Biometric Data Checklist: Inventory, Notice, Written Consent, Retention, and Deletion
By Casey Scott McKay ·
Biometric exposure enters a company through a purchase order and is discovered through a lawsuit. This checklist runs the compliance work in twelve phases: inventory the systems, establish what each actually stores, publish the retention policy, deliver pre-collection notice, obtain the written release before the first scan, build a destruction mechanism that runs, diligence and contract the vendors, satisfy the comprehensive privacy statutes, review insurance, remediate a legacy deployment, model the residual exposure, and set the annual review. Each box gives the reason, the authority, and the trap. Boxes marked as gates should clear before any enrollment. A worked remediation runs throughout.
IP and Technology > Privacy Data Security | Checklist | Published 31 December 2023 - Updated 20 January 2026 | Casey Scott McKay - marksy.us
Summary. Biometric exposure enters a company through a purchase order and is discovered through a lawsuit. This checklist runs the compliance work in twelve phases: inventory the systems, establish what each actually stores, publish the retention policy, deliver pre-collection notice, obtain the written release before the first scan, build a destruction mechanism that runs, diligence and contract the vendors, satisfy the comprehensive privacy statutes, review insurance, remediate a legacy deployment, model the residual exposure, and set the annual review. Each box gives the reason, the authority, and the trap. Boxes marked as gates should clear before any enrollment. A worked remediation runs throughout.
Keywords: biometric inventory, template storage, coverage analysis, public retention policy, pre-collection notice, written release, enrollment control, destruction job, vendor possession, data processing agreement, indemnity cap, insurance exclusion, sensitive data consent, data protection assessment, deletion capability, rights requests, acquisition diligence, legacy remediation, exposure model, annual review
How to use this checklist
| Phase | What it covers | |---|---| | 1 | Inventory the systems | | 2 | What each system stores | | 3 | The public retention policy | | 4 | The pre-collection notice | | 5 | The written release | | 6 | Destruction that runs | | 7 | Vendors | | 8 | The comprehensive privacy layer | | 9 | Insurance | | 10 | Remediating a legacy deployment | | 11 | Modeling the exposure | | 12 | Ownership and annual review |
Boxes marked [Gate] should clear before any person is enrolled.
The matter. A regional logistics company with eleven facilities discovered its exposure when a competitor was sued. The inventory found nine systems; technology knew about three.
Phase 1. Inventory
-
[ ] [Gate] Ask the functions that buy systems, not only technology.
- Why. Human resources bought the timeclock, facilities bought the door readers, security bought the yard cameras, and the contact center bought voice authentication.
- Trap. A questionnaire circulated to IT, which returns three systems out of nine.
-
[ ] List every system that identifies a person from a physical or behavioral characteristic.
- Why. Timeclocks, badge readers with biometric fallback, camera analytics, voice authentication, kiosks, vehicle and server room access.
-
[ ] Record for each: vendor, deployment date, locations, enrolled population, purpose, and any consent obtained.
-
[ ] Include remote employees resident in private-right-of-action states.
- Trap. A company with no facilities in a state assuming it has no exposure there.
-
[ ] Include products the company sells where a template may live on the company's servers.
-
[ ] Include systems acquired with a business.
Phase 2. What each system stores
-
[ ] [Gate] Get engineering documentation, not marketing.
- Why. Coverage turns on whether a template capable of identifying a specific person is created and retained.
- Authority. 740 ILCS 14/10.
-
[ ] Distinguish identification from detection.
- Why. Counting people or determining that a face is present, without identifying whose, is generally outside the statutes.
-
[ ] Distinguish recording from templating.
- Why. A call recording is not a voiceprint; a template derived to authenticate the caller is.
- Authority. 18 U.S.C. § 2511 for the separate interception analysis.
-
[ ] Establish where the data lives.
- Why. Device, local appliance, vendor cloud, backups, and any analytics pipeline that copied it.
-
[ ] Get the answer in writing.
