Chicago CT Book a consultation

Min read · BlogIT strategy & security

Illinois BIPA Compliance for Small Business: What Chicago Employers Need to Know

In shortA plain-English guide to Illinois BIPA compliance for Chicago small businesses using fingerprint clocks, facial recognition, or biometric access control.

If your Chicago business uses a fingerprint time clock, a facial recognition entry system, or a hand-scan access control panel on the warehouse door, you are collecting biometric data — and in Illinois, that puts you squarely inside one of the strictest privacy laws in the country. The Biometric Information Privacy Act, known as BIPA, has generated more class action litigation against Illinois employers than almost any other state statute, and small and mid-size businesses are not exempt. Many of the businesses that have settled BIPA claims for six and seven figures were not tech companies — they were restaurants, staffing agencies, gas stations, and warehouses that adopted a biometric time clock to simplify payroll without realizing the consent paperwork had to come first.

This matters more for Chicagoland employers than almost anywhere else in the country, because BIPA is uniquely Illinois law. A business with locations in Illinois and Indiana, or a franchise operator expanding from downstate into the city, cannot assume the compliance approach that works elsewhere in the Midwest applies here. Illinois courts have been consistently aggressive in enforcing BIPA's technical requirements, and the statute's private right of action means employees — not just regulators — can and do bring suit directly.

This guide walks through what BIPA actually requires, where Chicago small businesses most commonly get exposed, and the practical steps an IT and HR team can take to close the gap before it becomes a lawsuit.

What Counts as Biometric Data Under BIPA

BIPA defines "biometric identifiers" narrowly but specifically: retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry. It explicitly excludes photographs, physical descriptions, and information captured from health care treatment. The distinction matters — a security camera recording video of employees in a Chicago retail store is generally not a BIPA issue on its own, but running that footage through facial recognition software to identify individuals crosses into biometric identifier territory and triggers the law's requirements.

The most common sources of BIPA exposure for Chicagoland small businesses are: fingerprint or hand-scan time clocks used for payroll and attendance; facial recognition used for building access control or point-of-sale fraud prevention; voice authentication used in call center or phone banking applications; and biometric login for shared workstations in medical offices, where thumbprint scanners are common for accessing electronic health record systems. Any one of these, deployed without the required written policy and signed consent, creates liability.

The Four Requirements Every Chicago Business Must Meet

BIPA compliance rests on four specific obligations, and Illinois courts have shown little tolerance for businesses that satisfy some but not all of them:

A written, publicly available retention and destruction policy. The business must maintain a policy that establishes a retention schedule and guidelines for permanently destroying biometric identifiers — generally when the purpose for collection has been satisfied or within three years of the individual's last interaction with the business, whichever comes first. "Publicly available" typically means the policy is posted somewhere accessible, not buried in an internal drive only HR can see.

Written notice before collection. The individual must be informed in writing that their biometric identifier is being collected or stored, before the collection happens. A verbal explanation from a manager on day one does not satisfy this requirement.

Disclosure of purpose and retention length. The written notice must specify the specific purpose for collecting the data and the length of time it will be collected, stored, and used. Generic language like "for business operations" has been challenged as insufficiently specific in Illinois litigation.

A signed written release. The individual must sign a written release authorizing the collection before the first scan is taken. This is the step most frequently skipped by Chicago small businesses that roll out a biometric time clock quickly during a payroll system transition — the hardware gets installed and employees start clocking in with a thumbprint before the consent paperwork catches up. That sequencing error, even if corrected within days, is itself a BIPA violation for every employee who scanned before signing.

Why Small Businesses Are Not Protected by Size

A persistent misconception among Chicago small business owners is that BIPA enforcement targets large employers with thousands of workers. In reality, the statutory damages structure — $1,000 per negligent violation, $5,000 per intentional or reckless violation, with attorneys' fees recoverable on top — makes even a 20-person business a viable litigation target, because damages accrue per violation, and courts have interpreted each unauthorized scan as a separate violation. A restaurant with 15 employees clocking in and out five days a week for a year without proper consent can accumulate thousands of individual violations well within a single employee's tenure.

The 2019 Illinois Supreme Court decision in Rosenbach v. Six Flags Entertainment Corp. removed the last practical defense many businesses relied on: the plaintiff does not need to demonstrate actual financial harm to sue. The mere fact that biometric data was collected without complying with BIPA's procedural requirements is sufficient to bring a claim. That ruling opened the door to a wave of litigation against employers of every size across Illinois, and Chicagoland's dense concentration of small and mid-size businesses using time clock and access control systems has made the region a focal point.

Common BIPA Gaps We See in Chicago Businesses

Working with small businesses across the Chicagoland area, a few patterns show up repeatedly. First, businesses that switched payroll or time-and-attendance vendors and inherited a biometric time clock as part of the new system, without anyone confirming the vendor's consent workflow actually met BIPA's specific written-notice and signed-release requirements — many payroll vendors provide a generic terms-of-service checkbox that does not satisfy Illinois law. Second, businesses with high employee turnover — restaurants, retail, warehousing — where new hires are enrolled in the time clock on day one as part of a rushed onboarding process, and the consent form gets signed after the employee has already scanned their fingerprint during training. Third, security vendors installing facial recognition entry systems at a Chicago office or facility without flagging to the client that the system falls under BIPA at all, leaving the business owner unaware they have any compliance obligation until a demand letter arrives.

