Biometric Information Privacy: What Employers Need to Know About Federal Compliance and the Seventh Circuit’s BIPA Decision

Biometric technology is becoming increasingly common in the workplace. Employers may use fingerprints, facial recognition, hand geometry, voiceprints, iris scans or other biometric identifiers for timekeeping, facility access, identity verification, cybersecurity and employee authentication.

While these technologies can provide convenience and security, they also create privacy and compliance considerations for employers. Biometric information is particularly sensitive because, unlike a password or identification number, an individual’s physical or behavioral characteristics generally cannot simply be changed if compromised.

For employers, biometric privacy compliance is also becoming increasingly complex. There is not currently one comprehensive federal law that governs all employer collection and use of biometric information. Instead, employers may need to consider a combination of federal requirements, state and local laws, industry-specific regulations and enforcement actions.

Illinois’ Biometric Information Privacy Act (BIPA) provides one of the most significant examples of the potential legal and financial consequences associated with biometric data. A recent decision from the U.S. Court of Appeals for the Seventh Circuit, Clay v. Union Pacific Railroad Company, further demonstrates why employers should carefully evaluate how they collect and use biometric information.

Is There a Federal Biometric Privacy Law?

Unlike some areas of employment law, the United States does not currently have a single comprehensive federal biometric privacy statute that establishes uniform requirements for every employer collecting biometric information.

However, the absence of a comprehensive federal biometric privacy law does not mean biometric information is unregulated at the federal level. Depending on the circumstances, employers may need to consider federal laws addressing privacy, data security, discrimination, genetic information and consumer protection.

For example, the Federal Trade Commission (FTC) has stated that companies’ collection and use of biometric information can raise significant privacy and data-security concerns. The FTC has indicated that Section 5 of the Federal Trade Commission Act can apply when businesses engage in unfair or deceptive practices involving biometric information.

Other federal laws may also become relevant depending on how biometric information is collected or used. For example, the Genetic Information Nondiscrimination Act (GINA) restricts employers’ acquisition and use of certain genetic information, while federal anti-discrimination laws may come into play if biometric technologies are used in ways that result in discriminatory employment practices.

As a result, employers should not view biometric compliance as an issue limited to one particular law. The applicable requirements can depend on the type of information collected, the purpose for collection, the technology being used and where the employer operates.

Have Questions?

Get answers to questions about government rules and regulations that may affect your business by using MyHRConcierge. We provide expert guidance to employers that helps them stay compliant with state and federal labor laws—fast.

State Biometric Privacy Laws Add Another Layer of Compliance

Several states have enacted laws specifically addressing biometric information. Illinois’ BIPA is among the most significant and has generated extensive litigation. BIPA was enacted in 2008 to regulate how private entities collect, obtain, store, disclose, and destroy biometric identifiers as well as biometric information. Covered information can include fingerprints, retina or iris scans, voiceprints and scans of hand or face geometry.

For employers, these requirements can apply to seemingly routine workplace technologies. A biometric time clock, fingerprint-based building access system or facial recognition platform may create obligations under BIPA when used in Illinois.

BIPA generally requires covered entities to provide specific written disclosures and obtain a written release before collecting or otherwise obtaining covered biometric information. It also requires businesses to maintain a publicly available written policy addressing the retention and destruction of biometric information and restricts certain disclosures and sales of biometric information.

The law also gives individuals a private right of action, making BIPA particularly important from a litigation standpoint.

BIPA’s Private Right of Action and Potential Damages

One of the features that has made BIPA particularly consequential is its private right of action. An individual who is aggrieved by a violation can bring a lawsuit against the private entity responsible. Importantly, Illinois courts have held that an individual does not have to demonstrate additional actual harm, such as financial loss, to establish standing for certain BIPA claims. This has allowed employees and consumers to pursue claims based on alleged violations of their statutory privacy rights.

BIPA also provides for statutory damages of $1,000 for negligent violations and $5,000 for intentional or reckless violations or actual damages when greater. For employers using biometric technology repeatedly, the potential exposure can become substantial. That issue was at the center of the Illinois Supreme Court’s 2023 decision in Cothron v. White Castle System, Inc.

Case Study: Cothron v. White Castle

In this case, an employee alleged that White Castle collected her fingerprints to provide access to computers and employee pay information without obtaining the consent required by BIPA. The Illinois Supreme Court determined that a separate BIPA claim could accrue each time biometric information was collected or transmitted without the required consent. In practical terms, this created the possibility of “per-scan” damages.

For an employer using a biometric timekeeping system every day, the implications were substantial. A single employee could potentially generate hundreds or thousands of alleged violations over the course of employment. The decision illustrated how a seemingly routine workplace technology could create significant aggregate liability when the employer’s underlying consent and disclosure procedures did not satisfy BIPA.

The Illinois legislature subsequently amended BIPA in 2024 to address the potential for repeated damages arising from the same biometric information and the same individual.

The 2024 BIPA Amendment

Effective August 2, 2024, an amendment to BIPA’s damages provision established that when a private entity repeatedly collects the same biometric identifier or biometric information from the same individual using the same method in violation of certain BIPA provisions, those repeated instances constitute a single violation for purposes of recovery.

The amendment significantly changed the potential damages calculation. Instead of allowing a separate statutory recovery for every qualifying scan, the amended law generally limits recovery to one award for the repeated collection involving the same person and method. However, the amendment did not immediately answer an important question: Would the new damages limitation apply to BIPA lawsuits that were already pending when the amendment became effective? That question ultimately reached the Seventh Circuit.

Seventh Circuit Case Study: Clay v. Union Pacific Railroad Company

On April 1, 2026, the U.S. Court of Appeals for the Seventh Circuit issued its decision in Clay v. Union Pacific Railroad Company, along with two consolidated appeals involving similar BIPA issues. The cases presented a question about the retroactive application of the 2024 amendment. The case involved Reginald Clay, who alleged that Union Pacific required him to scan his fingerprints when entering and exiting company facilities and failed to provide the disclosures and consent required by BIPA. 

The financial stakes demonstrated the significance of the issue. Clay alleged that his fingerprints were scanned approximately 1,500 times. Under the prior per-scan interpretation, an intentional violation potentially could have resulted in $7.5 million in statutory damages for Clay alone. One of the other consolidated cases involved a putative class action with potential exposure reaching into the billions of dollars.

The question before the Seventh Circuit was not whether employers must comply with BIPA. Instead, the court was asked to determine whether the 2024 amendment limiting damages applied to cases that were already pending when the amendment became effective.

The Seventh Circuit’s Decision

The Seventh Circuit held that the 2024 amendment applies retroactively to BIPA cases that were pending when the amendment took effect. The court characterized the amendment as remedial and procedural rather than substantive. In reaching that conclusion, the court emphasized that the amendment changed the damages available under BIPA rather than changing the underlying conduct that constitutes a violation. 

The amendment did not eliminate BIPA’s notice, consent, or other substantive requirements. Instead, it limited the amount of statutory recovery available for repeated violations involving the same individual and collection method. As a result, plaintiffs in pending BIPA cases alleging thousands of scans cannot automatically seek a separate statutory recovery for every scan under the prior interpretation. The Seventh Circuit reversed the district court decisions that had concluded the amendment applied only prospectively and remanded the cases for further proceedings under the amended damages framework.

It is important to understand the role of the Seventh Circuit in this case. BIPA remains an Illinois state law. The Seventh Circuit is a federal appellate court, and its decision addressed how Illinois law should apply in the federal cases before it. The court relied on Illinois rules governing statutory interpretation and retroactivity when determining how the 2024 amendment should apply.

What Employers Should Do to Reduce Biometric Privacy Risk

Employers using biometric technology should begin by identifying what biometric information they collect and why they collect it. This includes reviewing timekeeping systems, building-access systems, authentication tools, employee portals, security technologies and other workplace applications.

Where required, employers should provide appropriate disclosures and obtain consent before collecting biometric information. Employers should also establish clear policies addressing the purpose of collection, retention periods, security practices, permitted disclosures and destruction of the information.

Vendor relationships deserve particular attention. Many employers rely on third-party providers to operate biometric timekeeping, access-control or authentication systems. Employers should understand what their vendors collect, where information is stored, who can access it, how information is transmitted and when it is deleted. Contracts should clearly address data handling and privacy responsibilities.

Employers should also periodically reassess biometric systems rather than treating compliance as a one-time implementation task. Technology, vendors, business practices and privacy laws can all change over time. It is important to consult qualified legal counsel regarding specific compliance obligations.

The Bigger Picture: Biometric Privacy Is an Evolving Compliance Issue

The growth of biometric technology is creating new opportunities for employers while also introducing new compliance challenges. Fingerprint time clocks, facial recognition, voice authentication and other biometric tools can improve security and streamline workplace processes, but they involve information that can carry heightened privacy concerns.

The federal regulatory landscape remains fragmented, while state laws such as BIPA impose specific obligations and can create significant litigation exposure. The Seventh Circuit’s Clay decision is a useful example of how quickly the legal landscape can evolve. The decision reduced potential damages exposure in certain pending BIPA cases, but it did not change the fundamental responsibility of employers to understand and comply with applicable biometric privacy requirements.

For employers, the key takeaway is simple: biometric data should be treated as highly sensitive information, and compliance should be considered before the first scan- not after the first lawsuit.

Need help reviewing your hiring practices? MyHRConcierge and MyHRScreens offer practical and compliant HR support. Contact us today at 855-538-6947sales@myhrconcierge.com. Or, schedule a convenient consultation below: