Do Employers Have To Get Consent Before Collecting Biometric Data?

Biometric data is becoming standard in workplaces nationwide. Employers increasingly rely on fingerprint scanners, facial recognition, voiceprints, and similar tools for timekeeping, access, attendance, and monitoring. While these tools may seem convenient for companies, they create serious risks for employees whose sensitive identifiers can never be replaced once exposed.
Many workers are unaware that employers collect this type of information, how long it is stored, or whether it is shared with third-party vendors. As attorneys who represent plaintiffs in cybersecurity and privacy cases nationwide, we understand how important it is for workers to know their rights. Consent requirements vary significantly depending on the state, the technology used, and the employer’s data practices. Our goal is to provide clarity and explain when employers must obtain consent, what laws apply, and what employees can do if their rights are violated.
Biometric data, such as fingerprints, facial geometry, hand scans, retinal scans, and voiceprints, is uniquely tied to each individual. Unlike passwords, it cannot be reset. When an employer mishandles biometric information or collects it without proper authorization, the consequences can be serious. Employees may face privacy violations, risk of identity theft, unlawful surveillance, and misuse by outside vendors.
Many states have now implemented strict rules that force employers to obtain written consent before collecting or storing any biometric identifier. These laws also require clear disclosures about how the data will be used, how long it will be retained, whether it will be shared, and when it will be destroyed. At Net Law Advocates, we represent plaintiffs whose biometric information was collected unlawfully or stored without adequate safeguards.
What Federal Laws Address Biometric Data?
Currently, there is no single federal biometric privacy law that applies to all employers in the United States. However, several federal laws address biometric-related issues in certain contexts.
- The Americans With Disabilities Act (ADA): Some biometric tools may collect health-related data, triggering ADA protections.
- The Health Insurance Portability and Accountability Act (HIPAA): Biometric identifiers used in healthcare settings may fall under HIPAA privacy rules.
- The Federal Trade Commission Act (FTC Act): The FTC brings enforcement actions when companies misrepresent how biometric information is used or fail to protect it adequately.
- The Fair Credit Reporting Act (FCRA): If biometric data is used in employment screening, FCRA regulations may apply.
Even without a federal statute specifically designed for biometric data, federal agencies increasingly warn companies that biometric information requires a high level of care. Employers that fail to protect biometric data may face federal enforcement in addition to state-level litigation.
State Laws That Require Biometric Consent
Several states have passed strong biometric privacy laws requiring employers to obtain informed consent before collecting or storing biometric identifiers. The most well-known and strictest law is:
Illinois Biometric Information Privacy Act (BIPA)
BIPA requires employers to:
- Obtain written consent before collecting biometric data.
- Inform employees of the specific purpose and duration of collection.
- Implement written retention and destruction schedules.
- Prohibit selling or sharing biometric data without authorization.
- Maintain reasonable security measures.
Violations may result in statutory damages of $1,000 per negligent violation and $5,000 per reckless violation, along with attorney’s fees.
Texas Capture or Use of Biometric Identifier Act (CUBI)
Texas requires companies to:
- Obtain consent prior to capturing biometric identifiers.
- Destroy the data within a reasonable period.
- Prohibit selling biometric data.
Washington State Biometric Privacy Law
Washington requires notice and prohibits companies from collecting biometric data for commercial purposes without authorization.
Other States With Biometric Provisions
Several states, including California, New York, Arkansas, Colorado, and Virginia—have privacy statutes that address biometric data within broader consumer privacy frameworks. Many require consent, detailed notices, or strict security procedures.
Because state biometric laws differ, employees often do not realize when statutory protections are violated. Our attorneys identify relevant laws and consent rules. Key takeaway: Employees should consult our attorneys to understand state-specific rights.
Why Consent Matters In The Workplace
Biometric data is extremely sensitive. Once compromised, it exposes workers to lifelong risk.
Consent is required in many states for several important reasons:
- It ensures employees understand what data is being collected.
- It prevents employers from storing biometric identifiers indefinitely.
- It restricts employers from sharing biometric data with outside vendors without authorization.
- It forces employers to follow retention and destruction rules.
- It protects workers from unauthorized surveillance and misuse.
Employers that collect biometric data without proper consent risk statutory damages, emotional distress claims, attorney’s fees, and other repercussions. In some states, every unauthorized biometric scan counts as a separate violation. Key takeaway: Each instance of nonconsensual data collection may lead to significant liability.
What Employees Can Do If Consent Was Not Obtained
Employees often discover unlawful biometric collection only after asking questions or learning about lawsuits involving their workplace. If an employer failed to obtain consent, violated retention rules, failed to disclose how data is used, or allowed third-party vendors to access biometric information improperly, the employee may have a strong claim.
Our attorneys work with clients to:
- Review employer policies and consent documents.
- Examine timekeeping or access systems.
- Determine whether biometric tools were used lawfully.
- Identify applicable state privacy laws.
- Evaluate damages and statutory compensation.
- Pursue lawsuits on behalf of affected employees.
Workers have a right to know how their biometric information is collected, stored, and shared. When employers ignore that obligation, legal action may be appropriate.
Biometric Data Frequently Asked Questions
What Counts As Biometric Data In The Workplace?
Biometric data includes fingerprints, facial geometry, retinal or iris scans, hand geometry, voiceprints, and other unique physical characteristics used for identification. Many time clocks, access panels, and security systems rely on biometric identifiers. These data types are protected because they cannot be replaced if compromised. If an employer uses any tool that captures these features, biometric privacy laws may apply.
Do Employers Need Written Consent To Use Fingerprint Time Clocks?
In Illinois, Texas, and several other states, yes. Under BIPA, written consent is mandatory before using fingerprint systems. Employers must also explain the purpose of the collection and how long the data will be stored. Even in states without specific biometric consent laws, employers may still violate privacy or consumer protection laws by failing to provide notice or failing to protect the data adequately. Our attorneys evaluate whether your employer followed the correct procedures.
What Should I Do If My Employer Collected My Biometric Data Without My Knowledge?
You should gather any documents you received during onboarding, review workplace policies, and take note of how biometric systems were used. Many employees discover violations only after learning that no consent form was provided. You may have legal rights to compensation, especially in states with statutory remedies. Our firm can review your situation and determine whether your employer failed to comply with privacy laws.
Can My Employer Share My Biometric Information With A Vendor Or Third Party?
Under laws like BIPA, biometric data cannot be shared without authorization. Many employers use third-party timekeeping companies or security vendors that store biometric information off-site. Sharing data without proper disclosures or consent may violate the law. Our attorneys investigate whether biometric identifiers were stored, processed, or transferred unlawfully.
What Damages May Be Available If My Rights Were Violated?
Depending on the state, employees may be entitled to statutory damages, emotional distress damages, attorney’s fees, and compensation for risk of identity theft. In BIPA cases, statutory damages can reach thousands of dollars per violation. We work to determine how many violations occurred and build claims that reflect the full impact on our clients.
How Long Can My Employer Store My Biometric Data?
Most biometric privacy laws require employers to delete biometric information within a defined period, usually when the purpose of collection ends or within a set timeframe. Storing biometric data indefinitely is often unlawful. If your employer lacks a destruction policy or fails to follow retention rules, it may violate state law.
Contact Net Law Advocates For A Free, Confidential Consultation
If your employer collected your biometric information without consent or failed to follow privacy rules, you may have the right to pursue compensation. Our cybersecurity and privacy attorneys represent employees nationwide in biometric privacy cases, data misuse claims, and workplace technology violations. We understand how sensitive biometric information is and how employers must treat it under the law.
If you believe your biometric information was collected or used unlawfully, please complete our secure web form. Our firm will evaluate your situation, review applicable state laws, and explain your legal options. At Net Law Advocates, we represent plaintiffs throughout the United States and are ready to assist you in protecting your privacy rights.