A fourth, less obvious gap: businesses that discontinue a biometric system but never delete the historical data. If a Chicago manufacturing business replaced its fingerprint time clock with a badge-based system two years ago but the old biometric templates are still sitting in a database or on a decommissioned server, that unretained data is itself a live BIPA violation regardless of whether the system is still in active use.

Practical Steps to Get Compliant

Start with an inventory. Identify every system in your business — time clocks, access control, point-of-sale fraud tools, medical record logins — that collects a fingerprint, face scan, iris scan, or voiceprint. Many Chicago business owners are surprised to find two or three systems doing this once IT actually audits the technology stack rather than relying on memory.

Draft or update the written retention and destruction policy, and make it genuinely accessible — posted on an internal HR portal at minimum, and ideally referenced in the employee handbook with a link or physical copy available on request. Confirm the policy's retention window is actually enforced in the underlying system's configuration, not just written down and ignored by the software's default settings.

Build the written notice and signed release into the onboarding sequence before system access is provisioned — not after. For Chicago businesses onboarding hourly staff quickly, this means the biometric consent form needs to be part of day-one paperwork completed before the employee is walked over to the time clock, not a follow-up task for the second week.

Finally, review your vendor contracts. If a third-party payroll, security, or point-of-sale vendor handles the biometric data on your behalf, confirm contractually who is responsible for retention, destruction, and breach notification — BIPA liability generally falls on the business collecting the data, not the vendor supplying the hardware, so a vendor's assurance that "we're BIPA compliant" does not automatically transfer that compliance to your business's own policies and consent records.

Working With an IT Partner on BIPA Compliance

BIPA compliance sits at the intersection of legal policy and technical configuration, which is why it often falls through the cracks between a business's attorney and its IT vendor. An attorney can draft the written policy language, but confirming that a time clock or access control system is actually configured to delete biometric templates on the retention schedule the policy promises — and that the consent capture workflow is technically enforced rather than optional — requires someone who understands the underlying systems. A Chicagoland IT consulting partner can audit which systems collect biometric data, verify vendor retention and deletion settings match your published policy, and build the consent capture step into your onboarding technology so it cannot be skipped during a busy hiring week.

Given the volume of BIPA litigation Illinois has seen since Rosenbach, treating this as a one-time compliance project rather than an ongoing part of IT governance is a mistake. New hires, new locations, and new vendor systems each reset the compliance clock, and a Chicago business that got its original time clock rollout right five years ago can still be exposed today if a newer facial recognition entry system or a replacement time-and-attendance vendor was never run through the same review.

Frequently Asked Questions

What is the Illinois Biometric Information Privacy Act (BIPA)?

The Illinois Biometric Information Privacy Act, passed in 2008, regulates how private entities collect, store, use, and share biometric identifiers such as fingerprints, facial geometry scans, iris scans, and voiceprints. It requires written consent before collection, a published retention and destruction policy, and a ban on selling or profiting from biometric information. BIPA includes a private right of action, meaning an employee or customer can sue directly for a violation without a state agency bringing the case first. For Chicago and Chicagoland small businesses using fingerprint time clocks, facial recognition systems, or biometric access control, BIPA compliance carries real financial exposure.

Does BIPA apply to a small business with a fingerprint time clock?

Yes. BIPA applies to any private entity operating in Illinois that collects biometric identifiers, with no small-business exemption. If a Chicago restaurant, warehouse, medical office, or retail store uses a fingerprint or hand-scan time clock, that business must comply with BIPA's consent, disclosure, retention, and security requirements before the first scan is taken. This has been confirmed in Illinois case law involving small and mid-size employers, not just large corporations, and the vendor supplying the time clock hardware is not automatically liable in the employer's place.

What are the penalties for a BIPA violation in Illinois?

BIPA allows statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation, plus attorneys' fees and costs, with no requirement to prove actual financial harm. Because Illinois courts have ruled that each individual scan without proper consent can count as a separate violation, damages compound quickly across an employee base clocking in and out daily. The 2019 Illinois Supreme Court ruling in Rosenbach v. Six Flags confirmed plaintiffs do not need to show actual injury beyond the statutory violation, and BIPA class actions against Illinois employers of all sizes have resulted in settlements from tens of thousands to millions of dollars.

What does a business need to do to comply with BIPA before using biometric technology?

Before collecting biometric identifiers, a business must publish a written retention and destruction policy, inform individuals in writing that biometric data is being collected and stored, disclose the specific purpose and length of time the data will be used, and obtain a signed written release before the first scan occurs. Consent obtained after the fact or a generic handbook clause does not satisfy BIPA. A Chicago IT consulting partner can help draft the required policy, build the consent workflow into onboarding, and configure retention settings to match the published policy.

How long can a Chicago business retain employee biometric data under BIPA?

BIPA requires biometric identifiers be permanently destroyed when the initial purpose for collection is satisfied, or within three years of the individual's last interaction with the business, whichever occurs first. For an employee time clock, this generally means fingerprint or hand-scan templates must be deleted promptly after termination rather than left indefinitely in the system's database. Businesses should confirm with their vendor exactly how deletion is triggered and verify it directly rather than assuming default settings meet BIPA's destruction timeline.

Keep readingIT strategy & security planning

Related articles

Get a plain-English IT plan.

A roadmap, a budget and a security baseline, in the right order. The first call is free, and we reply within one business day.

Book a consultation (224) 382-4084