Try BGBlur

Blur faces instantly with AI-powered face detection

Automatically detect and blur faces in your videos No need for tracking, masking, or in-depth workflows

Walmart Voiceprint Lawsuit: Is Your Voice Biometric? [2026]

A proposed Illinois class action filed in August 2026 alleges Walmart converted customer-service calls into biometric voiceprints without written consent. This guide explains what the complaint says, what the Illinois Biometric Information Privacy Act requires, what's still unproven, and how to protect your voice in any recording you share.

BIPAVoiceprintBiometric PrivacyClass ActionVoice AnonymizationIllinois
•By Yash Thakker
Featured image

You call a store to ask when an order will be ready. You hang up. According to a proposed class action filed in August 2026, a system may also have turned your voice into a voiceprint: a mathematical template that can identify you the next time you call. The suit, filed against Walmart under Illinois's Biometric Information Privacy Act (BIPA), argues that a voice is biometric data just like a fingerprint or a face, and that collecting it without written consent is illegal.

This guide explains what the complaint alleges, what BIPA requires, what has not been proven, and what the case means for anyone who records, edits or publishes audio. If you share video that captures other people's voices, BGBlur's voice anonymization is designed for exactly that job.

TL;DR: The Walmart Voiceprint Case

QuestionAnswer
Who is suing?Carol J. Krupke and Jeanne Thomas, on behalf of a proposed class
Where and when?U.S. District Court, Northern District of Illinois, August 6, 2026
Under what law?Illinois Biometric Information Privacy Act (BIPA)
What's alleged?Walmart built voiceprints from customer calls without written consent
What are the damages sought?$1,000 per negligent violation, $5,000 per intentional or reckless violation
Has Walmart responded?Not yet, as of reporting
Is it proven?No. These are allegations
What should creators do?Treat voices like faces: get consent or anonymize

What Does the Walmart Voiceprint Complaint Allege?

According to Courthouse News and the Biometric Update report, Krupke and Thomas allege that when customers phone Walmart stores, the company records the call and uses AI to extract distinguishing vocal characteristics. The complaint describes measuring "pitch, cadence, tone, and frequency spectrums" to build "a unique mathematical template" that can later be used to recognize the caller. The purpose alleged is fraud prevention.

The plaintiffs say they never signed a release authorizing collection, storage or disclosure of their voiceprints. The complaint reportedly does not name the vendor or the specific system that builds the templates, and it provides no technical records documenting the conversion process. Biometric Update notes that Walmart had not yet answered the allegations. Walmart's June 2018 privacy notice lists voiceprints as biometric information the company may collect, and the plaintiffs contend that this generic notice is not enough under BIPA.

What Does BIPA Actually Require?

BIPA is the Illinois law that governs biometric identifiers, and it is widely considered the toughest of its kind in the United States. In practice, a company that collects biometric data has to:

  1. Give written notice that biometric data is being collected and explain the specific purpose and how long it will be kept
  2. Obtain a written release from the person before collecting it
  3. Limit disclosure and refrain from profiting from the data without consent

The Walmart plaintiffs argue the company's generic fraud-prevention disclosure fell short and that it disclosed and profited from the data in ways BIPA prohibits. BIPA's damages are set by statute. The complaint seeks $1,000 per negligent violation or $5,000 per intentional or reckless violation, plus class certification, injunctive relief and attorney fees. Because damages apply per person and per violation, exposure can grow rapidly across a large class.

Why Does It Matter That a Voice Counts as Biometric?

Voice is a strong identifier that people give away constantly. Unlike a password, you cannot change your voice, and unlike a face, you don't need to be in front of a camera to be identified by it. A call center, a smart speaker, a meeting recorder or a video you upload can all capture it.

Two developments make voice data riskier. First, cheap AI cloning tools can now imitate a voice from a few seconds of audio, which we cover in our voice cloning scam guide. Second, courts and regulators are increasingly willing to apply biometric rules to speech, not just to faces and fingerprints. The Walmart suit is one more sign of that shift.

