Seventh Circuit Further Clarifies Application of CGL Exclusions to BIPA Claims
In the nearly two decades since Illinois adopted its Biometric Information Privacy Act (BIPA), Illinois appellate courts and the Seventh Circuit Court of Appeals have heard numerous cases about the extent to which various common provisions and endorsements in commercial general liability (CGL) policies apply. In that process, disagreements have arisen between the Illinois and federal courts about the application of Illinois law interpreting insuring agreements. The Seventh Circuit’s recent decision in Citizens Insurance Company of America v. Mullins Food Products Inc. resolves one such disagreement.
BIPA imposes restrictions on how a private employer may collect, retain, and disclose an individual’s biometric identifiers, like fingerprints. Among these restrictions, employers must inform an employee of the collection of this biometric information and obtain the employee’s written consent to distribute the information. In the underlying litigation, an employee of the insured corporation, as representative of a putative class, sued the insured alleging that it used employees’ fingerprints to monitor and manage employees’ work time. In doing so, the insured allegedly disseminated the fingerprint data to third-party vendors for time-keeping and payroll purposes, without the employees’ written consent and in violation of BIPA.
The insurer filed a declaratory judgment action seeking a declaration that it owed no duty to defend or indemnify the insured under a CGL policy. Of the three policy periods potentially implicated, two — 2016 and 2017 — included an “access or disclosure exclusion” barring coverage for claims “arising out of any access to or disclosure of any persons’ or organization’s confidential or personal information, including patents, trade secrets, processing methods, customer lists, financial information, credit card information, health information or any other type of nonpublic information.” All three policies included a standard “statutory violations exclusion,” barring coverage for “personal and advertising injury” arising out of the violation of three federal privacy statutes — the Telephone Consumer Protection Act (TCPA), the Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003 (CAN-SPAM Act), and the Fair Credit Reporting Act (FCRA) — and any other “statute, ordinance or regulation ... that addresses, prohibits, or limits the . . . communicating or distribution of material or information.”
The district court, following the Seventh Circuit’s holding and reasoning in an earlier case involving the same insurer — Citizen Insurance Co. of America v. Wynndalco Enterprises LLC — initially concluded that both exclusions were ambiguous with respect to BIPA and thus did not bar coverage. However, following an intervening decision from the Illinois Court of Appeals, which criticized the reasoning of Wynndalco, the insurer moved for reconsideration. The district court reversed itself, concluding that both exclusions unambiguously barred coverage for the BIPA claims.
On appeal, the Seventh Circuit resolved the conflict between its precedent and the Illinois Court of Appeals. First, as to the access or disclosure exclusion, the court rejected the insured’s argument that the inclusion of “patents” — which are public information — as one of the types of information covered rendered the exclusion’s catchall ambiguous. The court explained that the inclusion of “patents,” although out of step with the other types of information listed, did not affect the plain meaning of the phrase “confidential or personal information,” which would include fingerprints.
That, however, did not end the enquiry because the access of disclosure exclusion was present in only two of the three relevant policies. Turning to the statutory violation exclusion, the court rejected the reasoning of its earlier decision in Wynndalco. There, the court concluded that the catchall phrase, which addressed only statutes, regulations, and ordinances affecting the distribution of material or information, was ambiguous. That was so, the court had said, because reading the words literally would “swallow” a substantial portion of the coverage purportedly provided by the policy for “personal and advertising injury.” However, this was the reasoning criticized by the Illinois Court of Appeals, which concluded that exclusion, even read broadly, left significant coverage in place, because it did not exclude common law violations of the right to privacy.
Still, the Seventh Circuit concluded that the exclusion did not bar coverage for BIPA violations. Applying ejusdem generis — which holds that when a list is followed by catchall provision, the catchall is interpreted to encompass things list the specifically listed items — the court concluded that BIPA was different in kind from the federal statutes specifically enumerated in the exclusion — the TCPA, the CAN-SPAM ACT, and the FCRA. The first two, the court said, regulated the use of communications technology, not biometrics, and the third regulated credit history. Because BIPA was unlike all three of these, the court concluded that the catchall could not be read to include BIPA.
Accordingly, the court concluded that the statutory violation exclusion was inapplicable and, because the access or disclosure exclusion was not contained in one of the three potentially applicable policies, the insurer was not relieved of its duty to defend, nor potentially to indemnify, the insured by reason of these exclusions.
The information on this website is presented as a service for our clients and Internet users and is not intended to be legal advice, nor should you consider it as such. Although we welcome your inquiries, please keep in mind that merely contacting us will not establish an attorney-client relationship between us. Consequently, you should not convey any confidential information to us until a formal attorney-client relationship has been established. Please remember that electronic correspondence on the internet is not secure and that you should not include sensitive or confidential information in messages. With that in mind, we look forward to hearing from you.