Skip to main content

Biometric Data Collection at Work in Ohio: Your Rights

Last reviewed: July 2026

Quick Answer

Yes, your employer can collect biometric data in Ohio, but only with your written consent and compliance with the Ohio Biometric Privacy Act (Ohio Revised Code § 2963.01 et seq.). Before collecting fingerprints, facial recognition, voiceprints, iris scans, or other biometric identifiers, your employer must provide written notice explaining what data is being collected, how it will be used, stored, and destroyed. Your employer must also maintain a written policy for retaining and destroying your biometric information. Violations can result in statutory damages of $1,000 to $5,000 per violation.

Key Facts

  • Ohio employers must obtain written consent before collecting biometric data under Ohio Biometric Privacy Act.
  • Biometric data includes fingerprints, facial recognition, iris scans, and voiceprints requiring specific disclosures.
  • Employees can sue for statutory damages of $1,000 to $5,000 per violation or actual damages, whichever is greater.
  • Ohio law requires employers to have a written retention and destruction policy for biometric information.
  • Unauthorized sale or sharing of biometric data without consent triggers additional liability.

Federal Law: The Baseline

Federal law does not establish a comprehensive national biometric privacy statute governing private employers. The federal Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.) applies narrowly to financial institutions and their safeguarding of non-public personal information, which may include biometric data in limited contexts. The Health Insurance Portability and Accountability Act (HIPAA) (42 U.S.C. § 1320d et seq.) protects health-related biometric information only in healthcare settings. The Children's Online Privacy Protection Act (COPPA) (15 U.S.C. § 6501 et seq.) restricts collection of biometric data from children under 13 online, but does not broadly regulate employer collection from adult employees. The Americans with Disabilities Act (ADA) (42 U.S.C. § 12101 et seq.) may restrict certain biometric testing in limited contexts where it constitutes a medical examination, but does not establish baseline requirements for consent or notice.

At the federal level, the Equal Employment Opportunity Commission (EEOC) enforces discrimination laws that may tangentially apply if biometric data collection is used to discriminate based on protected characteristics, but this is an indirect protection rather than a direct biometric privacy requirement. The Federal Trade Commission (FTC) has authority under the FTC Act (15 U.S.C. § 45) to address unfair or deceptive practices involving biometric information, but does not have specific statutory biometric privacy rules for private employers. Many states have filled this gap with their own biometric privacy laws; Ohio is one of them.

Ohio Law: What's Different

Ohio's Biometric Privacy Act (Ohio Revised Code § 2963.01 et seq.) creates substantive employee protections significantly stronger than the federal baseline, which has no comprehensive private employer biometric regulation. Ohio law applies to all employers collecting biometric identifiers, defined as "a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry" (Ohio Revised Code § 2963.01(A)). Notably, Ohio extends coverage to all employers regardless of size; there is no employee threshold exemption.

Under Ohio Revised Code § 2963.03, employers must obtain written consent before collecting any biometric identifier. The consent must include specific disclosures: (1) what biometric identifiers are being collected, (2) the specific purpose and intended use of the identifiers, (3) a description of the retention schedule and method of destruction or anonymization, and (4) notice that the employee has the right to know whether their data has been sold, shared, or otherwise disclosed. This is materially stronger than federal law, which does not mandate pre-collection consent or disclosure.

Ohio Revised Code § 2963.04 requires employers to establish and maintain a written policy governing the acquisition, storage, use, retention, and destruction of biometric identifiers. The policy must include how data will be kept secure, who has access, how long it will be retained, and how it will be destroyed or rendered unusable. Employers must provide a copy of this policy to the employee before collecting data.

Under Ohio Revised Code § 2963.05, Ohio creates a private right of action allowing employees to sue employers for violations. An employee can recover statutory damages of $1,000 to $5,000 per violation (per piece of biometric data or per instance of noncompliance), or actual damages if those are greater. Additionally, employees can recover attorney's fees and costs. The statute also prohibits employers from selling, sharing, or disclosing biometric identifiers to third parties without explicit written consent, and violations of this restriction trigger additional liability.

Ohio law also protects against retaliation. Under Ohio Revised Code § 2963.07, employers are prohibited from retaliating against any employee who objects to biometric data collection, requests information about how their data is being used, or exercises rights under the statute. Unlike federal law, which has no specific biometric retaliation protection, Ohio's statute explicitly covers this scenario.

Key Numbers & Thresholds

Written consent required before any collection of biometric data. Statutory damages: $1,000 to $5,000 per violation or actual damages, whichever is greater. No employee count threshold; law applies to employers of all sizes. Retention policy must be established and provided to employee before collection occurs. Attorney's fees and costs recoverable in addition to statutory or actual damages.

Exceptions & Special Cases

Ohio Revised Code § 2963.02 provides important exceptions. The Biometric Privacy Act does not apply to: (1) certain government and law enforcement biometric collection when used for identification or investigative purposes; (2) biometric data collected as part of state or federal criminal justice systems; (3) biometric information collected and used exclusively for fraud prevention or security purposes when the collection is part of an essential electronic device or application function (e.g., fingerprint unlock on company-issued phones); (4) biometric data collected by healthcare providers for purposes of diagnosing or treating medical conditions or healthcare management; and (5) biometric data collected by financial institutions under federal banking regulations, where the collection is specifically authorized by federal law.

An at-will employment relationship does not exempt an employer from the Biometric Privacy Act. The statute applies regardless of employment contract type. However, if biometric collection is lawfully required by federal law (such as certain banking or healthcare contexts), the federal requirement may preempt Ohio law, though this remains a developing area of litigation.

Employers have a valid defense if they can demonstrate they had reasonable procedures in place to comply with the disclosure and consent requirements, though the statute does not provide a good-faith safe harbor. Simply having an inadequate policy is not a defense; employers must actually obtain written consent meeting the statutory requirements.

The statute does not apply to background check companies or third-party vendors collecting biometric data on behalf of employers, but employers remain liable for directing such collection. If a third party collects biometric data at an employer's request without proper consent, the employer is still responsible.

What to Do If Your Rights Are Violated

Step 1 — Document the violation. Keep records of: (a) the date and manner in which your biometric data was collected (e.g., fingerprint scan during onboarding, facial recognition for timekeeping), (b) any written notices or disclosures provided by your employer at the time of collection (or note if none were provided), (c) the employer's biometric data retention and destruction policy if you received one, (d) evidence that you did not provide written consent (emails, witness statements, your employment record), and (e) any communication regarding how your biometric data has been used, stored, sold, or shared. Take screenshots of any digital collection process and save all related emails or documentation.

Step 2 — Attempt internal resolution. Before filing a legal claim, send your employer a written letter (via email or certified mail) requesting: (a) confirmation of what biometric data was collected and why, (b) the specific written consent you signed (or explanation if no consent was obtained), (c) a copy of the employer's biometric data policy, (d) confirmation of the retention and destruction schedule for your data, and (e) written confirmation that your data has not been sold or disclosed to third parties without consent. Request a response within 14 days. Document the employer's response or lack thereof. This internal step is not legally required but establishes evidence of noncompliance and may prompt compliance.

Step 3 — File a civil lawsuit in Ohio state court. Unlike discrimination claims which may require EEOC filing first, Ohio Revised Code § 2963.05 creates a direct private right of action without an administrative filing requirement. You do not need to file with any state agency first. Consult an employment attorney licensed in Ohio and file a civil complaint in the appropriate court of common pleas (generally in the county where you worked or where the employer is located). The complaint should allege: (a) employer violated § 2963.03 (unlawful collection without written consent or inadequate disclosure), (b) employer violated § 2963.04 (failure to maintain a written policy), (c) employer violated § 2963.05 (unauthorized sale, sharing, or disclosure of data), and/or (d) employer violated § 2963.07 (retaliation). The statute of limitations for biometric privacy violations is generally four years under Ohio's general contract and tort statutes, though specific limitations periods may vary by claim type.

Step 4 — Understand the litigation process. Once a civil suit is filed, the employer will receive a copy of your complaint and has 30 days to respond. Discovery will follow, during which both parties exchange documents and conduct depositions. The employer may file a motion to dismiss if they claim the statute does not apply or that their conduct falls within an exception. Prepare to provide evidence: (a) testimony regarding when and how your biometric data was collected, (b) documents showing lack of consent or inadequate disclosure, (c) your employment records, (d) communications with the employer about the data collection, and (e) expert testimony if appropriate regarding standard practices for biometric data security. The case may proceed to settlement, mediation, or trial.

Step 5 — Consult an employment attorney before beginning formal legal proceedings. You should hire an attorney licensed in Ohio who specializes in employment law and privacy litigation. An attorney will review your factual situation, assess the strength of your claim, advise whether your state falls within an exception, evaluate the damages you can recover (statutory damages of $1,000–$5,000 per violation or actual damages, plus attorney's fees), and represent you throughout litigation. Because the statutory damage provision is relatively generous and attorney's fees are recoverable, many Ohio employment attorneys will take biometric privacy cases on contingency or reduced upfront cost. Contact the Ohio State Bar Association (www.ohiobar.org) for attorney referrals if needed.

Relevant Agency

Ohio Attorney General, Civil Rights Section

https://www.ohioattorneygeneral.gov/

614-466-3360

If your employer has collected your biometric data without proper consent or disclosure, an Ohio employment attorney can evaluate your claim and potential damages.

Get notified when employment law changes

Laws change every year. We'll email you when something changes that affects this topic.

Frequently Asked Questions

Does my employer need my consent to use my fingerprints for timekeeping?

Yes. Under Ohio Revised Code § 2963.03, your employer must obtain written consent before collecting your fingerprints or any other biometric identifier, even for routine timekeeping. The consent must be specific and include a written notice explaining what biometric data is being collected, why it is being collected (timekeeping), how long it will be retained, and how it will be destroyed. Simply using a fingerprint time clock without first obtaining written consent violates Ohio law. If your employer did not provide written consent before implementing biometric timekeeping, you may have a claim for statutory damages of $1,000 to $5,000 per violation. Oral consent or consent implied through continued employment is not sufficient under Ohio law.

Can my employer use facial recognition to monitor my work without telling me?

No. Facial recognition is explicitly defined as a biometric identifier under Ohio Revised Code § 2963.01(A). Your employer must obtain written consent before using facial recognition for any purpose, including monitoring work activity, timekeeping, access control, or identity verification. The written consent must specifically disclose that facial recognition will be used and for what purpose. Furthermore, under Ohio Revised Code § 2963.04, your employer must have a written policy governing how the facial images are stored, who has access, how long they are retained, and how they will be destroyed. Unauthorized use of facial recognition violates the statute and exposes your employer to statutory damages of $1,000 to $5,000 per violation. You have the right to object to facial recognition collection, and your employer cannot retaliate against you for refusing.

What happens if my employer shares my biometric data with a vendor without asking me?

Your employer has violated Ohio Revised Code § 2963.05. Ohio law explicitly prohibits employers from selling, sharing, transferring, or otherwise disclosing an employee's biometric identifiers to any third party (including background check companies, timekeeping vendors, or affiliates) without explicit written consent from the employee. Even if your employer has your consent to collect the biometric data, that consent does not automatically extend to sharing it with vendors. The employer must obtain separate, specific written consent for any disclosure. Unauthorized disclosure triggers statutory damages of $1,000 to $5,000 per violation (and potentially more if multiple vendors received the data), or actual damages if greater, plus attorney's fees. You can sue the employer directly in Ohio court without filing with a state agency first.

Can my employer require biometric data collection as a condition of employment?

Ohio law is unclear on whether employers can make biometric data collection a mandatory condition of employment, but the safest interpretation is that while employers may require it, they must still comply with the consent and disclosure requirements. Even if an employer makes biometric collection a condition of employment, they still must provide written notice explaining what data is being collected, the purpose, retention and destruction policies, and that the employee has rights under the statute. Making collection a condition does not eliminate the requirement for written consent or the disclosure obligations under Ohio Revised Code § 2963.03 and § 2963.04. Additionally, if an employee objects to biometric collection, the employer cannot retaliate under Ohio Revised Code § 2963.07. Some Ohio legal scholars argue that coercive conditions may violate the spirit of the statute, though this has not been definitively resolved by courts. If you are pressured to provide biometric data as a condition of employment without proper disclosure and consent, document this and consult an Ohio employment attorney.

What does my employer have to tell me about what they do with my biometric data?

Under Ohio Revised Code § 2963.03, your employer must provide written notice before collecting your biometric data that includes: (1) a description of which specific biometric identifiers will be collected (e.g., fingerprints, facial recognition); (2) the specific purpose and intended use of each biometric identifier; (3) a description of the retention schedule and method of destruction or anonymization (e.g., data will be deleted after employment ends, or after 90 days); and (4) notice that you have the right to know if your biometric data has been sold, shared, disclosed, or otherwise transferred to third parties. Additionally, Ohio Revised Code § 2963.04 requires your employer to maintain a written policy governing the acquisition, storage, use, retention, and destruction of biometric data, and to provide a copy to you. You also have the right to request confirmation from your employer about whether your data has been shared, and the employer must respond truthfully. If your employer refuses to provide this information or provides false information, that is a violation of the statute.

Related Topics in Ohio

See biometric data collection laws in every state →

Sources & References

  • Ohio Revised Code section 2963.01 et seq.Ohio Biometric Privacy Act establishing employer duties and employee rights.
  • Ohio Revised Code section 2963.05Private right of action for biometric data violations with statutory damages.
  • Ohio Revised Code section 2963.03Requirements for written consent and disclosure before collecting biometric identifiers.

Informational only. Not legal advice. Laws change — always verify with a licensed attorney.

Editorial standards: This guide is reviewed against primary government sources and cites 3 statutes. Last reviewed July 2026. Scheduled for re-verification by July 2027.

See our editorial policy for how content is created and verified, or report an inaccuracy.