A biometric time clock identifies employees by a physical characteristic rather than by something they carry or remember: a fingerprint, a hand or face geometry scan, or occasionally an iris or voiceprint. Because a fingerprint cannot be handed to a colleague, it eliminates buddy punching in a way no badge or PIN can.
That is the entire commercial case, and it is a good one. What almost no vendor page explains is the other half: in Illinois, collecting an employee’s fingerprint without written consent first can cost $1,000 to $5,000 per person, enforced by the employees themselves rather than by a regulator.
This guide covers how the technology works, where it fits, and what the law requires before you switch it on.
How a biometric time clock works
Two stages, and the distinction between them matters legally.
Enrolment. The employee presents the characteristic once. The system does not store a photograph or an image of the fingerprint; it extracts measurable features and converts them into a mathematical template. Good systems store only the template, and the template cannot be reversed back into the original.
Matching. At each punch, the device takes a fresh reading, generates a template, and compares it against the stored one. A match records the punch.
The important point for compliance: the template is still biometric data. Vendors sometimes imply that because no image is stored, privacy laws do not apply. Statutes generally cover the identifier and information derived from it, so a template extracted from a fingerprint is squarely within scope.
Common modalities in timekeeping:
| Method | How it reads | Notes |
|---|---|---|
| Fingerprint | Ridge pattern minutiae | Cheapest and most common; struggles with worn, wet or damaged fingers |
| Hand geometry | Finger length and hand shape | Durable in industrial settings; larger and more expensive hardware |
| Facial recognition | Facial landmark geometry | Contactless; sensitive to lighting and to face coverings |
| Iris | Iris pattern | Highly accurate, rarely used for timekeeping on cost |
| Voiceprint | Vocal characteristics | Used for phone-based clocking in field work |
What it solves
Buddy punching. One employee clocking in for another. It is the specific problem biometrics eliminate, because the credential cannot be lent.
Lost and shared credentials. No badges to replace, no PINs written on the wall next to the terminal.
Disputed punches. The record is tied to a person rather than to a card that person may or may not have been holding.
If buddy punching is not actually happening in your operation, most of the value disappears while all of the exposure remains. That is worth establishing honestly before buying, because the assumption is often inherited from a vendor rather than from evidence.
The trade-off

Biometrics sit at one end of a straightforward trade. They are the only method that genuinely cannot be shared, and they are the only method that creates permanent, unchangeable personal data about your employees.
That last part is the crux. A compromised password is changed in a minute. A compromised fingerprint template is a lifelong problem for the person it belongs to, and that asymmetry is why legislatures treat biometric data differently from other employment records.
BIPA and why it matters more than anything else
Illinois’ Biometric Information Privacy Act, 740 ILCS 14, was enacted in 2008 and is the reason biometric timekeeping carries the risk it does.
What makes BIPA different is the private right of action. Most privacy statutes are enforced by a regulator who decides which cases to pursue. BIPA lets the individual sue directly, with statutory damages of $1,000 for a negligent violation and $5,000 for an intentional or reckless one, plus attorneys’ fees. No proof of actual harm is required.
Workplace time clocks became the archetypal BIPA case for a simple reason: they are the highest-volume biometric collection most employees ever encounter.

The exposure has moved considerably, and understanding where it stands now matters:
February 2023, Cothron v. White Castle. The Illinois Supreme Court held that a claim accrues each time biometric data is collected or transmitted, not only the first. A fingerprint clock scanning an employee twice a day for three years generated over a thousand claims. The court itself acknowledged the arithmetic could produce annihilative totals and said the legislature should address it.
August 2, 2024, Public Act 103-0769. The legislature did. Repeated collection of the same identifier from the same person by the same method is now a single violation with at most one recovery. In effect, the ceiling for a common claim moved from $5,000 per scan to $5,000 per person.
April 2026, the Seventh Circuit. The federal appeals court held that the amendment applies retroactively to cases already pending, resolving the largest open question for defendants in existing litigation.
Two cautions. Illinois state courts have not uniformly settled retroactivity, so treat it as still developing. And more importantly: the amendment reduced damages and changed no compliance obligation whatsoever. Consent, policy, retention and destruction requirements are exactly what they were.
What compliance actually requires
Under BIPA, before collecting anything, a private entity must:
Publish a written policy that is made available to the public, setting out a retention schedule and guidelines for permanently destroying biometric identifiers. Destruction must occur when the purpose has been satisfied or within three years of the individual’s last interaction, whichever comes first.
Inform the individual in writing that biometric data is being collected or stored, and of the specific purpose and the length of term for which it will be collected, stored and used.
Obtain a written release from that individual. Signed, before enrolment, not after.
Not sell, lease, trade or otherwise profit from biometric data.
Not disclose it without consent, subject to narrow exceptions.
Store and transmit it using the reasonable standard of care for the industry, and at least as protectively as the entity handles other confidential information.
Three practical points that repeatedly go wrong:
Consent must precede enrolment. Collecting first and papering it later does not cure the violation.
A general employee handbook acknowledgment is not a biometric release. It needs to be specific.
Vendors carry their own exposure. A timekeeping vendor that receives templates is itself a collector under the statute. Ask what your vendor’s compliance position is before you sign, and check what happens to templates when the contract ends.
This is general information, not legal advice. BIPA compliance is fact-specific and worth putting in front of counsel before deployment rather than after a demand letter.
Other state laws
Illinois is not the only state, but it is the only one with this enforcement model.
Texas regulates the capture of biometric identifiers for commercial purposes under CUBI, with notice and consent requirements and civil penalties. Enforcement is by the Attorney General; there is no private right of action.
Washington has a biometric privacy statute, also enforced by the Attorney General rather than by individuals.
Colorado and several other states have added biometric provisions to broader consumer privacy legislation in recent years, with employee data increasingly in scope.
New York City requires notice where businesses collect biometric identifiers from customers, aimed at retail rather than employment.
The pattern to plan around: the substantive requirements converge on notice, consent, retention limits and destruction. What varies is who can enforce them, and Illinois is the outlier that has driven almost all of the litigation.
For employees outside the US, biometric data is a special category under the GDPR, with a correspondingly higher bar. Consent is a weak basis in employment because of the power imbalance, and a data protection impact assessment is generally expected. Our GDPR guide covers the framework.
Biometric time clocks in construction
Construction is where the case for biometrics is strongest, and where the practical obstacles are worst.
Why it fits. Multiple sites, subcontractors, high turnover, cash-adjacent payroll and genuine buddy punching risk. Job costing depends on knowing who was on which site for how long, and a badge system tells you only that a badge was present.
Why it struggles. Fingerprint readers perform poorly on hands that have been laying brick or handling solvents all morning. Sites lack power and connectivity. Terminals in dusty outdoor conditions have short lives. And the clock has to move as the site moves.
The practical answers in the field:
- Rugged or mobile terminals rather than office-grade hardware
- Facial recognition instead of fingerprint, since it is contactless and unaffected by hand condition, though it introduces its own consent questions
- Mobile app clocking with GPS or geofencing, which usually delivers most of the site-attendance benefit without collecting any biometric data at all
That last option deserves consideration before biometrics, particularly for multi-state contractors. It answers “was this person on this site” without creating a permanent identifier or a BIPA exposure.
Boost your business productivity
Track performance and streamline teamwork
Alternatives that carry less risk
PIN or badge. Cheapest, and the only method that is genuinely defeated by buddy punching.
Mobile app with GPS or geofence. Confirms location at clock-in. Covers site-based work without biometric collection. Requires phones and a location-use policy.
Photo capture at punch. The device photographs the person clocking in without generating a biometric template. It creates a reviewable record and a strong deterrent while avoiding the identifier question entirely, provided no facial recognition is applied to the image.
Desktop and web clocking with activity records. For office and remote teams, buddy punching is not the problem, and a software time clock with an audit trail answers everything that matters.
Choose the lightest method that solves your actual problem. Biometrics are the correct answer when buddy punching is real, measurable and expensive, and an unnecessary liability when it is not.
Choosing a system
Establish the problem first. Quantify the buddy punching you actually have. If you cannot, the case for biometrics is weaker than it appears.
Check your states. Any Illinois employee changes the analysis completely.
Ask where templates are stored. On-device, on your server, or in the vendor’s cloud. Each has different exposure and different answers at contract end.
Confirm templates cannot be reversed and ask the vendor to say so in writing.
Get the vendor’s compliance position in the contract, including who is responsible if consent is defective.
