A restaurant owner in suburban Chicago bought a $200 fingerprint time clock in 2019 to stop employees from clocking in for each other. Eight years, one class-action lawsuit, and a six-figure settlement later, that same time clock is the reason her lawyer now reviews every new piece of hardware she buys. The clock worked exactly as advertised. It just also happened to violate a law she'd never heard of.
That law is Illinois's Biometric Information Privacy Act (BIPA), and it's the reason "install a fingerprint scanner" went from a five-minute Amazon purchase to a decision that belongs on the same checklist as payroll tax registration. If your business has hourly employees and you're using — or thinking about using — a fingerprint, palm-vein, or facial-recognition time clock, this is the compliance layer that most point-of-sale and timekeeping vendors never mention in the sales pitch.
Why a Time Clock Purchase Turned Into a Legal Category
Biometric identifiers are different from every other kind of employee data a small business collects. A stolen password can be reset. A stolen Social Security number is bad, but it's at least theoretically replaceable through years of credit monitoring. A fingerprint can't be changed. Once it's compromised, it's compromised for the rest of that person's life — which is exactly the argument Illinois lawmakers made when they passed BIPA in 2008, years before biometric time clocks became a common small-business tool.
BIPA imposes four requirements on any business — including small employers — that collects fingerprints, palm scans, retina scans, or voiceprints:
- Written policy. You need a publicly available, written retention and destruction policy for biometric data, made before you collect a single fingerprint.
- Written notice. Employees must be told in writing that their biometric data is being collected and why.
- Written consent. You need signed, written authorization — not a verbal "is that okay?" at onboarding — before the first scan.
- No sale, no unnecessary retention. Biometric data can't be sold, and it must be destroyed once the reason for collecting it ends (usually when the employee leaves) or within three years, whichever comes first.
Miss any one of those four steps and every employee whose fingerprint you scanned without proper consent has a private right of action — meaning they can sue you directly, without waiting for a state regulator to act. That last detail is what makes Illinois's law categorically more dangerous to small businesses than almost any other privacy statute on the books.
What a BIPA Violation Actually Costs
The statute sets damages at $1,000 per negligent violation and $5,000 per reckless or intentional violation. For years, plaintiffs' attorneys argued that every single scan was a separate violation — so an employee who clocked in with a fingerprint twice a day for three years had generated over 2,000 individual violations. Do that math across a 40-person staff and a small business is suddenly facing exposure in the millions, all for a $200 time clock bought with good intentions and no legal review.
That "per-scan" theory is why BIPA settlements have run so high. A 2026 fingerprint-timeclock class action against workforce-management vendor EasyWorkforce settled for $1.69 million — and that's just one case among dozens filed against manufacturers, retailers, and restaurant groups over the past decade.
There's genuine relief on the horizon, but it's partial. In August 2024, Illinois amended BIPA so that repeated scans of the same biometric identifier by the same method count as one violation, not thousands — a fix aimed squarely at capping the runaway per-scan damages theory. The Seventh Circuit Court of Appeals confirmed in April 2026 (Clay v. Union Pacific) that this amendment applies retroactively, even to cases that were already pending. That caps the ceiling on any single lawsuit, but it does not eliminate liability. A business that never collected written consent is still liable for every affected employee — just once per employee instead of once per scan. For a company with 30 uncompensated employees, "only" $1,000–$5,000 each is still a five- or six-figure problem.
It's Not Just Illinois Anymore
Illinois remains the only state where BIPA-style private lawsuits are common, but it is no longer the only state regulating biometric data, and the trend line points toward more coverage, not less:
- Texas (CUBI — Capture or Use of Biometric Identifier Act). Requires informed consent before capturing a biometric identifier for a commercial purpose and limits retention, but enforcement is reserved for the Texas Attorney General — there's no private right of action, so individual employees can't sue directly. Civil penalties run up to $25,000 per violation.
- Washington. A 2017 law requires notice and consent before enrolling a biometric identifier in a database for a commercial purpose, enforced by the state Attorney General. Washington's 2023 My Health My Data Act goes further for biometric data tied to health information, and — notably — that law does include a private right of action.
- Roughly twenty other states now fold biometric identifiers into broader consumer-privacy statutes (in the mold of California's CCPA or Colorado's CPA) as a category of "sensitive data" requiring heightened consent, even without a dedicated biometric statute.
- New York City has its own local ordinance covering biometric data collected from customers (not employees) at retail and hospitality businesses.
The practical takeaway: even a business with zero Illinois locations can't assume biometric time clocks are unregulated. If you operate in multiple states, or plan to, the compliance bar is trending toward "treat every location as if a written-consent law applies," because more states are heading in that direction every legislative session.
A Compliance Checklist Before You Buy — or Keep — a Biometric Time Clock
- Write the policy first. Before any employee's fingerprint touches a scanner, have a written, publicly postable policy stating what biometric data you collect, why, how long you keep it, and how it's destroyed.
- Get signed consent, not implied consent. A line buried in the employee handbook doesn't satisfy most biometric statutes. Use a standalone authorization form, signed and dated, kept in the personnel file.
- Set a destruction trigger. Tie deletion to a concrete event — termination date plus 30 days, for example — and actually execute it. "We meant to delete it eventually" is not a defense.
- Vet your vendor's data handling, not just the device. Ask whether the vendor stores raw biometric templates, whether they're encrypted, whether the vendor itself could be selling or sharing that data, and whether the vendor will indemnify you if their system is the one that gets breached.
- Offer a non-biometric alternative where required or prudent. Some employees may object on religious or medical grounds; having a PIN-code or badge-swipe fallback avoids a separate ADA or Title VII issue on top of the biometric one.
- Audit existing systems now, not after a demand letter. If you already have a fingerprint clock installed, don't wait for a plaintiff's attorney to send the first letter — retroactive consent is far cheaper to obtain than a settlement.
Why This Belongs Next to Your Payroll Records, Not Just Your IT Files
Biometric time clock data isn't just a legal exposure — it's the input to your labor cost accounting. Every clock-in and clock-out event that a biometric scanner captures eventually becomes a line in payroll, and payroll is one of the largest and most error-prone expense categories a small business tracks. If a BIPA-style dispute ever forces you to change timekeeping vendors, or to purge and rebuild your consent and retention records, you want your labor-cost history to be independently verifiable — not locked inside a proprietary system you might have to abandon.
That's one of the quieter arguments for keeping your books in a transparent, version-controlled format. Beancount.io is a plain-text accounting platform where every transaction — including payroll runs and labor-cost allocations — lives in auditable, human-readable files you fully control, not a black box tied to any single vendor. Get started for free and keep your financial records portable no matter what compliance changes your timekeeping system next.