframes a routine customer-service interaction as a potential site of permanent biometric data collection. Think of that generic “this call may be recorded” message as the biometric equivalent of a cookie consent banner nobody reads — except this one allegedly stores data that cannot be changed, replaced, or revoked. The danger of such permanent records exposed in a breach is precisely what makes biometrics uniquely risky. Passwords expire. Credit card numbers get reissued. Voices do not.





























