Back to the hub

Does BIPA apply to employees?

Yes. Illinois BIPA has no employee exemption, so an employer that collects biometric identifiers such as fingerprint or face-scan timeclocks must follow the law. The Act expressly contemplates employment, defining a written release to include one an employee signs as a condition of employment. State and local government employers are excluded.

Applies to: Private employers in Illinois that collect biometric identifiers or information from employees, such as fingerprint, hand-geometry, or facial-recognition timeclocks and access systems.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

The biggest source of BIPA litigation is not consumer apps. It is the workplace, where employers put fingerprint and hand-scan timeclocks on the wall and never completed the notice-and-consent steps. If you collect biometric data from your own staff in Illinois, BIPA applies to you, and the statute says so in more than one place.

Is there an employee exemption in BIPA?

No. The Illinois Biometric Information Privacy Act sets duties for any "private entity" that collects biometric identifiers, with no exception for data collected from employees. Section 10 makes the employment context explicit: it defines a "written release" to include, "in the context of employment, a release executed by an employee as a condition of employment." A statute that spells out how workplace consent works is not a statute that exempts workplaces. Employers carry the full section 15 duties for staff biometrics.

What biometric systems at work are covered?

Section 10 defines a biometric identifier as a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. That description fits the everyday tools employers use: fingerprint and hand-geometry timeclocks, facial-recognition sign-in, and voice systems. When one of these reads an employee, it collects a biometric identifier, which triggers the written notice and consent duty in section 15(b) and the public retention policy in section 15(a). The rule applies before the first scan, at enrollment, not after a complaint.

Does the healthcare exemption cover hospital staff?

No. Section 10 excludes "information captured from a patient in a health care setting" and information used for treatment, payment, or operations under HIPAA. That carve-out is about patients, not employees. A hospital or clinic that scans a nurse's or technician's fingerprint to clock in is collecting employee biometric data, which the patient exclusion does not reach. Healthcare employers have to comply for their workforce the same as any other employer.

Who is not covered?

The definition of "private entity" in Section 10 excludes a State or local government agency, and also excludes any court, clerk, or judge. So a public-sector employer is outside BIPA's private right of action. Private employers, including nonprofits and companies of every size, are covered. If you are a private business scanning employees in Illinois, do not assume size or sector gets you out. For the penalties that attach to violations, see the BIPA statutory damages page.

Next step

If your timeclocks, door access, or apps read employee fingerprints or faces in Illinois, the free 2-minute Obligation Scan flags whether BIPA applies and lists the notice, consent, retention, and security steps you owe, so a workplace scanner does not become a class action. The US state privacy laws hub shows how Illinois sits alongside the other biometric laws.

Compliance checklist

  • List every workplace system that reads a fingerprint, hand, face, or voice, including timeclocks and door access.
  • Give each employee the section 15(b) written notice and obtain a written release, which may be a condition of employment, before the first scan.
  • Publish the written retention and destruction policy that section 15(a) requires.
  • Do not sell or profit from the biometric data (section 15(c)), and protect it with reasonable security (section 15(e)).
  • Check vendor contracts, because your timeclock provider receiving the data can also raise disclosure duties.

Sources

Last verified: 2026-08-12

Informational, not legal advice.