Walmart Voiceprint Lawsuit: Is Your Voice Biometric? [2026]
A proposed Illinois class action filed in August 2026 alleges Walmart converted customer-service calls into biometric voiceprints without written consent. This guide explains what the complaint says, what the Illinois Biometric Information Privacy Act requires, what's still unproven, and how to protect your voice in any recording you share.

You call a store to ask when an order will be ready. You hang up. According to a proposed class action filed in August 2026, a system may also have turned your voice into a voiceprint: a mathematical template that can identify you the next time you call. The suit, filed against Walmart under Illinois's Biometric Information Privacy Act (BIPA), argues that a voice is biometric data just like a fingerprint or a face, and that collecting it without written consent is illegal.
This guide explains what the complaint alleges, what BIPA requires, what has not been proven, and what the case means for anyone who records, edits or publishes audio. If you share video that captures other people's voices, BGBlur's voice anonymization is designed for exactly that job.
TL;DR: The Walmart Voiceprint Case
| Question | Answer |
|---|---|
| Who is suing? | Carol J. Krupke and Jeanne Thomas, on behalf of a proposed class |
| Where and when? | U.S. District Court, Northern District of Illinois, August 6, 2026 |
| Under what law? | Illinois Biometric Information Privacy Act (BIPA) |
| What's alleged? | Walmart built voiceprints from customer calls without written consent |
| What are the damages sought? | $1,000 per negligent violation, $5,000 per intentional or reckless violation |
| Has Walmart responded? | Not yet, as of reporting |
| Is it proven? | No. These are allegations |
| What should creators do? | Treat voices like faces: get consent or anonymize |
What Does the Walmart Voiceprint Complaint Allege?
According to Courthouse News and the Biometric Update report, Krupke and Thomas allege that when customers phone Walmart stores, the company records the call and uses AI to extract distinguishing vocal characteristics. The complaint describes measuring "pitch, cadence, tone, and frequency spectrums" to build "a unique mathematical template" that can later be used to recognize the caller. The purpose alleged is fraud prevention.
The plaintiffs say they never signed a release authorizing collection, storage or disclosure of their voiceprints. The complaint reportedly does not name the vendor or the specific system that builds the templates, and it provides no technical records documenting the conversion process. Biometric Update notes that Walmart had not yet answered the allegations. Walmart's June 2018 privacy notice lists voiceprints as biometric information the company may collect, and the plaintiffs contend that this generic notice is not enough under BIPA.
What Does BIPA Actually Require?
BIPA is the Illinois law that governs biometric identifiers, and it is widely considered the toughest of its kind in the United States. In practice, a company that collects biometric data has to:
- Give written notice that biometric data is being collected and explain the specific purpose and how long it will be kept
- Obtain a written release from the person before collecting it
- Limit disclosure and refrain from profiting from the data without consent
The Walmart plaintiffs argue the company's generic fraud-prevention disclosure fell short and that it disclosed and profited from the data in ways BIPA prohibits. BIPA's damages are set by statute. The complaint seeks $1,000 per negligent violation or $5,000 per intentional or reckless violation, plus class certification, injunctive relief and attorney fees. Because damages apply per person and per violation, exposure can grow rapidly across a large class.
Why Does It Matter That a Voice Counts as Biometric?
Voice is a strong identifier that people give away constantly. Unlike a password, you cannot change your voice, and unlike a face, you don't need to be in front of a camera to be identified by it. A call center, a smart speaker, a meeting recorder or a video you upload can all capture it.
Two developments make voice data riskier. First, cheap AI cloning tools can now imitate a voice from a few seconds of audio, which we cover in our voice cloning scam guide. Second, courts and regulators are increasingly willing to apply biometric rules to speech, not just to faces and fingerprints. The Walmart suit is one more sign of that shift.
The pattern is familiar from other biometric fights. Facial recognition faced the same consent question when Ring rolled out doorbell face scanning, and the company declined to offer the feature in Illinois. See our post on the Ring Familiar Faces lawsuit.

What Is Not Proven Yet?
Quite a lot, and it is worth being clear about it:
- No court has ruled. The case has just been filed, and Walmart has not responded to the allegations.
- The technology is unspecified. The complaint doesn't name a vendor or system, so what actually happens to call audio is unconfirmed.
- Class certification is uncertain. Whether the case proceeds on behalf of a broad class depends on rulings still to come.
- Legal theories may be tested. Defendants in BIPA cases commonly dispute whether a system creates an identifier at all, whether consent was given, and what damages are appropriate.
Nothing in this article should be read as saying Walmart violated the law. The value of the case for the rest of us is in how it frames the question.
Why Are BIPA Lawsuits So Common?
BIPA is unusual because it lets individuals sue directly and sets damages by statute, so plaintiffs don't have to prove they were financially harmed. That combination makes class actions attractive, and Illinois has become the venue where biometric consent questions get tested first. The Electronic Frontier Foundation, in its analysis of Ring's face recognition feature, points to the scale of earlier facial-scanning settlements, including $650 million from Facebook, as evidence of how costly consent failures can be. See EFF's legal analysis. Those cases involved faces, not voices, but the legal logic transfers: if a system builds a template that identifies a person, the notice-and-consent duties can attach.
The Walmart complaint also shows how these suits are built. The plaintiffs don't need internal system documents to file; they allege the behavior from the outside, from what a customer experiences and what the company's own privacy notice says, and then use discovery to learn how the system really works.
How Is a Voiceprint Different From a Call Recording?
This distinction decides most disputes, so it is worth spelling out.
| Term | What it is | Typical purpose | Biometric? |
|---|---|---|---|
| Call recording | Audio of the conversation stored as a file | Quality, training, disputes | Not by itself |
| Transcription | Speech converted to text | Search, analytics | Not by itself |
| Voiceprint | A mathematical template of a speaker's vocal characteristics | Recognize or verify who is speaking | Yes, this is the concern in the complaint |
| Voice analytics | Analysis of tone, emotion or stress | Sentiment, agent coaching | Depends on what is extracted and whether it identifies a person |
A company can record calls and transcribe them without building a voiceprint. The legal risk arises when a system extracts characteristics used to identify or verify a person. That is why the complaint focuses on allegations that Walmart isolates vocal characteristics and builds a template rather than on the recording itself.
Where Do Voices Leak in Everyday Video and Meetings?
Voiceprints aren't only a call-center issue. Voices are captured and stored in places most people don't think about:
- Recorded meetings and webinars. Participants' voices sit in recordings that may be shared widely. See our guide on how meeting recordings leak workplace privacy.
- Interview and vlog footage. Anyone who speaks near a microphone is in your audio track.
- Voice assistants and smart devices. These process speech continuously, with varying privacy controls.
- Voice cloning. Short public clips can train tools that imitate a voice, which is how scams like the ones in our voice cloning guide work.
The takeaway for a team is to map where voice is captured, decide what needs consent, and anonymize by default when you don't have it.
What Should Businesses Do About Voice Data?
If you record calls, meetings or interviews and use any speaker-identification, fraud-detection or analytics tool, take these steps:
- Inventory where audio is recorded and whether any tool identifies or verifies speakers
- Give specific written notice about what is collected, why and for how long, rather than a generic line in a long privacy notice
- Get a written release where the law requires one, before collection
- Set a retention limit and delete voice templates when the purpose ends
- Ask vendors what their systems actually create, since "transcription" and "voice biometrics" are different things
This is general information, not legal advice. Talk to counsel about your specific practices.
How Do I Protect Voices in Video I Share?
You don't have to run a call center to handle voice data. If you publish interviews, vlogs, training videos or street footage, other people's voices end up in your audio. The safe habit is to make speakers unidentifiable when you don't have consent. Our guides on whether you can publish someone's recorded voice and audio anonymization and voice distortion cover the consent rules and techniques.
Step 1: Upload your video
Open BGBlur and drop in your MP4, MOV or M4V file.
Step 2: Choose voice anonymization
Select voice anonymization to alter pitch and timbre so speakers can't be recognized while speech stays understandable.
Step 3: Add face blur if faces appear
A blurred face with an identifiable voice is still identifiable. Combine voice anonymization with face blur so neither the face nor the voice gives the person away.
Step 4: Preview and export
Listen to the whole clip before publishing. Processed files are deleted within 24 hours.
Honest Limitations
Voice anonymization reduces the chance that a listener or a recognition system can identify a speaker, but it is not a guarantee. Light pitch shifts can sometimes be reversed, and content itself, such as a name spoken aloud or a distinctive accent and phrasing, can still give someone away. For legal or investigative work where identification would cause real harm, remove or bleep identifying content as well and consider professional review. BGBlur also does not provide legal advice about BIPA compliance for call recording.
The Bottom Line
The Walmart lawsuit alleges that a phone call can quietly become a biometric record, and that Illinois law requires written notice and consent before that happens. The claims are unproven, but they add to a clear direction of travel: voices are being treated like faces. If you publish video with other people's voices, anonymize them when you don't have consent, and pair it with face blur. Try BGBlur's voice anonymization on your next clip.