Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

BIPA for Illinois Manufacturers: What Plant Operators Need to Know

August 11, 2026
hero-bipa-for-illinois-manufacturers-1.png

Yes, BIPA (Illinois’s Biometric Information Privacy Act) applies to Illinois manufacturers the same as any other private employer. Manufacturing is actually one of the industries most exposed under this law. That’s because so many plants run fingerprint time clocks to track hourly shift workers.

Your plant might use a fingerprint scanner, hand-geometry reader, or facial-recognition badge system. BIPA governs how you collect and store that data either way. This page is the plant-floor version of the answer. It covers what actually creates risk on a shop floor, not the general legal overview.

For the full legal breakdown, see LeadingIT’s Illinois BIPA compliance guide for employers.

Why Are Manufacturing Plants a BIPA Hot Spot?

Manufacturing has a specific mix of factors that push BIPA risk higher than a typical office employer:

  • High-volume hourly shift workers. Plants often run two or three shifts a day. Every clock-in and clock-out is a biometric scan.
  • Fingerprint or hand-geometry time clocks. These are the most common labor-tracking tool on a shop floor, and also the single most litigated BIPA use case in Illinois.
  • Biometric access control. Many plants use fingerprint or badge-plus-biometric readers to lock down entrances or restricted areas, like chemical storage or a loading dock.
  • Heavy reliance on staffing agencies. Line workers on a manufacturing floor are often temp or agency labor, not direct hires. That adds a second layer of exposure, covered below.

Are biometric time clocks legal in Illinois? Yes. But legal doesn’t mean automatic. The technology itself is fine. The compliance steps around it are not optional.

The 4 Steps Before a Single Fingerprint Gets Scanned

BIPA doesn’t ban biometric time clocks. It conditions their use on four specific steps, spelled out in 740 ILCS 14/15. All four have to happen before you scan a single employee’s fingerprint, not after.

4 Steps Before Scanning
  1. Give written notice. Tell the worker, in writing, that you’re collecting biometric data.
  2. Get a written release. The worker signs a written release authorizing the collection, before the first scan.
  3. Publish a retention and destruction policy. The policy has to set a retention schedule and destruction guidelines, and it has to be public. Data gets destroyed once its purpose is met, or within 3 years of the worker’s last interaction, whichever comes first.
  4. Never sell the data. You can’t sell, lease, trade, or profit from a worker’s biometric data. Disclosure is allowed only in narrow cases, like a subpoena or the worker’s own consent.

Skip any one of these steps, and every scan that follows is a separate compliance gap.

Who’s Liable When Staffing Agency Workers Use a Biometric Time Clock?

Plenty of manufacturing plants staff their line with a mix of direct hires and staffing agency workers. Both groups punch the same fingerprint clock. So who’s on the hook if that clock isn’t compliant: the plant, or the staffing agency?

Matrix showing that liability for a biometric time clock follows whoever operates and controls it, not whoever merely supplies the workers, per the Salinas v. Surestaff ruling.

A recent Illinois appellate ruling answered that question directly. In Salinas v. Surestaff, the court sided with the staffing agencies. The case involved a food manufacturing facility in Elgin, Illinois, that used biometric fingerprint time clocks. The staffing agencies had enrolled workers in the system and tracked their hours. But they didn’t operate or control the time clock itself.

The court rejected what’s called the “conduit theory,” the idea that simply facilitating someone else’s data collection creates liability. BIPA requires actually acquiring or controlling the biometric data.

Liability follows whoever actually operates and controls the biometric time clock, not whoever merely supplies the workers using it.

Here’s what that ruling means on a manufacturing floor:

  • If your plant owns and runs the time clock system, your plant carries the compliance burden.
  • That’s true whether the worker punching in is a direct hire or a staffing agency placement.
  • The staffing agency isn’t automatically off the hook either. Liability turns on what role it actually plays in the system.
  • In the typical setup, where the plant picks the vendor and stores the fingerprint templates, the compliance load sits with the plant.

That has a practical consequence for your paperwork. You can’t treat staffing agency workers as someone else’s compliance problem. If they’re scanning into your clock, you need their paperwork on file. That means written notice and signed consent, the same as for a direct hire.

Your Time Clock Vendor Carries Its Own BIPA Exposure

Your plant likely didn’t build its own time clock software. You bought it from a vendor. That vendor collects, stores, and processes the fingerprint data behind the scenes.

Vendor Due Diligence Checklist

That vendor carries its own BIPA exposure, separate from yours. A gap in their process can become a gap in yours.

A concrete example: WorkEasy Software, formerly marketed as EasyWorkforce, EasyClocking, and TimeLogix, agreed to a $1.69 million class settlement.

The lesson for a plant operator: vendor due diligence isn’t optional. Before you sign a time clock contract, ask:

  • What happens to fingerprint templates once they’re captured, on the device or in the vendor’s cloud?
  • How long does the vendor retain the data, and does that match your own published policy?
  • Has the vendor been named in a BIPA suit, and how was it resolved?
  • Will the vendor put its data handling practices in writing, in the contract itself?

This is exactly the kind of gap LeadingIT’s Illinois compliance services is built to catch on the technical side. The consent language itself still needs an employment attorney’s sign-off.

What It Costs to Get This Wrong

BIPA damages add up fast on a shift-based workforce. Every fingerprint scan without valid consent counts as a violation.

BIPA Violation Counting Timeline

Illinois law sets two damage tiers:

Prevailing plaintiffs can also recover attorney’s fees and costs. That’s part of why BIPA suits keep coming.

In Cothron v. White Castle System, the court examined repeat scans of the same worker. It ruled a new claim accrues every time a scan happens, not just the first one. For a plant running multiple shifts a day, that multiplied the exposure fast.

The legislature responded in 2024. Under the amendment, repeat scans of the same person by the same method count as one violation. They no longer count as one violation per scan. Federal courts are still split on whether it applies to conduct from before that date.

That case didn’t involve a manufacturing plant. But it shows what BIPA exposure looks like at industrial, shift-based scale, the same scale many Illinois plants run at.

Illinois courts have also settled how far back a claim can reach.

A Practical Checklist for Plant Operators

Use this checklist to sanity-check your plant’s biometric setup, for both direct hires and staffing agency workers:

BIPA compliance checklist covering written notice, signed consent, a published retention policy, and destroying biometric data within three years.
  • [ ] Written notice on file for every worker before their first scan
  • [ ] Signed written consent on file for every worker, direct hire or staffing agency
  • [ ] A retention and destruction policy that’s actually published, not just written
  • [ ] Data destroyed on schedule: purpose met, or 3 years since the worker’s last interaction, whichever comes first
  • [ ] Vendor contract reviewed for how fingerprint templates are stored, shared, and destroyed
  • [ ] No selling, leasing, or trading biometric data to any third party
  • [ ] For high-turnover roles, consider a PIN or badge system instead of biometrics

Fewer new hires enrolled in a biometric system means less BIPA exposure to manage long-term.

Many plants also require pre-employment physicals for safety-sensitive roles. Those screenings can trigger a different Illinois privacy law. See is GIPA the next BIPA for what that covers.

See Where You Stand

Not sure where your plant actually stands on BIPA? Answer 8 plain-English questions about your time clock, badge, or access control setup, including staffing agency workers, and see your exposure level plus the gaps to fix. No sign-up required to see your result.

Take the free 2-minute BIPA risk assessment

Frequently Asked Questions

Does BIPA apply to staffing agency workers on our line?

Yes, but liability usually falls on whoever operates the biometric system, not the staffing agency. A 2026 Illinois appellate ruling confirmed staffing agencies aren’t automatically liable for a client’s time clock. If your plant owns and runs the system, the compliance burden is on your plant. That’s true for direct hires and staffing agency workers alike.

Is a fingerprint time clock illegal in Illinois?

No, biometric time clocks are legal in Illinois. BIPA doesn’t ban the technology, it conditions its use on specific steps. Before the first scan, you need written notice, signed consent, and a published retention and destruction policy. Skip those steps and the clock itself becomes the compliance problem.

How long can we keep employee fingerprint data?

Illinois law sets the outer limit at 3 years. You must destroy biometric data once its collection purpose is met. The limit is 3 years after the worker’s last interaction, whichever comes first. A published written policy has to state your actual schedule.

Can we get sued if our time clock vendor didn’t get proper consent?

Possibly, yes. Vendors carry their own BIPA exposure, but that doesn’t automatically shield the employer that deployed the system. One vendor, formerly marketed as EasyWorkforce, settled a class action for $1.69 million over fingerprint data collected without consent. Vetting your vendor’s consent and retention practices before you sign is the best protection.

Courts can also award attorney’s fees to a winning plaintiff. A 2024 amendment treats repeat scans of the same person and method as one violation, not one per scan. That limits the exposure, but doesn’t eliminate it.</p> </details>

What’s the fastest way to reduce BIPA exposure on the shop floor?

For high-turnover roles, switching from biometric time clocks to a PIN or badge system removes most of the risk. Fewer people enrolled in a biometric system means fewer consent gaps to manage. For roles where biometrics stay in place, tightening your consent paperwork and vendor contract matters most.

Securing the Technical Side, So You’re Not Guessing

BIPA compliance has two sides. Your employment attorney handles the consent language and legal review. LeadingIT handles what happens to the data once it’s collected.

On the technical side, that can mean:

  • Securing the connection between your time clock vendor and your network
  • Locking down where fingerprint templates get stored
  • Helping you migrate to a PIN or badge system, if you’d rather cut biometric risk entirely

LeadingIT doesn’t draft consent forms or give legal advice. It makes sure the technical environment behind your time clock matches what your policy says on paper.

Ready to check your setup? Book a call with LeadingIT, see LeadingIT’s Illinois compliance services for the done-for-you path, or contact us with questions.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.