Biometric Data Laws: Fingerprints, Face Scans and Your Legal Rights

Photo of author
Author: Alex
Published:
Updated:
Fingerprint with shield and gavel icons representing biometric data collection laws and employee rights

Direct Answer: In the US, Illinois BIPA requires written consent before employers scan fingerprints or faces, with penalties of $1,000 to $5,000 per violation. In the EU, GDPR classifies biometric data as a special category with strict protections. The UK’s ICO has taken enforcement action against employers using biometric attendance systems without proper legal basis.

Biometric data collection laws are becoming one of the most contested areas of employment law in the US, EU, and UK. Picture this: you start a new job, and on your first day, someone asks you to press your thumb on a scanner to clock in. No paperwork. No explanation of where that data goes. This scenario has triggered billions of dollars in lawsuits and major regulatory enforcement across multiple jurisdictions. The legal rules that apply depend heavily on where you work. Learn more about where facial recognition technology is legal.

The Short Version

  • In the US, only three states have dedicated biometric privacy statutes: Illinois (BIPA), Texas (CUBI), and Washington. Illinois is the only state allowing individuals to sue employers directly.
  • Under GDPR in the EU, biometric data is classified as special category data under Article 9. Collecting it requires explicit consent or another narrow legal exception — plus a standard Article 6 legal basis on top.
  • The UK’s ICO ordered Serco Leisure in February 2024 to stop using fingerprint scanning and facial recognition on over 2,000 employees, calling it disproportionate.
  • No federal law in the US specifically governs commercial biometric data collection by employers as of 2026.

What Biometric Data Collection Laws Actually Require

United States Illinois BIPA Leads the Way

The Biometric Information Privacy Act (BIPA, 740 ILCS 14), enacted in Illinois in 2008, remains the strongest biometric privacy law in the country. BIPA covers fingerprints, iris scans, voiceprints, and scans of hand or face geometry.

Under BIPA, any private entity including employers must inform individuals in writing about what biometric data is being collected and why, disclose storage duration, and obtain a signed written release before the first scan.

What makes BIPA uniquely powerful is its private right of action (Section 20). Individuals can sue directly, with statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation, plus attorney fees. The Illinois Supreme Court confirmed in Rosenbach v. Six Flags (2019) that a technical violation alone is enough no actual harm required.

A 2024 amendment (Public Act 103-769) changed damages calculations. Repeated collection of the same identifier from the same person now counts as a single violation, not one per scan. The Seventh Circuit confirmed this applies retroactively in Clay v. Union Pacific Railroad (April 2026).

Texas and Washington also have biometric statutes, but neither allows individuals to sue. In Texas, enforcement rests with the attorney general, who secured a $1.4 billion settlement from Meta in 2024. About 20 additional states protect biometric data under broader consumer privacy laws.

European Union GDPR Article 9

In the EU, GDPR (2018) classifies biometric data as special category data under Article 9 when processed to uniquely identify a person the most restrictive classification in European data protection law.

Processing is prohibited by default. Employers must satisfy two legal tests simultaneously: a lawful basis under Article 6 and a specific exception under Article 9(2). Workplace consent is problematic because regulators note the power imbalance between employer and employee means consent is rarely “freely given.”

Fines for Article 9 violations reach €20 million or 4% of global annual turnover, whichever is higher.

United Kingdom ICO Enforcement

The UK retains its own version of GDPR (the UK GDPR), classifying biometric data as special category data with the same two-layer legal test.

In February 2024, the Information Commissioner’s Office (ICO) ordered Serco Leisure to stop using fingerprint scanning and facial recognition to track attendance of over 2,000 employees at 38 leisure facilities. The ICO found Serco failed to show why biometric scanning was necessary when less intrusive alternatives like ID cards or fobs existed. Employees had no genuine alternative and effectively had to submit biometric data just to get paid.

Serco was ordered to destroy all collected biometric data within three months.

Real-World Examples

The Warehouse Time Clock. A logistics company in Illinois installs fingerprint scanners for shift workers without written notice or a consent form. Under BIPA, every affected employee has grounds for a claim even without showing actual harm.

The Office Face Scanner. A UK employer rolls out facial recognition at building entrances to replace key cards. The ICO’s guidance makes clear that where less intrusive methods achieve the same purpose, biometric processing cannot be justified under UK GDPR.

