12960 Linden Church Road
Clarksville, Maryland 21029

You Just Installed Fingerprint Time Clocks

You Just Installed Fingerprint Time Clocks. Here’s the Law You Might Not Know Exists.

Aug 19, 2026

Your company hit 40 employees. Buddy punching became a real problem, so you bought a fingerprint scanner for the warehouse entrance. Or maybe you upgraded office security to facial recognition badges. Smart operational move.

Here’s what most growing companies don’t realize: you just triggered a category of law completely separate from standard employment compliance. Biometric privacy law.

Why This Category Is Different

Most data privacy rules treat biometric data as uniquely sensitive, more like a Social Security number than an email address. Unlike a password, you can’t reset a fingerprint. Once it’s compromised or mishandled, the person can’t get a new one.

Several states have enacted biometric privacy laws, including Illinois (BIPA), Texas (CUBI), Washington (WBPA), and California (CCPA/CPRA biometric provisions). Illinois BIPA has generated the most private litigation to date, building specific legal requirements around collecting fingerprints, facial geometry, retina scans, and voiceprints.**740 ILCS 14/15, Tex. Bus. & Com. Code § 503.001, Rev. Code Wash. (ARCW) § 19.375.020. Other states have followed with their own versions, and more are introducing bills every year.

If your company operates in one of these states, or employs people who do, this law can apply to you even if you’ve never thought of yourself as a “tech company” or a “data company.” A biometric time clock or an access-control badge system is enough.

The Compliance Gap Growing Companies Fall Into

At 10 employees, you’re focused on product and revenue. Biometric systems feel like a convenience upgrade, not a legal event. By the time you’re at 40 or 50 employees with multiple locations, you’ve likely rolled out these systems across departments without anyone flagging the legal requirements attached to them.

The typical gaps we see:

  • No written policy explaining what biometric data is collected and why
  • No documented retention and destruction schedule
  • No signed, specific consent from employees before their fingerprint or face is scanned
  • Third-party vendors (the company that sold you the time clock) storing biometric data without proper contractual protections

Each of these gaps is a separate compliance failure. And several biometric privacy laws include a private right of action, meaning employees can sue directly, not just file a regulatory complaint.

Why the Numbers Get Serious Fast

Under BIPA, statutory damages run $1,000 per negligent violation and $5,000 per intentional or reckless violation, per employee, per instance.740 ILCS 14/20 Courts have interpreted “per violation” broadly. If your fingerprint scanner logs an employee’s clock-in twice a day, some courts have allowed each scan to count separately. Cothron v. White Castle Sys., 2023 IL 128004, Jenkins v. Regal Cinemas, 2025 U.S. Dist. LEXIS 6118.

Now multiply that across 50 employees clocking in and out daily for months without a compliant consent process in place. Class action firms specifically target this category of claim because the math is so favorable to plaintiffs. This isn’t a hypothetical risk category. It’s an active, growing area of employment litigation, and companies your size are exactly the profile that gets targeted, because you’ve scaled fast enough to adopt these systems but not slow enough to catch the legal requirement.

One interesting note is that if your workforce is subject to a collective bargaining agreement under the Railway Labor Act (airline and railroad employers), BIPA claims may require resolution through the RLA’s adjustment board process rather than court litigation. Consult counsel familiar with both BIPA and RLA requirements.

What Actually Needs to Happen

Fixing this isn’t complicated, but it does require deliberate action, not just an IT decision:

  1. Written biometric policy. Spell out what data you collect, why, how long you keep it, and how it gets destroyed.
  2. Specific employee consent. General handbook acknowledgment isn’t enough in most states. Consent needs to reference biometric data specifically.
  3. Vendor contract review. If a third party handles your time-clock data, your agreement with them needs biometric-specific protections, not generic data security boilerplate.
  4. Retention schedule enforcement. Data that should have been destroyed after an employee left but wasn’t is one of the most common triggers for claims.

This is exactly the kind of issue Claudia handles for our clients. Employment and HR compliance questions like this one live in a gray zone most business attorneys don’t specialize in, and most IT vendors definitely aren’t equipped to advise on.

The Real Takeaway

Biometric time clocks and access systems aren’t inherently risky. Unaddressed consent and retention gaps are. If your company has adopted fingerprint or facial-recognition technology anywhere in your operations, in any state, it’s worth a quick audit before it becomes a plaintiff’s exhibit A.About Garcia-Zamor: We’re the fractional general counsel for innovators, protecting both your business operations and your intellectual property. Ruy Garcia-Zamor (founder with 25+ years experience in patents, trademarks, intellectual property, business strategies and is a registered patent attorney with the U.S. Patent and Trademark Office), Elliott Alderman (40+ years experience in intellectual property and providing guidance to businesses), Claudia Castillo (decades of experience in business law focusing on all employment issues), and Amulya Annasamudram (focuses on patents and intellectual property and is a registered patent attorney with the US Patent and Trademark Office). Contact us at garcia-zamor.com or (410) 531-9853.