Skip to content
ADRO

Facial Recognition Time Clocks in Construction: Benefits and Biometric Privacy Compliance (BIPA, CUBI, and More)

Facial recognition at the gate confirms who is really on site, but biometric privacy laws such as Illinois BIPA come with strict rules. This guide covers the benefits and the checklist to complete before you enroll a single face.

By the ADRO team. Published , 9 min read.

Facial recognition at the jobsite gate solves a problem every superintendent knows: you cannot be sure the person on the timesheet is the person who was on site. Cards get handed over, PINs get shared, and sign-in sheets get filled in for friends. A face cannot be lent to a coworker.

But facial recognition also brings legal obligations that a QR code or access card does not. Several US states regulate biometric data, and one of them, Illinois, allows individuals to sue directly for violations. Employers have been sued over workplace biometric systems, such as fingerprint scanners, that collected data without the proper notice and consent. This guide covers both sides: the practical benefits of a facial recognition time clock on construction sites, and what you need to have in place before you turn it on.

This article is general information, not legal advice. Biometric privacy laws change and depend on where your workers and projects are; confirm your obligations with counsel.

The short answer: a facial recognition time clock confirms that the person checking in is the enrolled worker, which stops buddy punching and makes headcounts reliable. To use one lawfully in states with biometric privacy laws, you generally need a written biometric policy with a retention and destruction schedule, written notice to workers explaining what is collected and why, written consent (a signed release) before enrollment, secure storage, no selling of the data, and deletion when the purpose is fulfilled.

How does a facial recognition time clock work?

A facial recognition time clock enrolls each worker's face once, converts the image into a mathematical template, and then compares the face it sees at the gate against the stored templates to identify the worker and record a check-in. The whole process has three steps:

  1. Enrollment. The worker provides a face photo once, usually at the gate kiosk or from a phone. The system converts the image into a mathematical representation, often called a face template or encoding.
  2. Check-in. At the gate, a camera captures the worker's face. The system compares it with stored templates and identifies the worker.
  3. Record. A check-in is recorded for that worker, project, and time, exactly as with a card or QR scan.

The template is what most biometric laws regulate, along with the underlying face geometry. That is why the same rules apply whether the system stores photos, templates, or both.

What are the benefits on a construction site?

On a construction site, facial recognition stops buddy punching, removes cards and PINs that get lost or shared, works hands-free with gloves on, and gives you a headcount made of actual people. It is also fairer to the workers who show up on time. The main benefits:

BenefitWhy it matters on a jobsite
Stops buddy punchingOne worker cannot check in for another. See what buddy punching really costs.
Nothing to lose or forgetNo cards to replace, no stickers to reprint, no PINs to reset.
Hands-freeWorks with gloves on, no touching a shared screen.
Reliable headcountThe list of who is on site reflects actual people, which matters for emergencies and manpower logs.
Fair to everyoneWorkers who show up on time are not subsidizing those who do not.

Where facial recognition is less suitable

  • Small crews where everyone knows everyone, and a card or QR code is enough.
  • Projects where the owner or union agreement restricts biometrics.
  • Workers who do not consent, who need an alternative method.
  • Very bright or very dark gate locations, unless the kiosk is positioned and shaded carefully.

Which biometric privacy laws do you need to know about?

The main US laws that specifically regulate biometric data are Illinois's Biometric Information Privacy Act (BIPA), Texas's Capture or Use of Biometric Identifier Act (CUBI), and Washington's biometric identifier law. Illinois is the strictest because individuals can sue directly. As of this writing, here is what each one requires:

Illinois: Biometric Information Privacy Act (BIPA)

BIPA is the strictest and most litigated. It applies to private entities that collect biometric identifiers, including scans of face geometry, from people in Illinois. Its key requirements, set out in Section 15 of the Act, include:

  • A publicly available written policy with a retention schedule and guidelines for permanently destroying biometric data when the initial purpose is satisfied or within three years of the individual's last interaction with the entity, whichever comes first.
  • Written notice to the individual that biometric data is being collected, the specific purpose, and the length of time it will be collected, stored, and used.
  • A written release from the individual before collection.
  • No selling, leasing, trading, or otherwise profiting from biometric data.
  • Limits on disclosure to third parties without consent.
  • Protection of the data using a reasonable standard of care, at least as protective as for other confidential information.

BIPA gives individuals a private right of action, with liquidated damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation, plus attorneys' fees. In Rosenbach v. Six Flags (2019), the Illinois Supreme Court held that a person does not need to show an actual injury beyond the violation of their BIPA rights to sue. In Cothron v. White Castle (2023), a case about an employee who scanned her fingerprint to access work computers and pay stubs, the court held that a separate claim accrues with each scan or transmission made without prior consent. A 2024 amendment (SB 2979) responded by clarifying that repeated collection from the same person using the same method counts as a single violation with at most one recovery, and that a written release can be given by electronic signature. Exposure can still be large across a workforce.

Texas: Capture or Use of Biometric Identifier Act (CUBI)

Texas law requires notice and consent before capturing biometric identifiers for a commercial purpose, prohibits selling them in most cases, and requires destruction within a reasonable time, generally no later than one year after the purpose expires. CUBI is enforced by the Texas Attorney General rather than through private lawsuits, and penalties can reach $25,000 per violation.

Washington: biometric identifier law

Washington requires notice and consent (or a mechanism to prevent later commercial use) before enrolling biometric identifiers for a commercial purpose, and is enforced solely by the state Attorney General. Washington's separate My Health My Data Act also lists biometric data as consumer health data, although its definition of a consumer excludes individuals acting in an employment context. Review how both apply to your workforce with counsel.

Other laws to watch

  • New York City requires certain commercial establishments to post notice when they collect biometric identifiers from customers. It is aimed at businesses serving the public rather than employee time clocks, but check with counsel if you operate in NYC.
  • Comprehensive state privacy laws in states such as California, Colorado, Connecticut, and others treat biometric data as sensitive information with extra requirements. Coverage of employee data varies by state.
  • Collective bargaining agreements may address biometrics. Involve the union early where applicable.

New laws are proposed every year. Treat the strictest applicable standard as your baseline, especially if you have projects or workers in more than one state.

A practical compliance checklist

Before enrolling a single face, work through this list with your counsel:

  1. Map where you operate. Which states are your projects in, and where do your workers live?
  2. Publish a written biometric policy with a clear retention schedule and destruction guidelines.
  3. Prepare a written notice explaining what is collected (face geometry or templates), the purpose (identity verification for timekeeping and site access), and how long it is kept.
  4. Collect a signed written release from each worker before enrollment. Keep a record of each consent.
  5. Offer an alternative such as an access card, QR code, or helmet sticker for workers who decline, and make sure declining has no negative consequences.
  6. Cover subcontractor workers. If subcontractor employees will use facial recognition on your site, decide contractually who provides notice and obtains consent. Do not assume the sub has done it.
  7. Restrict access to biometric data and settings to people who need it, using role-based permissions.
  8. Delete on schedule. Remove a worker's biometric data when they leave the project or company, and in any case within your stated retention period.
  9. Review your vendor. Ask how biometric data is stored and protected, whether it is ever shared or sold, and how deletion works.
  10. Train supervisors on what to say when workers ask questions.

Questions to ask a facial recognition time clock vendor

  • Where are face images and templates stored, and are they encrypted?
  • Do you ever sell, share, or use our biometric data to train models for other customers?
  • How do we delete a worker's biometric data, and is deletion permanent?
  • Can we require consent to be recorded before enrollment?
  • Can we use other check-in methods for workers who decline?
  • Can we turn facial recognition on for some projects and off for others?
  • Who on our team can view or manage face data?

What mistakes create biometric risk?

Five avoidable mistakes account for much of the biometric risk employers take on: collecting data before the policy and consent are in place, assuming the vendor handles consent, forgetting subcontractor workers, keeping data forever, and offering no alternative check-in method. Each one is easy to prevent if you plan for it before the first enrollment.

Turning it on first and writing the policy later

Many biometric claims are about the order of operations: data was collected before a policy existed or before written consent was obtained. Have the policy, notice, and consent process ready before the first enrollment, not after.

Assuming the vendor handles consent

The vendor can provide tools, but under most biometric laws the company collecting data from its workers is responsible for notice and consent. Make sure your team knows who owns the process.

Forgetting about subcontractor workers

On a GC-run site, many of the faces at the gate belong to subcontractor employees. Decide in writing whether the GC or each subcontractor provides the notice and collects the release, and keep proof either way.

Keeping data forever

Projects end and workers move on, but their face templates often stay in the system. Build deletion into your project closeout and offboarding checklists so it actually happens within the retention period you published.

No alternative method

If facial recognition is the only way to check in, a worker who declines has no path to site access. Keep a card, QR, or sticker option available.

How should you talk to crews about facial recognition?

Talk to crews plainly. Explain that facial recognition only confirms who is checking in, that it is not used to watch the work area, that the data is not sold, that it is deleted when they leave, and that they can choose another method. Workers are more likely to accept it when you cover these points:

  • It is used only to confirm who is checking in, for accurate hours and site safety.
  • It is not used for surveillance of the work area.
  • The data is not sold or shared for marketing.
  • It is deleted when they leave, according to the written policy.
  • They can choose another method if they do not want to use it.

Provide the notice in the languages your crews use. Multilingual enrollment makes this much easier.

Frequently asked questions

Is a facial recognition time clock legal?

In most US states, yes, provided you meet the applicable notice, consent, retention, and security requirements. In states with specific biometric laws, those requirements are detailed and enforced. Confirm the rules for each state you operate in with counsel.

Does a photo taken at check-in count as biometric data?

A plain photo reviewed by a person is often treated differently from a face template used for automated matching, but the line depends on the law and how the system uses the image. Ask your counsel and your vendor exactly what is stored and processed.

Can we use facial recognition on only some projects?

That is often the best approach. Use it where the verification benefit is highest and simpler methods elsewhere.

How ADRO handles this

ADRO supports facial recognition as one option among several, so you can use it where it makes sense and skip it where it does not:

  • Face scan check-in at the gate kiosk, after a one-time enrollment photo. Supervisors can also face-scan any worker on site as a spot check.
  • Alternative methods: an access card at the same kiosk, or the gate QR code on the worker's own phone with a 4-digit code sent by text, so workers who decline have another option.
  • Raspberry Pi kiosks that keep working offline. See offline time tracking for jobsites.
  • Admin control over face photos, so data can be managed and removed.
  • Custom roles with 80+ permissions to limit who can access biometric settings, plus sign-in with a one-time code sent by text and a record of changes.
  • Worker enrollment in English or Spanish so workers can read the enrollment steps in their own language.

Your company remains responsible for providing notice and obtaining consent from your workers, and ADRO's tools are designed to support that process. Learn more on the ADRO jobsite time tracking overview, or compare options in our construction time clock buyer's guide.

Sources

Want to see it on your own jobsite? Book a 20-minute ADRO demo and we'll walk through it with your projects.

  • facial recognition
  • biometric privacy
  • bipa
  • time clock
  • compliance
Share: LinkedIn X Email