Biometric Time Clocks: Pros, Cons & Compliance | Netchex

Netchex launches Mesh AI HR Teammates for the Deskless Workforce

Learn More Arrow

Biometric Time Clocks: Pros, Cons, and Compliance Considerations

Biometric Time Clocks: Pros, Cons, and Compliance Considerations
Blog

Share

It’s 5:47 a.m. at an auto parts plant outside Toledo, and the line starts at 6. Marcus badges in, grabs his coffee, then swipes his coworker Dave’s badge too, because Dave is stuck behind a train and texted him to cover. Nobody thinks twice about it. It happens most weeks. That’s exactly the gap biometric time clocks are built to close, since a fingerprint or a palm scan can’t be handed to a friend like a badge or a PIN.

Plenty of manufacturers, hospitals, restaurants, and retailers have made the switch. The pitch is simple: tie the clock punch to the actual person, cut down on time theft, and stop arguing over who was really on the floor during a shift. But biometric data isn’t a badge number. It’s part of someone’s body, and a small but growing group of states treat it that way under the law. Illinois has the toughest rules on the books, and several other states have followed with their own versions. Get this wrong and a time clock upgrade can turn into years of litigation.

Last updated: August 2026

What Counts as a Biometric Time Clock?

A biometric time clock verifies identity using a physical trait instead of a badge, PIN, or password. Most systems on the market today rely on one of four methods, and each carries a slightly different level of legal exposure.

MethodHow It WorksCommon Use Case
Fingerprint scanReads ridge patterns on one or more fingersManufacturing floors, warehouses, retail back rooms
Hand or palm geometryMeasures the shape and size of the handDistribution centers, hospitals
Facial recognitionMaps facial features via cameraMobile check-in for field crews, kiosk clock-ins
Iris or retina scanReads unique patterns in the eyeHigh-security facilities, some healthcare settings

Under Illinois law, the definition is narrower than most people assume. The Biometric Information Privacy Act defines a “biometric identifier” as a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry, and it specifically excludes photographs, physical descriptions, and things like X-rays. That distinction matters. A standard security camera photo is not regulated the same way a fingerprint template is.

The Real Case for Biometric Time Clocks

Here’s why operators keep asking about this. A badge can be lost, shared, or swiped by someone else. A PIN can be texted to a coworker in thirty seconds. A fingerprint or palm scan can’t be handed off, which removes the single most common form of time theft in shift-based workplaces.

That accuracy matters for more than payroll cost control. Under the federal Fair Labor Standards Act, employers must keep accurate records of hours worked each day and each workweek, along with straight-time and overtime earnings. The Department of Labor’s guidance gives employers flexibility in how they track that time, whether it’s a punch clock, a supervisor’s log, or an electronic system, as long as the method is complete and accurate. A biometric clock that ties every punch to a specific person makes that recordkeeping obligation easier to defend if a wage claim ever surfaces.

  • Eliminates buddy punching by design, since identity can’t be transferred to a coworker
  • Removes the cost and hassle of replacing lost badges or resetting forgotten PINs
  • Creates a cleaner audit trail for wage and hour disputes, since each punch links to one verified person
  • Speeds up clock-in lines at shift change, which matters when forty people hit the same door at once

None of that is theoretical. Ask any plant manager who has tried to untangle a “who actually worked Tuesday’s double” argument, and they’ll tell you it eats up more time than it should.

The Catch: Biometric Data Isn’t Just Another Timekeeping Field

A badge number can be reissued. A fingerprint can’t. That permanence is exactly why a handful of states regulate biometric data differently than a name, address, or Social Security number. If a database of employee fingerprints ever gets breached, there’s no way to issue everyone a new fingerprint the way you’d cancel a compromised credit card.

Illinois recognized this back in 2008 when it passed the Biometric Information Privacy Act, better known as BIPA. It’s still the most aggressive biometric privacy law in the country, and it has generated a steady stream of class action lawsuits against employers who rolled out fingerprint time clocks without doing the legal groundwork first. Real cases have targeted grocery chains, hotel groups, and healthcare systems over exactly this issue: fingerprint punch clocks installed without the written consent BIPA requires.

So what does the law actually require? Let’s look at it section by section, because the details are where most employers get tripped up.

Illinois BIPA: What Every Multi-State Employer Should Understand

BIPA applies to any private entity that collects biometric identifiers or biometric information from someone in Illinois, which includes employees clocking in at an Illinois location even if the company is headquartered somewhere else. Under Section 15 of the Act, a private entity in possession of biometric data must do three things before it ever collects that data:

  1. Inform the person in writing that biometric data is being collected or stored
  2. Disclose in writing the specific purpose and length of time the data will be kept
  3. Obtain a signed, written release from the employee before collecting it

On top of that consent requirement, BIPA requires private entities to develop a written, publicly available policy that sets a retention schedule and a destruction timeline. Under the statute, biometric data has to be permanently destroyed within three years of the individual’s last interaction with the company, or as soon as the original purpose for collecting it has been satisfied, whichever comes first. Selling biometric data outright is banned entirely, no exceptions.

Here’s the part that gets an employer’s attention: BIPA gives individuals a private right of action, meaning an employee doesn’t need a state agency to sue on their behalf. They can go straight to court. A prevailing plaintiff can recover $1,000 or actual damages, whichever is greater, for a negligent violation, and $5,000 or actual damages, whichever is greater, for an intentional or reckless one, plus attorneys’ fees and costs. Multiply that by a few hundred employees at a single facility, and the exposure adds up fast.

That math is exactly why the Illinois legislature stepped in. A 2024 amendment to BIPA (Public Act 103-769) added a “single violation” limitation, clarifying that when the same biometric data is collected or disclosed from the same person through the same method multiple times, it counts as one violation for damages purposes rather than a fresh violation on every scan. It’s a narrower exposure than before, but it’s still real money, and it still starts with the same root cause: no written consent before the first scan.

Texas, Washington, and the Broader State Patchwork

Illinois isn’t the only state with a biometric privacy statute, and the rules aren’t identical from one to the next. That’s the tricky part for any employer running locations in more than one state.

Texas has the Capture or Use of Biometric Identifier Act, known as CUBI, codified at Texas Business and Commerce Code Section 503.001. It requires a business to inform an individual and get consent before capturing a biometric identifier for a commercial purpose. Where CUBI differs from Illinois is the destruction window: biometric identifiers must generally be destroyed within one year after the purpose for collecting them expires, not three. CUBI also bans selling, leasing, or otherwise disclosing biometric data outside a short list of exceptions, such as completing a transaction the person requested or responding to a valid warrant. The biggest structural difference is enforcement. CUBI has no private right of action. Only the Texas Attorney General can bring a case, and violations carry civil penalties of up to $25,000 each.

Washington takes a similar approach under RCW 19.375. The law requires a business to provide notice and get consent, or offer a way to opt out, before enrolling someone’s biometric identifier in a database for a commercial purpose. It also restricts sharing that data with third parties unless a specific exception applies, such as a legal requirement or a court order. Retention is limited to what’s reasonably necessary to comply with a legal obligation, prevent fraud, or provide the service the data was collected for. Like Texas, Washington enforces its biometric law through the state’s Consumer Protection Act rather than through individual lawsuits, so it’s the Attorney General’s office bringing the case, not an employee’s private attorney.

What does this mean in practice? A company with plants in Illinois, Texas, and Washington can’t run one blanket biometric consent form and call it compliant everywhere. The consent language, the retention schedule, and the legal exposure all shift depending on where the employee clocks in.

Legal Disclaimer

This article provides general information about biometric timekeeping technology and selected state biometric privacy laws. It is not legal advice and shouldn’t be treated as a substitute for advice from a licensed attorney in your state. Biometric privacy laws vary significantly from state to state, change over time, and carry real financial exposure for noncompliance. Employers should consult employment counsel before adopting biometric time and attendance technology in Illinois, Texas, Washington, or any other jurisdiction that regulates biometric data.

Rolling Out Biometric Time Clocks Without Creating a Legal Problem

None of this means biometric time clocks are off the table. It means the rollout needs to happen in a specific order, with legal review built in before the first fingerprint ever gets scanned.

  • Get written consent first, every time. Build a standalone consent form that names the specific purpose (time and attendance), the retention period, and the destruction process. Collect a signature before enrollment, not after.
  • Publish a retention and destruction policy. Illinois requires this policy to be publicly available. Texas and Washington don’t spell out the same publication requirement, but having one in writing protects you either way.
  • Offer a real alternative. Some employees will object on religious or medical grounds. Under Title VII, employers generally have to provide a reasonable accommodation for a sincerely held religious belief unless doing so creates a substantial burden on the business, a standard the Supreme Court clarified in its 2023 decision in Groff v. DeJoy. A badge or PIN backup option handles most of these situations without much friction.
  • Encrypt and restrict access to the biometric template. Store the mathematical template, not a raw image, and limit who inside the company can access it. Fewer hands on the data means fewer ways for it to leak.
  • Map every location against its state law before you standardize a policy. A single-state small business has one set of rules to follow. A multi-location employer in retail, healthcare, or food service needs a location-by-location legal check, because the same fingerprint scanner can be fully compliant in one state and a lawsuit waiting to happen in another.

This is where the technology conversation and the legal conversation have to happen together, not one after the other. A paired time and attendance system should give administrators clear controls over how any biometric data is collected, stored, and retired, and those controls need to map to whichever state’s rules apply at that specific location. If your provider can’t answer a direct question about retention and consent workflows, that’s worth a pause before you sign anything.

For industries with tight labor markets and high turnover, like restaurants and retail, the accuracy gains from biometric verification can be real. So can the compliance workload. Weighing those two things honestly, before the purchase order goes out, is what separates a smooth rollout from a demand letter eighteen months later. A strong HR team that already tracks state-specific compliance requirements is usually the difference-maker here, since this isn’t a decision IT or payroll should make alone.

Frequently Asked Questions

This article reflects publicly available legal information as of August 2026, including Illinois’ Biometric Information Privacy Act (740 ILCS 14), Texas’ Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code Sec. 503.001), and Washington’s biometric privacy law (RCW 19.375). Laws change and vary by jurisdiction. This is not legal advice. Consult a licensed attorney for guidance specific to your business and locations.

Disclaimer: Any product roadmap or future plans provided herein are for informational purposes only. They do not represent a commitment to deliver any material, code, feature, or functionality. Plans may change without notification. The development, release and timing of any features or functionality described remain at the sole discretion of Netchex, its affiliates, and partners. Netchex does not give legal, tax, or accounting advice. You are responsible for ensuring your use of Netchex product meets your individual business and compliance requirements.

Related events

GPS Time Tracking for Field Service and Building Services Employees
09/01/26

GPS Time Tracking for Field Service and Building Services Employees

View Event
How to Manage Split Shifts in Payroll Software
09/01/26

How to Manage Split Shifts in Payroll Software

View Event
How to Enforce Attendance Policies Fairly in High-Turnover Environments
08/31/26

How to Enforce Attendance Policies Fairly in High-Turnover Environments

View Event
Scheduling Software vs. Time Tracking Software: What’s the Difference?
08/31/26

Scheduling Software vs. Time Tracking Software: What’s the Difference?

View Event