- Why. It will be the central factual question in any claim and a technical witness must support it.
- Authority. Fed. R. Evid. 702.
-
[ ] Note the statutory exclusions.
- Why. Photographs, writing samples, signatures, demographic data, physical descriptions, donated tissue, health care setting information, and imaging. A template derived from a photograph is not excluded.
Phase 3. The public retention policy
-
[ ] Publish it.
- Authority. 740 ILCS 14/15.
- Trap. A policy in a compliance binder, which documents the obligation and fails the requirement.
-
[ ] State the retention schedule in statutory terms.
- Why. Destruction when the initial purpose has been satisfied or within three years of the individual's last interaction, whichever occurs first.
-
[ ] State the destruction guidelines.
- Why. How, by whom, and on what cadence.
-
[ ] Name the categories and the systems.
- Why. Naming the systems is what makes the policy credible.
-
[ ] State that the company does not sell, lease, trade, or profit from biometric data.
-
[ ] State the security standard applied.
-
[ ] Name the responsible function and a contact.
Phase 4. The pre-collection notice
-
[ ] [Gate] Make it a separate document, delivered before the first scan.
- Trap. Folding it into the general privacy policy or the handbook.
-
[ ] Name the specific identifier.
- Why. "A scan of finger geometry," not "biometric data."
-
[ ] State the specific purpose.
- Trap. "Business purposes," which is not a purpose.
-
[ ] State the length of term for which it will be collected, stored, and used.
-
[ ] Identify who holds it, including any vendor.
-
[ ] Version it, and record which version each person received.
- Why. The evidentiary question is always what this person was told on this date.
Phase 5. The written release
-
[ ] [Gate] Obtain it before the first scan.
- Trap. After enrollment, at the next review cycle, or by continued use of the system. None of these is execution.
-
[ ] Get a signature, wet or electronic, with a retrievable record.
-
[ ] Reference the notice version and identify the system.
-
[ ] In employment, it may be executed as a condition of employment.
- Why. The statute permits this expressly, which makes omission harder to explain.
-
[ ] Retain it with the enrollment record.
-
[ ] [Gate] Build an enrollment control.
- Why. The system should not create a template for a person without a release on file. Process without a technical control fails across four years and two thousand hires.
-
[ ] Plan for refusals in advance.
- Why. A badge, a PIN, or a supervisor override, documented.
-
[ ] Plan for re-enrollment, transfers, and rehires.
- Why. A rehire whose data was destroyed on schedule is a new enrollment.
-
[ ] Plan for minors where the workforce includes them.
-
[ ] Where the population cannot sign, reconsider deploying.
- Why. Retail customers, visitors, and third-party drivers cannot practically be asked to sign, and signage is not a release.
Phase 6. Destruction that runs
-
[ ] [Gate] Build the job, do not merely write the policy.
- Trap. The most commonly documented and least commonly executed obligation in the program.
-
[ ] Cover every location.
- Why. Device, appliance, vendor cloud, and backups.
-
[ ] Trigger on departure, not only at the three-year outer limit.
-
[ ] Log every run.
-
[ ] Test annually by asking for evidence that a named person's data was deleted.
-
[ ] Reconcile with litigation holds.
- Why. A pending claim may require preserving exactly what a requester wants deleted, and the conflict should be resolved deliberately.
Phase 7. Vendors
-
[ ] Determine who possesses what.
- Why. A vendor storing templates has its own obligations and may be a defendant alongside you.
-
[ ] Require the vendor's own compliance.
-
[ ] Prohibit use for the vendor's purposes, including model training and product improvement.
-
[ ] Require deletion on termination, with certification.
-
[ ] Require deletion on individual request within your statutory response window.
- Authority. Cal. Civ. Code § 1798.105.
- Trap. A system that disables an account without removing the template.
-
[ ] Read the indemnity cap.
- Trap. A cap tied to fees paid, an order of magnitude below realistic exposure.
