Skip to content

Privacy and preparation

Biometric timeclock data: keep it out of every export

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Biometric timeclock data, meaning fingerprint, hand and face templates plus the enrollment and verification records tied to them, should be excluded from every dataset a company licenses. It adds little useful for AI training and may carry serious legal exposure under laws such as Illinois's BIPA. Exclude the whole subsystem and strip biometric fields from punch records.

Key takeaways

  • Biometric templates, enrollment records and verification logs never belong in a licensing export, whatever else is in scope.
  • Punch records often carry biometric traces such as a verification method, match result or terminal enrollment ID, and those fields must go.
  • Treat encrypted or hashed templates as biometric data.
  • Biometric details leak into free text, so search tickets, email and HR documents for scanner and enrollment terms.
  • Which biometric and privacy laws may apply is assessed deal by deal with counsel.

Why biometric timeclock data stays out#

Biometric timeclock data stays out of every licensing export because its legal risk is high and its training value is close to none. AI developers license operational records for the decisions and outcomes they capture; a fingerprint template or a face match result says nothing about how a job was estimated, scheduled or resolved.

The legal side is why the rule should be absolute rather than case by case. Illinois's Biometric Information Privacy Act, known as BIPA, has made employer fingerprint and hand-scan timeclocks a frequent subject of litigation, other states have their own biometric rules, and many comprehensive state privacy laws treat biometric data as sensitive data.

Any notice or consent employees gave at enrollment was typically written for timekeeping and payroll. Sharing the same data with an outside party for a different purpose is a different question, and the simplest answer is to make sure it never comes up.

Where biometric data sits in HR and payroll systems#

Biometric data sits in more places than the timeclock itself. Depending on the product and how it was configured, the template may live on the terminal, in the timekeeping vendor's cloud or on a local server, and traces of it spread into punch records, HR files and support conversations. Ask the vendor where its templates are stored rather than assuming.

Where biometric data sits in HR and payroll systems
LocationWhat it can holdTreatment
Timeclock terminals and their backupsTemplates, enrollment lists and, on some models, face imagesExclude entirely; never copy or image a terminal for an export
Timekeeping system enrollment tablesTemplate references, enrollment dates, re-enrollment historyExclude entirely
Punch records and timecard exportsVerification method, match result, terminal ID, photo at punchDrop biometric fields, and usually leave the export out altogether
Photo-at-punch and badge photo librariesFace images tied to employee IDsExclude entirely
HR document managementBiometric notices, signed releases, retention schedulesExclude; these stay in the HR record
IT and help desk ticketsEnrollment failures, scanner faults, employee complaintsSearch, then redact or exclude matching tickets
Door and access control systemsFingerprint or face readers for secure roomsExclude the system and its logs
Email and chatVendor setup threads and attached enrollment reportsSearch by keyword and exclude matching threads

The exclusion rule, step by step#

The biometric exclusion rule is short: no biometric identifier, no record of anyone's biometric enrollment or verification, and no image of a face or hand leaves the company in a licensing export. Applying it takes a checklist that IT and HR complete together, signed off by the privacy lead.

  • Name every system that captures or stores biometrics, including timeclocks, access readers and mobile clock-in apps with face verification.
  • Mark those systems and their backups as excluded in the data inventory before any scoping discussion starts.
  • Remove timekeeping and payroll exports from scope unless a specific, approved need exists.
  • Where punch data stays, drop verification method, match result, terminal enrollment ID and photo fields, and replace employee identifiers.
  • Search tickets, email, chat and shared drives for terms such as fingerprint, finger scan, face scan, biometric, enrollment and template, and review every hit.
  • Exclude HR documents about biometric notices, releases and vendor setup.
  • Record each exclusion, the search terms used and who signed off.

Can punch times stay without the biometrics?#

Punch times can stay in a dataset without the biometric fields, but most companies find they do not need them. Labor time on a job is usually better captured in operational records: dispatch arrival and completion times in a field service system, labor entries on ERP work orders, or time entries against a project in a professional services tool.

If punch records are kept, treat them as employee personal data even after the biometric fields are gone. Replace names and employee IDs with role codes, consider coarsening timestamps, and remove location and device fields that could point to one person. Open the raw export to check for hidden columns or attachments the timekeeping system added.

Which laws may apply#

Several layers of law may apply to biometric timekeeping data, and which ones matter depends on where employees work and where the company operates. BIPA is the best known; other states have biometric-specific statutes; and comprehensive state privacy laws often classify biometric data as sensitive, with consent requirements for certain uses, though some of those laws carve out employee records, so coverage varies by state.

