Are Biometric Time Clocks Legal in Illinois?
Yes, biometric time clocks are legal in Illinois. The Illinois Biometric Information Privacy Act, or BIPA, does not ban fingerprint or facial recognition time clocks. It puts strict conditions on them instead. Skip a condition and you’re exposed to a lawsuit, not a warning letter.
That surprises a lot of business owners. Vendors sell fingerprint and facial scan clocks as simple attendance tools. They rarely mention that Illinois gives employees the right to sue over how that data gets collected, stored, and destroyed. This guide breaks down exactly what BIPA requires before you scan a single employee.
Biometric time clocks are also the single most common source of real BIPA lawsuits in Illinois. Most cases involve routine attendance scanners, not facial recognition surveillance or high-tech security systems. That’s the part most vendors leave out of the sales pitch.
Key Takeaways
- Biometric time clocks are legal in Illinois under BIPA, but only with written notice, a signed release, a retention policy, and vendor security controls in place.
- BIPA gives employees a private right to sue, unlike most other state biometric laws.
- The Illinois Supreme Court set a five-year statute of limitations for BIPA claims in Tims v. Black Horse Carriers.
- A 2024 amendment caps damages per person per collection method, but courts are still split on whether it applies retroactively.
- Time clock vendors carry their own BIPA exposure, not just the employer running the hardware.
Why Biometric Time Clocks Trigger So Many BIPA Lawsuits
BIPA is the Illinois Biometric Information Privacy Act, 740 ILCS 14. It regulates how private companies collect, store, use, and destroy biometric identifiers. That includes fingerprints, iris scans, voiceprints, and face or hand geometry. Unlike most state biometric laws, BIPA lets an individual sue directly. That’s what makes it different, and expensive to get wrong.

Workplace time clocks are the most common trigger because they’re the highest-volume form of biometric collection most employees ever encounter. Every employee, every shift, every scan. Retail biometric payment systems and school security systems generate lawsuits too, but time clocks dominate the case law.
BIPA applies to private companies operating in Illinois. That includes any employer running a fingerprint or facial recognition time clock. It also includes any vendor that processes that data for the employer. Government agencies are excluded.
The BIPA Compliance Checklist Before You Scan a Single Fingerprint
Illinois law lays out specific compliance steps an employer must complete before collecting biometric data. Skip one, and the time clock itself becomes evidence in a lawsuit.

- Give written notice. Tell the employee, in writing, that you’re collecting biometric data before you collect it.
- State your purpose and timeline. Explain in writing why you’re collecting the data and how long you’ll keep it.
- Get a signed written release. Have the employee sign a release authorizing the collection before their first scan.
- Publish a retention and destruction policy. Set a schedule for destroying biometric data, no later than three years after the employee’s last interaction with you, or when the purpose for collecting it ends, whichever comes first.
- Never sell or profit from the data. Only disclose it with consent, to complete a transaction the employee requested, or when the law requires it.
- Secure it like your other sensitive data. Store and transmit biometric data using the same or better protections you use for other confidential information.
BIPA requires biometric data be destroyed within three years of an employee’s last interaction, or when the reason for collecting it ends, whichever comes first.
Your Time Clock Vendor Is Part of Your BIPA Exposure Too
Most fingerprint and facial recognition time clocks run on a third-party vendor’s software. That vendor collects, stores, and sometimes transmits your employees’ biometric data too. Under BIPA, that makes the vendor a data handler with its own exposure, not just a hardware supplier.
This isn’t hypothetical.
Before you sign a time clock contract, ask your vendor three things. Where is the biometric data stored? Who else can access it? What happens to it if you cancel the contract?
What Happens If You Skip a Step
Missing a step doesn’t trigger a warning. It creates a lawsuit exposure that can last years, with real damages attached.
| Legal Detail | What It Means for Employers |
|---|---|
| Statute of limitations | Five years from the violation, set by the Illinois Supreme Court’s 2023 ruling in Tims v. Black Horse Carriers |
| Negligent violation damages | $1,000 per violation, or actual damages, whichever is greater |
| Intentional or reckless violation damages | $5,000 per violation, or actual damages, whichever is greater |
| 2024 amendment | Multiple scans of the same person by the same method now count as one violation for damages purposes, not one per scan; courts remain split on whether this applies retroactively |
| Attorney’s fees | Prevailing employees can recover attorney’s fees and costs on top of damages |
BNSF and Facebook: Why This Isn’t Theoretical
Two cases show the scale of BIPA exposure when biometric collection goes wrong. Neither involved small numbers. Both are worth understanding before you roll out a scanner.
| Case | What Happened | Outcome |
|---|---|---|
| Facebook (2021) | A federal judge approved a class-action settlement over facial recognition data collected without consent | $650 million settlement, one of the largest privacy settlements in U.S. history |
Neither case involved a Chicagoland small business. But BNSF’s exposure came from the same kind of technology many local companies use. A fingerprint scanner at a job site.
Alternatives to Biometric Time Clocks
If you’d rather skip BIPA exposure entirely, you have options. None of them require scanning a body part.
| Method | BIPA Exposure | Trade-off |
|---|---|---|
| PIN code entry | None, no biometric data collected | Employees can share or forget PIN codes, easier “buddy punching” |
| Badge or proximity card reader | None, no biometric data collected | Cards can be lost or shared, replacement adds a recurring cost |
| Fingerprint or facial recognition scanner | Full BIPA exposure, requires the compliance checklist above | Hardest to defeat with buddy punching, but carries real legal risk if compliance steps are skipped |
There’s no universal right answer here. It comes down to how much buddy punching risk you’re willing to accept versus how much compliance process you’re willing to run.
A Compliant Rollout: What It Looks Like in Practice
Picture a Chicagoland manufacturer switching from paper timesheets to a fingerprint clock. Before the vendor installs anything, HR drafts a written notice explaining what’s collected and why. Every employee signs a release before their first scan. The company publishes a retention policy.
Fingerprint templates get deleted three years after an employee leaves, or sooner if a project wraps first. IT vets the vendor’s data storage and encryption before the contract is signed. That order matters. Consent and policy come first, hardware goes in second.
LeadingIT doesn’t draft the consent language or the retention policy language itself. That’s an employment attorney’s job. LeadingIT’s role is technical. It secures the vendor connection and locks down access to stored fingerprint templates. It also helps produce the documentation your attorney needs to finalize consent paperwork. For the full regulatory walkthrough, see LeadingIT’s Illinois BIPA compliance guide for employers.
See Where You Stand
Before you sign a time clock contract (or if you already have one running), take the free 2-minute BIPA Risk-Check. Answer 8 plain-English questions and see your Illinois BIPA exposure level and the gaps to fix, no sign-up required.
Take the free 2-minute BIPA Risk-Check
Related Guides
- Illinois BIPA Compliance: The Employer’s Guide
- Is GIPA the Next BIPA? What Illinois Employers Need to Know
Frequently Asked Questions
Yes. Illinois law does not ban fingerprint or facial recognition time clocks. It requires written notice, a signed release, a retention policy, and reasonable security before you collect any biometric data. Skip those steps and you’re exposed to a lawsuit under the state’s biometric privacy law.
A biometric identifier is a retina or iris scan, a fingerprint, a voiceprint, or a scan of hand or face geometry. The law excludes things like photographs, physical descriptions such as height or eye color, and most medical test samples. Biometric information is any data derived from one of those identifiers used to identify a person.
BIPA is the Illinois Biometric Information Privacy Act, found at 740 ILCS 14. It’s considered the strictest state biometric privacy law in the country because it lets individuals sue directly, not just regulators.
Five years. The Illinois Supreme Court set a single five-year statute of limitations for all BIPA claims in its 2023 ruling in Tims v. Black Horse Carriers. That applies whether the claim involves a late notice, a missing release, or a mishandled retention policy.
Not automatically. In Mosby v. Ingalls Memorial Hospital, the Illinois Supreme Court excluded nurses’ fingerprint scans used specifically to access medication cabinets for patient care. The court was clear this wasn’t a blanket exemption for healthcare employers. A general attendance time clock unrelated to patient treatment likely isn’t covered, and a healthcare employer should confirm this with an employment attorney before assuming otherwise.
Usually not, if the agency doesn’t control the system. Liability tends to fall on whoever actually runs the system, typically the site operator or plant owner. That means the site operator still needs valid consent from staffing agency workers, not just its own employees.
The vendor can face its own BIPA liability, separate from yours. Vetting your vendor’s data handling before you sign is part of your own compliance process, not optional due diligence.
Get Your Time Clock Rollout Right the First Time
Getting biometric time clock compliance right isn’t a one-time checklist. It’s an ongoing vendor and security relationship. LeadingIT helps Chicagoland businesses secure that relationship end to end, from vendor vetting to access controls.
See LeadingIT’s Illinois compliance services for the done-for-you path. Or book a call to talk through your specific setup.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