-
[ ] Require security commitments consistent with the reasonable standard of care in the industry.
-
[ ] Ask the eight procurement questions before signing.
- Why. Does it identify; what is stored and where; who possesses; do you supply consent materials; can you delete a named person; can you enforce retention automatically; will you indemnify and at what cap; where are your other customers deployed.
Phase 8. The comprehensive privacy layer
-
[ ] Classify biometric data as sensitive.
-
[ ] Obtain consent or offer the limit-use right, by state.
- Authority. Va. Code § 59.1-578; Cal. Civ. Code § 1798.121.
-
[ ] Conduct the data protection assessment.
- Authority. Colo. Rev. Stat. § 6-1-1308.
-
[ ] Update the notice at collection.
- Authority. Cal. Civ. Code § 1798.100.
-
[ ] Build and test deletion capability.
-
[ ] Verify requesters without collecting more biometric data to do it.
-
[ ] Log every rights request and its disposition.
-
[ ] Put processors under a compliant data processing agreement.
-
[ ] Check the Texas and Washington requirements where applicable.
Phase 9. Insurance
-
[ ] Read the policies now, not at tender.
- Trap. Many carriers added express biometric exclusions after the first wave of coverage litigation.
-
[ ] Check the personal and advertising injury coverage and any statutory-violation exclusion.
-
[ ] Check the cyber policy for a privacy wrongful acts extension.
-
[ ] Notify promptly on any claim.
- Why. Late notice is a coverage defense independent of the merits.
-
[ ] Do not rely on the vendor indemnity alone.
Phase 10. Remediating a legacy deployment
-
[ ] [Gate] Stop the accrual first.
- Why. Obtain releases prospectively or suspend the system. Every day of continued operation adds exposure.
-
[ ] Obtain releases going forward, with a clean notice and a dated record.
- Why. This does not cure the prior period and it stops the growth.
-
[ ] Do not backdate anything.
- Trap. Remediation documents suggesting earlier consent convert a paperwork case into a fraud case.
-
[ ] Suspend deployments where the population cannot sign.
-
[ ] Document the remediation.
- Why. It bears on the negligent-versus-reckless question, which changes the statutory figure substantially.
-
[ ] Assess the defenses.
- Why. Coverage, exemptions, extraterritoriality, labor preemption under 29 U.S.C. § 185, and class certification under Fed. R. Civ. P. 23.
Phase 11. Modeling the exposure
-
[ ] Count distinct individuals enrolled, not current headcount.
- Why. Turnover means the enrolled population over six years far exceeds today's workforce, and personnel records are the reliable source.
-
[ ] Identify the state footprint, including remote workers.
-
[ ] Fix the period per individual, from enrollment to consent or suspension.
-
[ ] Apply the accrual rule in force during each part of the period.
- Why. Per-scan accrual before the limiting amendment; the amendment applies prospectively.
-
[ ] Apply the five-year limitations period.
- Authority. 740 ILCS 14/20.
-
[ ] Split negligent from reckless.
-
[ ] Discount for class certification and the defenses.
-
[ ] Benchmark against published settlements, adjusted for population.
-
[ ] Present a range with the assumptions named.
- Trap. A single number, which invites disbelief and gets discounted wholesale.
Phase 12. Ownership and annual review
-
[ ] Name one accountable owner, not "legal."
-
[ ] Add one question to the purchasing workflow.
- Why. Does this system identify people from a physical or behavioral characteristic. Routed to legal when the answer is yes, it catches nearly everything before deployment.
-
[ ] Brief human resources, facilities, security, and store operations annually.
-
[ ] Fund the engineering.
- Why. Enrollment gates and deletion jobs require developer time, and an unfunded technical control is a policy binder.
-
[ ] Re-run the inventory annually.
-
[ ] Confirm the destruction job ran, with evidence.
-
[ ] Sample enrollments for releases on file.
-
[ ] Review the state footprint, the vendor contracts, and the insurance.