The Call Center Voiceprint. A financial services company creates voiceprints during customer calls without telling callers. In Illinois, voiceprints are explicitly covered by BIPA, and multiple class actions have been filed over unconsented collection.

Biometric time clock scanner with consent and retention icons showing employer data collection requirements

IMAGE 3 — Pinterest Featured Image (vertical 2:3 ratio)
Image prompt: Vertical 2:3 ratio Pinterest graphic with a light gray background. Top third: bold white text on a dark navy (#1b4a7a) banner reading "Biometric Data Laws: What Happens When Your Employer Scans Your Fingerprint?" in a clean sans-serif font. Middle section: a large stylized fingerprint in dark navy with three jurisdiction flag-colored dots (blue for EU, red-white-blue for US, red-white for UK) connected to the fingerprint by thin lines, each with a small legal scales icon beside it. Bottom section: the Jovonk.com logo or wordmark in dark navy. No human faces. Clean flat design with subtle shadows for depth. Professional and approachable mood throughout.
File name: biometric-data-collection-laws-pinterest.jpg
Title: Biometric Data Laws — Your Fingerprint Rights at Work in 2026
ALT text: Biometric data collection laws infographic showing fingerprint rights across US, EU, and UK jurisdictions

What People in This Situation Typically Do

  1. Check the jurisdiction. The laws that apply depend on the state or country where the data is collected not where the company is headquartered.
  2. Look for written consent records. Many people in this situation check whether their employer provided written notice and obtained a signed consent form before the first scan. Under BIPA, missing documents are themselves a violation.
  3. Request the biometric data policy. Under BIPA, companies must have a publicly available policy covering retention and destruction timelines. Under GDPR and UK GDPR, a Data Protection Impact Assessment (DPIA) a formal risk evaluation is expected for biometric processing.
  4. File a complaint with the relevant regulator. In the UK, complaints go to the ICO. In the EU, to the national data protection authority. In Illinois, individuals can file directly with the courts.
  5. Consult an employment attorney. BIPA class actions have produced settlements exceeding $100 million, so many employees seek legal counsel when they believe biometric data was collected improperly.

Related Articles

Frequently Asked Questions

Can my employer require biometric time clock scanning?

It depends on jurisdiction. In Illinois, BIPA requires written notice and signed consent before any scanning employers cannot skip these steps. In the UK, the ICO has ruled employers cannot require biometric scanning when less intrusive alternatives exist. Under EU GDPR, workplace consent is heavily scrutinized due to the employer-employee power imbalance.

What is BIPA and which states have similar laws?

BIPA is the Illinois Biometric Information Privacy Act (740 ILCS 14), enacted in 2008. It is the only US biometric law giving individuals the right to sue companies directly. Texas and Washington have similar statutes but limit enforcement to the attorney general.

How long can companies keep my biometric data?

Under BIPA, companies must publish a retention schedule and destroy biometric data when the original purpose is fulfilled or within three years of the individual’s last interaction whichever comes first. Under GDPR and UK GDPR, biometric data must be deleted once the collection purpose no longer applies.

What are my rights if a company loses my biometric data?

Most US states require breach notification even without a dedicated biometric statute. Under GDPR and UK GDPR, organizations must notify the supervisory authority within 72 hours and affected individuals if the breach poses high risk. Under BIPA, individuals may pursue statutory damages if the breach resulted from inadequate security.

The legal rules around biometric data collection laws are moving quickly, with new enforcement actions and court decisions shaping the landscape across the US, EU, and UK. The core principle across all three jurisdictions is the same: biometric identifiers like fingerprints and face scans are uniquely sensitive because they cannot be changed if compromised. Anyone whose employer collects this type of data benefits from understanding the specific protections available in their jurisdiction.

This article is for educational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change frequently. For advice specific to your situation, consult a qualified attorney.

Sources & Further Reading

Biometric data collection laws infographic showing fingerprint rights across US, EU, and UK jurisdictions

Written by Alex

Alex is the editorial pen name of Mohammed Ez-Zayady, a law student based in Morocco and the founder of Jovonk. The content is provided for educational purposes and does not constitute legal advice.