All posts

Privacy9 min read

Fingerprint and face time clocks: the law you may not know applies to you

A white security camera mounted on an industrial ceiling beside a strip light.

Biometric time clocks solve buddy punching in the most direct way available: a fingerprint cannot be lent to a colleague. It is a genuinely good answer to a genuinely hard problem, and it is why so many of these devices are sold. It also puts a class of legal obligation onto your business that most buyers learn about long after the clock is on the wall.

The short version

  • A fingerprint or face scan solves buddy punching directly, because a fingerprint cannot be lent to a coworker. It also creates an ongoing legal obligation in Illinois, Texas and Washington.
  • A photograph is not a biometric identifier. A measurement of face geometry derived from that photograph is one, and that line decides which set of rules you are under.
  • Illinois is the statute that matters, because it gives individuals a private right of action with damages set in the statute and does not require proof of any injury beyond the violation itself.
  • If you use biometrics, written notice and a signed release must come before the first scan, and you must publish a retention and destruction schedule and then follow it.

What counts as a biometric identifier

This is the distinction everything turns on, and it is narrower than people assume. A biometric identifier is a measurement derived from your body that can be used to identify you. A fingerprint. A scan of hand geometry. A retina or iris scan. A voiceprint. And, critically for time clocks, a scan of face geometry.

A photograph is not a biometric identifier. Illinois law says so explicitly: writing samples, written signatures, photographs, human biological samples used for valid scientific testing, demographic data and physical descriptions are all excluded from the definition.

A photograph of a person is a photograph. A measurement of the geometry of their face, derived from that photograph, is a biometric identifier.

That line is not a technicality, and Illinois courts have repeatedly held that deriving face geometry from a photograph brings the resulting data inside the statute even though the photograph itself sits outside it. If your time clock takes a picture and a person looks at it, you are in one world. If your time clock takes a picture and software measures the distance between the eyes to decide whether this is the same employee as yesterday, you are in a different one.

It is the reason our own product does the first and refuses the second. On Post photographs every clock in and hands the image to a manager. It derives no face geometry, matches no faces and runs no recognition of any kind. That was a decision rather than a limitation, and this is the paragraph that explains it.

Three states, and one of them is not like the others

Texas and Washington both regulate the capture of biometric identifiers for commercial purposes. Both require notice and consent, both restrict disclosure, both require reasonable care in storage and destruction within a defined period. Both are enforced by the state attorney general. If you get it wrong, the state can act.

Illinois works differently, and the difference is the entire story of biometric litigation in the United States.

Why the Illinois statute is the one that matters

The Biometric Information Privacy Act gives a private right of action. An individual can sue, on their own behalf and on behalf of a class, with liquidated damages set in the statute: $1,000 for each negligent violation and $5,000 for each reckless or intentional one, plus attorneys’ fees.

Two decisions turned that into the risk it is today. In Rosenbach v. Six Flags (2019) the Illinois Supreme Court held that a person need not show any actual injury beyond the violation of their rights under the statute. The procedural failure is itself the harm. Then in Cothron v. White Castle (2023) the court held that a separate claim accrued each time biometric data was collected, which in a time clock context means every scan by every employee on every shift. The court acknowledged in the opinion that damages in that case could exceed seventeen billion dollars.

What changed in 2024, and what did not

In August 2024 Illinois amended the statute. A private entity that collects the same biometric identifier from the same person by the same method more than once now commits a single violation, with at most one recovery available. The same amendment confirmed that an electronic signature is a valid written release.

This is a meaningful reduction in exposure and it is not an all clear. The private right of action is intact. The per person damages are intact. Class actions are intact, and the class in an employment case is your entire workforce over the relevant period. A hundred employees at $1,000 each is still a six figure claim arising from a consent form nobody printed.

What compliance actually requires

If you do use biometrics, the Illinois requirements are the strictest and are a reasonable template. Before you collect anything, you must:

  1. Inform the person in writing that a biometric identifier is being collected or stored.
  2. Inform them in writing of the specific purpose and the length of term for which it is being collected, stored and used.
  3. Obtain a written release from the person, signed before collection begins.

And on an ongoing basis you must:

  • Publish a written retention and destruction policy, publicly available, saying when biometric data is destroyed. The outside limit is when the purpose has been satisfied or three years after the last interaction, whichever is first.
  • Actually destroy the data on that schedule. A published policy you do not follow is worse than no policy, because it is evidence.
  • Not sell, lease, trade or profit from it. Flatly prohibited.
  • Store it with at least the care you use for other confidential information, and not less than the industry standard.

The operational trap hides in the timing. The consent has to come before the first scan. A new hire enrolled on their first morning, before the paperwork is done, is a violation on day one, and the enrolment is exactly the moment when everybody is busy.

Six questions for any vendor selling you a biometric clock

None of this means biometrics are a bad choice. It means they are a choice with conditions, and a vendor who cannot answer these quickly has not thought about your side of it.

  1. Do you store the biometric, or a template derived from it? Most modern devices store a mathematical template and discard the image. That is better practice, and it is still a biometric identifier under these statutes. A vendor who tells you a template puts you outside the law is wrong.
  2. Where is it stored, and who else can reach it? On the device, in your tenant, or in a shared vendor system. Disclosure to a third party is separately regulated.
  3. Do you provide the consent workflow, or am I printing my own forms? If the product enrols an employee without capturing consent first, the product is designed to put you in breach.
  4. What is the destruction schedule and can I see it run? Ask for the evidence, not the setting.
  5. What happens when someone leaves? Their template should go on a defined schedule, and you should be able to confirm it did.
  6. Who indemnifies whom? Read that clause carefully. In most of these contracts the answer is that you carry the risk.

If you already have one running

Most people read this after buying, not before, and the useful question then is what to do about it. Nothing here is legal advice and a lawyer should look at your specifics, but there is a sensible order of work.

  1. Find out what you are actually collecting. Ask the vendor, in writing, whether the device stores an image, a template, or both, and where each one lives. You cannot answer any of the rest until you know this.
  2. Check whether consent was ever taken, and when. Not whether there is a policy. Whether there is a signed release for each enrolled person, dated before their first scan. This is the gap in most small businesses, and it is the one the statute is built around.
  3. Write and publish the retention schedule if there is not one. It has to be publicly available, and the outside limit in Illinois is the earlier of the purpose being satisfied or three years after the last interaction.
  4. Fix the new hire path first. Whatever you do about the existing enrolments, stop adding to the problem: the release is signed before the finger touches the reader, on the same day the person fills in their other paperwork.
  5. Then deal with the existing enrolments. Getting releases signed now does not undo a collection that already happened, but it stops the ongoing one, and a business that has tidied up is in a materially different position from one that has not.

The instinct to rip the device out immediately is usually wrong. Deleting the data in a hurry can destroy the evidence of what you were holding and for how long, which is exactly what you would need to show good faith. Get advice before you delete anything.

What to use instead, if you would rather not

The reason to consider an alternative is not that biometrics are unsafe. It is that they create an ongoing compliance obligation to solve a problem that has other answers, and small businesses tend to be the worst placed to carry ongoing compliance obligations.

The property you actually need is the one from the buddy punching problem: a credential that is a physical object rather than a piece of information, whose absence somebody would notice. A badge or a name tag satisfies both. It is lendable in principle, and lending it means working a shift without the thing you are visibly supposed to be wearing, in front of colleagues and customers.

Pair it with a photograph reviewed by a person and you get most of what a fingerprint reader offers, with two advantages. The photograph is evidence a human can evaluate and explain, rather than a match score. And a photograph, reviewed by a person and never measured, stays a photograph.

One honest caveat, because this is the section where it would be easy to oversell. A badge is not identity. A card can be cloned by somebody who wants to badly enough, and two people who have agreed to cover for each other can still do it. What the pairing buys is that the attempt leaves a trace, and that somebody would have to look at the photograph and decide it was fine. That is a different kind of protection from a fingerprint, and for most businesses it is enough.

If you are in Illinois, Texas or Washington and you are weighing this up, the single most useful thing you can do is ask your lawyer the question before you buy rather than after. It is a short conversation in advance and a long one afterwards.

Common questions

Are fingerprint time clocks legal?
Yes, everywhere in the United States, but three states regulate them specifically. Texas and Washington require notice, consent, restricted disclosure and destruction within a defined period, enforced by the state attorney general. Illinois requires the same things and adds a private right of action, which is what makes it the one most businesses hear about. Legal with conditions is the accurate summary, and the conditions are ongoing rather than one time.
Is a photograph taken at clock in a biometric identifier?
No. Illinois law explicitly excludes photographs from the definition, along with writing samples, written signatures, demographic data and physical descriptions. What is covered is a scan of face geometry, including one derived from a photograph. A time clock that takes a picture and shows it to a manager is in a different position from one that measures the face to decide whether this is the same employee as yesterday.
What are the damages under BIPA?
The statute sets liquidated damages of 1,000 dollars for each negligent violation and 5,000 dollars for each reckless or intentional one, plus attorneys fees. An August 2024 amendment limited multiple collections of the same identifier from the same person by the same method to a single violation with one recovery, which reduced exposure considerably. The private right of action, the per person damages and class actions all remain, and in an employment case the class is your workforce.
We already have a fingerprint clock running. What now?
Work in order. Find out from the vendor in writing whether the device stores an image, a template or both and where each lives. Check whether a signed release exists for each enrolled person, dated before their first scan, which is the usual gap. Publish a retention and destruction schedule. Fix the new hire path first so you stop adding to the problem. Do not delete anything in a hurry, because that can destroy the evidence of what you held and for how long, and take advice before you do.

Sources

This is general information about how these rules work, not legal advice. Wage and hour law varies by state and by industry, and your own counsel is the right place to take a specific question.

On Post is a time clock that proves who clocked in

A badge tap or a QR code on the name tag your team already wears, a framed photo on every clock in, and timesheets that are ready for payroll. Free for small teams.

Start free trial

More from the blog