There are two kinds of Illinois employers running biometric time clocks right now. The first group has no BIPA consent process at all — they scanned the first face on day one and kept scanning. They know the exposure is there and are quietly hoping no plaintiff-side firm notices. The second group has a consent form. Employees signed something at onboarding. HR filed it. The HRIS admin checked the box.

The second group usually has the same problem as the first. Because the consent form names the employer and describes a biometric time clock. What it almost never names is where the biometric data actually goes after the scan: the clock vendor’s cloud infrastructure, the UKG tenant where the punch lands, and any AI processing pipeline that sits in between. Under BIPA, an omission in the vendor chain is not a paperwork technicality — it is a separate disclosure violation for every scan that occurred after the subprocessor relationship began.

CloudApper AI TimeClock for UKG includes facial recognition at no extra cost and runs on any standard Android tablet or iPad, syncing directly with UKG Ready and Pro WFM at roughly 25% of the cost of proprietary Intouch hardware. For Illinois employers deploying it, the compliance question is not whether a consent form exists. It is whether that form names every downstream processor the biometric data touches — and whether it was signed before the first scan.

Workforce-Management-CloudApper-AI-TimeClock-For-UKG-Dimensions

Free Case Study

Knighted Ventures Automated Time Tracking and Ensured Meal Break Compliance with CloudApper AI TimeClock for UKG Pro WFM

What BIPA Requires — and What Most Summaries Leave Out

Illinois Biometric Information Privacy Act, 740 ILCS 14, has four requirements before an employer collects biometric data. Three of them are widely understood. The fourth is the one that drives most of the litigation.

The widely understood three. An employer must: (1) establish and publicly post a written policy that includes the retention schedule and destruction guidelines for biometric data; (2) inform the subject in writing that data is being collected, state the purpose and duration, and receive a written release signed before collection begins; (3) use reasonable care to store, transmit, and protect biometric data at least as carefully as other sensitive confidential information.

The one that gets missed. Section 15(d) prohibits disclosing, redisclosing, or otherwise disseminating biometric data to any third party — including vendors and cloud processors — without the employee’s explicit written authorization. If your consent form does not name every downstream processor — the time clock vendor, the vendor’s cloud host, and the UKG tenant receiving the punch — the authorization for third-party disclosure is probably deficient. The general biometric privacy framework for UKG time clocks is well-documented, but the specific subprocessor disclosure obligation is where most Illinois consent forms fall short.

BIPA consent requirements infographic subprocessor disclosure facial geometry retention Illinois
BIPA requires written consent that names every downstream processor — the clock vendor’s cloud, the UKG tenant, and any AI inference engine that touches the biometric data.

The Cothron Ruling: Why the Gap Multiplies

Before Cothron v. White Castle System, Inc. (2023), the prevailing interpretation was that a single BIPA violation accrued at enrollment — the first unconsented collection was the claim, not every subsequent scan. The Illinois Supreme Court rejected that reading. Each biometric collection, capture, or transmission is a separate claim.

For an employer with 400 Illinois hourly workers clocking in and out twice daily, a consent form that failed to name the cloud processor handling facial templates generates roughly 800 potential BIPA claims per day — $1,000 per negligent occurrence, $5,000 per intentional or reckless one — for every day those employees continued scanning after the subprocessor relationship began. The five-year practical lookback turns that into a number no HR team wants to see in a demand letter.

The Cothron ruling applies to the transmission prong as well: each transmission of biometric data to an unnamed third party is a separate violation, not just a continuation of the original collection. Adding a new cloud integration, migrating to a new UKG tenant, or updating the biometric processing pipeline without refreshing the consent form to name the new processor restarts the clock on a fresh violation stream. UKG admins who have upgraded their time clock vendor or migrated UKG tenants since original biometric enrollment without re-executing consent should treat this as a priority audit item. The documentation mindset that drives wage and hour audit readiness applies here — the record needs to be contemporaneous, specific, and complete, not reconstructed.

RightPunch-Case-Study-YMCA-YWCA-of-Manitoba

Free Case Study

YMCA-YWCA of Manitoba Automated Employee Time Capture with Facial Recognition Using CloudApper AI TimeClock

What Your Consent Form Must Actually Name

A BIPA-compliant written release for a biometric time clock program at a UKG-integrated Illinois location needs to cover more than most HR teams have included.

The specific biometric identifier. “Facial geometry” is the correct BIPA term for facial recognition. “Fingerprint” for fingerprint scanners. Generic “biometric data” is too vague to constitute adequate notice for the specific identifier being captured.

CloudApper-Solution-Community-for-UKG

AI TimeClock

Employee Time Clock

Turn any iPad or tablet into an affordable UKG time clock.

