Skip to main content

Biometric Data Collection at Work in Pennsylvania: Your Rights

Last reviewed: July 2026

Quick Answer

Pennsylvania has no state-specific biometric privacy law, unlike Illinois and other states. Employers may legally collect biometric data (fingerprints, facial recognition, iris scans) if they provide written notice and obtain written consent. However, employers must handle the data responsibly under common law duties of care; unauthorized collection, inadequate security, or misuse may expose the employer to tort liability for breach of confidentiality or negligence. There is no statutory private right of action like the Illinois Biometric Information Privacy Act (BIBA, 740 ILCS 14/1), which provides $1,000–$5,000 per violation; Pennsylvania employees must rely on breach notification law and general tort claims.

Key Facts

  • Pennsylvania has no state biometric privacy law; federal BIPA does not apply to most private employers.
  • Employers may collect biometric data with written consent and disclosure under common law principles.
  • Some Pennsylvania municipalities have local biometric restrictions on government contractors.
  • Employees have limited recourse unless data breach or negligence occurs under tort law.

Federal Law: The Baseline

The United States has no federal biometric privacy law. The only comprehensive state biometric statute is the Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14/1 et seq.), which applies only to employers and vendors doing business in Illinois and collecting the biometric information of Illinois residents. BIPA requires written disclosure and consent before collection, prohibits sale or profitable disclosure without consent, and mandates reasonable security measures and a written retention schedule.

Federal law does not regulate private-sector biometric collection. The Fourth Amendment and wiretapping laws apply only to government actors. The Americans with Disabilities Act (ADA) may require disability accommodations related to biometric systems (e.g., alternative authentication methods for employees with fingerprint loss), but the ADA does not restrict collection itself.

Outside Illinois, employers in most states—including Pennsylvania—face minimal statutory constraints. However, they remain subject to state data breach notification laws, unfair trade practices acts, and common law torts such as invasion of privacy, breach of confidentiality, negligence, and unjust enrichment. The Federal Trade Commission (FTC) can pursue enforcement against deceptive or unfair biometric data practices under the FTC Act (15 U.S.C. § 45), but only against companies that violate their own privacy policies or engage in flagrant misconduct.

Pennsylvania Law: What's Different

Pennsylvania does not have a dedicated biometric information privacy statute. Unlike Illinois (BIPA), California (CCPA/CPRA), Texas (BIPA), Washington, Massachusetts, and other jurisdictions, Pennsylvania lawmakers have not enacted a law specifically regulating employer collection, use, retention, or sale of biometric data.

However, Pennsylvania employers are not entirely free to collect biometrics without legal risk. Biometric collection is governed by three overlapping legal regimes:

**1. Common Law Confidentiality and Duty of Care.** Pennsylvania courts recognize an implied covenant of good faith and fair dealing in employment relationships, and a duty of care in handling sensitive personal information. An employer that collects biometric data without disclosure or consent, or that stores it negligently, may face tort liability for breach of confidentiality, invasion of privacy, or negligence. The Pennsylvania Supreme Court has acknowledged privacy interests in personal and biological information (see cases involving medical records and genetic information). An employee can sue for damages if an employer's misconduct causes harm.

**2. Pennsylvania Data Breach Notification Law (Pa. Stat. Ann. tit. 73, § 2201 et seq.).** Pennsylvania requires any person or entity that experiences a breach of unencrypted personal information (including biometric identifiers) to notify affected individuals without unreasonable delay. Biometric data qualifies as personal information. Failure to notify can result in civil liability and regulatory action by the Pennsylvania Attorney General. However, this law does not restrict collection; it governs response to breaches.

**3. Unfair Trade Practices and Uniform Trade Secrets Act.** Under the Pennsylvania Uniform Trade Secrets Act (12 Pa.C.S. § 5301 et seq.), biometric templates and authentication algorithms can be protected as trade secrets if properly safeguarded. An employer can pursue civil action against theft or misappropriation. Conversely, an employee harmed by breach or inadequate security may assert a counterclaim for failure to protect their biometric data as a secret or confidential asset.

**Key Differences from Federal and Stronger State Laws:**

Unlike Illinois (BIPA), Pennsylvania does not provide a statutory private right of action with statutory damages of $1,000–$5,000 per violation per person per day. An employee must prove actual damages or negotiate a settlement. Pennsylvania offers no statutory right to a written disclosure or retention schedule, nor a ban on sale without consent (though such a sale without disclosure might breach confidentiality). Unlike California (CPRA), Pennsylvania has no consumer privacy right to know what biometric data is collected or to request deletion.

**Employer Obligations Under Pennsylvania Law:**

1. **Disclosure and Consent.** While not strictly required by statute, Pennsylvania common law and principles of fairness require an employer to disclose in writing that it will collect biometric data, the purpose, and how long it will be retained, and to obtain written consent. Employers that collect without disclosure face tort liability and potential regulatory action.

2. **Reasonable Security.** Employers must implement reasonable security measures (encryption, access controls, audit logs) consistent with industry standards. Negligent storage or breach of biometric data creates liability.

3. **Breach Notification.** If a breach occurs, the employer must notify affected individuals and the Pennsylvania Attorney General if the breach involves Pennsylvania residents' data, without unreasonable delay (typically within 60 days).

4. **Limited Retention and Use.** While no statute mandates a specific retention schedule, common law confidentiality principles suggest that biometric data should not be retained indefinitely or used for purposes beyond those disclosed. Using biometric data for surveillance unrelated to employment or selling it to third parties without consent constitutes breach of confidentiality and potentially conversion.

**Municipal and Local Restrictions:**

Some Pennsylvania municipalities (e.g., Philadelphia) have enacted local laws restricting government contractors' use of facial recognition technology on government property. Private employers are not directly bound, but those contracting with municipalities must comply with those local rules.

**Comparison to Federal:** Pennsylvania law offers less protection than Illinois BIPA but aligns with the common-law baseline that exists in most non-BIPA states. Employees in Pennsylvania have narrower remedies than those in Illinois or California but are not without protection.

Key Numbers & Thresholds

Pennsylvania has no statutory employer size threshold, biometric collection fee, or filing deadline for a state biometric privacy complaint (because Pennsylvania has no dedicated biometric law). Relevant thresholds from related laws: Pennsylvania data breach notification must occur within a reasonable time, typically construed as 30–60 days. Lawsuits for tort violations (breach of confidentiality, negligence) must be filed within the general Pennsylvania statute of limitations for tort claims: four years from discovery of injury. No minimum employee count triggers biometric regulation in Pennsylvania.

Exceptions & Special Cases

Pennsylvania law provides several exceptions and limitations on biometric privacy protection:

**1. Government and Law Enforcement Exception.** Biometric collection by government agencies, law enforcement, and courts is not restricted by Pennsylvania employment law because those entities are not subject to the common law duty of fairness in the same way private employers are. However, government must comply with the Fourth Amendment if collection is coercive or violates due process. Police and prosecution are exempt from breach notification laws in some circumstances.

**2. No Statutory Private Right of Action.** Pennsylvania has no biometric-specific statute creating a private right of action. An employee cannot sue simply because an employer violated best practices; the employee must prove a traditional tort (breach of confidentiality, negligence, invasion of privacy, conversion) and show actual damages or egregious conduct. Proving causation and damages is harder than the $1,000 per violation under Illinois BIPA.

**3. Consent Defense.** If an employee provides clear, written, informed consent to biometric collection and the employer discloses the purpose and retention period, the employer has a strong defense against a confidentiality claim. The employee's consent to collection does not, however, consent to negligent storage, unauthorized sale, or use for undisclosed purposes.

**4. Business Justification Defense.** An employer may argue that collection of biometric data (e.g., fingerprints for background checks, facial recognition for workplace access control) is a legitimate business interest justified by security, fraud prevention, or operational needs. Pennsylvania courts may recognize this as a qualified privilege defense, similar to the common law defense in other states. However, the employer must show the data is reasonably necessary and proportionate; mass surveillance or collection for marketing is harder to justify.

**5. No Statutory Retention Schedule Requirement.** Unlike BIPA states, Pennsylvania does not mandate that employers destroy biometric data after a set period (e.g., 3 years after separation). However, retention beyond the period of legitimate business use may support a negligence or breach claim if the data is later breached.

**6. Contractor and Third-Party Exception.** An employer that uses a third-party vendor (e.g., a biometric authentication company, background check firm) may not be directly liable if the vendor breaches, if the employer exercised reasonable care in selecting and monitoring the vendor. However, the employer remains liable for its own negligent disclosure to the vendor or failure to ensure contractual data protection obligations.

**7. De-Identified Data Exception.** Biometric data that is anonymized or de-identified (genuinely cannot be linked to an individual) is not regulated as personal information. However, in practice, biometric data is rarely truly de-identified because templates can often be reverse-engineered or linked via metadata.

**8. Public Records Exception.** Biometric data held by government agencies may be subject to Pennsylvania's Right-to-Know Law (RTKL, 65 P.S. § 66.1 et seq.), which requires disclosure of public records. However, privacy exemptions exist for information that would violate a privacy law or reasonable expectation of privacy. Biometric data of public employees may be disclosable unless an exemption applies.

**9. At-Will Employment Context.** Pennsylvania is an at-will employment state. An employer may condition employment on submission to biometric collection without violating employment law, as long as the condition is lawful and not discriminatory. An employee cannot refuse biometric collection and claim wrongful termination in the absence of a public policy exception (e.g., refusal to submit to an illegal search or a statutory violation like BIPA in another state). However, if an employer collects biometric data in violation of a protected class law (e.g., using facial recognition to screen out applicants of a certain race), discrimination law applies.

**10. Collective Bargaining Agreement (CBA) Override.** If a unionized employee is covered by a CBA that restricts or prohibits biometric collection, the CBA terms override the at-will default. Employers must comply with negotiated biometric limitations.

**11. Statutory Damages Cap Absence.** Unlike BIPA, Pennsylvania tort law does not provide statutory damages per violation. An employee must prove actual damages (e.g., cost of credit monitoring after a breach, emotional distress, lost wages) or achieve a settlement. Class actions are more difficult to certify without statutory damages.

What to Do If Your Rights Are Violated

**Step 1: Document Everything**

If you suspect your employer is collecting biometric data unlawfully or handling it negligently, begin documenting immediately. Keep records of: (1) written communications (emails, notices, consent forms) in which the employer disclosed biometric collection or requested consent, or the absence of any disclosure; (2) dates and circumstances of biometric collection (e.g., fingerprint scan for access control, facial recognition scan at a meeting); (3) any written or oral statements by management about the purpose, storage, or retention of biometric data; (4) evidence that the data was breached, improperly accessed, or used for undisclosed purposes (e.g., forwarded to third parties, used for surveillance unrelated to employment); (5) any symptoms of identity theft or fraud following the collection or breach; (6) written requests you made asking the employer to disclose, delete, or secure the biometric data, and the employer's response; (7) names of colleagues also subjected to the same collection or breach.

Save copies of all documents in a secure location outside the workplace (personal email, cloud storage, external drive). Photograph notices or policies posted in the workplace. If your employer uses biometric systems, request copies of any contracts or agreements with vendors, the data retention policy, and security measures (this is a reasonable business request).

**Step 2: Make an Internal Complaint**

Before filing with a government agency, attempt to resolve the issue internally. Send a written email or letter to the human resources department and your direct supervisor describing your concern in clear, non-accusatory language. For example: "I have not seen a written disclosure or consent form regarding the collection of my fingerprint or facial recognition data. Please provide information about why this data is being collected, how long it will be retained, and how it is secured. I am concerned about the privacy and security of my biometric information." Request a written response within 10 business days.

Why this matters: (1) Many employers will remedy the issue once informed—lack of disclosure is often oversight, not malice. (2) A documented internal complaint creates evidence of your good faith and strengthens your position in subsequent disputes. (3) Some legal claims require proof of internal notice. (4) If you later file a government complaint or lawsuit, you can demonstrate that the employer had notice and failed to cure the violation.

Keep a copy of your complaint and any response. If the employer fails to respond or dismisses your concern without correcting the problem, move to Step 3.

**Step 3: File a Complaint with the Appropriate Agency**

Pennsylvania has no dedicated biometric privacy agency. Instead, file based on the violation type:

**Option A: Data Breach Notification Complaint (If Breach Occurred)**

If the employer has experienced a breach of biometric data, file a complaint with the Pennsylvania Attorney General's Office, Consumer Protection Bureau.

—**Agency:** Pennsylvania Attorney General, Bureau of Consumer Protection

—**URL:** https://www.attorneygeneral.gov/contact-us/file-a-complaint/

—**Phone:** 1-800-441-2555 (Consumer Fraud Hotline)

—**What to include:** A detailed written complaint describing the breach (when discovered, what data was compromised, how many individuals affected), whether the employer notified you, dates of notification, and evidence of breach (credit reports showing fraudulent accounts, notification letters from vendors, etc.). Provide copies of any breach notification you received from the employer. The PA Attorney General may investigate if the breach notification was inadequate or untimely.

—**Timeline:** File as soon as you discover the breach. There is no statutory deadline, but filing promptly strengthens your claim.

**Option B: Unfair/Deceptive Practices Complaint (If Misrepresentation)**

If the employer misrepresented the purpose or use of biometric data (e.g., stated it was only for access control but used it for surveillance or sold it), file a complaint with the Pennsylvania Attorney General under the Unfair Trade Practices and Consumer Protection Law (Pa. Stat. Ann. tit. 73, § 201-1 et seq.).

—**Agency:** Pennsylvania Attorney General, Bureau of Consumer Protection

—**URL:** https://www.attorneygeneral.gov/contact-us/file-a-complaint/

—**Phone:** 1-800-441-2555

—**What to include:** Written description of the misrepresentation (what the employer promised vs. what actually happened), dates, and documentary evidence (consent form stating one use, evidence of another use).

—**Timeline:** Complaints should be filed within a reasonable time of discovering the misconduct. Pennsylvania has a general statute of limitations of 4 years for fraud.

**Option C: EEOC/State Human Rights Complaint (If Discrimination)**

If biometric collection is linked to discrimination (e.g., facial recognition is being used to screen out applicants of a particular race, or disabled employees are not offered alternative authentication), file a charge with the U.S. Equal Employment Opportunity Commission (EEOC) and/or the Pennsylvania Human Relations Commission (PHRC).

—**Agencies:** EEOC (federal) and PHRC (state)

—**EEOC:** https://www.eeoc.gov/filing-charge-discrimination

—**EEOC Phone:** 1-800-669-4000

—**PHRC:** https://www.phrc.pa.gov/

—**PHRC Phone:** 717-787-9780 or 1-888-744-7472

—**What to include:** A charge of discrimination naming the respondent (employer), describing the protected class (race, gender, disability, age, etc.), the biometric practice (e.g., facial recognition screening), how it adversely affected you, and any comparators (other employees treated differently). Include dates, witnesses, and documentary evidence.

—**Timeline:** You have 180–300 days to file with the EEOC depending on whether Pennsylvania is a "deferral" state (it is). File with the PHRC first (within 180 days of the discriminatory act), and the PHRC will defer to the EEOC or vice versa. To be safe, file with both simultaneously.

**Step 4: Expect Investigation and Resolution Process**

Once filed, here's what to expect:

**With the PA Attorney General (data breach or unfair practices):**

The Bureau of Consumer Protection will review your complaint. If a pattern of violations is identified (multiple complaints, or serious misconduct), the Attorney General may open an investigation. This can take 2–6 months. The Attorney General may demand that the employer explain its practices, produce records, and take corrective action. If the employer refuses, the Attorney General may pursue civil enforcement, seeking restitution to harmed consumers and penalties. You will not receive direct updates unless you are a named plaintiff in a civil action, which is rare. However, if the Attorney General settles or obtains a judgment, a press release may announce the result.

