Illinois
BIPA Compliance for Employers (2026): Step-by-Step
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 4 primary sources cited on this page. How we verify our legal content
Most BIPA lawsuits target employers that use fingerprint or face-scan timeclocks without consent. Compliance comes down to seven duties under Section 15: written notice, a written release, a retention policy, timely destruction, no sale, controlled disclosure, and reasonable security.
Jurisdiction scope: This is a general compliance overview of the Illinois Biometric Information Privacy Act (740 ILCS 14) for employers. It is general legal information, not legal advice; consult an attorney licensed in Illinois.
The Seven Steps
- Give written notice first. Before collecting a fingerprint, face scan, or voiceprint, tell the employee in writing that biometric data is being collected and stored, and state the specific purpose and how long it will be kept.
- Get a written release. Obtain the employee's signed consent before the first scan. After the 2024 amendment, an electronic signature satisfies this requirement.
- Publish a retention and destruction policy. Make a written schedule publicly available.
- Destroy data on time. Delete biometric data when its purpose is met or within three years of the employee's last interaction, whichever is first, and keep records that you did.
- Never sell or profit from it. Selling, leasing, or trading biometric data is prohibited outright.
- Control disclosures. Do not share biometric data, including with your timeclock or payroll vendor, unless the employee consented or the law requires it.
- Secure it. Protect biometric data at least as well as your other confidential and sensitive information.
A Quick Self-Check
Use the educational self-assessment below to see which of the seven requirements your current practices may not meet. It does not provide legal advice or a compliance opinion.
BIPA Compliance Self-Check
Answer the seven questions below to see which BIPA requirements your practices may not yet meet. This is an educational self-assessment, not a legal audit or legal advice.
1. Before collecting any biometric data (fingerprints, face or hand geometry, voiceprints), do you give the person a written notice stating that it is being collected and the specific purpose and retention period?
2. Do you obtain a signed (or electronically signed) written release consenting to the collection before the first scan?
3. Do you maintain a publicly available written retention and destruction policy for biometric data?
4. Do you destroy biometric data when its purpose is satisfied, or within 3 years of the person's last interaction, whichever is first?
5. Do you avoid selling, leasing, trading, or otherwise profiting from biometric data?
6. Do you limit sharing biometric data with third parties (including your timeclock or software vendor) to disclosures the person consented to or that the law requires?
7. Do you store and transmit biometric data using at least the reasonable standard of care for your industry?
Why Vendors Matter
A company that builds and operates the biometric timeclock or access system is itself a private entity under BIPA and can be sued directly, and many BIPA suits name both the employer and the technology vendor. What decides the question is control over the data. In G.T. v. Samsung Electronics America, Inc., No. 25-1120 (7th Cir. Aug. 7, 2026), the Seventh Circuit held that the words possession in Section 15(a) and collect, capture, and obtain in Section 15(b) all require the company to have or have obtained some degree of control over the biometric data. Affirming dismissal, the court found the complaint did not plausibly allege that Samsung could access, modify, or use face templates that stayed on the user's own phone. That ruling turned on what that particular complaint failed to allege, and the court assumed without deciding that face templates are biometric identifiers at all, so it does not settle the ordinary workplace case, where the vendor usually enrolls, stores, and administers the biometric database itself. When you evaluate a biometric system, confirm in writing how the vendor handles consent, retention, and security, and who actually holds the data, because their failures can become your liability.
More on BIPA
Frequently Asked Questions
Can an employer require a fingerprint timeclock in Illinois?
Yes, but only after giving written notice of what is collected, the purpose, and the retention term, and obtaining the employee's signed or electronically signed consent, plus following a published retention and destruction policy.
What is the most common BIPA mistake employers make?
Rolling out a fingerprint or face-scan timeclock without first giving written notice and obtaining written consent. That single gap is behind most BIPA class actions.
Does an electronic signature count as BIPA consent?
Yes. The 2024 amendment (Public Act 103-0769) confirms that an electronic signature satisfies BIPA's written-release requirement.
Is our timeclock vendor liable too?
A vendor that stores or controls the biometric data is a private entity under BIPA and can be sued directly, and many cases name both the employer and the vendor. In G.T. v. Samsung Electronics America, Inc., No. 25-1120 (7th Cir. Aug. 7, 2026), the Seventh Circuit held that Sections 15(a) and 15(b) require some degree of control over the data, so supplying hardware or software that a customer runs entirely on its own may not be enough. Confirm in writing both the vendor's compliance and who actually holds the data.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Removed a link in the More on BIPA list that pointed back to this same page.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Illinois Compiled Statutes Chapter 740, Act 14 (Biometric Information Privacy Act)
§ 15Retention; collection; disclosure; destructionIn forcecited in 5 of our articles
(a) A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information when the initial purpose for collecting or obtaining such identifiers or information has been satisfied or within 3 years of the individual's last interaction with the private entity, whichever occurs first. Absent a valid warrant or subpoena issued by a court of competent jurisdiction, a private entity in possession of biometric identifiers or biometric information must comply with its established retention schedule and destruction guidelines.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at ilga.gov
Also relied on in: BIPA Explained: Illinois Biometric Privacy Act (740 ILCS 14), Do You Have a BIPA Claim? Check Your Eligibility (2026), Illinois Data Privacy Laws: BIPA, Consumer Rights & Penalties (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Illinois Biometric Information Privacy Act, 740 ILCS 14(ilga.gov).gov
- 740 ILCS 14/20 - Right of Action and Damages(ilga.gov).gov
- Public Act 103-0769 (SB 2979) - 2024 BIPA Amendment(ilga.gov).gov
- Cothron v. White Castle System, Inc., 2023 IL 128004(courtlistener.com)
- Tims v. Black Horse Carriers, Inc., 2023 IL 127801(courtlistener.com)
- 740 ILCS 14/15 - Retention; collection; disclosure; destruction(ilga.gov)
- 740 ILCS 14/10 - Definitions ("written release" includes electronic signature)(ilga.gov)
- G.T. v. Samsung Electronics America, Inc., No. 25-1120 (7th Cir. Aug. 7, 2026) (published opinion, Lee, J.)(media.ca7.uscourts.gov).gov