The purpose and retention schedule. “Time and attendance tracking via UKG integration” states the purpose with appropriate specificity. The retention schedule should state exactly when biometric data will be destroyed — typically when the employment relationship ends or within three years of collection, whichever comes first — not merely reference a separately posted policy.

Every named downstream processor. This is the section most consent forms omit. If the time clock vendor’s cloud stores the facial templates, that vendor is named. If facial data or derived authentication tokens are transmitted to the employer’s UKG tenant, that disclosure needs to be authorized. If the time clock vendor uses a third-party AI inference engine for spoof detection, that processor appears by name. The consent form needs to match the actual data flow — not a generic description of “our time clock vendor.” The principle that attestation documentation must be specific and contemporaneous applies with equal force to BIPA consent: a generic form signed before the specific processors existed does not authorize the current data pipeline.

A mechanism for updates. Best practice is a consent form that explicitly states the employee will be notified and asked to re-consent if new processors are added to the data pipeline. This creates a defined process for the vendor change and platform migration scenarios that would otherwise generate fresh Cothron exposure.

The UKG Partnership Argument That Backfires

One of the most common assumptions HR teams make when deploying a UKG-integrated biometric time clock is that the vendor’s UKG Technology Partner status means the privacy compliance is handled at the partnership level. It is not.

Casestudy-Applegreen-Success-with-AI-Time-Clock-for-UKG-Dimensions

Free Case Study

Applegreen Transforms Workforce Management with AI and UKG Integration by CloudApper – The Ultimate Compliance Solution!

UKG’s partner program covers technical interoperability — the punch data format, the API connection, the sync logic. It does not extend indemnity for BIPA compliance to the partner’s biometric data collection and processing on the employer’s behalf. The employer is the data controller for BIPA purposes. When an employee brings a BIPA claim for a missing subprocessor disclosure, the claim is against the employer — not against UKG and not against the clock vendor.

This matters practically because the consent form and the BIPA policy are the employer’s responsibility to draft, update, and re-execute whenever the data pipeline changes. The partner badge confirms the technical integration works. It does not confirm the consent form names the partner’s cloud infrastructure as an authorized subprocessor. Assumptions that vendor integrations handle compliance automatically are a recurring source of timekeeping and payroll errors — BIPA is the same pattern at the privacy layer.

Auditing Your Current BIPA Posture

Map the data flow first. Before reviewing consent forms, document where biometric data goes from the moment of capture to destruction: on-device template storage, clock vendor cloud, UKG punch transmission, payroll sync, AI processing. Every step that touches the data is a potential Section 15(d) disclosure that needs authorization.

Match consent forms to the data flow. For every processor in the data flow, confirm it appears by name in the signed consent form. A processor not named in the consent is a disclosure violation for every transmission that has already occurred. Multi-location UKG configurations that process Illinois employees’ data through shared infrastructure across state lines need to confirm that the Illinois-specific consent covers the shared infrastructure.

CloudApper-Solution-Community-for-UKG

AI TimeClock

Employee Time Clock

Replace expensive UKG time clock hardware with AI-powered tablets.

Confirm pre-scan execution timestamps. The consent record must predate the enrollment biometric capture. A consent form signed on day three of employment, when biometric clock-in started on day one, does not cover the first two days of scans. Pull the enrollment timestamps from your time clock system and compare them to the consent signature dates in your HR records.

Audit destruction practices for former employees. Biometric data for employees who left more than three years ago must already be destroyed. Retained biometric data past the policy’s destruction date is a BIPA violation independent of the original consent. The compounding cost of errors that go undetected until litigation applies here — destruction policy violations discovered in discovery are worse than the same violations discovered in an internal audit.

RightPunch-Case-Study-Marsh-Plating-Corp

Free Case Study

Electroplating Company Chose CloudApper AI Time Capture Solution to Eliminate Manual Data Entry

How CloudApper AI TimeClock Closes the BIPA Enrollment Gap

CloudApper AI TimeClock for UKG runs on standard Android tablets or iPads and syncs directly with UKG Ready and Pro WFM. The facial recognition capability is included in licensing — making tablet-based biometric time tracking accessible at roughly 25% of the cost of proprietary UKG Intouch hardware. For Illinois employers, the terminal-level BIPA enrollment workflow is what makes that capability deployable.

When an employee is enrolled in facial recognition at a CloudApper AI TimeClock terminal, the enrollment workflow surfaces the required BIPA disclosures before the facial template is captured: the specific biometric identifier, the purpose and retention schedule, and the named downstream processors. The employee acknowledges each element. The acknowledgment is tied to the employee’s identity, timestamped, and synced to UKG as part of the time clock profile. The consent event precedes the biometric capture — the sequence BIPA requires — and the record is retained and accessible for audit and litigation response.

CloudApper-Solution-Community-for-UKG

AI TimeClock

Employee Time Clock

Capture employee time accurately with a smarter UKG time clock.

When the data pipeline changes — a new cloud integration, a processor update — CloudApper AI TimeClock can surface a re-consent workflow at the terminal for affected employees, creating a new acknowledgment record tied to the updated disclosure. This directly addresses the Cothron exposure for ongoing scans after a new processor relationship begins.

CloudApper AI TimeClock’s 24/7 AI assistant also allows employees to ask questions about the biometric program at the terminal — what data is collected, where it goes, how to request deletion — in plain language, in the employee’s preferred language. For Illinois workforces with questions about the biometric data they consented to provide, routing those answers through the terminal rather than HR reduces queue volume and creates a documented record of the information the employee received. The broader compliance advantages of biometric time clocks in UKG environments are well-established; BIPA-compliant enrollment workflow is the prerequisite for capturing those advantages legally in Illinois.

CloudApper AI TimeClock BIPA enrollment screen named subprocessors consent biometric facial recognition
CloudApper AI TimeClock surfaces the full BIPA disclosure — including named downstream processors — before the first biometric scan is captured, syncing the timestamped consent record to UKG.

Frequently Asked Questions

Q: Does BIPA apply to facial recognition time clocks used by Illinois employees?

Yes. BIPA applies to any private entity that collects, captures, or stores biometric identifiers from Illinois residents. Facial geometry — the unique facial measurements captured during a facial recognition scan — is a biometric identifier under BIPA. If your UKG-integrated time clock uses facial recognition at Illinois locations, BIPA applies to every scan.

CloudApper-Solution-Community-for-UKG

AI TimeClock

Employee Time Clock

Simplify employee time capture with an affordable UKG tablet time clock.

Q: Do we need to name our biometric time clock vendor in the BIPA consent form?

Yes. Section 15(d) of BIPA prohibits disclosing biometric data to third parties without the employee’s written consent. Your time clock vendor, their cloud infrastructure provider, and any other processor that receives biometric data are third parties for BIPA purposes. A consent form that authorizes the employer to collect biometric data but does not specifically authorize disclosure to the named processors handling that data is likely deficient under Section 15(d).

Q: What did the Cothron v. White Castle ruling change about BIPA exposure?

The Illinois Supreme Court held in Cothron (2023) that a separate BIPA claim accrues each time biometric data is collected, captured, or transmitted without prior written consent — not just at original enrollment. For employers whose consent form omits required subprocessor disclosures, each individual clock-in and clock-out is a separate potential violation at $1,000 to $5,000 per occurrence, multiplied across the workforce for the full lookback period.

CloudApper-Solution-Community-for-UKG

AI TimeClock

Employee Time Clock

Modernize UKG time tracking with AI-powered time capture.

Q: What happens to BIPA consent obligations if we switch biometric time clock vendors?

A vendor change requires updating the consent form to name the new vendor and their processors, and re-executing that updated consent with all enrolled employees before the new vendor’s system begins processing biometric data. Employees who continue scanning during a platform migration, without updated consent naming the new processor, generate fresh Section 15(d) exposure for the transition period.

Q: Can employees be required to use biometric time clocks as a condition of employment in Illinois?

BIPA does not explicitly prohibit making biometric time clock use a condition of employment, but consent obtained under coercion may be challenged by plaintiff-side firms. Providing alternative clock-in options — PIN, badge, QR code — reduces the coercion argument and is best practice for Illinois biometric time clock programs.

Q: Does BIPA compliance transfer from the time clock vendor to the employer?

No. The employer is the data controller for BIPA purposes. A time clock vendor’s UKG Technology Partner status covers technical interoperability, not BIPA indemnity. The employer is responsible for drafting, distributing, and maintaining the consent form, the public retention policy, and the destruction schedule — regardless of which vendor’s terminal is capturing the biometric data.

Q: How long must BIPA consent records be retained?

Biometric data must be destroyed when the employment relationship ends or within three years of collection, whichever comes first. Consent records should be retained for at least five years after the last biometric scan associated with that consent, given that Illinois courts have applied a five-year limitations period in some BIPA cases. The records need to be producible in discovery — not just filed in an HR system that no longer has the original employee profile active.

Closing

The BIPA consent form most Illinois employers have on file covers the employer’s collection of biometric data. What it usually does not cover is the pipeline that data flows through after the scan — and under Cothron, every transmission through an unnamed processor is its own violation. The exposure is not in the absence of a form. It is in the gap between what the form says and where the data actually goes.

If your Illinois UKG locations are running facial recognition time clocks without a BIPA enrollment workflow that names every downstream processor and executes before the first scan, the gap is the exposure. Explore how CloudApper AI TimeClock for UKG handles BIPA-compliant biometric enrollment at the terminal: https://ukg.cloudapper.ai/affordable-ukg-kronos-time-clock/