Microsoft is facing a federal class action lawsuit filed in February 2026 that alleges the company unlawfully collected voiceprint data from Microsoft Teams users without their knowledge or written consent, in violation of Illinois’s Biometric Information Privacy Act (BIPA). The lawsuit, Basich et al. v. Microsoft Corporation (Case No. 2:26-cv-00422), filed in the U.S.
District Court for the Western District of Washington, claims that Microsoft’s real-time transcription feature—which launched in 2021—captures and analyzes users’ voices to identify who made specific comments during meetings, effectively creating digital voiceprints for identification purposes. According to the plaintiffs, Microsoft failed to inform users that their voice data was being collected, how it would be used, or how long it would be retained, all of which are required under BIPA before collecting any biometric information. The case centers on a fundamental privacy violation: collecting sensitive biometric data without explicit written consent. Under Illinois law, companies cannot collect voiceprints or other biometric identifiers without first providing users with detailed written information about the collection, the specific purposes for the collection, and the length of time the data will be stored and used. Microsoft’s transcription feature captures not just words but the unique characteristics of each person’s voice—pitch, tone, and timbre—which are biometric identifiers under BIPA. The named plaintiffs are five Illinois residents who used Teams during meetings where their voices were captured and analyzed without their knowledge that this data collection was occurring.
Table of Contents
- How Microsoft Teams’ Transcription Feature Creates Voiceprints
- What BIPA Requires and Why Microsoft’s Conduct Allegedly Violates It
- The Damages Sought and What Class Members Could Recover
- How This Compares to Other Tech Privacy Lawsuits and Settlements
- What the Lawsuit Alleges About Microsoft’s Intent and Knowledge
- The Broader Implications for Enterprise AI and Meeting Transcription
- Current Status and Timeline for the Case
How Microsoft Teams’ Transcription Feature Creates Voiceprints
Microsoft’s real-time transcription feature in Teams, launched in March 2021, was designed to automatically convert spoken words into written text during video meetings. However, the technology goes beyond simple speech-to-text conversion. To correctly attribute comments to the right speakers, the system analyzes voice characteristics including pitch, tone, and timbre—the unique vocal fingerprint that makes each person’s voice distinctive. This process creates what’s called a “voiceprint,” a biometric identifier that functions like a fingerprint but based on voice characteristics.
The system can then use this voiceprint data to identify which team member said what, even in crowded meetings with multiple speakers. The lawsuit alleges that Microsoft collected these voiceprints continuously from March 2021 onward whenever users participated in Teams meetings with transcription enabled, without ever disclosing this practice. Users who enabled the transcription feature did so believing they were simply getting a text record of their meeting—they were not informed that their biometric voice data was being captured, processed, and stored. This distinction is critical because transcription (converting speech to text) is a different activity than voiceprint collection (capturing biometric voice characteristics for identification purposes). The plaintiffs argue that Microsoft deliberately failed to separate these two processes in its user communications and privacy disclosures.
What BIPA Requires and Why Microsoft’s Conduct Allegedly Violates It
The Illinois Biometric Information Privacy Act (BIPA), part of the Illinois Compiled Statutes Chapter 740, imposes strict requirements on any private company that collects, stores, or uses biometric information. Biometric information under BIPA includes fingerprints, retina scans, iris scans, voiceprints, hand scans, facial geometry, DNA, and other unique biological or physiological information that can be used to identify an individual. BIPA mandates that before collecting any biometric data, a company must provide the person in writing with: (1) a detailed description of what biometric information will be collected and how it will be used; (2) the specific purpose or purposes for which the information is being collected; and (3) how long the biometric information will be stored and used. Beyond disclosure, BIPA requires companies to obtain the person’s written consent before proceeding.
As of a 2024 amendment to BIPA, written consent can be provided through an electronic signature, but the company must still obtain affirmative, informed written permission. The law also prohibits companies from selling, sharing, or profiting from biometric data without additional consent for each specific use. Additionally, any company handling biometric information must maintain a reasonable standard of care to protect that data and must have a publicly available written policy describing their practices for storing, using, and protecting biometric information. The lawsuit alleges that Microsoft violated every one of these requirements: it did not disclose the voiceprint collection in writing, did not explain the purpose or duration of storage, and did not obtain written consent from any Teams user.
The Damages Sought and What Class Members Could Recover
The Basich lawsuit seeks statutory damages of at least $1,000 per negligent violation and potentially higher amounts if the court finds that Microsoft’s conduct was willful. Because BIPA violations can occur repeatedly—every time a user’s voiceprint was captured and used without consent—the damages could multiply significantly for each class member. A user who participated in Teams meetings with transcription enabled over the course of several years could potentially have dozens or hundreds of violations associated with their account, depending on how many meetings generated voiceprint data. The lawsuit also seeks actual damages on top of statutory damages, meaning if a court determines that the voiceprints were misused or that users suffered concrete harm from the unauthorized collection, they could recover additional compensation beyond the statutory minimum.
The class is defined as Microsoft Teams users in Illinois whose voice data was collected through the transcription feature beginning March 1, 2021, without their written consent. Determining the class size is significant because BIPA cases have resulted in some of the largest privacy settlements in recent years due to the volume of affected users and the multiplicity of violations. Unlike some privacy laws that limit damages to one claim per person per incident, BIPA allows for damages per violation, meaning each instance of unauthorized biometric data collection can be a separate claim. If the case proceeds to trial and Microsoft loses, or if the parties reach a settlement, registered class members would be eligible to file claims for compensation based on their use of Teams during the relevant period.
How This Compares to Other Tech Privacy Lawsuits and Settlements
The Microsoft Teams case is not the first lawsuit alleging unauthorized biometric data collection in the tech industry, but it represents a significant test of BIPA’s application to enterprise communication platforms. Previous BIPA cases have targeted retailers and social media companies: Facebook agreed to pay $650 million in 2020 to settle allegations that it collected biometric data (facial templates) from users’ photos without consent. Google faced multiple BIPA lawsuits over its face recognition practices in Google Photos. These settlements established that BIPA violations carry substantial financial consequences and that courts take the law seriously when companies fail to disclose biometric collection practices.
However, the Teams case differs in important ways from previous cases. First, it involves an enterprise platform rather than a consumer-facing application, which raises questions about workplace privacy and consent (employees may feel less able to refuse consent requirements imposed as conditions of employment or meeting participation). Second, the voiceprint data collection is a byproduct of a legitimate feature (transcription) rather than the primary function of the product, which complicates the question of whether users could have reasonably anticipated the biometric collection. Third, the case implicates both business users and their external meeting participants, potentially expanding the class size. The outcome of the Basich case could influence how other software companies disclose and manage biometric data collection embedded within their applications.
What the Lawsuit Alleges About Microsoft’s Intent and Knowledge
The Basich complaint includes allegations that Microsoft’s failure to disclose voiceprint collection was not accidental but deliberate. The plaintiffs argue that Microsoft “intentionally” collected voice data and knowingly failed to provide the legally required written disclosures. This language is significant because it suggests the lawsuit may seek not just statutory damages for negligent violations but potentially enhanced damages or punitive measures if the court agrees that Microsoft acted willfully and with knowledge of BIPA’s requirements. Microsoft is a major technology company with significant compliance resources; the argument goes that a company of its size and sophistication should have been aware of BIPA’s requirements when rolling out a feature that captures biometric voice characteristics.
One potential weakness in proving intent is that the Teams transcription feature was rolled out in 2021, and BIPA enforcement against tech companies was less prominent at that time compared to 2024-2026. Microsoft could argue that the company did not initially understand that voiceprint data fell under BIPA’s definition of biometric information or that creating voiceprints was a necessary technical step in speaker attribution. However, the lawsuit was filed in 2026, five years after the feature launched, which provides a strong argument that Microsoft has had ample opportunity to implement BIPA-compliant practices and chose not to do so. Courts have previously held that delays in implementing required disclosures, once a company becomes aware of privacy law obligations, can support a finding of negligent or willful conduct.
The Broader Implications for Enterprise AI and Meeting Transcription
The Teams case raises important questions about how enterprise AI and transcription technologies interact with biometric privacy laws. As more companies deploy AI-powered transcription, translation, and speaker identification features in their business tools, they are often collecting biometric voice data as a necessary component of those services. If the Basich lawsuit succeeds, it will establish that companies must provide BIPA-style disclosures whenever their AI transcription systems create voiceprints or other biometric identifiers, not just when the primary purpose of the system is biometric identification. This could require widespread changes to how vendors implement and disclose their transcription and meeting analysis features.
Some experts have pointed out that the ruling could create a template for similar claims against other platforms. Google Meet, Zoom, Cisco Webex, Amazon Chime, and other video conferencing and unified communication tools that offer automatic transcription and speaker identification features may face similar exposure if they operate in Illinois or serve Illinois residents and have not implemented BIPA-compliant consent and disclosure practices. The case is also significant because it suggests that voice data captured in business contexts may receive different treatment under privacy laws than voice data captured in consumer contexts. Even though the Teams users were participating in work meetings, they retain privacy rights under Illinois law, and their employers’ use of Teams does not automatically strip away those protections.
Current Status and Timeline for the Case
As of June 2026, the Basich v. Microsoft case remains in early litigation stages in the U.S. District Court for the Western District of Washington. The case was filed on February 5, 2026, and is proceeding under the case number 2:26-cv-00422. No settlement has been announced, and the case has not yet moved to trial.
Early motions may include Microsoft’s attempt to dismiss the case, arguments over the scope of the class definition, and discovery disputes about what internal Microsoft documents and communications the plaintiffs’ legal team can access. Class certification—the court’s approval that the case can proceed as a class action rather than individual lawsuits—typically comes later in the process and is often a contested issue in large privacy cases. The timeline for resolution is uncertain. BIPA cases can take multiple years to resolve, and cases involving major technology companies often involve complex settlement negotiations. If Microsoft moves to dismiss or if there are appellate proceedings, the case could extend well into 2027 or beyond. In the meantime, anyone who used Microsoft Teams with transcription enabled and was based in Illinois during the relevant period (March 1, 2021, onward) should monitor the case status, as they may be eligible to join the class and file a claim if the case results in a settlement or judgment in favor of the plaintiffs.
- —
You Might Also Like
- Netflix Privacy Class Action Claims Viewing Data Was Shared Without Proper Consent
- Cerebral Privacy Class Action Claims Telehealth Data Was Disclosed Without Proper Consent
- Amazon Prime Video Privacy Class Action Claims Viewing Data Was Shared Without Consent