**With the EEOC/PHRC (discrimination):**

After you file, the agency will send you and the employer a copy of the charge. The employer is required to respond within 20–30 days, explaining its position. The agency will then investigate: requesting documents, interviewing you and the employer, and analyzing whether there is reasonable cause to believe discrimination occurred. Investigation typically takes 90–180 days. You may be contacted for additional information. If the agency finds reasonable cause, it will attempt to conciliate (mediate a settlement). If conciliation fails, the agency may sue the employer on your behalf (rare) or issue a right-to-sue letter allowing you to sue in court. If no reasonable cause is found, you still receive a right-to-sue letter and can pursue a private lawsuit.

**Step 5: Consult an Attorney**

Consider consulting an employment law attorney in the following circumstances:

—**Before filing:** If the matter is complex (e.g., you suspect discrimination, breach, or large-scale negligence), an attorney can advise you on the strongest legal theory and agency to file with, and help prepare a compelling complaint.

—**After filing:** If the agency investigation stalls or finds no reasonable cause, an attorney can evaluate your options for a private lawsuit based on common law torts (breach of confidentiality, negligence, invasion of privacy).

—**For a lawsuit:** If you intend to sue the employer for damages, hire an employment law attorney licensed in Pennsylvania. The attorney can advise on the strength of your tort claims, likelihood of success, and potential damages (actual damages and possibly punitive damages for egregious conduct). Many employment attorneys work on contingency (you pay only if you win or settle).

—**Class action:** If multiple employees were harmed identically (e.g., a widespread biometric breach), an attorney may be able to organize a class action lawsuit, which spreads costs and increases leverage.

**Types of attorneys to seek:**

—Employment law specialists (biometric privacy and data security experience a plus).

—Consumer protection or civil rights attorneys (experienced in EEOC and PHRC claims).

—Data breach/cybersecurity attorneys (if the core issue is negligent security).

Most will offer a free initial consultation. Ask about fee structure, experience with biometric claims, and realistic assessment of your case's strength under Pennsylvania law.

Relevant Agency

Pennsylvania Attorney General, Bureau of Consumer Protection

https://www.attorneygeneral.gov/contact-us/file-a-complaint/

1-800-441-2555

If you need guidance on your rights regarding biometric data collection, consider consulting a Pennsylvania employment law attorney experienced in data privacy.

Get notified when employment law changes

Laws change every year. We'll email you when something changes that affects this topic.

Frequently Asked Questions

Does Pennsylvania have a law that gives me the right to know what biometric data my employer collects about me?

Pennsylvania does not have a statute like the California Consumer Privacy Act (CCPA) or Illinois BIPA that gives you a legal right to know, access, or delete biometric data. However, you have common-law rights to reasonable notice and fair treatment. An employer should disclose in writing what biometric data it collects (e.g., fingerprints, facial recognition), the purpose, and how long it is retained. If the employer refuses to disclose, that refusal is evidence of breach of the implied covenant of good faith and fair dealing and may support a tort claim. You can also make a written request to HR asking for this information; if the employer uses a biometric vendor, request a copy of the vendor's data security agreement. If the request is unreasonably denied, consult an attorney about your options.

Can my employer use facial recognition to monitor me at work in Pennsylvania?

Pennsylvania law does not prohibit facial recognition surveillance of employees. However, the employer's use must be disclosed, reasonable, and consistent with the employment relationship. If an employer uses facial recognition only at building entrances for security (disclosed in advance), that is likely permissible. But if the employer uses hidden cameras or facial recognition to track your behavior throughout the day without disclosure, that could constitute invasion of privacy or breach of confidentiality under Pennsylvania common law, and you may have a tort claim. Additionally, if facial recognition is used in a way that discriminates against a protected class (e.g., rejecting applicants of a certain race), that violates state and federal employment discrimination law. Always ask your employer directly what biometric monitoring systems are in place and how the data is used. If you are not given a clear answer, document the question and non-response in writing.

If my biometric data is breached, what must my employer do, and what are my legal rights?

Pennsylvania's data breach notification law (Pa. Stat. Ann. tit. 73, § 2201 et seq.) requires any entity that experiences a breach of unencrypted personal information (including biometric data) to notify affected individuals without unreasonable delay. The notification must describe the breach, the data compromised, steps the entity is taking to investigate and prevent future breaches, and contact information for questions. The employer must also notify the Pennsylvania Attorney General if the breach affects Pennsylvania residents. If the employer fails to notify you or delays unreasonably (generally more than 60 days), you can file a complaint with the PA Attorney General. Additionally, if the breach resulted from negligent security measures, you may have a tort claim against the employer for negligence and seek damages for identity theft costs, credit monitoring, emotional distress, or time spent remediating fraud. Save all breach notification letters and document any fraud that follows; these are critical for a damages claim.

Can I be fired for refusing to provide biometric data to my employer in Pennsylvania?

Yes, Pennsylvania is an at-will employment state, and absent a union contract, company policy, or statutory exception, an employer can generally condition employment on submission to biometric collection and can fire you for refusing. However, there are important exceptions. If biometric collection is part of a discriminatory scheme (e.g., targeted at a particular race or gender), you are protected under federal Title VII and Pennsylvania Human Relations Act. If you are disabled and biometric collection prevents you from working (e.g., fingerprint scanning when you have severe arthritis), the employer may owe you a reasonable accommodation under the ADA and state disability law. If the biometric collection is part of an illegal practice (e.g., BIPA violation in Illinois if you work near the border), federal law may protect you. If you are unionized, your contract may restrict biometric collection. Before refusing, consult an attorney to understand your specific situation, as wrongful termination claims in Pennsylvania are difficult to prove without a statute or policy violation.

What should I do if my employer asks me to consent to biometric collection but won't tell me why the data is needed or how it will be used?

Refuse consent in writing, and document your refusal. A written consent form should include: (1) a clear description of what biometric data will be collected (fingerprints, iris scan, face scan, voice, etc.); (2) the specific purpose (access control, fraud prevention, payroll, etc.); (3) how long the data will be retained (e.g., during employment plus 1 year); (4) who has access to it (HR, security, third-party vendors); and (5) a statement that you are voluntarily consenting. If the employer's consent form is vague or the employer refuses to provide one, that is a red flag. Send a written email to HR stating: "I am not comfortable providing biometric consent without clear information about the purpose, retention period, security, and vendors involved. Please provide a detailed disclosure before I decide." If the employer still refuses to disclose and disciplines you for non-compliance, consult an employment attorney. The lack of transparency may support a breach of confidentiality claim and is leverage in negotiating your rights.

Does Pennsylvania law allow my employer to sell my biometric data to a third party without my permission?

Pennsylvania law does not explicitly prohibit an employer from selling biometric data, but doing so without disclosure or consent would likely violate the employee's common-law right to confidentiality and fair dealing. If your employment consent form states that biometric data will be used only for internal access control or background checks, and the employer then sells it to a data broker, marketing company, or other vendor for profit, that is a breach of the implied contract and confidentiality duty. You could pursue a tort claim for breach of confidentiality, conversion (treating the data as the employer's property rather than yours), or unjust enrichment. Additionally, if biometric data is sold without encrypting or anonymizing it, the employer may face liability under Pennsylvania's breach notification law if the third party is breached. Always check any biometric consent form for language about third-party sharing; if the form allows sharing, you have the right to know which parties and for what purpose. If selling occurred without disclosure, file a complaint with the PA Attorney General and consult an attorney about damages.

Related Topics in Pennsylvania

See biometric data collection laws in every state →

Sources & References

  • Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14/1 et seq.Federal baseline for biometric privacy; does not apply in Pennsylvania.
  • Pennsylvania common law duty of care and confidentialityGoverns employer handling of employee personal and biometric data.
  • Pennsylvania Uniform Trade Secrets Act, 12 Pa.C.S. § 5301 et seq.Protects biometric templates as trade secrets if properly safeguarded.

Informational only. Not legal advice. Laws change — always verify with a licensed attorney.

Editorial standards: This guide is reviewed against primary government sources and cites 3 statutes. Last reviewed July 2026. Scheduled for re-verification by July 2027.

See our editorial policy for how content is created and verified, or report an inaccuracy.