Skip to content

Logistics and distribution

Biometric time clocks in warehouses: BIPA exposure and data handling

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A biometric time clock creates BIPA exposure when it captures fingerprint, hand or face data from workers in Illinois without the written policy, informed written consent, retention schedule and disclosure controls the law generally requires. For data licensing the rule is simple: biometric templates, scans and enrollment records are excluded from any dataset, without exception.

Key takeaways

  • BIPA questions turn on whether a clock captures a biometric identifier, not on what the vendor calls the feature.
  • A written retention and destruction policy, informed written consent and disclosure controls are the core items counsel will check.
  • Staffing agencies, timekeeping vendors and payroll providers can all touch the same scans, so exposure is shared and contracts matter.
  • Biometric templates, scan images and enrollment records are never part of a licensed dataset.
  • Punch times and labor records need their own privacy review even after biometrics are removed.

Why do biometric time clocks create BIPA exposure?#

Biometric time clocks create BIPA exposure because they collect a biometric identifier, such as a fingerprint, hand geometry or a face scan, when a worker enrolls and often at every punch. Illinois's Biometric Information Privacy Act regulates how private entities collect, store, disclose and destroy that information, and it lets affected individuals sue.

Warehouses adopted these clocks to stop buddy punching across shifts and temporary crews. The features that make them useful also make them sensitive: the clock, the vendor's cloud and sometimes the payroll integration may each hold templates or derived data. Fingerprint time clocks are a well-known category of BIPA litigation, and suits have reached logistics employers as well as timekeeping vendors.

Many clocks store a mathematical template rather than an image of the finger, and vendors sometimes present that as a reason the law does not apply. Whether a template counts as a biometric identifier or biometric information is a question counsel should assess on the facts, not settle from a product sheet.

What does BIPA generally require from an employer?#

BIPA generally requires a private entity that collects biometric identifiers to publish a policy, obtain informed written consent first, limit disclosure, protect the data and destroy it on schedule. The table maps those areas to the warehouse records counsel will ask to see.

The stakes come from the remedy. BIPA lets a prevailing party recover liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation, or actual damages if greater. In Rosenbach v. Six Flags, decided January 25, 2019, the Illinois Supreme Court held that a person need not show actual injury beyond a violation of their BIPA rights to sue.

The law has also changed. Illinois SB 2979, signed August 2, 2024, limits recovery to a single violation per person when the same biometric identifier is collected repeatedly by the same method, which matters for clocks that scan at every punch. Check the current text and case law with counsel rather than relying on older summaries or a vendor's compliance page.

What does BIPA generally require from an employer?
Requirement areaWhat it generally coversWhat to check in a warehouse
Written policyA publicly available policy with a retention schedule and destruction guidelinesWhether the policy exists, where it is posted and whether it covers the clock vendor
Informed written consentNotice of what is collected, why and for how long, with a signed release before collectionReleases for every enrolled worker, including temps and rehires, dated before the first scan
Disclosure limitsRestrictions on sharing biometric data without consent or another legal basisVendor, payroll and staffing agency access, and the contracts that govern it
No profitingA bar on selling, leasing, trading or otherwise profiting from biometric dataAny reuse of clock data beyond timekeeping, including analytics or licensing
Security and destructionReasonable care in storage, and destruction when the purpose ends or the schedule says soDeletion at separation, deletion logs and templates left on retired clocks

Who carries the exposure: employer, agency or vendor?#

Exposure in a warehouse is usually shared among the company that runs the site, the staffing agency that supplies temporary workers, and the vendor whose clock and cloud store the scans. Depending on the facts, each may be treated as collecting or possessing biometric data.

Temporary labor is where gaps appear. An agency worker may enroll on the site's clock during a first shift before anyone collects a signed release, with the agency and the operator each assuming the other handled consent. The staffing agreement should say who presents the notice, who keeps the signed release and who deletes data when the assignment ends.

Vendor contracts need the same attention. Look for where templates are stored, whether the vendor uses them for anything beyond timekeeping, how deletion requests are executed, and what happens to stored data when the subscription ends.

A compliance checklist for biometric clocks#

A biometric clock checklist should be run site by site, because enrollment practices drift between buildings, shifts and supervisors. Operations gathers the facts; counsel decides what each finding means and what remediation is needed.

