
Personal identification technologies at the workplace come with some unique risk to employees and companies, as some new biometric authentication tech can allow hackers to access a system and steal employee biometric data.
As a result, thousands of impacted individuals have had their biometric data leaked. Following such data theft events, victims have hired privacy attorneys to assist in filing class action data theft lawsuits.
Biometric authentication offers several advantages over passwords and PINs. Security is the primary one. A fingerprint or facial scan cannot be guessed or copied the way a six-digit code can, which makes unauthorized access significantly more difficult.
Speed is another benefit. Most employees can unlock a device or clock in with a single scan rather than entering credentials manually. There is also less risk of credentials changing hands.
The technology has limitations. Systems occasionally fail to recognize authorized users, a problem known in the industry as a false negative. This occurs often enough to be a common complaint in workplaces that rely on fingerprint scanners.
Illinois passed its Biometric Information Privacy Act in 2008, and the law has since produced two of the largest privacy settlements in the country. Facebook paid $650 million in 2020 over a facial recognition tagging feature. TikTok settled a comparable claim in 2021 for $92 million, after being accused of collecting facial and other biometric data without proper notice or consent. California imposes similar obligations under the CCPA/CPRA, though its penalty structure differs from Illinois's approach.
Permanence presents a further concern and a breach involving biometric data has lasting consequences, since there is no way to reset a face or a thumbprint the way one would reset a login credential.
Several practices reduce these risks. Multi-factor authentication is one of the simplest measures to implement, since it does not depend on biometrics alone. Pairing a fingerprint with a password or a code adds a meaningful layer of protection.
Encryption is equally important. NIST's Digital Identity Guidelines, published as SP 800-63, set specific standards for handling biometric data securely. Organizations that disregard these standards are often the ones that appear in breach reports later.
Limiting data collection also matters. Companies should gather only what a role requires and delete it once it is no longer needed. Consent should not be reduced to a form that goes unread. Employees are entitled to know what is being collected and who has access to it.
Employees should review a company's privacy policy before providing any biometric information. Some organizations manage this responsibly. Others do not, and the Facebook and TikTok settlements illustrate the consequences of getting it wrong.
The Lyon Firm has experience handling a variety of data privacy litigation and is currently involved in invasion of privacy, data theft and data breach class actions. Contact Joe Lyon for a free case review.
Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there: