BIPA for Illinois Construction Firms: What Contractors Need to Know
BIPA applies to Illinois construction firms exactly like it applies to any other private employer in the state. If your jobsite uses a fingerprint time clock or a biometric turnstile, BIPA covers you. BIPA stands for the Illinois Biometric Information Privacy Act, the state’s biometric data law. Construction adds one real wrinkle most industries never face.
Job sites mix direct hires, subcontractors, and workers dispatched from a union hall. A general contractor’s turnstile or time clock can scan all of them at once. That raises a hard question: who is legally responsible for getting consent first?
This guide covers what changes for construction specifically. It also covers the four steps BIPA requires before any scan. And it explains a 2026 court ruling on who’s liable on a shared job site. For the general rules that apply to every Illinois employer, see our Illinois BIPA compliance guide for employers.
Why Construction Jobsites Are Different
Two biometric use cases show up constantly on construction sites. The first is jobsite security. Turnstiles and badge readers scan a fingerprint or hand geometry to control gate access. The second is labor cost tracking. Fingerprint time clocks record hours for payroll, including certified payroll reporting on prevailing-wage jobs.

Both uses count as collecting biometric data under BIPA. It doesn’t matter whether the scan is for security or for payroll. The moment a system captures a fingerprint or hand geometry template, BIPA’s rules apply.
Construction crews rarely come from one employer. A job site often mixes the GC’s own employees with subcontractor crews. Union hall dispatch can add a rotating cast of workers too. Every one of them may walk through the same turnstile or punch the same time clock.
Biometric time clocks themselves are legal in Illinois. BIPA doesn’t ban the technology. It just conditions its use on a specific compliance process, covered next. See are biometric time clocks legal in Illinois for the full rundown on that question.
The 4 Steps Before Anyone Gets Scanned
Before a worker’s fingerprint or hand geometry gets scanned, BIPA lays out four specific requirements. Skip any one of them and you’re out of compliance, even if the scan itself is routine.

- Written notice. Tell the worker in writing that you’re collecting their fingerprint or hand geometry, and why.
- Written release. Get a signed release before the first scan, not after the fact.
- Public retention policy. Publish a written policy on how long you’ll keep the data and when you’ll destroy it.
- No selling the data. You can never sell, lease, trade, or profit from a worker’s biometric data.
There’s also an outer limit on how long you can hold the data. Destroy the data once the purpose is done, or within three years of the worker’s last day, whichever comes first. On a job site with high turnover between projects, that clock matters more than it does in a typical office.
Who’s Liable on a Multi-Employer Job Site?
Here’s the scenario. A general contractor installs a biometric turnstile at the gate. It scans everyone, including subcontractor and staffing agency crews. Under BIPA, the “private entity” that must get consent is the one collecting the data. But which company is that, when three or four employers all send workers through the same gate?
A 2026 Illinois court answered a version of this question. In Salinas v. Surestaff, staffing agencies had placed workers at a facility that used a fingerprint time clock. The staffing agencies didn’t operate that system. The facility did. The court ruled the staffing agencies weren’t liable under BIPA.
BIPA liability follows whoever actually operates and controls the biometric system, not whoever merely supplies the workers who use it.
The same logic applies to a construction job site.
| Role on the job site | Controls the biometric system? | Where BIPA liability tends to land |
|---|---|---|
| General contractor (owns the turnstile or time clock) | Yes | The general contractor |
| Subcontractor (crew uses the GC’s system) | No | The general contractor, not the sub |
| Staffing agency (dispatches workers only) | No | Whoever operates the system, not the agency |
This isn’t a blanket shield for subs and staffing agencies, and it isn’t a blanket trap for GCs either. Control decides liability, not who signs the paycheck. A subcontractor that brings its own biometric system onto a site would carry its own BIPA obligations for it. The same staffing-agency liability question comes up in BIPA for Illinois manufacturers, another industry that leans heavily on subcontracted and agency labor.
The GC’s Blind Spot
Here’s the practical trap. A general contractor sets up the gate system for its own crew. It never thinks about the subcontractor’s workers who walk through it too.
Those subcontractor employees never signed the GC’s consent paperwork. They may have never seen a BIPA notice at all. But under the Salinas control test, the GC (not the sub) is the one who operates and controls the scanner.
That means the GC’s compliance exposure runs to every worker the system scans, not just its own payroll. Assuming “the sub’s employer handled it” is not a safe assumption. It’s a guess, and BIPA doesn’t reward guesses.
The fix is simple in concept. Get consent at the gate, for everyone who passes through it, regardless of whose paycheck they’re on. That means building consent collection into site badge-in or access onboarding, not just new-hire paperwork for direct employees.
What It Costs to Get This Wrong
BIPA damages scale with how many people got scanned without consent, and for how long. Violations carry set liquidated damages even without proof of actual harm.

Prevailing workers can also recover attorney’s fees and costs. Courts can order an entity to stop the violating practice entirely.
For years, Illinois courts treated every single scan as a separate violation. A worker who badged in twice a day for a year could rack up hundreds of violations on their own.
The legislature responded. Now, scanning the same person’s same biometric identifier by the same method counts as one violation for damages purposes, not one violation per scan. Whether that change applies retroactively to older conduct is still being litigated in federal court, so it isn’t a settled defense for anything that happened before the amendment.
For a sense of scale, look at BNSF Railway’s case. The jury’s verdict was $228 million. It’s not a construction case, but it’s the same fact pattern: a large field workforce, routine fingerprint scans, and no valid consent process in place.
Checklist for GCs and Subs
Before your next jobsite goes live with badge or biometric access, work through this:
- Consent paperwork built into onboarding. Every worker who’ll badge or scan in, direct hire, sub, or agency dispatch, signs written notice and release before their first scan.
- A published retention and destruction policy. State how long you’ll keep the data and when you’ll destroy it, and make the policy publicly available.
- Contract language on who owns compliance. Have your attorney spell out, in the GC/sub agreement, which party is responsible for BIPA compliance on a shared access system. This is a legal drafting question, not an IT one.
- PIN or badge alternatives for short-term labor. For a single-project crew or short-duration sub, a PIN code or physical badge sidesteps BIPA’s biometric consent requirements entirely.
None of this replaces legal review. An employment attorney should confirm your consent forms and contract language before you scan a single worker.
See Where You Stand
Not sure where your jobsite access setup actually stands under BIPA? Answer 8 plain-English questions about your badge, turnstile, or time clock setup, including subcontractor and union crews, and see your exposure level and the gaps to fix. No sign-up required to see your result.
Take the free 2-minute BIPA Risk-Check
Related Guides
- Illinois BIPA Compliance: The Employer’s Guide
- Are Biometric Time Clocks Legal in Illinois?
- BIPA for Illinois Manufacturers
- Is GIPA the Next BIPA? What Illinois Employers Need to Know
Frequently Asked Questions
Does BIPA apply to subcontractors and staffing agency workers on a construction site?
Yes, but liability follows whoever controls the biometric system, not whoever signs the worker’s paycheck. A 2026 Illinois appellate ruling found staffing agencies weren’t liable for a client’s fingerprint time clock because they didn’t operate it. On most job sites, that means the general contractor or site operator carries the compliance burden for a shared access system.
Are biometric time clocks legal on Illinois construction sites?
Yes. BIPA doesn’t ban fingerprint or hand-geometry time clocks. It conditions their use on written notice, a signed release before the first scan, a published retention and destruction policy, and a ban on selling the data. Most reported BIPA lawsuits involve exactly this kind of routine time clock or access-control use, which is why getting the process right matters.
Who is responsible for BIPA compliance when a GC’s turnstile scans a subcontractor’s crew?
Generally, whoever owns and operates the turnstile or time clock system. Courts have held that BIPA liability requires actually acquiring or controlling biometric data, not just supplying the workers who use it. On most sites, that puts the compliance burden on the general contractor, since they run the system.
How long can a construction firm keep biometric data?
Biometric identifiers and biometric information must be destroyed once the original purpose for collecting them is satisfied, or within three years of the worker’s last interaction with the company, whichever happens first. A published written policy has to spell out this retention and destruction schedule.
Prevailing workers can also recover attorney’s fees and costs, and courts can order the violating practice stopped.</p> </details>
Did the 2024 BIPA amendment change how damages are calculated?
Yes. Before the amendment, Illinois courts treated each individual scan as a separate violation, which multiplied damages fast for daily-use systems like time clocks. Whether it applies to conduct before that date is still being argued in federal court.
Can a construction firm avoid BIPA compliance obligations entirely?
The only sure way to avoid BIPA’s requirements is to not collect biometric identifiers at all. A PIN code or physical badge system for site access or time tracking sidesteps BIPA entirely, which is a real option for short-duration or single-project labor where building out a full consent process isn’t practical.
Get Your Technical Side Squared Away
BIPA compliance is ultimately a legal question, and an employment attorney should draft your consent forms, notices, and retention policy. But the technical side of a biometric access system, how it’s configured, who can access the stored data, how it’s secured, is where a lot of exposure actually lives day to day.
LeadingIT helps Illinois contractors select and configure jobsite access and time-clock systems, secure the vendor relationship and data flow behind them, and produce the documentation your attorney needs to finalize compliant consent paperwork. If you’d rather move away from biometrics altogether, we can help you migrate to a PIN or badge system instead.
See our Illinois compliance services for a done-for-you path, or book a call to walk through your jobsite setup.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
