Privacy Ref Blog

Is Your Biometric Clock Ticking?

I recently read an article published on the Society for Human Resource Management’s website on the prevalence of biometrics in the employment context. Specifically, the author referenced a Spiceworks’ survey of IT professionals from February 2018 that provided, in my mind, surprising results.

And the survey says…

The survey showed that 62% of the respondent companies presently use biometrics for security and business purposes (for example, fingerprint scanning, facial recognition, or retinal scan), with an additional 24% planning to use such within the next 2 years. A quick Google search showed that, at a minimum, biometric time clocks (which are used by a multitude of employers for time and attendance tracking) are alive and well and quickly becoming the norm in many industries – and not just for defense contractors or companies into super-secret, competitive research.

Given this growing, across-the-board popularity of biometrics in the workplace, I immediately wondered about the privacy and security issues surrounding such use. Granted, a few states include biometrics as protected personal information in the event of a data breach, but should companies be allowed to obtain such unique data at all absent explicit consent? If they collect it, how do they store it and protect it? Are they allowed to sell it to or share it with third-parties, including the government, without consent? Clearly, this is just one of many examples of where technology has outpaced the law.

Legal requirements

At present, there are only a small number of U.S. states that have laws specifically addressing the collection, use, protection, and sharing of biometric data – cue Illinois, Texas, and Washington. While other states (less than half) do protect biometric data in some fashion, their laws currently aren’t as comprehensive as those in the aforementioned three states (although the new California Consumer Protection Act comes close). And, naturally, U.S. law has not kept pace with the EU, which generally prohibits (under the GDPR) the use of biometric data as a unique identifier of an individual, although an exception for employment purposes is recognized (albeit with prior approval from the EU or Member State or if collectively bargained) – cue France, whose Data Protection Authority just issued a proposed regulation on “work biometrics.”

To be clear, I am not advocating for or against the use of biometrics – there are pros and cons on both sides of the equation. But I do find such academic discussions quite interesting, privacy nerd that I am. In the meantime, I will continue to wait (with not-so-bated-breath) to see if our U.S. government steps in with an all-encompassing (and, hopefully, preemptive) federal law to put all discussions to bed, once and for all (rumor has it that federal consumer privacy “standards” are in the works).

What you should do

Until that happens, however, if you are a company collecting the biometrics of your employees (or any individual, for that matter), make sure you keep abreast of relevant state (or, as applicable, international) law and update your policies and procedures accordingly. Otherwise, that ticking you hear from your biometric time clock could turn out to be a biometric time bomb.

Privacy Ref provides consulting and assessment services to build and improve organizational privacy programs. For more information call Privacy Ref at (888) 470-1528 or email us at

Posted on September 21, 2018 by Kelly Cheary

« »

No Responses

Comments are closed.

« »

Subscribe to our mailing list

Please fill out the form below.


Want to find out more?

Simply go to the contact page, fill out the form, and someone from Privacy Ref will be in touch with you. You can also send an email to or call (888) 470-1528.


April 5, 2019

See you at the Summit
Visit us at Booth 500 at the IAPP Global Privacy Summit. Bob Siegel will be facilitating the CIPM course. April 30th-May 1st, 9 am - 5 pm. Meeting time available to discuss your privacy needs is available for signup here.

Latest Blog Posts

April 19, 2019

Do you have 1 minute? Check out our New weekly Quick Privacy Ref-erence series.

At Privacy Ref we are always thinking of ways to improve the experience of our followers and clients alike. Weekly on our YouTube channel you will find a relevant privacy topic being discussed in a 1-minute video such as: 

  • Cookies walls and the Dutch DPA - Ben Siegel discusses his research on the Dutch Personal Data Authorities' guidance on cookies walls and freely given consent. A cookie wall is a notice from the website, informing the user about the use of cookies on the website, without a reject option. Ben provides insight into the difference between functional cookies and tracking cookies and why the Dutch DPA's advises that websites’ basics functions are to remain available for everyone and not just for those that accept all cookies (including tracking cookies).   
Continue reading this post...

April 12, 2019

Protect Your Privacy Spring Cleaning

I’ll be honest, my blog idea was generated from an article about spring cleaning.  Let’s face it, lots of things could benefit from spring cleaning:  homes, cars, desk drawers… How about your inbox?  Maybe the ever-growing number of presentation drafts in your documents folder?  How about the flash drive in your desk drawer?  Anything in the cloud that’s been hanging out for years?  Maybe there’s a number of bookmarks or favorites on your list that hasn’t been used or accessed in a while.

Continue reading this post...

Other Recent Posts