Plan for exceptions. Some proportion of any workforce will not enrol successfully, and some will object. You need a non-biometric fallback that is not punitive.
Budget the process, not just the hardware. Policy, written releases, storage, destruction schedule and a records system for the releases themselves.
Common mistakes
Enrolling first and collecting consent later. The order is the requirement.
Treating a handbook acknowledgment as a biometric release. It needs to be specific and separate.
Assuming templates are exempt because no image is stored. Data derived from an identifier is covered.
Overlooking the destruction schedule. Retention limits and permanent destruction are obligations, not best practice.
Forgetting former employees. Templates for people who left years ago are a common finding in these cases.
Assuming the 2024 amendment fixed the problem. It reduced damages. Every compliance requirement survives unchanged.
Not asking about the vendor’s own exposure. They are a collector too.
How Monitask helps
Not every timekeeping problem needs a biometric answer, and for office, remote and hybrid teams it almost never does. Buddy punching requires a shared physical terminal; it is not the failure mode of distributed work.
Monitask records hours through a software time clock. Employees clock in when they start and clock out when they stop, and no biometric data is collected at any point.

- Software clock-in and clock-out with an audit trail, on desktop, mobile and web.
- Optional proof-of-work screenshots visible to the employee, which address the verification question without biometric collection.
- Project and task time for job costing, which is usually the real reason site attendance is being tracked.
- No biometric identifiers stored, which keeps the entire category of exposure described above out of scope.
See how it works: Monitask online timesheets.
Sources
- Illinois Biometric Information Privacy Act, 740 ILCS 14 — written policy, retention and destruction schedule, informed written consent, prohibition on profiting from biometric data, and statutory damages of $1,000 and $5,000.
- Cothron v. White Castle System, Inc., 2023 IL 128004 (February 17, 2023) — per-scan claim accrual.
- Illinois Public Act 103-0769, signed August 2, 2024 — repeated collection by the same method treated as a single violation with one recovery.
- US Court of Appeals for the Seventh Circuit, April 2026 — the 2024 damages amendment applies retroactively to pending cases.
- Texas Capture or Use of Biometric Identifier Act and Washington’s biometric privacy statute — notice and consent requirements enforced by state Attorneys General rather than by private action.
Related reading
- Employee Monitoring Laws
- GDPR Requirements for Employee Monitoring
- Understanding Time Card Fraud: Identifying and Preventing Workplace Time Theft
- Attendance Sheet Template
- Small Business Time Tracking
- How to Keep Your Applicant and Employee Data Secure
FAQ
Are biometric time clocks legal?
Yes, in most of the US, subject to state requirements. Illinois, Texas and Washington impose notice and consent obligations, and Illinois additionally allows employees to sue directly.
What is BIPA?
The Illinois Biometric Information Privacy Act, 740 ILCS 14. It requires a published policy, informed written consent before collection, retention limits and destruction, and it provides statutory damages of $1,000 or $5,000 per violation with a private right of action.
Did the 2024 BIPA amendment remove the risk?
No. It limited damages to one recovery per person per collection method rather than one per scan. Every compliance obligation is unchanged, and a claim is still worth $1,000 to $5,000 plus fees.
Do I need employee consent for a fingerprint time clock?
In Illinois, yes, in writing and before enrolment. Elsewhere it depends on state law, but written consent obtained in advance is the safest practice everywhere.
Do biometric time clocks store fingerprints?
Most store a mathematical template rather than an image. The template is still biometric data under these statutes, so storing no image does not remove the obligations.
Can an employee refuse to use a biometric time clock?
They can object, and religious or disability-related objections may require accommodation. A non-biometric alternative is worth having in place before the question arises.
What is the best time clock for construction?
Rugged or mobile terminals, with facial recognition often working better than fingerprint on site because hand condition does not affect it. Mobile app clocking with a geofence delivers much of the same site-attendance benefit without collecting biometric data.
How long can biometric data be kept?
Under BIPA, until the purpose is satisfied or three years after the individual’s last interaction with the entity, whichever comes first.
Are there alternatives to biometric time clocks?
Yes: PIN or badge, mobile app clocking with GPS or geofencing, photo capture at punch without facial recognition, and software time clocks with audit trails. Choose the lightest method that solves the problem you actually have.