Biometric time clocks (face or fingerprint) stop buddy punching cold — but if you collect a faceprint without proper consent, laws like Illinois’ BIPA let employees sue for $1,000–$5,000 per violation. The good news: doing it right is straightforward.

What the law requires before you scan a face

  • Written notice that you’re collecting a biometric identifier.
  • The specific purpose and how long you’ll keep it.
  • A written release (affirmative consent) from the employee.
  • A public retention & destruction policy — destroy the data when the purpose ends or within 3 years of last use.
  • No selling or sharing the biometric data with third parties.

What good biometric consent looks like

The employee sees a clear notice, ticks an explicit “I agree” box, and can decline and use a PIN instead. You store a mathematical faceprint — never raw photos — and delete it when they leave. That combination satisfies BIPA and CCPA-style laws.

ClockAll’s face check is built this way: an affirmative consent screen with the retention term and no-sale promise, on-device face processing (images never leave the phone), automatic deletion when an employee is deactivated, and a hard 3-year cap — all recorded in an audit trail.

Related reading

Frequently asked questions

Which states regulate biometric time clocks?

Illinois (BIPA) is the strictest and allows private lawsuits. Texas and Washington have biometric laws enforced by the state, and CCPA/CPRA covers biometric data in California. Written consent is best practice everywhere.

Do we store the actual photo of someone’s face?

You shouldn’t. Good systems store only a mathematical embedding (a set of numbers) that can’t be turned back into a photo, and keep any images on the device.