Timekeeping Traps in Illinois

Article
Beware if you are using biometric readers as part of your timekeeping system in Illinois. Employers in Illinois are facing an increasing number of lawsuits alleging violations of the Illinois Biometric Information Privacy Act (BIPA). The lawsuits primarily challenge employers’ use of timekeeping systems that rely upon biometric data (e.g., employee fingerprints, retina or iris scans) to track hours worked. The lawsuits do not allege misuse of the data. Instead, they challenge the employers’ alleged failure to follow BIPA’s specific notice and consent requirements. To avoid potential litigation by your employees in Illinois, you should be familiar with BIPA and take steps to ensure compliance with its notice and consent requirements.

What is BIPA?  BIPA was enacted in 2008 in response to growing concerns about the use and disclosure of biometric information and the growing risk of identity theft. BIPA makes it unlawful for employers to collect an employee’s biometric information without notice and consent. Unlike similar laws in other states, BIPA expressly regulates employer conduct. Key provisions of the law include the following:

  • Definition of Biometric Information. Biometric information is broadly defined to include any “biometric identifier” such as a retina or iris scan, fingerprint, or the scan of a hand or face. Significantly, the definition also includes any information based on a biometric identifier, which includes the size or measurement of an employee fingerprint. Many timekeeping systems store measurements associated with an employee’s fingerprints – not the actual fingerprint. Collecting these measurements is subject to BIPA.
  • Notice and Consent Requirements. Under BIPA, employers are required to:
    • Inform employees that biometric information is being collected and the purpose for the collection.
    • Inform employees how long the biometric information will be retained.
      • BIPA requires employers to permanently destroy biometric information when the initial purpose for collecting the information has been satisfied or within 3 years, whichever occurs first.
    • Obtain employees’ written consent to collect the biometric information.
    • Develop a written policy establishing a retention schedule and guidelines for permanently destroying biometric data.
    • Comply with the written policy.
    • Protect the biometric information from unlawful disclosure.
  • Additional Prohibitions: Employers cannot sell, lease, trade or otherwise profit from the biometric information, and they cannot disclose or otherwise disseminate the information unless the employee consents.
  • Penalties for Violations: BIPA allows an employee to sue to recover the greater of actual damages or $1,000 per violation ($5,000 if the violation was intentional or reckless).

Are there defenses to BIPA lawsuits?  The best defense to a BIPA lawsuit is to develop in advance the required written policy and provide employees the required written notices. Employers should also require that employees sign a written release – consenting to the collection and storage of the biometric data – as a condition of employment. For those employers already in litigation, some have successfully argued that there has been no actual harm to the employee when the only violation was a failure to provide notice or obtain written consent. In some instances, courts have held that “bare procedural violations” of BIPA (i.e., failing to notify and obtain requisite consent) – without additional allegations of wrongful use or disclosure of biometric information resulting in harm – were insufficient to state a valid claim against the employers. There is significant litigation risk, however, which can easily be avoided by addressing the BIPA issues in advance.

Contact Information. For more information, please contact Randall Constantine (404.888.8877) or Emily Friedman (404.888.8871).

Media Contact

Public Relations Contact
Kate Lenders
Senior Marketing Manager
klenders@sgrlaw.com
312-360-6478

Jump to Page

Smith, Gambrell & Russell, LLP Cookie Preference Center

Your Privacy

When you visit our website, we use cookies on your browser to collect information. The information collected might relate to you, your preferences, or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. For more information about how we use Cookies, please see our Privacy Policy.

Strictly Necessary Cookies

Always Active

Necessary cookies enable core functionality such as security, network management, and accessibility. These cookies may only be disabled by changing your browser settings, but this may affect how the website functions.

Functional Cookies

Always Active

Some functions of the site require remembering user choices, for example your cookie preference, or keyword search highlighting. These do not store any personal information.

Form Submissions

Always Active

When submitting your data, for example on a contact form or event registration, a cookie might be used to monitor the state of your submission across pages.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek