Skip to main content

Biometric Data Collection at Work in North Carolina: Your Rights

Last reviewed: June 2026

Quick Answer

North Carolina employers may collect biometric data such as fingerprints and facial scans, but only with the employee's prior written consent. There is no North Carolina-specific biometric privacy law; instead, employers must comply with the Biometric Information Privacy Act (BIPA), which is a federal framework. The employer must also comply with any state or local laws regarding data retention, use, and deletion. Violations can result in civil liability and statutory damages up to $5,000 per violation under BIPA.

Key Facts

  • North Carolina employers may collect biometric data but must comply with federal BIPA and any contractual obligations regarding consent.
  • The Biometric Information Privacy Act (BIPA) is federal law; North Carolina has no separate state biometric privacy statute.
  • Employers must obtain written consent before collecting fingerprints, facial recognition, or iris scans for identification or payment purposes.
  • Violations of biometric data collection can result in civil lawsuits, statutory damages, and attorney fees under BIPA.
  • Exceptions exist for law enforcement, background checks, and limited government identification programs.

Federal Law: The Baseline

The Biometric Information Privacy Act (BIPA), codified at 740 Ill. Comp. Stat. § 14/1 et seq., is the primary federal framework governing biometric data collection in the United States, including North Carolina. BIPA applies to any private employer that collects, uses, stores, or discloses biometric identifiers (fingerprints, iris scans, facial geometry, voice recognition, and other unique biological characteristics) for purposes of identification, payment, or any other purpose.

Under BIPA, covered employers must obtain written, informed consent before collecting biometric data; cannot disclose biometric data to third parties without consent; must establish a written retention schedule for deletion of biometric data; and must implement reasonable security measures to protect the data from unauthorized disclosure or theft. BIPA prohibits the purchase or sale of biometric data for profit.

BIPA covers all employers regardless of size. The law does not exempt small businesses or nonprofits. Employees and job applicants have a private right of action to sue employers for violations. Statutory damages range from $1,000 to $5,000 per violation, and employees may recover actual damages if greater. The EEOC does not directly enforce BIPA; instead, enforcement is through private litigation and state attorneys general.

North Carolina Law: What's Different

North Carolina does not have its own comprehensive biometric data privacy statute. Therefore, employers in North Carolina are governed solely by the federal Biometric Information Privacy Act (BIPA) and general state law principles regarding data privacy and identity theft.

Because BIPA is a federal law with nationwide application, North Carolina employers are subject to the same written consent, data retention, and deletion requirements as employers in other states. However, North Carolina courts may apply state common law principles of privacy tort liability if an employer's collection or misuse of biometric data is unreasonable or violates an employee's reasonable expectation of privacy.

North Carolina General Statute § 14-458.1 addresses identity theft and fraud, which may provide a basis for liability if an employer uses or discloses biometric data unlawfully to facilitate identity theft. Additionally, North Carolina recognizes the tort of invasion of privacy, which could be asserted in cases where biometric data collection is conducted without consent or in a manner that violates a reasonable expectation of privacy.

Unlike California (California Consumer Privacy Act § 1798.100 et seq.) or Illinois (which enacted BIPA), North Carolina has not enacted a standalone biometric privacy law that creates additional rights beyond the federal BIPA framework. This means North Carolina employers have somewhat more latitude than employers in states with stricter biometric privacy regimes, provided they comply with BIPA's baseline requirements. However, employers should note that any contract, collective bargaining agreement, or company policy that restricts biometric data collection or requires additional consent creates binding obligations that supersede the minimum BIPA standard.

Remedies under North Carolina law are limited to BIPA private right of action (statutory and actual damages), common law privacy tort, and potential enforcement by the North Carolina Attorney General under consumer protection statutes.

Key Numbers & Thresholds

Written consent must be obtained before biometric data collection under BIPA. BIPA statutory damages: $1,000–$5,000 per violation or actual damages, whichever is greater. No employee count threshold; BIPA applies to all employers. Biometric data must be deleted within reasonable time after purpose is fulfilled or within 3 years of last use, whichever is sooner. No North Carolina-specific filing deadline for biometric data claims; general civil statute of limitations of 3 years applies to BIPA private actions in federal court.

Exceptions & Special Cases

BIPA contains several important exceptions where employers may collect biometric data with limited or no consent requirements. Law enforcement collection for criminal investigation, arrest, prosecution, or identification purposes is exempt from BIPA's consent and written policy requirements, though retained biometric data must still be handled securely.

Background check companies and third-party vendors conducting background checks under the Fair Credit Reporting Act (15 U.S.C. § 1681 et seq.) are exempt from BIPA requirements if they use biometric data solely to verify identity. Government benefits programs that use biometric identification for eligibility verification (such as unemployment insurance or SNAP) may operate under reduced BIPA restrictions, though some state-level oversight applies.

Healthcare providers collecting biometric data for legitimate medical purposes may have limited exemptions, though hospitals and clinics are generally required to obtain consent. Employees in positions requiring government security clearances or working at military installations may face different biometric collection standards due to federal security protocols.

North Carolina employers are NOT exempt from BIPA based on business size, industry, or nonprofit status. Common employer defenses include: (1) the employee provided valid written consent; (2) the employer promptly deleted the biometric data per the stated policy; (3) the biometric data was collected and used solely for the stated lawful purpose; and (4) the employer implemented reasonable security measures. However, the burden of proof is on the employer to demonstrate compliance.

What to Do If Your Rights Are Violated

Step 1: Document the biometric data collection practice. Keep records of when biometric data (fingerprints, facial scans, iris recognition, voice samples, hand geometry) was collected, what employee consent forms (if any) were used, what the stated purpose was (timekeeping, building access, payment authorization), how long data was retained, and whether it was deleted. Photograph or screenshot the employer's biometric collection device or portal. Retain any written policies regarding biometric data. Save copies of emails discussing the collection.

Step 2: Request internal remediation and documentation. File a written request with your employer's human resources or legal department asking: (1) why your biometric data was collected; (2) what written consent (if any) you provided; (3) how long the data will be retained; (4) who has access to the data; and (5) when it will be deleted. Request confirmation in writing. If the employer cannot provide evidence of written consent or a lawful purpose, document that refusal.

Step 3: File a complaint with the appropriate agency or attorney. Unlike EEOC complaints, BIPA violations are typically pursued through private litigation in federal court, not through an administrative agency. You may file suit directly in federal district court (e.g., U.S. District Court for the Eastern District of North Carolina or Middle District of North Carolina) without exhausting administrative remedies. You may also contact the North Carolina Attorney General's Consumer Protection Division (919-716-6000; www.ncdoj.gov) to report the violation, though criminal prosecution is rare. The deadline to file a federal civil action is 3 years from the date of the violation.

Step 4: Expect discovery and investigation. Once a BIPA lawsuit is filed, the employer will produce records regarding consent, data retention policies, security measures, and the scope of disclosure. You will likely be deposed (questioned under oath). The court may grant summary judgment if the facts clearly show consent was never obtained or if the employer admits violation. Many BIPA cases settle before trial because statutory damages create predictable liability.

Step 5: Consult an attorney experienced in privacy law or employment litigation. BIPA cases often involve complex issues regarding what constitutes 'biometric data,' what 'written consent' requires, and what constitutes a 'violation.' A civil rights attorney or privacy lawyer can evaluate whether the employer's conduct violated BIPA and estimate damages. Many attorneys work on contingency in BIPA cases because statutory damages are available.

Relevant Agency

North Carolina Attorney General, Consumer Protection Division

https://www.ncdoj.gov/getting-help/consumer-protection/

919-716-6000

If you believe your biometric data was collected without consent or misused, an employment attorney can review your claim and estimate potential damages.

Get notified when employment law changes

Laws change every year. We'll email you when something changes that affects this topic.

Frequently Asked Questions

Can my North Carolina employer require me to provide fingerprints or facial scans for building access or timekeeping?

Your employer may collect fingerprints or facial scans only if they first obtain your prior written consent. Under BIPA, written consent must be clear, informed, and specific to the purpose for which the biometric data will be used. If your employer implemented biometric timekeeping or building access without first obtaining written consent from you, that is a violation of BIPA. Even if the system is convenient, consent is legally required. If you were never asked to sign a consent form before your fingerprint or facial scan was collected, you likely have a claim for statutory damages of $1,000 to $5,000 per unauthorized collection event.

What happens if my employer loses or misuses my biometric data?

If your employer loses, discloses, or misuses your biometric data (for example, by selling it, sharing it with third parties without consent, or failing to delete it after the stated purpose expires), you can sue for BIPA violations. You are entitled to recover statutory damages of $1,000 to $5,000 per violation, plus any actual damages (such as costs to monitor your credit or identity theft losses), plus attorney fees. You do not need to prove that you suffered actual harm or identity theft; the unauthorized disclosure itself triggers statutory liability. A data breach affecting hundreds of employees can result in total damages in the millions of dollars. You should consult a privacy attorney if your biometric data was compromised.

Does my employer have to delete my biometric data after I leave the job?

Yes. BIPA requires employers to delete biometric data within a reasonable time after the purpose for which it was collected has been fulfilled, or within 3 years of the employee's last contact with the employer, whichever is sooner. Most courts interpret 'reasonable time' to mean within 30–60 days after termination or after the stated purpose ends. If your employer continues to retain your fingerprints or facial scans in a database years after you quit without a legitimate ongoing purpose, that is a violation. You should request deletion in writing (email is acceptable) and keep the copy. If the employer refuses or ignores the request, that refusal may support a BIPA lawsuit.

Can my employer use biometric data collected for one purpose (like timekeeping) for a different purpose (like security surveillance)?

No. BIPA prohibits the use of biometric data for purposes other than those disclosed when consent was obtained. If you consented to biometric timekeeping, your employer cannot use that same fingerprint or facial scan data for building security surveillance, criminal investigation, or any other purpose without obtaining new written consent. Any use outside the stated purpose is a violation. Additionally, your employer cannot sell or disclose your biometric data to third parties (such as a security contractor or marketing company) without obtaining separate consent for that disclosure. Courts have found that vague consent language (e.g., 'for employment purposes') is insufficient to cover multiple distinct uses.

Is there a time limit to sue my employer for biometric data collection violations in North Carolina?

Yes, you have 3 years from the date of the violation to file a lawsuit in federal court. The 'violation' is typically dated from either the date of unauthorized collection or the date of unauthorized disclosure or failure to delete. If your employer collected your fingerprints without consent in January 2022, you would have until January 2025 to file suit. However, if the employer continues to retain your data in violation of BIPA's deletion requirements, each day of continued retention may constitute a separate violation, extending your window to sue. You should not delay; consult an attorney as soon as you discover the violation. There is no administrative filing deadline or agency notification requirement for BIPA claims, but filing promptly preserves evidence and prevents spoliation (destruction) of relevant data.

Related Topics in North Carolina

See biometric data collection laws in every state →

Sources & References

  • Illinois Biometric Information Privacy Act (BIPA), 740 Ill. Comp. Stat. 14/1 et seq.Federal framework regulating biometric data collection; applies nationwide including North Carolina.
  • 42 U.S.C. § 1983Provides remedy for constitutional violations of privacy rights in biometric collection.
  • North Carolina General Statute § 14-458.1Addresses identity theft; tangentially relevant to biometric data misuse.

Informational only. Not legal advice. Laws change — always verify with a licensed attorney.

Editorial standards: This guide is reviewed against primary government sources and cites 3 statutes. Last reviewed June 2026. Scheduled for re-verification by June 2027.

See our editorial policy for how content is created and verified, or report an inaccuracy.