Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Illinois BIPA Compliance: The Employer’s Guide to the Biometric Information Privacy Act

August 11, 2026
hero-bipa-compliance-guide-employers-1.png

Illinois BIPA compliance starts with one rule: get written consent before you scan anyone’s fingerprint, face, or voice. BIPA stands for the Biometric Information Privacy Act, a state law passed in 2008 that controls how private companies collect, store, and destroy biometric data. It is widely considered the strictest biometric privacy law in the country. The reason is simple: BIPA lets an individual sue over a violation directly, without waiting on a regulator to act (source: 740 ILCS 14).

For Illinois employers, that private right of action changes the math. A single fingerprint time clock rolled out without the right paperwork can expose you to a lawsuit from every employee who ever punched in on it. This guide walks through what counts as biometric data, who the law covers, what you must do before you scan anyone, and what happens if you skip a step.

Key Takeaways

  • BIPA is the Illinois Biometric Information Privacy Act, in force since 2008, and it gives individuals the right to sue over violations directly.
  • Fingerprints, hand and face geometry, retina or iris scans, and voiceprints all count as biometric identifiers. Photos and physical descriptions do not.
  • BIPA applies to private employers, not government agencies, and covers time clocks, access badges, and biometric payment systems.
  • Before scanning anyone, you need written notice, a signed release, a public retention policy, and a promise not to sell the data.
  • Your time clock vendor is part of your BIPA risk. The law requires reasonable security over any vendor that touches biometric data.

What Is the Illinois Biometric Information Privacy Act?

The Biometric Information Privacy Act, known as BIPA, is an Illinois statute found at 740 ILCS 14. Lawmakers passed it in 2008. It sets rules for any private entity that collects, stores, uses, or shares biometric identifiers or biometric information.

What makes BIPA different from most other state privacy laws is enforcement. Many state biometric or privacy laws only let a state attorney general bring a case. BIPA does not work that way. Any person harmed by a violation can file a lawsuit on their own. That single feature has driven a wave of class-action litigation against Illinois employers over the past decade, most of it tied to fingerprint time clocks.

If your business operates in Illinois and touches fingerprint scanners, facial recognition cameras used for access, or voice authentication systems, BIPA applies to you regardless of your industry or size.

What Counts as a Biometric Identifier Under BIPA?

BIPA’s definition is specific. It covers four types of data, and it explicitly excludes several others that people often assume are included (source: 740 ILCS 14/10).

Covered as a biometric identifierNOT covered by BIPA
FingerprintPhotograph (standing alone)
Retina or iris scanPhysical description (height, eye color)
VoiceprintWriting sample
Scan of hand or face geometryTattoo description
Most biological samples used for other medical testing

“Biometric information” is a related, broader term. It covers any data, however it was captured or stored, that is based on one of those identifiers and used to identify a specific person. In practice, this means a badge photo on file is not a BIPA problem by itself. A facial-geometry template your access-control system generates from that same photo is.

Who Does BIPA Apply To?

BIPA applies to “private entities” operating in Illinois. Government agencies are excluded from that definition entirely (source: 740 ILCS 14/10). Everyone else is fair game, from a five-person shop to a large manufacturer.

For employers specifically, three workplace scenarios trigger BIPA most often:

  • Fingerprint or hand-geometry time clocks. The most common trigger by far, and the source of most reported BIPA lawsuits.
  • Access badges with biometric readers. Facial recognition or fingerprint checks used to unlock a door, a server room, or a secured area.
  • Point-of-sale fingerprint pay. Retail and food-service systems that let customers or staff authorize a transaction with a fingerprint.

None of these uses are illegal under BIPA. The law does not ban biometric technology. It conditions your use of it on a specific set of steps you must complete first.

The 4 Things BIPA Requires Before You Scan Anyone

Missing any one of them is a violation.

#RequirementWhat it means in practice
1Written noticeTell the employee in writing that you’re collecting biometric data, and why.
2Written releaseGet a signed consent form before the first scan. A verbal okay does not count.
3Public written policyPublish a policy that sets a retention schedule and destruction rules.
4No selling the dataNever sell, lease, or trade biometric data, or profit from it.

The retention piece has a hard deadline built in. You must permanently destroy biometric data once the reason you collected it no longer applies, or within three years of the employee’s last interaction with your company, whichever comes first.

BIPA requires you to destroy biometric identifiers within 3 years of an employee’s last interaction with your company, or sooner if the original purpose for collecting the data has been satisfied.

Disclosure is restricted the same way collection is. You can only share biometric data with the employee’s consent, to complete a transaction they requested, when a law requires it, or under a valid warrant or subpoena.

The Security Standard of Care: Your Vendor Is Part of Your BIPA Exposure

BIPA does not stop at notice and consent. Once you have biometric data, you have to protect it. The law requires you to store, transmit, and secure biometric data using the reasonable standard of care for your industry.

This is where a lot of employers get exposed without realizing it. Most fingerprint time clocks are not built in-house. They run on a third-party vendor’s hardware and software. That vendor typically stores the biometric templates your employees generate, on their servers or yours, depending on the setup.

Under BIPA, that vendor relationship does not sit outside your compliance picture. It sits inside it. A few practical questions to ask before you sign with any biometric time clock or access-control vendor:

  • Where does the vendor store biometric templates, and who can access them?
  • Does the vendor encrypt biometric data at rest and in transit?
  • What happens to the data if you cancel the contract?
  • Does the vendor’s own retention practice match the three-year, purpose-based destruction clock BIPA requires of you?

