Workplace Facial Recognition Attendance: Laws and Refusal

TL;DR

Facial recognition attendance has moved from warehouses and trucking yards into restaurants, retail back rooms, and corporate offices. In a few states the law treats your face scan like a fingerprint: you have to give written informed consent before your employer collects it, the employer must publish a retention schedule, and you can sue if they collect without consent. In most states the law is silent or weak, and the practical limit on what your employer can do is whatever your state legislature and the Equal Employment Opportunity Commission decide. This guide walks through what the systems actually store, which laws say you can refuse, and how to ask for an alternative without getting fired.

What a facial recognition clock-in actually collects

When an employer rolls out face-based attendance, the worker stands in front of a camera at the start and end of each shift. The system captures an image, converts it into a numeric template, and compares that template to the one stored when the employee first enrolled. Each clock-in produces a "yes, this is the enrolled person" or "no, this is not" decision, plus a score and a timestamp.

The biometric identifier covered by name in the major state laws is "facial geometry": the measurement-based pattern unique to a face. The American Civil Liberties Union of Illinois, summarising what counts under the Illinois Biometric Information Privacy Act (BIPA), lists "retina or iris scans, fingerprints, voiceprints, hand scans, facial geometry, DNA, and other unique biological information" as the identifiers the statute reaches.[1] Washington's biometric statute, RCW 19.375.010, defines "biometric identifier" the same way by category, including fingerprints, voiceprints, eye retinas, irises, and "other unique biological patterns or characteristics that is used to identify a specific individual."[2]

The exact data stored depends on the vendor and is one of the questions worth asking in writing before enrolling. After enrollment, every punch-in compares the live capture against the stored reference, so the workflow looks the same from the worker's side whether the system saves a face template, a face image, or both.

Two secondary collection points often travel with face attendance: liveness detection to prevent photo spoofing, and geolocation. Fixed terminals sit at the time clock and pair the face check with the location of that terminal; mobile apps can pair the face check with the phone's GPS coordinates so the employer can confirm the worker really is on site at clock-in and clock-out.

The real workplace data: not just the template

What is collected, retained, and shared varies more than vendors usually admit. Washington's statute calls out the operator side of the pipeline by defining a "biometric system" as "an automated identification system capable of capturing, processing, and storing a biometric identifier, comparing the biometric identifier to one or more references, and matching the biometric identifier to a specific individual."[2] That is the whole stack: capture, storage, comparison, match.

For a worker, the relevant questions are:

  • What data leaves the device? A pure on-device match can run without sending anything off the clock-in terminal. A cloud system sends the template to a vendor server for comparison.
  • How long is the template kept? State biometric laws in Washington and Texas set a "timely" or scheduled destruction requirement, with the time limit pegged to the original purpose for which the data was collected.[2]
  • Who else gets it? Ask whether the matching engine runs on the vendor's server or on a third-party AI service, and whether the vendor has a process for handing biometric data over to law enforcement requests. That is information most employers will need to look up before answering, which is the point.

Each of these flows without a state biometric law in the worker's favor is governed by whatever the employer's own policy says it is, which usually means whatever is most convenient for the employer.

The state map: who can refuse, who cannot

U.S. biometric privacy law is a patchwork, not a floor. Below is what the three named biometric laws actually give a worker, plus what happens in states with no biometric statute at all.

Illinois (BIPA): the private right of action

BIPA was signed into law on October 3, 2008, and is the only state biometric statute with a private right of action that workers can use directly.[3] BIPA requires that, before a "private entity" collects a biometric identifier from a person, it must (1) inform the person in writing of what is being collected or stored, (2) inform the person in writing of the specific purpose and length of time for which the data is being collected, stored, and used, and (3) obtain a written release.[1] Per the ACLU of Illinois summary, a worker whose employer scans their face at clock-in without those three steps in place has a BIPA claim whether or not anything bad happened with the data afterwards.

BIPA's damages structure is what made it a litigation magnet. The statute allows the aggrieved person to recover $1,000 per negligent violation or actual damages, whichever is greater, and $5,000 per intentional or reckless violation or actual damages, whichever is greater, plus reasonable attorneys' fees and costs.[3] For employers using fingerprint or face time clocks, settlements ran into hundreds of millions: Facebook paid $650 million in 2020, TikTok's parent settled for $92 million in 2021, Google settled for $100 million in 2022, and Pret A Manger settled a fingerprint-timeclock class action for $677,000 covering around 800 workers.[4]

For face-clocked employees, the BIPA exposure used to scale with every scan. That math changed on April 1, 2026, when the U.S. Court of Appeals for the Seventh Circuit decided Clay et al. v. Union Pacific Railroad Co. et al., Nos. 25-2185 et al. The court held that the August 2, 2024 amendment to BIPA Section 20 (Public Act 103-0769) applies retroactively to pending cases: a single violation caps damages at one recovery of $5,000 intentional or $1,000 negligent per person, even when the plaintiff was scanned thousands of times.[5] The Clay plaintiff had alleged about 1,500 fingerprint scans at facility access points, which on the old per-scan theory translated to roughly $7.5 million of potential exposure.[5] Willis, another consolidated case, involved biometric timekeeping allegations with putative class exposure that the dissent described as billions.[5]

The April 2026 ruling did not erase BIPA, it recalibrated it. The Seventh Circuit treated the amendment as procedural because it governs damages rather than the underlying collection rules, so it applies retroactively under Illinois law. Plaintiffs still have a path to one recovery per person; defendants just no longer face eight-figure per-scan damages in pending cases. Plaintiffs' lawyers are likely to keep filing, but the size of the settlement pressure is now lower than during the per-scan era.[6]

Washington (RCW 19.375): consent, but the state sues

Washington's biometric statute, codified at RCW 19.375, defines what counts as a biometric identifier and a biometric system, and Section 19.375.020 sets the operative consent rule: "A person may not capture or collect a biometric identifier of an individual, unless the individual first receives notice of and affirmatively grants consent to the capture or collection of the biometric identifier."[2]

The catch for workers is enforcement. RCW 19.375.030 makes Washington's biometric statute enforceable under the state's Consumer Protection Act, with the attorney general bringing actions. There is no private right of action and no class-action mechanism.[4] The Epstein Becker Green litigation roundup confirms: "Enforcement in both [Texas and Washington], however, is left to the state attorney general, not private lawsuits. This means no BIPA-style class actions."[4]

What the worker gets from Washington law is therefore the right to refuse and let the AG do the suing. Documenting the request in writing is the move. If the employer collects anyway, the documentation is what an attorney general complaint needs.

Texas (Business and Commerce Code Chapter 503, CUBI): consent + AG enforcement

Texas's biometric law is the Capture or Use of Biometric Identifier Act, codified at Texas Business and Commerce Code Chapter 503. CUBI's structure is similar to Washington's on the consent side: a private entity must give notice and obtain consent before capturing a biometric identifier. Like Washington, enforcement is by the Texas attorney general; CUBI does not create a private right of action, which Epstein Becker Green confirms in the cross-state comparison: "Enforcement in both states, however, is left to the state attorney general, not private lawsuits. This means no BIPA-style class actions."[4]

The practical Texas experience is that the AG goes after the big cases, not individual workers. Workers who want to push back in Texas should put the refusal in writing and report. The Texas attorney general's office accepts consumer complaints online, and CUBI gives the AG the standing to act on a documented pattern.

The rest of the country: silence

Most U.S. states have no dedicated biometric privacy statute. In those states the question of whether your employer can face-scan you at clock-in is governed by general privacy law, common-law torts, contract, and the ADA's accommodation process. Twenty-three states have passed or expanded a biometric statute by 2025, per this site's state-by-state breakdown, but only Illinois has a private right of action.[7]

The Epstein Becker Green litigation roundup tracks the bills pending outside Illinois: "New York's legislature has repeatedly considered a 'Biometric Privacy Act' modeled on Illinois' BIPA," with similar bills pending in Massachusetts and Missouri, and "As of mid-2025, these bills have not yet become law."[4] Until they do, the rule outside Illinois is whatever the employer puts in the employee handbook.

The refusal playbook: how to push back without losing your job

Refusing facial recognition at clock-in is a workplace conversation, not a courtroom one. The legal hooks above matter, but the first move is procedural.

  1. Ask for the policy in writing. "What data is collected, how long is it kept, who gets it" is exactly what Washington's RCW 19.375.020 already requires before consent.[2] If the employer cannot answer in writing, that itself is a tell. Workforce management vendors publish data-handling documentation; ask the vendor's site as well as your HR contact.
  2. Offer an alternative. Most vendor systems support multiple clock-in methods: badge or fob, PIN, fingerprint, or face. The face option is often sold to management as the secure default because it stops buddy-punching. A badged or PIN clock-in is not as secure but it is usually available. A written request for the badge or PIN alternative turns "I refuse" into "I am willing to use a less secure method," which is harder to discipline.
  3. If you are in Illinois, document the consent problem. Under BIPA, collection without "written release" after written notice of the specific purpose and retention period is the violation, not "your face template leaked."[1] The right move is to ask HR, in writing, whether BIPA's three-step notice-and-consent process was followed before you enrolled. If the answer is fuzzy or no, that conversation is the start of a BIPA record even if you never file suit.
  4. If you are in Washington or Texas, document and report. Since neither statute has a private right of action, the practical play is to put the refusal in writing and report. The Washington attorney general's office accepts Consumer Protection Act complaints online; the Texas attorney general's office accepts CUBI complaints the same way.
  5. ADA angle if the system is unreliable for you. The ADA requires reasonable accommodation for disability, and facial recognition systems that fail on certain faces, dark skin, women, certain ages, are documented.[7] If the system does not work for you, the request for an alternative timekeeping method is an accommodation request, which triggers a different (and stricter) process for the employer.
  6. Religious objection angle if relevant. Title VII of the Civil Rights Act requires reasonable accommodation of religious observance and practice. If you have a sincere religious reason to refuse biometric enrollment (some faith traditions treat biometric capture as a bodily or spiritual integrity question), the request becomes a Title VII accommodation request, not just a privacy complaint. Frame it that way only if it is true; otherwise it is a privacy-based request, not a Title VII claim.

The worst move is the silent enrollment. Standing in front of the camera because everyone else is doing it counts as consent under most state biometric laws because the "affirmative" grant can be a physical act of participation. If the system is already live and you have not objected in writing, send a written objection now: "I am not consenting to biometric collection under [state statute where applicable]. Please provide a non-biometric timekeeping method." That email is the paper trail a later complaint will turn on.

What still has not been decided in court

A few open questions will decide how much cover the law gives you over the next year or two:

  • How BIPA's per-person cap plays out in facial-recognition cases. The Seventh Circuit's April 1, 2026 ruling stopped the per-scan damages theory, but the per-person claim still exists. The next battle will be whether face-clock workers can aggregate a "single violation" across years of clock-ins into something bigger than $5,000 of statutory damages. The statute caps it. The plaintiffs' bar will try to route around the cap with state common-law claims. Clay is the foundational ruling but not the last word.
  • Whether New York's proposed biometric privacy act ever becomes law. New York's legislature has repeatedly considered a "Biometric Privacy Act" modeled on Illinois' BIPA, with similar bills pending in Massachusetts and Missouri; as of the Epstein Becker Green litigation roundup, these bills had not yet become law. If any of them pass, the litigation map expands to a second jurisdiction.[4]
  • Whether other states add a private right of action. Massachusetts, Missouri, and other states have carried biometric-privacy bills without passing them. The Pret A Manger-scale class actions continue to be filed only in Illinois. The day another state passes a BIPA-equivalent, the litigation floodgates open in a second jurisdiction.

Until any of that lands, the operational reality is two-track. Track one is the legal hook: written informed consent under BIPA for Illinois workers, with the rest of the country waiting on legislative action. Track two is the workplace conversation: a clear written objection, a request for a non-biometric alternative, and ADA or Title VII framing where the facts support it. The face-clock terminal at the time clock is not the place to have that conversation. Email is.

Sources

  1. ACLU of Illinois: Biometric Information Privacy Act (BIPA). Quoted text on covered biometric identifiers ("retina or iris scans, fingerprints, voiceprints, hand scans, facial geometry, DNA, and other unique biological information") and on the BIPA written-consent sequence (inform in writing of what is being collected or stored, inform in writing of the specific purpose and length of time, then obtain written release).
  2. Washington State Legislature: RCW 19.375.010, Definitions, and RCW 19.375.020. Verbatim: "A person may not capture or collect a biometric identifier of an individual, unless the individual first receives notice of and affirmatively grants consent to the capture or collection of the biometric identifier." Definitions of "biometric identifier" and "biometric system" quoted in the article. Enacted by 2017 c 299 § 3.
  3. Wikipedia: Biometric Information Privacy Act. Background only: BIPA enacted October 3, 2008; statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation; private right of action. Wikipedia is capped as one tertiary citation per the site's sourcing rule; load-bearing BIPA claims elsewhere in this article are tied to primary sources.
  4. Epstein Becker Green: Biometric Backlash: The Rising Wave of Litigation Under BIPA and Beyond. Settlement figures: Facebook $650 million (2020), TikTok $92 million (2021), Google $100 million (2022), Pret A Manger $677,000 (~800 workers, fingerprint timeclock); August 2024 BIPA amendment (Public Act 103-0769) caps damages to one per person; Texas and Washington biometric laws enforced by state attorney general only; New York's S1422 and parallel bills in Massachusetts and Missouri had not yet become law as of mid-2025.
  5. Duane Morris Class Action Defense Blog: Seventh Circuit Holds BIPA Amendment Applies Retroactively, Reversing Three Illinois Federal Court Decisions (April 3, 2026). Clay et al. v. Union Pacific Railroad Co. et al., Nos. 25-2185 et al., decided April 1, 2026. Quoted: "a single violation" entitling "at most, one recovery"; Clay plaintiff alleged ~1,500 scans; Willis involved "biometric timekeeping" with putative class exposure described by the dissent in billions.
  6. Fisher Phillips: Major Biometric Win for Business in Illinois. Confirms the Seventh Circuit's procedural/remedial classification of the August 2024 amendment, explains why the ruling is retroactive, and describes the practical impact on remand (no vested right to a particular remedy before judgment, lower statutory damages exposure, possible reconsideration of subject-matter jurisdiction).
  7. State of Surveillance: 23 States Now Have Biometric Privacy Laws: Here's What Protects You (And What Doesn't). The site's existing state-by-state tracker, used here for the 23-state count and for the demographic-failure framing of the ADA-accommodation playbook. Sibling reference, not a primary source for any claim above.