Skip to content
imRosterimRoster
Back to blog

Biometric Time Clocks: Legal Risks and Alternatives (2026)

Kemal Özdemir
A wall-mounted fingerprint time clock beside a smartphone showing a shift schedule with location-based clock-in

A decade ago, the fingerprint time clock was the safe, boring purchase. It killed buddy punching overnight, it never lost a badge, and payroll finally matched reality. In 2026 that same device is one of the most litigated objects in the workplace: Illinois employers have paid eight-figure settlements over fingerprint punch clocks, and the UK data protection regulator has ordered an employer to stop scanning its staff's faces and destroy the data. Attendance hardware has quietly become a legal exposure line item.

In short: biometric time clocks that scan fingerprints or faces process legally protected data. Illinois's BIPA lets employees sue for $1,000 to $5,000 per violation, Texas penalties reach $25,000 per violation, and UK and EU regulators treat employee consent to scanning as largely invalid. Badge, PIN, and phone-based location check-in deliver attendance control without that liability.

This guide maps the risk by jurisdiction — Illinois, Texas, Washington, Colorado, New York, the UK and the EU — explains why a stack of signed consent forms is weaker protection than it sounds, and walks through the practical alternatives: badges, PINs, and phone-based, location-verified clock-in that processes no biometric data at all.

Why are biometric time clocks a legal risk in 2026?

A fingerprint template or a face-geometry map is unlike any other piece of HR data. You can reissue a badge, reset a PIN, or change a password; nobody can change their fingerprints. Legislators and courts on both sides of the Atlantic have drawn the same conclusion from that permanence: biometric identifiers deserve a special, stricter class of protection, and the burden of justifying their use sits with the employer.

The risk arrives through two different machines. In the United States, state statutes attach fixed money penalties to procedural failures — no written notice, no signed release, no retention schedule — and in Illinois every affected employee can sue, which converts a 300-person workforce into a class action. In the UK and EU, regulators do not wait for lawsuits: data protection authorities can order a company to switch the system off and destroy the data, as the UK Information Commissioner's Office did in 2024. Neither machine requires anyone to prove a data breach or concrete harm; deploying the clock the wrong way is itself the violation.

The trend line matters as much as the rules. Defense-firm trackers counted more than a hundred new BIPA class actions filed in 2025 alone, time-clock vendors themselves are now settling claims alongside their customers, and the ICO has said publicly that its enforcement is meant to put industry on notice.

What is BIPA, and what does a fingerprint punch clock cost in Illinois?

The Illinois Biometric Information Privacy Act (BIPA), passed in 2008, is the strictest biometric statute in the United States and the only one with a private right of action. Before collecting a fingerprint or face scan, an employer must inform the person in writing, state the purpose and storage period, and obtain a written release. It must also publish a retention schedule and destroy the data once the purpose ends — at the latest three years after the last interaction. Miss any step, and each affected employee can claim $1,000 per negligent violation or $5,000 per intentional or reckless one, plus attorneys' fees.

The stakes peaked with Cothron v. White Castle. In February 2023 the Illinois Supreme Court ruled, 4 to 3, that a separate claim accrues every single time a device scans a finger without valid consent — not just on the first scan. White Castle itself estimated that this per-scan arithmetic could expose it to up to $17 billion in damages for a single class of employees.

The Illinois legislature then stepped in. Senate Bill 2979, signed on August 2, 2024, amended BIPA so that repeated collection of the same biometric data by the same method counts as a single violation, entitling each person to at most one recovery; it also allowed consent via electronic signature. In April 2026 the Seventh Circuit confirmed that the amendment applies retroactively to pending cases, ending the era of astronomic per-scan exposure.

Amended BIPA is still expensive. One recovery per person across a workforce is real money — 500 employees at $1,000 to $5,000 each is $500,000 to $2.5 million before legal fees — and settlements keep coming. An Illinois federal court approved Speedway's $12.1 million fingerprint-clock settlement in October 2025, and time-clock vendors Accu-Time and WorkEasy settled their own BIPA classes for $1.5 million and roughly $1.7 million, with individual payouts of about $100 to $750 per class member. Note the pattern: plaintiffs now sue the device makers as well as the employers who bought the devices.

Which other US states regulate biometric time clocks?

Texas's Capture or Use of Biometric Identifier Act (CUBI) requires informing the individual and obtaining consent before capturing a biometric identifier for a commercial purpose. Only the Texas Attorney General can enforce it — but at up to $25,000 per violation, with no cap. Anyone tempted to dismiss attorney-general-only enforcement as toothless should note the Texas Attorney General's $1.4 billion biometric settlement with Meta in 2024, the largest privacy recovery ever obtained by a single US state.

Washington's 2017 biometric law requires notice and consent before enrolling biometric identifiers for a commercial purpose and is enforced by the state Attorney General under consumer protection law. Colorado amended its Privacy Act with House Bill 24-1130, effective July 1, 2025: employers need a written biometric policy, a retention schedule and employee consent, with only narrow purposes — such as secure-site access and timekeeping — where biometric collection may be tied to employment, and enforcement by the Attorney General and district attorneys. New York's Labor Law, meanwhile, generally prohibits requiring employees to be fingerprinted as a condition of employment, subject to narrow exceptions. And states with comprehensive privacy laws, including California, Virginia and Connecticut, classify biometric data as sensitive data requiring opt-in consent.

Here is the risk map in one view — the jurisdictions an ops or HR leader most often has to answer for, what each rule demands, and what non-compliance costs.

JurisdictionRuleWho enforcesExposure
IllinoisBIPA (2008): written notice + signed release before collection, retention schedule, destruction dutyPrivate lawsuits, typically class actions$1,000 negligent / $5,000 reckless per violation + attorneys' fees; one recovery per person since Aug 2024
TexasCUBI: notice + consent before capture for a commercial purposeAttorney General onlyUp to $25,000 per violation, uncapped
Washington2017 biometric law: notice + consent before enrollmentAttorney General (consumer protection route)Civil penalties; no private lawsuits
ColoradoPrivacy Act as amended by HB 24-1130 (from July 1, 2025): biometric policy, retention schedule, consentAttorney General and district attorneysCivil penalties under state consumer protection law
New YorkLabor Law: compulsory employee fingerprinting generally prohibitedState regulatorsBan applies regardless of consent, narrow exceptions
United KingdomUK GDPR Art. 9 + Data Protection Act 2018: special category data, DPIA requiredICOStop-and-destroy enforcement notices; fines up to £17.5m or 4% of global turnover
European UnionGDPR Art. 9: processing prohibited unless a strict exception applies; employee consent rarely validNational data protection authoritiesFines up to €20m or 4% of global turnover; e.g. €725,000 Dutch fine for fingerprint attendance

For multi-state and multi-country operators the practical rule is simple: comply at the level of your strictest jurisdiction. If you have even one Illinois site, run the whole program to BIPA standards — written notice, signed release before the first scan, published retention schedule — or do not run biometrics at all.

Can UK employers use facial recognition or fingerprints for staff attendance?

In February 2024 the UK Information Commissioner's Office answered with an enforcement action rather than a consultation. The ICO ordered Serco Leisure, Serco Jersey and seven associated community leisure trusts to stop using facial recognition and fingerprint scanning to monitor staff attendance, finding they had unlawfully processed the biometric data of more than 2,000 employees across 38 leisure centres. The companies were ordered to stop the processing and destroy all biometric data they were not legally required to keep, within roughly three months.

The ICO's reasoning is the template every UK and EU employer should read. Serco could not show the scanning was necessary or proportionate when less intrusive options — ID cards or fobs — existed. Employees were never offered an alternative: scanning was presented as a requirement in order to get paid. And because of the imbalance of power between employer and staff, the ICO judged that workers could not realistically refuse. The regulator stated that the action was intended to put industry on notice that biometric technologies cannot be deployed lightly.

The ICO published dedicated guidance on biometric recognition the same month. UK employers who still want biometric systems must complete a data protection impact assessment before deployment, establish a lawful basis that clears Article 9's higher bar, and offer a genuine, penalty-free alternative. Fines under the UK GDPR can reach £17.5 million or 4% of global turnover, and ignoring an enforcement notice is itself a further breach.

Does employee consent make biometric clock-in legal under the GDPR?

Under Article 9 of the GDPR, biometric data processed to uniquely identify a person is special category data: processing is prohibited unless a specific exception applies. For an attendance clock the only plausible exception is explicit consent — and this is where employers' consent forms collapse. Consent under the GDPR must be freely given, and European regulators have repeatedly held that an employee facing their employer rarely consents freely, because refusal may carry consequences for their job.

The enforcement record backs this up. The Dutch Data Protection Authority fined a company €725,000 in 2020 for using fingerprint scanning for attendance and time registration, holding the employees' consent invalid precisely because they depend on their employer. Spain's AEPD went further in November 2023 with guidance that — following the EDPB's April 2023 position that even one-to-one biometric verification counts as special category processing — treats biometric time-and-attendance as close to impossible to justify in an ordinary workplace.

There is also a structural catch-22 worth internalizing. To make consent free, you must offer a non-biometric alternative with no detriment for those who refuse. But if a fob or a PIN works fine for the refusers, the biometric system is by definition not necessary for anyone — which undermines the proportionality argument for having it at all. That logic is why, in the EU and the UK, biometric attendance is best treated as presumptively unlawful: the burden is on the employer to prove otherwise, and regulators have shown little appetite to accept the proof.

What are the best alternatives to a biometric time clock?

Be honest about why the fingerprint reader was bought in the first place: buddy punching. Any replacement has to answer the same question — how do I know the person clocking in is the person scheduled — without processing data that carries statutory damages. Three families of alternatives exist, and they are not equal.

MethodData processedLegal risk profileBuddy-punching resistanceHardware needed
Fingerprint / face clockBiometric templates (special category / statutory biometric data)High: statutory damages in the US, stop-and-destroy orders in UK/EUVery strongDedicated biometric terminals
Badge or fobCard ID number, punch timestampsLow: ordinary personal dataWeak to moderate — cards can be lentReaders + cards for every worker
PIN code on terminalCode entry, punch timestampsLow: ordinary personal dataWeak — codes get sharedShared terminal or tablet
Phone app + location checkAccount identity + one-time location at clock-inLow with transparency and data minimization; no special category dataStrong — personal device plus geofence plus shift contextNone; runs on employees' phones

Badges and fobs are the regulator-endorsed baseline — the ICO itself pointed to ID cards and fobs as the less intrusive option — but a card verifies the token, not the person, and tokens get lent. PINs are cheaper still and weaker still. The interesting option for shift-based teams is the last row: clock-in on the employee's own phone with a location check at the moment of punching in. A personal phone is rarely handed over, the geofence confirms the person is actually at the site, and the roster confirms they were supposed to be. No fingerprint, no face map — no special category data, and none of the notice-and-release machinery that BIPA-style statutes attach to biometrics.

Location data still deserves care: check position only at the moment of clock-in and clock-out, never track continuously, and state plainly in the privacy notice what is checked and when. Handled that way, phone-based clock-in sits under ordinary personal data rules rather than Article 9, and in the US it simply falls outside the biometric statutes. This is the model imRoster uses: employees see their shifts on their phone and confirm attendance with a location-based check-in when the shift starts, and no biometric data is ever collected or processed.

How do you migrate off a biometric time clock without losing attendance control?

Switching off the scanner is the easy part; the residual liability lives in the stored templates and the missing paperwork. A clean migration for a mid-sized operation fits into roughly a quarter.

PhaseWeeksActions
Audit1–2Inventory every biometric device, vendor and integration; map where templates live (terminal, vendor cloud, backups); pull contracts and retention clauses
Replace3–6Pilot badge or phone-based clock-in at one site; publish the updated privacy notice and handbook policy; train supervisors on exceptions
Destroy7–10Delete templates from devices, vendor systems and backups; obtain written certification of destruction from the vendor; record the dates
Verify11–12Reconcile payroll against the new system for a full cycle; close the DPIA or compliance file; brief leadership on any residual claim exposure

The destruction step is not optional housekeeping. BIPA requires destruction under a published schedule, and the ICO ordered Serco to destroy all biometric data it was not legally obliged to retain — regulators treat a lingering template database as an ongoing violation, not a legacy detail. Keep the vendor's certificate of deletion with the same discipline you keep payroll records: it is your evidence if a claim surfaces years later.

Finally, pick the replacement with scheduling in mind, because attendance data is only useful against the plan it should match. In imRoster the roster an employee sees on their phone is the same object their location-verified clock-in is checked against, so a missed or misplaced punch surfaces immediately instead of at payroll close — attendance control without a single biometric identifier in the system.

FAQ

Are biometric time clocks illegal in the United States?

There is no federal ban, but state law can make them impractical. Illinois requires written notice and a signed release and lets employees sue for $1,000 to $5,000 per violation; Texas, Washington and Colorado impose consent duties enforced by their attorneys general; New York generally bars compulsory employee fingerprinting. Multi-state employers usually apply the strictest state's standard everywhere.

We collected signed consent forms — are we safe?

In the US, a compliant written release obtained before the first scan is the core of BIPA compliance, but you also need the written notice, a published retention schedule and actual destruction of old data. In the UK and EU, consent usually fails regardless of paperwork: regulators such as the ICO and the Dutch Data Protection Authority hold that employees cannot freely consent to their employer, so the forms carry little weight.

How much does a BIPA lawsuit actually cost?

Statutory damages are $1,000 per negligent violation and $5,000 per intentional or reckless one, plus attorneys' fees, with one recovery per person since the August 2024 amendment. Across a workforce that still adds up fast: Speedway's fingerprint-clock class settlement, approved by an Illinois federal court in October 2025, was $12.1 million.

Did the 2024 BIPA amendment end the litigation risk?

No. It ended per-scan stacking of damages — a change the Seventh Circuit confirmed applies retroactively in 2026 — but the private right of action, per-person statutory damages and fee awards all remain, and defense-firm trackers counted more than a hundred new BIPA class actions filed in 2025. The amendment shrank worst-case exposure from billions to millions; it did not shrink it to zero.

Is phone-based, location-verified clock-in GDPR compliant?

Location data is personal data but not special category data, so Article 9's near-prohibition does not apply. Check location only at the moment of clock-in, explain it in the privacy notice, avoid continuous tracking, and document the assessment — run a DPIA if scale or context raises risk. Designed that way, it is a widely accepted low-risk approach.

What should we do with biometric data we already collected?

Delete it everywhere it lives — terminals, vendor cloud, backups — and obtain written certification of destruction from the vendor. BIPA requires destruction under a published retention schedule, and the ICO ordered Serco Leisure to destroy staff biometric data in 2024. Keep the destruction records; they are your defense if a claim is filed later.

Do badges or PINs actually stop buddy punching?

Only partially, because both can be shared: a badge verifies the token and a PIN verifies knowledge, not the person. Pairing clock-in with the employee's own phone and a location check at the scheduled site is the strongest non-biometric control — personal devices are rarely lent, and the punch has to happen at the right place and time against the right shift.