The BIPA Ruling Every HR Leader Rolling Out a Biometric Time Clock Needs to Read Correctly
If you searched for anything about the Seventh Circuit's April 2026 BIPA ruling and landed on a law firm's client alert, you probably came away with one takeaway: damages are capped now. Per-scan liability is dead. The "$5,000 per fingerprint punch" math that turned a single distribution center into a billion-dollar exposure is gone.
All of that is true. None of it means what most HR and payroll leaders who aren't currently being sued will assume it means.
Every piece of coverage on Clay v. Union Pacific Railroad Co. — and there's a lot of it — is written for general counsel managing active litigation. That's the right audience for a ruling about damages calculation. But if your actual question is "we're about to roll out biometric time clocks at our Illinois distribution centers, does this change anything for us," the litigation-defense framing answers a question you're not asking and skips the one you are.
What the Court Actually Decided
Illinois's Biometric Information Privacy Act has required written consent, a public retention and destruction policy, and specific notice before collecting a fingerprint, hand geometry, or face scan since 2008. In 2023, the Illinois Supreme Court's Cothron v. White Castle decision held that a violation accrues every time a company scans biometric data without proper consent — not once per employee, but once per punch. For an hourly employee clocking in and out daily for years, that math produced the kind of numbers that make headlines: White Castle faced a theoretical exposure north of $17 billion before settling.
You might also like to read: Who's Liable When an AI Safety Platform Misclassifies an OSHA-Recordable Injury?
In August 2024, the Illinois legislature amended the statute (SB 2979) to cap recovery at one violation per person per collection method, regardless of how many times the scan happened. What the amendment didn't say was whether that cap applied to lawsuits already filed before it took effect — leaving companies facing pre-2024 claims in limbo for nearly two years while district courts split on the answer.
On April 1, 2026, the Seventh Circuit resolved that split in Clay, holding that the amendment is a remedial change to how damages are calculated, not a substantive change to what conduct is unlawful — and remedial changes apply retroactively under Illinois law. The court's reasoning turned on a specific distinction: the legislature amended BIPA's damages provision (Section 20), not its liability provision (Section 15), which defines what counts as a violation in the first place. Practically, that means every pending case, no matter when it was filed, now gets recalculated on a per-person basis instead of a per-scan basis.
The Part That Doesn't Change — and Why It's the Part That Matters to You
Section 15 is untouched. Every requirement that determines whether your company is violating BIPA in the first place — written consent before the first scan, a publicly available retention and destruction schedule, a stated purpose for collection, a prohibition on selling or profiting from the data — is exactly as strict on April 2, 2026 as it was on March 31. The Seventh Circuit didn't say collecting fingerprints without consent is fine now. It said that if you did it wrong, the bill for having done it wrong just got a lot more predictable and a lot smaller.
That distinction matters enormously depending on where your company sits. If you're already a defendant in a BIPA suit, the ruling is unambiguously good news — your damages exposure just became finite instead of open-ended, and settlement conversations that were stalled on nine-figure demands can now proceed on realistic numbers. Every law firm alert on this ruling is written for exactly that audience, and for that audience, the advice is sound.
You might also like to read: How Healthcare IT Teams Are Accelerating Internal App Development Without Violating HIPAA
If you haven't been sued yet and you're evaluating, piloting, or expanding biometric time clocks, the ruling changes almost nothing about your compliance obligations and arguably raises the stakes on getting rollout right the first time. Here's the mechanism: a lower, more predictable per-person damages figure makes plaintiffs' firms more willing to bring claims on behalf of an entire facility's workforce at once, rather than betting on a handful of named plaintiffs in a slower-moving class action strategy built around uncapped exposure. A capped, certain number per employee, multiplied across a thousand-person distribution center that never obtained proper written consent, is still a very large number — and it's now a number a plaintiff's firm can model with confidence before filing, which tends to accelerate filings rather than slow them.
What a Pre-Rollout Compliance Sequence Actually Looks Like Now
None of the legal commentary on Clay is wrong to focus on litigation strategy for pending cases. But if you're the HR or payroll leader deciding whether to move forward with biometric clocks this quarter, the operative question was never "how much would we owe per scan" — it was always "did we get consent right before the first scan happened." That sequence hasn't moved:
Written, informed consent has to be collected before any biometric identifier is captured — not folded into an onboarding packet an employee signs without reading, but a standalone disclosure that names the specific identifier being collected (fingerprint, hand geometry, or facial geometry), states the purpose (time and attendance), and is signed before enrollment. A publicly available retention and destruction policy has to exist and actually be public — posted somewhere employees can find it, not sitting in an HR drive — stating how long the data is kept and how it's destroyed when the purpose for collecting it ends, which for most employers means at termination or within a fixed window afterward. Employers using a third-party vendor (which is nearly everyone) remain on the hook for that vendor's handling of the data; the statute doesn't recognize outsourcing biometric collection as outsourcing the compliance obligation, so the vendor contract needs to address sub-processors, breach notification, and destruction on the same terms you're promising employees. And employees who object on religious or disability grounds need a genuine non-biometric alternative — a PIN or badge fallback — because a system that functionally requires biometric enrollment with no accommodation path invites a second claim under Title VII or the ADA layered on top of a BIPA claim.
None of this is new because of the Seventh Circuit's ruling. It's the same sequence that was correct before Clay was decided. What the ruling actually changes is the incentive structure on the plaintiff's side — and that's worth knowing before you assume a damages cap is the same thing as reduced urgency.
You might also like to read: Why Your AI Coding Tools Are Creating a Compliance Blind Spot — And How to Close It Before Your Next Audit
The One Real Update Worth Acting On
If your company already has biometric time clocks deployed in Illinois, this is a reasonable moment to run an actual audit rather than assume existing paperwork is fine: confirm every current employee using the system has a signed consent form on file (not just new hires since your last policy update), confirm the retention and destruction policy is dated recently enough to reflect current practice, and confirm your time clock vendor's contract terms match what your public policy promises employees. That audit was worth doing before April 2026. It's worth doing now specifically because a more litigable damages number, sitting behind a workforce that's never been properly consented, is exactly the fact pattern the next wave of BIPA claims is likely to target.

Comments
Post a Comment