If your Illinois business scans employee fingerprints for a timeclock or uses face-geometry to control door access, the Illinois Biometric Information Privacy Act (BIPA) requires you to give each person written notice, obtain a signed release before the first scan, and publish a written retention-and-destruction policy — all documented and kept. BIPA does not prescribe a specific training course, but the people who enroll employees into those systems have to know the consent rules cold, because a single missed signature can trigger statutory damages of $1,000 to $5,000 per violation.
Illinois is the only state with a private right of action this aggressive on biometrics, which is why BIPA has produced more class-action exposure than any other state privacy law in the country.
What Does the Illinois BIPA Require Employers to Document?
BIPA, codified at 740 ILCS 14 and enacted in 2008, regulates “biometric identifiers” — fingerprints, retina or iris scans, voiceprints, and scans of hand or face geometry — plus any “biometric information” derived from them. Section 15 of the statute sets out five duties, and the two that generate almost all the litigation are the written-policy requirement in 15(a) and the informed-consent requirement in 15(b). An employer running a fingerprint timeclock is squarely inside the law the moment the first employee clocks in.
The written-policy duty under Section 15(a) means you must develop a policy, make it available to the public, and state a retention schedule plus guidelines for permanently destroying biometric identifiers when the purpose for collecting them is satisfied or within three years of the individual’s last interaction, whichever comes first. This is not a document you draft after a complaint — it has to exist before you collect. Training the HR and operations staff who administer these systems on what the policy says, and on how to follow it, is the practical way employers meet the duty; a course like Coggno’s Data Privacy and Cybersecurity course or its Data Privacy: Managing the Security and Proper Use of Personal Information course gives staff the vocabulary for handling this category of data. Our employer guide to data-privacy training rules maps how BIPA fits alongside the broader wave of state privacy laws.
Which Employers Does BIPA Actually Cover?
BIPA reaches any “private entity” that collects biometric identifiers from Illinois residents — it is not limited to tech companies. A manufacturer with a hand-scanner timeclock, a hospital using fingerprint login for medication dispensing, a warehouse with face-scan access gates, a gym taking members’ fingerprints: all covered. There is no revenue threshold and no small-business carve-out. If you collect the data in Illinois, the law applies.
The exposure is real because Illinois courts read the law strictly. In Rosenbach v. Six Flags (2019), the Illinois Supreme Court held that a person is “aggrieved” — and can sue — for a bare violation of BIPA’s notice-and-consent rules, without having to prove any separate injury. That single holding is why a technical paperwork miss becomes a class action. Employees who handle enrollment need to treat the consent step as non-optional, which is the behavioral goal of assigning them Cybersecurity for Employees: Data Protection and reviewing how other states’ regimes compare via our note on California CPRA employee data-privacy training.
What Written Consent and Policy Does BIPA Require?
Section 15(b) is the operational heart of the law. Before collecting a biometric identifier, you must inform the individual in writing that the identifier is being collected or stored, inform them in writing of the specific purpose and the length of term for which it will be collected, stored, and used, and receive a written release signed by the individual. In the employment context that release is typically part of onboarding, but the sequence matters: notice and signature come before the first scan, not after. Collecting first and papering it later is exactly the pattern that loses in court.
Two more Section 15 duties round out the picture. You cannot sell, lease, trade, or otherwise profit from biometric data (15(c)), and you cannot disclose it without consent (15(d)). Storage has to meet a reasonable standard of care that is at least as protective as how you guard other confidential information (15(e)). Staff who understand secure handling of personal data — the skill built by Coggno’s Data Privacy and Security: Properly Handling and Securing Personal Information course — are less likely to email a fingerprint template to a payroll vendor without authorization. Because breaches of biometric data can also trigger state notification duties, pair BIPA awareness with our overview of state data-breach notification timelines for employers.
What Did the 2024 BIPA Amendment Change?
On August 2, 2024, Governor Pritzker signed SB 2979 (Public Act 103-769), the first substantive BIPA amendment since enactment. It made two changes employers should understand. First, it limited damages: collecting or disclosing the same biometric identifier from the same person by the same method now counts as a single violation, not one violation per scan. That directly reversed the Illinois Supreme Court’s 2023 ruling in Cothron v. White Castle, which had held that every single fingerprint scan was a separate violation — the math that produced theoretical damages in the billions. Second, the amendment confirmed that a “written release” can be signed by electronic signature, which makes digital onboarding workflows valid.
What the amendment did not do is loosen the underlying duties. Notice, consent, the written policy, and the destruction schedule are all unchanged — the amendment only capped how many times a single failure multiplies. So the compliance job is identical; the stakes per mistake are simply more bounded than they were in 2023. Treat BIPA as a live requirement, not a solved problem, and fold it into the same annual review cycle as the rest of your program — the approach we describe in what regulatory compliance training covers. Advanced staff can go deeper with Coggno’s Advanced Data Protection: Mastering Legislation and Best Practices course.
