Biometric Data at Work: A Compliance Primer for Employers

Labor & Employment Law Navigator Blog
Aug 11, 2026

If your workplace uses a fingerprint to clock employees in and out, facial recognition to unlock a door, or an iris scan to access a secure area, you’re likely collecting biometric data, and you may not even realize what that entails.

Bottom line: Biometric data is legally different from other employee information. It differs in the way that employers are required to provide notice, obtain consent, adopt written governance policies, carefully safeguard, and eventually destroy this data. Getting these steps wrong has cost some employers hundreds of millions of dollars. Getting it right starts with understanding the basics below.

Why Biometric Data is Different

At a very basic level, and unlike a PIN, passcode, or even social security number, biometric information can’t simply be changed if it’s compromised. You can reset a passcode. You can update a password. You cannot change your fingerprint or your face.

That permanence is exactly why a handful of states have singled biometric data out for special treatment and regulation and why the compliance stakes are higher than they are for most other employee personal data.

Illinois’ Biometric Information Privacy Act (BIPA) is currently the most aggressive law in this space. Not only does it come packed with substantive compliance requirements, but it also allows employees to sue employers directly for statutory damages.

Those numbers can add up fast in a class action: Meta settled a BIPA class action concerning its use of facial recognition technology for $650 million, and BNSF Railway faced a $228 million jury verdict over fingerprint scans collected from truck drivers without proper consent before ultimately settling the action for $75 million.

These are cautionary tales, not outliers, and Illinois is far from the only state where employers face this level of exposure. Before you can manage the risk, though, it helps to know exactly what you’re dealing with.

What Counts as Biometric Data?

Biometric data refers to physical characteristics that can be used to identify a person. Common examples include:

  • Fingerprints
  • Facial recognition or facial geometry
  • Iris or retina scans
  • Voiceprints
  • Hand or palm scans

Employers are increasingly using this technology for practical reasons, including building security, identity verification, timekeeping, and access to sensitive areas.

It’s important to note that the technology itself isn’t the problem (at least not from a legal perspective). The issue is that collecting such biometric data triggers obligations for policies and procedures most employers don’t have in place for other types of employee personal or identifying information. Before your company begins to collect biometric information, it is critical to determine what additional notices, consents, policies, and storage/retention procedures are required for employee biometric information in the state you are operating.

What’s the Law? 

There’s no federal law governing the collection of biometric data in the workplace, so protection depends entirely on the state (and sometimes the city) where the data is collected. As of 2026:

  • Colorado, Illinois, Texas, and Washington have dedicated biometric privacy laws. Illinois’ BIPA is the most stringent and is the only one with a private right of action.
  • About twenty more states treat biometric data as a “sensitive” category under broader consumer privacy laws, layering on additional notice and consent requirements.
  • Other states address biometric data only indirectly, through general data-breach notification rules.

For multi-state employers: a policy that satisfies one state’s requirements may fall short in another.

What the Laws Typically Require 

These laws often require employers to:

  • Provide advance, written notice before collection – sometimes with statutorily mandated notice terms and language
  • Obtain informed, written consent prior to collecting any biometric information
  • Maintain a written retention and destruction policy
  • Store and safeguard the data using reasonable security measures, which may be more stringent than how other personal data is stored
  • Destroy the data on a defined timeline, which may be set by statute

The Takeaway

If your organization is using or considering using biometric technology, don’t treat it as just another system rollout. Taking the time to understand your obligations before implementation is far easier (and cheaper) than untangling a compliance gap or a class action after the fact.

Whether you’re evaluating biometric technology or already have it in place and want a compliance check, our skilled team of lawyers is happy to help assess your obligations before they become a problem. Please reach out to Stacey M. Sanderson, Jim Ickes, Bradley D. Reed, or any member of our Labor & Employment, Data Privacy & Cybersecurity, and AI Enterprise Governance groups with questions or for more information.