-
[ ] Refresh the assessment.
-
[ ] Put biometric systems in acquisition diligence by name.
- Trap. A general compliance representation, which is what most purchase agreements rely on.
-
[ ] Report to the board where the exposure is material.
Phase 13. Deployment-pattern boxes
Six patterns account for nearly all of the litigation. Run the pattern-specific boxes for whichever apply.
Workforce timekeeping
- [ ] Confirm the release predates the first scan for every enrolled person, including those who left.
- [ ] Confirm the enrollment system will not create a template without a release flag.
- [ ] Confirm the destruction trigger fires on departure, not only at three years.
- [ ] Confirm the vendor's cloud copy is covered by the destruction job.
- [ ] Identify union-represented populations, where preemption may apply.
- Authority. 29 U.S.C. § 185.
Staffing and contractor placements
- [ ] Determine who runs the enrollment, and place the release obligation there.
- [ ] Paper the allocation between the agency and the client, with indemnity.
- [ ] Confirm the agency's releases name the client's system, not the agency generally.
Retail loss prevention
- [ ] Confirm no template is created for anyone who has not signed.
- Trap. Signage at the entrance, which is not a written release.
- [ ] Consider disabling matching in private-right-of-action states.
- [ ] Confirm the watchlist itself is not retained beyond its purpose.
Consumer platforms
- [ ] Confirm whether templates are derived from uploaded images.
- Why. The photograph exclusion covers the image, not the derived template.
- [ ] Confirm the consent flow precedes template creation, not merely account creation.
- [ ] Confirm deletion removes templates and not just the visible feature.
Voice authentication
- [ ] Distinguish the recording from the voiceprint.
- [ ] Confirm two-party consent compliance for the recording separately.
- Authority. 18 U.S.C. § 2511.
- [ ] Confirm the enrollment disclosure precedes the first authenticated call.
Access control and facilities
- [ ] Confirm facilities-purchased systems are in the inventory.
- [ ] Confirm visitors and contractors are handled, or excluded from biometric entry.
- [ ] Confirm device-local templates are covered by the destruction job.
Phase 14. What clients ask, with the answers
-
[ ] "We turned the system off — are we fine?"
- Answer. No. Claims accrued while it ran and the limitations period runs from accrual. Turning it off stops the bleeding.
-
[ ] "Our vendor said it was compliant."
- Answer. That usually means the template is encrypted, not that anyone obtained a release from your employees. The obligation is not delegable, though an indemnity is negotiable.
-
[ ] "Nobody complained."
- Answer. No harm is required. These cases are brought as class actions by counsel who located the deployment, not by an aggrieved employee.
-
[ ] "It's in the handbook."
- Answer. A handbook provision is not a written release executed before collection.
-
[ ] "Can we get consent now?"
- Answer. Yes, prospectively, and it does not cure the prior period.
-
[ ] "Is this covered by insurance?"
- Answer. Read the policy now. Many carriers added express exclusions after the first coverage cases.
-
[ ] "What about the company we bought last year?"
- Answer. Inherited. Ask what systems, since when, and whether releases exist for everyone enrolled.
-
[ ] "What should we do first?"
- Answer. The inventory. Every other conclusion depends on it, and most companies find a system they did not know about.
Phase 15. The three documents, element by element
The public policy
- [ ] Scope: the categories collected and the systems that collect them, named.
- [ ] Purpose: why each category is collected.
- [ ] Retention schedule, in statutory terms: destruction when the initial purpose has been satisfied or within three years of the last interaction, whichever occurs first.
- [ ] Destruction guidelines: how, by whom, on what cadence.
- [ ] Disclosure: no sale, lease, trade, or profit; the limited circumstances of disclosure.
- [ ] Security: the standard of care applied.
- [ ] Contact: where questions and rights requests go.
- [ ] Publicly available, and findable.
- Authority. 740 ILCS 14/15.
The pre-collection notice
- [ ] The specific identifier, named.
