08/27/2026
You Just Installed Fingerprint Time Clocks. Hereâs the Law You Might Not Know Exists.
Hereâs what most growing companies donât realize: you just triggered a category of law completely separate from standard employment compliance.
Biometric privacy law.
Why This Category Is Different
Most data privacy rules treat biometric data as uniquely sensitive, more like a Social Security number than an email address.
Unlike a password, you canât reset a fingerprint. Once itâs compromised or mishandled, the person canât get a new one.
Several states have enacted biometric privacy laws, including Illinois (BIPA), Texas (CUBI), Washington (WBPA), and California (CCPA/CPRA biometric provisions). Illinois BIPA has generated the most private litigation to date, building specific legal requirements around collecting fingerprints, facial geometry, retina scans, and voiceprints.**740 ILCS 14/15, Tex. Bus. & Com. Code § 503.001, Rev. Code Wash. (ARCW) § 19.375.020.
Other states have followed with their own versions, and more are introducing bills every year.
If your company operates in one of these states, or employs people who do, this law can apply to you even if youâve never thought of yourself as a âtech companyâ or a âdata company.â
A biometric time clock or an access-control badge system is enough.
The Compliance Gap Growing Companies Fall Into
Full article in the comments