The pattern is familiar from other biometric fights. Facial recognition faced the same consent question when Ring rolled out doorbell face scanning, and the company declined to offer the feature in Illinois. See our post on the Ring Familiar Faces lawsuit.

Written consent form beside a microphone representing biometric voiceprint consent

What Is Not Proven Yet?

Quite a lot, and it is worth being clear about it:

  • No court has ruled. The case has just been filed, and Walmart has not responded to the allegations.
  • The technology is unspecified. The complaint doesn't name a vendor or system, so what actually happens to call audio is unconfirmed.
  • Class certification is uncertain. Whether the case proceeds on behalf of a broad class depends on rulings still to come.
  • Legal theories may be tested. Defendants in BIPA cases commonly dispute whether a system creates an identifier at all, whether consent was given, and what damages are appropriate.

Nothing in this article should be read as saying Walmart violated the law. The value of the case for the rest of us is in how it frames the question.

Why Are BIPA Lawsuits So Common?

BIPA is unusual because it lets individuals sue directly and sets damages by statute, so plaintiffs don't have to prove they were financially harmed. That combination makes class actions attractive, and Illinois has become the venue where biometric consent questions get tested first. The Electronic Frontier Foundation, in its analysis of Ring's face recognition feature, points to the scale of earlier facial-scanning settlements, including $650 million from Facebook, as evidence of how costly consent failures can be. See EFF's legal analysis. Those cases involved faces, not voices, but the legal logic transfers: if a system builds a template that identifies a person, the notice-and-consent duties can attach.

The Walmart complaint also shows how these suits are built. The plaintiffs don't need internal system documents to file; they allege the behavior from the outside, from what a customer experiences and what the company's own privacy notice says, and then use discovery to learn how the system really works.

How Is a Voiceprint Different From a Call Recording?

This distinction decides most disputes, so it is worth spelling out.

TermWhat it isTypical purposeBiometric?
Call recordingAudio of the conversation stored as a fileQuality, training, disputesNot by itself
TranscriptionSpeech converted to textSearch, analyticsNot by itself
VoiceprintA mathematical template of a speaker's vocal characteristicsRecognize or verify who is speakingYes, this is the concern in the complaint
Voice analyticsAnalysis of tone, emotion or stressSentiment, agent coachingDepends on what is extracted and whether it identifies a person

A company can record calls and transcribe them without building a voiceprint. The legal risk arises when a system extracts characteristics used to identify or verify a person. That is why the complaint focuses on allegations that Walmart isolates vocal characteristics and builds a template rather than on the recording itself.

Where Do Voices Leak in Everyday Video and Meetings?

Voiceprints aren't only a call-center issue. Voices are captured and stored in places most people don't think about:

  • Recorded meetings and webinars. Participants' voices sit in recordings that may be shared widely. See our guide on how meeting recordings leak workplace privacy.
  • Interview and vlog footage. Anyone who speaks near a microphone is in your audio track.
  • Voice assistants and smart devices. These process speech continuously, with varying privacy controls.
  • Voice cloning. Short public clips can train tools that imitate a voice, which is how scams like the ones in our voice cloning guide work.

The takeaway for a team is to map where voice is captured, decide what needs consent, and anonymize by default when you don't have it.

What Should Businesses Do About Voice Data?

If you record calls, meetings or interviews and use any speaker-identification, fraud-detection or analytics tool, take these steps:

  • Inventory where audio is recorded and whether any tool identifies or verifies speakers
  • Give specific written notice about what is collected, why and for how long, rather than a generic line in a long privacy notice
  • Get a written release where the law requires one, before collection
  • Set a retention limit and delete voice templates when the purpose ends
  • Ask vendors what their systems actually create, since "transcription" and "voice biometrics" are different things

This is general information, not legal advice. Talk to counsel about your specific practices.

How Do I Protect Voices in Video I Share?

You don't have to run a call center to handle voice data. If you publish interviews, vlogs, training videos or street footage, other people's voices end up in your audio. The safe habit is to make speakers unidentifiable when you don't have consent. Our guides on whether you can publish someone's recorded voice and audio anonymization and voice distortion cover the consent rules and techniques.

Step 1: Upload your video

Open BGBlur and drop in your MP4, MOV or M4V file.

Step 2: Choose voice anonymization

Select voice anonymization to alter pitch and timbre so speakers can't be recognized while speech stays understandable.

Step 3: Add face blur if faces appear

A blurred face with an identifiable voice is still identifiable. Combine voice anonymization with face blur so neither the face nor the voice gives the person away.

Step 4: Preview and export

Listen to the whole clip before publishing. Processed files are deleted within 24 hours.

Honest Limitations

Voice anonymization reduces the chance that a listener or a recognition system can identify a speaker, but it is not a guarantee. Light pitch shifts can sometimes be reversed, and content itself, such as a name spoken aloud or a distinctive accent and phrasing, can still give someone away. For legal or investigative work where identification would cause real harm, remove or bleep identifying content as well and consider professional review. BGBlur also does not provide legal advice about BIPA compliance for call recording.

The Bottom Line

The Walmart lawsuit alleges that a phone call can quietly become a biometric record, and that Illinois law requires written notice and consent before that happens. The claims are unproven, but they add to a clear direction of travel: voices are being treated like faces. If you publish video with other people's voices, anonymize them when you don't have consent, and pair it with face blur. Try BGBlur's voice anonymization on your next clip.

Frequently Asked Questions

Carol J. Krupke and Jeanne Thomas filed a proposed class action against Walmart on August 6, 2026, in the U.S. District Court for the Northern District of Illinois. As reported by Courthouse News and Biometric Update, they allege Walmart records calls to its stores, isolates callers' vocal characteristics with AI, and builds mathematical templates that can identify them later, all without the written consent Illinois law requires. Walmart had not yet answered the allegations at the time of reporting, and none of the claims are proven.

Illinois's Biometric Information Privacy Act (BIPA) lists voiceprints among its covered biometric identifiers, and the Walmart plaintiffs invoke that protection. BIPA generally requires a company to give written notice of what it collects and why, state how long it will keep the data, and obtain a written release before collecting it. Whether Walmart's specific systems created voiceprints, and whether its disclosures were enough, are the questions the court will decide.

The complaint seeks $1,000 per negligent violation and $5,000 per intentional or reckless violation, plus class certification, injunctive relief and attorney fees. Those are BIPA's statutory damages, which apply per violation and per person, so exposure can multiply quickly across a large class. That is why BIPA suits draw attention even when the underlying technology, such as fraud-prevention voice analysis, seems routine.

The complaint says Walmart's own privacy notice, dated June 2018, lists voiceprints among biometric information it may collect, according to Biometric Update's summary. The plaintiffs argue that a generic fraud-prevention disclosure does not meet BIPA's requirement for a written, specific notice and a signed release. The complaint does not name the vendor or the specific AI system that allegedly builds the templates.

Possibly. BIPA is the strictest U.S. biometric statute and the model other suits copy, but Texas, Washington and other states have biometric rules, and many comprehensive state privacy laws treat biometric data as sensitive. Companies that operate nationally often apply Illinois-grade consent everywhere, so a ruling here can change practices far beyond Illinois. For creators, the takeaway is to treat voices with the same care as faces.

Often yes, but consent and local recording laws matter, especially for private conversations and for any analysis that identifies a speaker. Publishing someone's recognizable voice also carries privacy, defamation and harassment risks. The safe approach for sensitive footage is to blur faces and alter voices so speakers cannot be identified. Our guide on whether you can publish someone's recorded voice walks through the consent rules.

Use a voice anonymization tool that changes pitch and timbre enough to prevent recognition while keeping speech intelligible. Upload the video to BGBlur, choose voice anonymization, and combine it with face blur so neither the face nor the voice identifies the person. Preview the result before publishing, since light pitch shifts can be reversed and are not a guarantee against identification by a determined listener.