- [ ] The specific purpose.
- [ ] The length of term for collection, storage, and use.
- [ ] Who holds it, including any vendor.
- [ ] A pointer to the public policy.
- [ ] A version number.
- [ ] Delivered before the first scan, with a record of delivery.
The release
- [ ] Acknowledgment of receipt of the notice, identifying the version.
- [ ] Consent to collection, storage, and use for the stated purpose.
- [ ] Consent to disclosure to the named vendor for that purpose.
- [ ] Date and signature, retrievable.
- [ ] In employment, a statement that it is executed as a condition of employment where the company relies on that provision.
The test that matters
- [ ] For any enrolled person, on any date, the company can produce what they were told and what they signed.
- Why. That is the evidentiary question in every case, and a program that cannot answer it has not complied regardless of what its documents say.
Phase 16. Failure modes, collected
- [ ] The inventory missed a system. Facilities bought the door reader and nobody asked.
- [ ] Coverage assessed from a datasheet rather than engineering documentation.
- [ ] The policy exists but is not public.
- [ ] Notice folded into the general privacy policy.
- [ ] Notice delivered at enrollment with no record of the version.
- [ ] A handbook acknowledgment treated as a release.
- [ ] The release obtained after enrollment.
- [ ] No enrollment control, so process depends on memory across years and thousands of hires.
- [ ] The destruction job was written and never built.
- [ ] Deletion tested only on paper, where the system disables an account without removing the template.
- [ ] Vendor possession never determined.
- [ ] Indemnity cap tied to fees paid.
- [ ] Insurance reviewed at tender.
- [ ] Remote employees in private-right-of-action states overlooked.
- [ ] Acquisition diligence relied on a general compliance representation.
- [ ] Backdated remediation documents.
- Trap. This converts a paperwork case into a fraud case, and it has happened.
- [ ] Signage relied on for public-facing collection.
- [ ] The pilot approved without modeling the rollout.
- Why. Fifty people at one site is manageable; the same system at eleven sites over six years is not, and the decision is made at the pilot.
Phase 17. The deploy-or-not decision
Compliance is a cost. For some deployments the honest recommendation is not to proceed, and the analysis takes an hour.
-
[ ] Ask what the biometric buys over the alternative.
- Why. A hand-geometry clock prevents buddy punching; so does a photo badge and a supervisor. The marginal benefit is often smaller than the exposure it creates.
-
[ ] Ask whether the population can sign.
- Why. Employees can, contractors can with coordination, and retail customers, visitors, and third-party drivers generally cannot.
-
[ ] Ask whether the system can be configured outside coverage.
- Why. Detection without identification, matching without retention, or on-device processing with nothing transmitted. Several vendors support these modes and do not advertise them.
-
[ ] Model the rollout, not the pilot.
-
[ ] Consider a state-limited deployment.
- Why. Deploying everywhere except two states is operationally awkward and several national retailers have concluded the arithmetic supports it.
-
[ ] Test whether the vendor will stand behind it.
- Why. A vendor that will not answer the technical questions in writing, cannot delete on request, and will not move the indemnity cap is telling you how much risk you are absorbing.
-
[ ] Write the decision down either way.
- Why. A documented analysis concluding deployment is appropriate with controls in place is worth having if litigated; a documented decision not to deploy is worth more.
Phase 18. Where this sits in the wider privacy program
-
[ ] Biometric obligations do not replace the general privacy program.
- Why. The comprehensive statutes add assessments, notices, rights handling, and processor contracts on top of the biometric paperwork, and neither set subsumes the other.
-
[ ] Coordinate with the breach response plan.
- Why. Biometric data in a breach triggers notification analysis under state statutes and, in some states, a private right of action for failures of reasonable security. Cal. Civ. Code § 1798.150. See Incident Response Checklist.
-
[ ] Coordinate with the vendor management program.
- Why. The same diligence and contracting workflow should handle biometric processors, with the additional terms noted in Phase 7.
-
[ ] Coordinate with records retention.
- Why. The three-year outer limit is shorter than most corporate retention schedules, and a general schedule that keeps personnel data for seven years will retain templates in violation.
-
[ ] Coordinate with employment counsel.
- Why. The condition-of-employment provision, the refusal path, and the union preemption question are all employment matters.
-
[ ] Coordinate with the FTC exposure.
- Why. Deceptive statements about biometric practices are separately actionable. 15 U.S.C. § 45.
-
[ ] Keep one page current.
- Why. Systems in scope, releases on file, destruction job status, state footprint, insurance position, and the modeled residual. It is what a board, a regulator, or successor counsel reads first.
Phase 19. Defending a claim, if one arrives
The defenses are narrower than defendants hope and they are mostly threshold arguments. Assemble them in this order.
-
[ ] Coverage.
- Why. The system does not create or retain an identifier within the statutory definition. This requires a technical witness who can say what is stored, not a datasheet.
- Authority. 740 ILCS 14/10; Fed. R. Evid. 702.
-
[ ] Exemption.
- Why. Health care setting, federal health privacy law, financial institution, or government contractor. Each is narrower than it sounds — a hospital's employee timeclock is not in a health care setting.
- Authority. 15 U.S.C. § 6801.
-
[ ] Labor preemption for union-represented employees.
- Authority. 29 U.S.C. § 185.
- Why. Where resolution requires interpreting the collective bargaining agreement, on the reasoning that the union may bargain over the subject. This turns on the management rights clause.
-
[ ] Extraterritoriality.
- Why. The statute reaches conduct occurring primarily and substantially within the state, which limits a nationwide class.
-
[ ] Consent in fact.
- Why. A signed acknowledgment, an onboarding form, or an enrollment flow that captured agreement. Whether it satisfies the release requirement depends on what it said and when it was signed.
-
[ ] Class certification.
- Authority. Fed. R. Civ. P. 23.
- Why. Where enrollment practices varied by location, by year, or by supervisor, individualized questions may defeat predominance. This is the defense with the largest practical effect on exposure.
-
[ ] Damages discretion.
- Why. The liquidated amounts are a ceiling subject to judicial discretion. This is an argument at the end of a case rather than a reason to be in one.
-
[ ] Know what does not work.
- Why. That nobody was harmed, that the data was well protected, that the vendor should have said something, or that the company fixed it on learning. Motions on those grounds fail. Fed. R. Civ. P. 12.
-
[ ] Preserve the remediation record.
- Why. It bears on the negligent-versus-reckless question, and the statutory figures differ substantially between them.
-
[ ] Tender to insurers and vendors immediately.
- Why. Late notice is a coverage defense independent of the merits, and vendor indemnities usually require prompt written tender.
Phase 20. The ninety-day plan
For a company starting from nothing, this is the sequence and the pace.
- [ ] Week one. The inventory, reaching human resources, facilities, security, store operations, and the contact center.
- [ ] Week two. Technical answers in writing from each vendor: what is created, what is retained, and where it lives.
- [ ] Week three. The paperwork audit — what policy, notice, and releases exist today, if any.
- [ ] Week four. The decision on each system: keep and remediate, reconfigure outside coverage, or suspend.
- [ ] Weeks five to eight. Build. Public policy published, per-system notices drafted and versioned, release form, enrollment control, and the scheduled deletion job with logging.
- [ ] Weeks nine and ten. Re-consent every current enrollee before the next scan, with a documented path for refusals.
- [ ] Weeks eleven and twelve. Vendor contract amendments and the insurance review.
- [ ] Throughout. The exposure model, updated as facts arrive, and a one-page status the board can read.
The whole program is a part-time assignment for one lawyer, one engineering change, and a vendor negotiation. Set against the modeled exposure of a six-year unconsented deployment, that ratio is the entire argument for doing it before somebody else's lawsuit prompts it.
Outcome. The inventory found nine systems where technology knew of three, and eight were in scope. Yard camera matching was suspended because the drivers were third-party contractors who could not practically sign. A public policy, per-system notices, releases, an enrollment control, and a monthly deletion job were built in eight weeks, and every current employee re-consented before the next scan. The general liability policy was found to contain a biometric exclusion added at the prior renewal; a cyber endorsement was obtained. Six years of prior collection at two facilities remained exposed, but accrual had stopped and the remediation record existed.
Key Authorities at a Glance
| Authority | Proposition | Phase | |---|---|---| | 740 ILCS 14/10 | Definitions; identifiers and exclusions | 2 | | 740 ILCS 14/15 | Policy, notice, release, disclosure, care | 3, 4, 5 | | 740 ILCS 14/20 | Right of action; damages; fees | 11 | | Tex. Bus. & Com. Code § 503.001 | Informed consent; destruction | 8 | | Wash. Rev. Code § 19.375.020 | Enrollment; notice and consent | 8 | | Cal. Civ. Code § 1798.100 | Notice at collection | 8 | | Cal. Civ. Code § 1798.105 | Deletion | 7, 8 | | Cal. Civ. Code § 1798.121 | Limit use of sensitive data | 8 | | Cal. Civ. Code § 1798.140 | Sensitive personal information | 8 | | Cal. Civ. Code § 1798.150 | Private right of action for breaches | 9 | | Va. Code § 59.1-575 | Sensitive data | 8 | | Va. Code § 59.1-578 | Consent and assessment | 8 | | Colo. Rev. Stat. § 6-1-1303 | Definitions | 8 | | Colo. Rev. Stat. § 6-1-1308 | Consent and assessments | 8 | | 15 U.S.C. § 45 | FTC unfair or deceptive practices | 8 | | 15 U.S.C. § 6801 | Financial privacy; exemption basis | 10 | | 29 U.S.C. § 185 | Labor preemption defense | 10 | | 18 U.S.C. § 2511 | Interception; voice capture | 2 | | Fed. R. Civ. P. 23 | Class certification | 10, 11 | | Fed. R. Civ. P. 12 | Motions to dismiss | 10 | | Fed. R. Evid. 702 | Technical testimony on what is stored | 2 |
The five things people get wrong
One: they inventory by asking IT. The timeclock came from human resources, the door readers from facilities, and the cameras from security. An inventory that does not reach the functions who buy systems finds a third of them.
Two: they assess coverage from a datasheet. Whether a template capable of identifying a person is created and retained is an engineering question, and the answer decides everything downstream. 740 ILCS 14/10.
Three: they treat a handbook paragraph as a release. The statute requires a written release executed before collection. Continued employment is not execution and a policy acknowledgment is not a release. 740 ILCS 14/15.
Four: they write the destruction policy and never build the job. It is the most documented and least executed obligation in the program, and a policy nobody runs is worse than none because it establishes the obligation.
Five: they check the insurance at tender. Many carriers added express biometric exclusions after the first coverage cases, and the time to discover that is at renewal rather than after a complaint. See Building a Biometric Compliance Program.
Related Documents
Articles
- Your Face as Data
- The First Seventy-Two Hours
- The Data Behind the Marketing
- Who Owns the Data
- The Legal Layers of a Website
Guides
- Building a Biometric Compliance Program
- Running a Data Breach Response
- Building a Privacy Compliance Program for a Consumer Brand
- Negotiating a Technology Agreement
Checklists
- Incident Response Checklist
- Marketing Privacy Compliance Checklist
- Technology Agreement Checklist
- Data Collection and Scraping Risk Checklist
Toolkits
- Biometric and Sensitive Data Toolkit
- Incident Response and Breach Notification Toolkit
- Privacy and Marketing Data Toolkit
- Software, Data, and Open Source Toolkit
Templates & Forms
This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Biometric compliance turns on specific systems, records, and state statutes. Marksy is not a law firm.