Time Tracking with Screenshots Logo
  • How it works
  • Prices & FAQ
  • Blog
  • Sign Up
  • Log In
  • Contact Us
  • Try SCREENish for free
  1. SCREENish
  2. Blog
  3. Is a Face Recognition Time Clock Legal for Remote Employees?

Is a Face Recognition Time Clock Legal for Remote Employees?

A face recognition time clock is legal for remote employees in most places, but only if you follow the biometric rules of the place where each employee actually is when their face is checked, and those rules are stricter than the ones for ordinary time tracking. Illinois requires a written notice, a written release and a public retention policy before the first scan; Texas and Washington require notice and consent and are enforced by their attorneys general; California treats a face template as sensitive personal information; the EU and the UK treat it as special-category data, where an employer's consent alone is rarely enough. This guide walks through what each of those regimes asks of an employer with a distributed team, as of September 2026. It is general information, not legal advice.

Why remote work changes the analysis

Nearly every guide to biometric time clocks assumes a terminal on the wall of a building. The employer, the clock and the employee are in the same state, and one law applies. Remote teams break that assumption. A company in Colorado can have one employee clocking in from Chicago, one from Austin and one from Lisbon, and each of those scans happens where the employee sits, not where the company is registered.

Courts and regulators have generally looked at where the person was when their biometric data was captured. That means a single face verification feature can be perfectly lawful for one member of your team and a statutory violation for another, on the same day, with the same settings. The practical consequence is simple to state and easy to forget: before you enable face verification for anyone, you need to know where they work from, and you need to apply the rules of that place.

Illinois: the strictest rules, and the ones with a private right of action

Let SCREENish handle your time tracking Learn how SCREENish saves you money Time tracking with screenshots, honest reports and hands-off payroll. Free to try — no credit card. Start free →

The Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14) is the law that most employer lawsuits over time clocks have been brought under. It covers scans of face geometry, so it reaches face-based verification even though a plain photograph on its own is excluded. Before you collect a biometric identifier from someone in Illinois, BIPA requires you to:

  • inform the person in writing that a biometric identifier is being collected or stored, for what specific purpose and for how long;
  • obtain a written release, which since the 2024 amendment can be an electronic signature; a release executed by an employee as a condition of employment is expressly contemplated by the statute;
  • publish a written policy, available to the public, that sets a retention schedule and guidelines for permanently destroying the data once the purpose has been satisfied or within three years of the person's last interaction with you, whichever comes first;
  • never sell, lease or trade the data, and never disclose it without consent outside the narrow exceptions;
  • protect it with the same or a higher standard of care than you use for other confidential information.

BIPA is enforced by private lawsuits, with statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless one. The 2024 amendment limited recovery to one violation per person per method of collection, which removed the per-scan multiplication that had produced very large settlements, but a class of employees is still a class. An employer with even one remote worker in Illinois should meet the full BIPA checklist for that worker, and many employers with multi-state teams simply apply the Illinois standard to everyone because it is the most demanding.

Texas: consent, deletion within a year, and an active attorney general

Texas regulates biometric identifiers under the Capture or Use of Biometric Identifier Act (Business and Commerce Code section 503.001). You may not capture a person's biometric identifier for a commercial purpose without informing them and obtaining their consent. You may not sell or disclose it except in limited cases, you must protect it with reasonable care, and you must destroy it within a reasonable time and no later than one year after the purpose for collecting it expires. For employment, the statute says the purpose expires when the employment relationship ends.

There is no private right of action in Texas; the attorney general enforces the law with civil penalties of up to $25,000 per violation. That office has pursued biometric cases aggressively in recent years, so the absence of class actions is not the absence of risk.

Washington: notice and consent for commercial enrollment

Washington's biometric identifier law (RCW 19.375) prohibits enrolling a biometric identifier in a database for a commercial purpose without notice, consent or a mechanism to prevent later commercial use, and limits retention to what is reasonably necessary. Its definition excludes photographs and video and data generated from them, so how squarely it applies to a webcam-based check is less settled than in Illinois. It is enforced by the attorney general under the state's Consumer Protection Act. Treat the notice-and-consent requirement as applying and you are on the safe side of the question.

Colorado: employer-specific biometric rules since 2025

Colorado amended its privacy act with biometric provisions that took effect on 1 July 2025 and apply to any organisation that controls biometric identifiers, without the revenue and volume thresholds that limit the rest of the act. Controllers must adopt and make available a written policy with a retention schedule and a deletion protocol, and must obtain consent before collecting. The law speaks directly to employers: consent may be required as a condition of employment only for a short list of purposes, and recording the start and end of an employee's workday is one of them. If your team includes Colorado residents, the written policy and the purpose limitation are the two things to get right.

California: sensitive personal information under the CCPA

California has no stand-alone biometric statute, but the California Consumer Privacy Act, as amended, treats biometric information used to identify a person as sensitive personal information, and since January 2023 it applies in full to employees and job applicants. That brings a notice at collection that states the purpose and the retention period, purpose limitation, the right to limit the use of sensitive personal information, and the right to know and to delete. The regulations adopted in 2025 add risk assessments for processing that involves sensitive data, on a phased timetable. For an employer, the notice at collection and a documented retention period are the two items to have in place before the first scan.

Other states, briefly

New York's biometric rules mostly target fingerprints as a condition of employment and customers of commercial establishments, not face checks of staff, but proposals at city and state level keep moving. Most of the comprehensive state privacy laws passed since 2023 classify biometric data as sensitive data requiring consent, while exempting employee data from their scope; the exemptions differ, so check the state of each remote worker rather than assuming. Where a state has no specific rule, general employment law, wage-and-hour law and any collective agreement still apply, and a written notice and consent remain the sensible baseline.

The EU and the UK: special-category data, and consent is not the easy answer

Under the GDPR and the UK GDPR, biometric data processed to uniquely identify a person is a special category of personal data. Processing it needs a lawful basis under Article 6 and, separately, a condition under Article 9. Explicit consent is one of those conditions, but European regulators have repeatedly said that consent from an employee is rarely freely given, because the employee depends on the employer. The Dutch data protection authority fined a company that made fingerprint attendance mandatory, and the UK Information Commissioner ordered a leisure operator in 2024 to stop using facial recognition and fingerprint scanning for staff attendance where employees had no real alternative.

What works in practice is a genuine choice: the feature is optional for the individual, an equivalent way to record attendance exists for those who decline, and declining carries no disadvantage. Several member states also allow biometric processing in employment on the basis of national law under Article 88, with conditions. In every case a data protection impact assessment is expected before rollout, because face verification of staff is systematic monitoring of special-category data. Keeping the processing on the employee's own device, limiting what is kept and for how long, and giving the person control over their consent are the mitigations assessments look for.

A checklist for a distributed team

  1. Map where each person works from. The law of that place governs their scan. Update the map when someone moves.
  2. Make face verification opt-in per person. Enable it individually, never as a blanket setting, and keep an ordinary way to record time for anyone who declines.
  3. Give written notice before enrollment. What is collected, why, for how long, and who can see it.
  4. Obtain and record consent. Electronic is fine in Illinois since 2024. Keep the record, and let people withdraw as easily as they agreed.
  5. Publish a retention and destruction schedule. Illinois and Colorado require it to be public; everyone else expects a documented period.
  6. Delete when the purpose ends. At the latest when the employment ends, and within the statutory maximum where one exists.
  7. Never sell or share biometric data, and put your software vendor under a contract that binds them to act only on your instructions.
  8. Run an impact assessment for anyone in the EU or the UK, and keep it with your other compliance records.
  9. Use it for what you said. A time clock verifies who clocked in. Using the same data for anything else needs a new notice and a new legal basis.
  10. Write it all down. Every regime above rewards documentation, and every dispute starts with a request for it.

Where SCREENish fits

SCREENish is face recognition time tracking that puts consent first: software on the employee's computer rather than a terminal on the wall. The employer decides whether to enable face verification and for whom, and is responsible for the legal basis that applies to each person; the employee sees a notice and gives or withdraws consent in their own dashboard, and the feature stays off until they do. What is kept and for how long is set out in the privacy policy. Everything else in SCREENish, from screenshots to timesheets, works the same whether or not face verification is on, so a team member who declines is not a team member who cannot be paid.

Regulation in this area moves quickly. The rules above are current as of September 2026; check the law of each jurisdiction where your people work before you enable biometric verification, and speak to a lawyer where the answer matters.

Ready to see your team's real hours?

SCREENish is free to try — no credit card required.

Start free

← All posts

  • How it works
  • Prices & FAQ
  • Blog
  • Sign Up
  • Log In
  • Contact Us
  • Try SCREENish for free
  • Cookie Settings

Solutions

  • Mouse Jiggler Detection Software
  • Faked Activity Detection
  • Overemployment Detection for Remote Teams
  • Remote Employee Identity Verification
  • Face Recognition Time Tracking
  • Employee Attendance & Overtime Reports
  • Compare Alternatives
  • Feature Guides
  • Blog Articles
  • Pricing & Plans

From the Blog

  • Can Employers Detect Mouse Jigglers?
  • How to Tell If Activity Is Real: What the OS Flags as Fake Input
  • 12 Signs a Remote Employee Is Working Two Jobs
  • Proxy Workers: How to Tell If Someone Else Is Doing the Job
  • GDPR-Compliant Employee Monitoring: A Practical Checklist
  • Best Time Tracking Software with Screenshots (2026)
  • If an Employee Deletes a Screenshot, What Can the Employer Still See?
  • Idle Time Settings: How Many Minutes to Deduct
  • A Fair Mouse-Jiggler Policy for Remote Teams
  • Overemployment in 2026: The Numbers
© SCREENish 2026 All right reserved. By SCREENish.com | Terms of Service | Privacy Policy | Cookie Policy