Skipping this vendor review is one of the most common gaps in an otherwise reasonable BIPA program. The scan on the wall is only half the picture. What happens to that data after it leaves the reader is the other half.

What Happens When You Get BIPA Wrong

BIPA itself sets no deadline for filing a claim. The Illinois Supreme Court settled that gap in February 2023, in Tims v. Black Horse Carriers. The court ruled that a single five-year statute of limitations applies to every BIPA claim. That gives a scanned employee years to sue over a form you never had them sign.

Damages add up fast once a claim is filed.

A negligent BIPA violation carries damages of $1,000 or actual damages, whichever is greater. An intentional or reckless violation carries $5,000 or actual damages, whichever is greater. Multiply that by every employee who used an uncompliant time clock, and the number gets large quickly.

How large a single violation counts as has itself been litigated. In 2023, the Illinois Supreme Court ruled in Cothron v. White Castle that every individual scan is a separate violation, not just the first one. For a daily time clock, that turned one employee into hundreds of claims. Illinois lawmakers stepped in. On August 2, 2024, Governor Pritzker signed Public Act 103-0769 into law. It caps recovery at one violation per person, per collection method, no matter how many times they scanned. Federal courts in Illinois are still split on whether that cap applies to older claims filed before the law changed.

Two settlements show what this looks like at scale. Here’s the enforcement record so far:

DateCaseOutcome
Feb. 2023Tims v. Black Horse CarriersIllinois Supreme Court sets a uniform 5-year statute of limitations for all BIPA claims.
Aug. 2024Public Act 103-0769Caps damages at one violation per person, per method, going forward.

The BNSF number is the one to sit with. It came from truck drivers scanning in at rail yards, the exact same kind of use case as a shop-floor time clock.

What a Compliant BIPA Program Looks Like

None of this requires exotic legal work. It requires doing five things, in order, before anyone scans in.

  1. Write a public biometric data policy. State what you collect, why, and your retention schedule. Post it somewhere an employee (or a court) can find it.
  2. Get a signed written release before the first scan. Not a verbal okay, not an email reply. A signed form, collected before the employee ever touches the reader.
  3. Review your vendor’s security and retention practices. Ask where templates are stored, whether they’re encrypted, and what happens to the data if you cancel.
  4. Set and follow a destruction clock. Purge biometric data once its purpose is met, or within three years of the employee’s last interaction, whichever comes first.
  5. Keep records of all of it. The notice, the signed release, the vendor review, and the destruction log. If a claim comes in years later, you need to show you did this at the time.

None of these steps requires a lawyer to execute technically. Drafting the actual consent language and retention policy does. That’s an employment attorney’s job, not your IT provider’s.

Where GIPA Fits Into the Picture

BIPA isn’t the only Illinois privacy law employers should watch. The Illinois Genetic Information Privacy Act, known as GIPA, restricts how employers can collect and use genetic and family medical history. It carries even higher damages than BIPA and has seen a sharp rise in class-action filings since 2023. It’s a separate statute with separate triggers, most commonly a pre-employment health questionnaire that asks about family history. See is GIPA the next BIPA for the details specific to that law.

Are Biometric Time Clocks Worth the Risk?

Biometric time clocks are legal in Illinois. BIPA doesn’t ban the technology. It just makes the paperwork non-negotiable. Whether a fingerprint or facial-recognition clock is worth deploying, given that paperwork burden, depends on your size, your workforce turnover, and what a PIN or badge alternative would cost you instead. See are biometric time clocks legal in Illinois for a closer look at that tradeoff.

See Where You Stand

Not sure where your current setup falls on this? Answer 8 plain-English questions about your time clock, access control, or POS biometric system and see your exposure level and the specific gaps to fix. No sign-up required to see your result.

Take the free 2-minute BIPA Risk-Check

Frequently Asked Questions

BIPA stands for the Illinois Biometric Information Privacy Act. Illinois lawmakers passed it in 2008. It regulates how private companies collect, store, and destroy fingerprints, facial scans, and other biometric data.

Yes. Before you scan anyone, you must give written notice, get a signed written release, and publish a written retention and destruction policy. A verbal agreement or an unsigned form does not satisfy the requirement.

You must destroy biometric identifiers once the original reason for collecting them is satisfied, or within three years of the employee’s last interaction with your company, whichever happens first.

A negligent violation carries damages of $1,000 or actual damages, whichever is greater. An intentional or reckless violation carries $5,000 or actual damages, whichever is greater. Prevailing employees can also recover attorney’s fees.

The Illinois Supreme Court ruled in 2023 that a single five-year statute of limitations applies to all BIPA claims. That gives employees a long window to bring a case over old paperwork gaps.

It used to work that way, and it made daily time clock use expensive to get wrong. A 2024 state law now caps damages at one violation per person, per collection method, for conduct going forward. Whether that cap applies retroactively is still being litigated in federal court.

Get the Technical Side Locked Down

Writing the policy and collecting signatures is your attorney’s lane. Securing the system underneath it, the time clock hardware, the vendor connection, the stored templates, is where LeadingIT comes in. If you want a done-for-you path, book a call to talk through your specific setup.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.