  • List every clock by site, model, firmware and biometric mode, and note which units already run on badge or PIN.
  • Identify where templates live: on the device, in the vendor's cloud, in a payroll or HR system, or in backups.
  • Collect the published biometric policy and confirm it states a retention schedule and destruction method.
  • Match signed releases to enrollment records for employees, temporary workers and rehires, and flag any scan that predates a release.
  • Review staffing agency and vendor contracts for consent, access, deletion and indemnity terms.
  • Confirm how templates are deleted at separation and whether each deletion is logged.
  • Locate retired or spare clocks and confirm stored templates were wiped.
  • Note sites in other states or cities with their own biometric rules, such as Texas or Washington, so counsel can map them.

How should biometric data be handled day to day?#

Biometric data should be handled as a separate class of record with its own owner, access list and deletion routine. Mixing it into general HR or timekeeping exports is how templates end up in places nobody planned.

Keep punch records and biometric data apart in practice. A timekeeping export used for payroll audits or labor planning should carry an employee ID and timestamps, never a template or enrollment image. If the clock vendor's admin console offers reports with enrollment photos, restrict them to the few administrators who need them.

System changes are the high-risk moments. Replacing clocks, switching timekeeping vendors or closing a building can leave templates on devices, in vendor archives or in database backups. Add biometric deletion to the decommissioning checklist and file the deletion confirmation with the policy.

Why biometric records stay out of any dataset#

Biometric records stay out of any licensed dataset because the law restricts profiting from them and because no AI developer needs them to learn warehouse workflows. SourceX treats fingerprint templates, scan images, face data and enrollment records as excluded by default, whatever their consent status.

In the SourceX five-step transaction, the Rights and Preparation steps confirm that exclusion, and the SourceX Evidence Packet records it in the privacy record. The supplier's counsel and any buyer can then see that biometric material was considered and deliberately kept out.

Why biometric records stay out of any dataset
RecordTreatment in a licensing review
Fingerprint, hand or face templates and imagesExcluded; never exported, sampled or described in detail
Biometric enrollment logs and signed releasesExcluded; kept only as compliance evidence
Raw punch times tied to named workersGenerally excluded; considered only in aggregate, if at all
Labor standards and productivity rates by workerSeparate privacy and employment review before any use
WMS task and exception records with worker IDs replacedPossible candidates after rights and privacy review

Illustrative: a fictional contract warehouse operator runs buildings in Illinois and Indiana, with hand-scan clocks at every entrance and most peak labor supplied by a staffing agency. While scoping warehouse exception records for a possible license, its general counsel asks for the biometric file.

The review finds a posted policy and signed releases for direct employees, but agency workers at one Illinois building enrolled before signing anything. Counsel opens a separate remediation project, the staffing agreement is renegotiated, and the company moves that building to badge punches with documented template deletion.

The licensing scope never depended on timekeeping. The company proceeds only with WMS exception and inventory adjustment records, with worker IDs replaced, after its own counsel signs off on the privacy record.

Frequently asked questions

Does a clock that stores only a template avoid BIPA?

Not necessarily. Whether a template is a biometric identifier or biometric information is a question counsel should assess on the facts. Treat template-based clocks as covered for policy, consent and deletion purposes unless counsel advises otherwise.

Do temporary workers need to sign our release as well as the agency's?

It depends on who collects and possesses the data and what the staffing agreement says. Many operators require a release before any worker scans at their site, regardless of employer of record. Agree the process in writing with the agency and keep copies of every signed release.

If we switch to badge or PIN clocks, is the issue closed?

Switching stops new collection, but data already collected still needs handling. Confirm that templates are deleted from devices, vendor systems and backups, keep the deletion records, and ask counsel whether past collection raises any remaining questions.

Do other states regulate biometric time clocks?

Several may. Texas and Washington have biometric privacy laws, some cities regulate biometric use, and comprehensive state privacy laws can treat biometric data as sensitive. Run the same inventory at every site and let counsel map which laws may apply.

Can de-identified punch data ever be licensed?

Possibly, but punch data is employee data even without biometrics. Any use would need a privacy and employment review, removal or aggregation of identifiers, and a check of employee notices. In practice, warehouse exception and workflow records are more useful and less sensitive.

Sources

  • BIPA liquidated damages are $1,000 per negligent and $5,000 per intentional or reckless violation; SB 2979, signed August 2, 2024, limits recovery to a single violation per person for repeated collection by the same method. Source
  • Rosenbach v. Six Flags (Ill. Jan. 25, 2019): no actual injury beyond a BIPA violation is needed to be an aggrieved party. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify