Clavira
← Back to Blog

industry insights

Biometric time clock consent form: what it must say

Troy SatchellAugust 16, 20266 min read

A working consent form for fingerprint and hand-scan time clocks, the alternative you owe anyone who refuses, and the record that decides the case.

A thumb pressed to the green-lit fingerprint sensor of a wall-mounted time clock with a keypad and small display

Key Takeaways

  • Written consent has to be signed before the first scan. After is not consent, it is evidence.
  • The form needs the specific identifier, the purpose, the retention period, and the destruction trigger.
  • Offer a non-biometric alternative. A refusal handled badly becomes the plaintiff's best exhibit.
  • The form is not the defense. The dated enrollment record is.

Yes, you can put a fingerprint time clock in the break room. You need a written consent form, signed by each employee, before the first scan.

That is the short answer. The rest of this is what the form has to say, what you owe the person who refuses, and the record that decides the case if this ever goes wrong.

Most of what is written on this topic is published by someone selling a time clock, a form builder, or a payroll platform. We sell none of those, so here is the version without the product attached.

Are biometric time clocks legal?

Legal in every state, subject to consent rules that vary a lot.

Illinois is the strict one. The Biometric Information Privacy Act, 740 ILCS 14/, requires written notice and a written release before collection, and it lets employees sue directly. Texas and Washington have biometric statutes enforced only by their attorneys general. Colorado added biometric provisions through HB 24-1130. Minnesota treats biometric data as sensitive under its consumer privacy act.

If you operate in more than one state, write to the strictest rule you touch. In practice that means Illinois. Check our biometric law tracker for current status before you rely on any of this, because these move every legislative session.

What a biometric time clock consent form must say

Four elements. Miss any one and the form does not do its job.

The specific identifier. Name it. Say "fingerprint" or "hand geometry scan," not "biometric data." Vague scope is the most common defect in forms I see.

The purpose. Why you are collecting it. For a time clock that is timekeeping and payroll accuracy. Not "security and business purposes."

The retention period. How long you keep it, stated as a rule someone can apply. Illinois Section 15(a) sets the outer edge: destroy at the earlier of the purpose being satisfied or three years after the person's last interaction with you.

The destruction trigger. What event starts the clock. For employees it is usually separation.

Then a signature and a date. The date is the part that matters most, and it is the part most often missing.

A consent form template for a biometric time clock

Start from this. Have your employment counsel adapt it to your states before anyone signs. This is a starting point, not legal advice, and it is not a substitute for review. Bracketed items are fill-ins.

Consent to Collection and Use of a Biometric Identifier

[Company] uses a time clock that collects a biometric identifier: a scan of your fingerprint. The system converts the scan into a mathematical template. [Company] does not retain the image of your fingerprint.

Purpose. [Company] collects and uses this identifier solely to record your hours worked and to administer payroll.

Retention. [Company] will retain the identifier until the purpose of collection has been satisfied, or three years after your last interaction with [Company], whichever occurs first. Upon separation of employment, [Company] will permanently destroy the identifier within [30] days.

Disclosure. [Company] will not sell, lease, trade, or otherwise profit from your identifier. [Company] will not disclose it except as required by law, or to [Vendor], which operates the timekeeping system under contract.

Alternative. If you do not wish to use the biometric time clock, [Company] will provide a non-biometric method of recording your hours at no cost and with no effect on your terms of employment. Contact [role] to arrange it.

Consent. I have read the above. I consent to [Company] collecting, storing, and using my biometric identifier as described. Signed, dated, with the employee's printed name.

Two notes on the template. The vendor disclosure line matters because the clock manufacturer usually processes the template, and that is a disclosure. The alternative paragraph is not required by BIPA in those words, but including it converts your best defense into a document.

Can an employee refuse to use a fingerprint time clock?

They can decline to sign. What happens next is where employers get into trouble.

BIPA requires informed written consent. It does not, in terms, guarantee an employee a badge or a PIN. But consent obtained under a threat to someone's job is a weak document, and a plaintiff's lawyer will say so. There are also separate accommodation duties: a sincerely held religious objection or a disability affecting the scan can trigger obligations under Title VII or the ADA that have nothing to do with biometric law.

The practical rule: never make the scanner the only way to get paid.

What you owe the employee who says no

Offer a real alternative, at no cost, with no penalty. A PIN pad, a badge, a supervisor-attested paper record.

Then document three things. That you offered it. What they chose. The date. A refusal you handled well is a non-event. A refusal you handled badly is the plaintiff's opening exhibit, and it will be read aloud.

Do not route the objection through the manager who wants the clock working. Route it to HR.

Why time clocks generated the largest exposure in BIPA history

This is the part most guidance skips, and it is about your exact system.

Cothron v. White Castle System, Inc., 2023 IL 128004 was a fingerprint time clock case. The Illinois Supreme Court held that each individual scan was a separate violation. Employees clock in and out, often twice more for breaks, five days a week, for years.

Run that arithmetic across a workforce and it produced a theoretical exposure figure of roughly $17 billion for a single employer, a number White Castle itself put forward in the litigation. The court said the number was the legislature's problem to fix.

Your break-room clock is the same fact pattern.

What changed in 2024, and what it does not change

The legislature fixed it. Public Act 103-769, signed 2 August 2024, amended BIPA Section 20 so a person recovers once per subsection regardless of how many times they were scanned.

In April 2026 the Seventh Circuit held that limit applies retroactively to cases already pending, in Clay v. Union Pacific Railroad Company, No. 25-2185 (7th Cir. Apr. 1, 2026). The court reasoned the amendment is remedial because it governs damages rather than liability. Clay had alleged the railroad collected his fingerprint scans approximately 1,500 times, which the opinion noted could have produced $7.5 million in statutory damages for him alone had the violations been found intentional. After the ruling, that is one recovery.

Now the part that did not change. Section 20 damages are still $1,000 for a negligent violation and $5,000 for an intentional or reckless one, per person, per subsection. Employees can still sue directly. The limitations period is still five years, per Tims v. Black Horse Carriers, Inc., 2023 IL 127801. A class of 400 employees with no valid consent on file is still a serious number.

The multiplier shrank. The obligation did not.

The enrollment record that decides the case

Here is the question worth sitting with. If a former employee sued you tomorrow over a scan from 2023, could you produce the consent that covers it, with a date earlier than their first scan?

Most employers cannot. They have a signed form in a personnel file and a time clock database, and no reliable link between them. The form proves someone signed something. It does not prove the sequence, and sequence is the whole case.

What actually holds up is a record showing the consent was captured, when enrollment happened, that they were offered the alternative, and that the template was destroyed on schedule after separation. Four facts, each with a date, each independently verifiable.

That is the work we do at Clavira. We record tamper-evident metadata about biometric events: when consent was captured, when an enrollment occurred, when a retention deadline came due. We never see, store, or process the biometric data itself. The output is a court-defensible record of what your organization did, built so it can be handed to the person it concerns.

None of this is legal advice. Have counsel review your form before anyone signs it. But when you do, ask them a second question after "is this form good?" Ask them: three years from now, what will prove this person signed it before we scanned them?

That answer is the one that matters.