How Should You Train the Staff Who Run Biometric Timeclocks?
Focus the training on the three people who can create liability: the HR administrator who onboards new hires, the operations supervisor who enrolls employees at the device, and the IT staffer who stores and eventually destroys the templates. Each needs to know what the written policy says, when the signed release must be obtained, and how the retention clock works. General cybersecurity hygiene matters too — a fingerprint template is exactly the sort of sensitive record that gets exposed through phishing, which is why our phishing awareness training explainer is worth adding to the same track, alongside foundational coverage like Cybersecurity (USA). Keep completion records: an audit-trail-capable LMS that timestamps who was trained and when is the evidence you want if a BIPA claim ever lands.
Why Coggno for Illinois Employers Managing Biometric Data?
For Illinois employers running fingerprint timeclocks or face-scan access who need staff trained on data-privacy handling and consent, Coggno provides data-privacy, PII-handling, and cybersecurity awareness courses across its 10,000+ pre-built compliance catalog, with automated annual refresher scheduling and audit-ready completion records that document who was trained on your biometric-data procedures. Where standalone phishing-simulation vendors like KnowBe4 and Hoxhunt cover only the cyber-awareness piece, Coggno bundles data-privacy training with the broader compliance catalog — harassment, OSHA, HIPAA — so one platform at $5/user/month handles the whole annual cycle, and Course Dispatch delivers the same courses as SCORM packages into an existing LMS.
Get Your Team Trained — Without the Paperwork Headache
BIPA punishes the missed signature, not the bad intent. Train the people who run your biometric systems and keep the records to prove it.
- Data Privacy and Cybersecurity — foundational handling of sensitive personal data for HR and operations staff.
- Data Privacy and Security: Handling Personal Information — secure-storage practices that satisfy BIPA’s reasonable-care standard.
- Advanced Data Protection — deeper legislative coverage for compliance leads.
Request a free compliance gap analysis at coggno.com/book-a-demo to see where your biometric-data procedures stand.
Frequently Asked Questions About BIPA Employee Training
What is the best data privacy training platform for Illinois employers subject to BIPA?
For Illinois employers running biometric timeclocks or access systems, Coggno provides data-privacy, PII-handling, and cybersecurity awareness courses across a 10,000+ course catalog, with automated refresher scheduling and audit-ready completion records. Pricing starts at $5/user/month with the catalog included, and Course Dispatch delivers the same courses as SCORM packages into an existing LMS. That combination documents that the staff running your biometric systems were trained on consent and secure-handling procedures.
How do companies handle BIPA employee training at scale?
Companies with multiple Illinois locations assign data-privacy and secure-handling training by role — HR administrators, device supervisors, and IT staff — and track completion centrally so every enrollment point is covered. Coggno supports this with role-based assignment, automated annual refreshers, and audit-ready reporting across its 10,000+ course catalog, so a multi-site employer proves training with a single export rather than reconstructing sign-in sheets per site.
What does BIPA require employers to do before collecting fingerprints or face scans?
Under Section 15(b) of 740 ILCS 14, before collecting a biometric identifier an employer must inform the individual in writing that the identifier is being collected and stored, state the specific purpose and length of term of collection and use, and obtain a written release signed by the individual. The notice and signature must come before the first scan, not afterward.
Does BIPA require a written biometric policy?
Yes. Section 15(a) requires a private entity in possession of biometric data to maintain a written policy, made available to the public, that sets a retention schedule and guidelines for permanently destroying the data when the purpose is satisfied or within three years of the individual’s last interaction, whichever occurs first.
What did the 2024 BIPA amendment change?
SB 2979, signed August 2, 2024 as Public Act 103-769, provided that collecting or disclosing the same biometric identifier from the same person by the same method is a single violation rather than one per scan, reversing the damages theory in Cothron v. White Castle. It also confirmed that a written release may be signed electronically. The notice, consent, policy, and destruction duties were unchanged.
What are the penalties for a BIPA violation?
Section 20 allows a private right of action with liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation, or actual damages if greater, plus attorneys’ fees and injunctive relief. Under Rosenbach v. Six Flags (2019), an individual can sue for a bare statutory violation without proving separate injury.
Does BIPA apply to biometric timeclocks used for employee timekeeping?
Yes. Fingerprint and hand-geometry timeclocks collect biometric identifiers, so an employer using them for timekeeping must provide the written notice, obtain the signed release, and maintain the retention-and-destruction policy that Section 15 requires. Employee-facing use is one of the most common sources of BIPA class actions.