BIPA shows why the exposure can be large. The statute lets a prevailing party recover liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation, or actual damages if greater. In Rosenbach v. Six Flags, decided in January 2019, the Illinois Supreme Court held that a person need not allege actual injury beyond the violation of their BIPA rights to sue. A 2024 amendment, SB 2979, limits recovery to a single violation per person when the same identifier is collected repeatedly by the same method, but it does not remove the underlying notice and consent duties.

Employment law, collective bargaining agreements, the timekeeping vendor's contract and the company's own notices and retention schedules add further limits. None of this can be assessed generically, and counsel reviews it deal by deal. That is one more reason the practical answer is exclusion: removing the data avoids the analysis instead of trying to win it.

Which laws may apply
LayerWhat counsel will want to see
State biometric statutes such as BIPAWhere employees enrolled and worked, and which notices and releases were collected
Comprehensive state privacy lawsWhether biometric data counts as sensitive data there and whether employee records are covered
Employment agreements and union contractsTerms on workplace monitoring, notice and use of employee data
Timekeeping vendor contractWho controls templates and exports, and any limits on how timekeeping data may be used
Company notices and retention schedulesWhat employees were told and when biometric data is due to be destroyed

Illustrative: a mechanical contractor scopes its job history#

Illustrative: a fictional mechanical contractor runs dispatch, estimates and invoices in ServiceTitan and uses fingerprint timeclocks in its shop and warehouse, feeding a separate payroll system. The owner is considering licensing job histories that connect service calls, diagnoses, parts used and callbacks.

The first inventory draft includes a payroll export to show technician hours. The privacy lead finds a column recording the verification method for each punch and a folder of enrollment reports on the HR share. A keyword search of the IT ticket queue turns up threads about failed finger scans that name individual employees.

The team removes the payroll export and the timeclock system from scope, excludes the HR folder, and drops the matching tickets. Technician time comes from ServiceTitan arrival and completion timestamps instead, with technician names replaced by role codes. The owner approves a package that contains no timekeeping data, with every exclusion documented.

How SourceX handles biometric exclusions#

SourceX treats biometric data as an exclusion decided during Rights and enforced during Preparation, the second and third stages of the SourceX five-step transaction (Supply, Rights, Preparation, Approval, Delivery). Timeclocks, access readers and related HR records are listed as out of scope early, so they never reach a sample or an export.

The exclusion, the search terms and the reviewer's sign-off are recorded in the privacy record of the SourceX Evidence Packet. The supplier approves the final scope before anything is delivered, and the initial fit check collects only metadata, never files.

Frequently asked questions

Is an encrypted or hashed fingerprint template still biometric data?

Treat it as biometric data. Legal definitions generally focus on what the information was derived from and what it can be used for, not on how it is stored, and vendors describe their templates in different ways. Encryption protects a template in storage but does not change what it is.

Our employees signed biometric consent forms. Does that change anything?

Usually not for licensing. Timeclock consent and notice forms are typically written for timekeeping and payroll, not for disclosure to an outside party or use in AI training. Counsel can review the exact wording, but the practical route is still to leave biometric data out.

What if the timekeeping vendor stores the templates, not us?

The exclusion still covers everything you can export: enrollment reports, punch records with verification fields and support threads with the vendor. Never request template data from the vendor for a licensing purpose, and review the vendor contract for limits on how timekeeping exports may be used.

Are badge photos and directory headshots biometric data?

Not always under every law, but they are personal data, and face images can become biometric data when used for matching. For licensing, exclude badge photos, directory headshots and photo-at-punch images along with timeclock data.

Does the rule cover mobile clock-in apps?

Yes. Some mobile time-tracking apps verify identity with face matching or capture a photo at clock-in, and many also record location. Treat face verification data as biometric, exclude photos, and give location history its own review as sensitive personal data.

Sources

  • BIPA lets a prevailing party recover liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation, or actual damages if greater; SB 2979, signed August 2, 2024, limits recovery to a single violation per person when the same biometric identifier is collected repeatedly by the same method. Source
  • In Rosenbach v. Six Flags Entertainment Corp., decided January 25, 2019, the Illinois Supreme Court held that a person need not allege actual injury beyond a violation of their BIPA rights to be an aggrieved party entitled to sue. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify