Biometric Data Collection at Work in South Carolina: Your Rights
Last reviewed: September 2026
Quick Answer
South Carolina does not have a state-specific biometric data privacy law. Employers may collect biometric data (fingerprints, facial recognition, iris scans, voiceprints) if they obtain informed written consent from employees and comply with federal law, primarily the Fair Credit Reporting Act (FCRA) for background checks and the Americans with Disabilities Act (ADA) if collection creates accessibility issues. No state statute limits biometric collection, but data security and breach notification under South Carolina's general data breach laws (S.C. Code § 40-99-30) may apply.
Key Facts
- •South Carolina has no state biometric privacy law; federal standards apply.
- •Employers may collect biometric data if employees provide informed consent.
- •FCRA applies to biometric background checks; GDPR affects data of EU residents.
- •No specific state law prohibits biometric collection for fingerprinting or timekeeping.
- •Employee consent and notice requirements depend on federal law, not state.
Federal Law: The Baseline
Federal law does not comprehensively regulate private-sector biometric collection, creating a patchwork of protections. The Fair Credit Reporting Act (FCRA), 15 U.S.C. § 1681, is the primary federal statute applicable when employers use third-party vendors to collect biometric data for background checks; it requires written notice and authorization before collection, and a separate disclosure if the data will be used to make an adverse employment decision. The Americans with Disabilities Act (ADA), 42 U.S.C. § 12101, prohibits employers from collecting biometric data that reveals disability status unless it is job-related and consistent with business necessity. The Gramm-Leach-Bliley Act (GLBA), 15 U.S.C. § 6801, applies only to financial institutions. The Privacy Act of 1974, 5 U.S.C. § 552a, protects federal employees' biometric records held by government agencies.
For employers subject to GDPR (those processing data of EU residents), biometric data is classified as special category personal data requiring strict legal basis and explicit consent under Regulation (EU) 2016/679. The Algorithmic Accountability Act and various state laws create additional obligations. Federal law does not require employers to destroy biometric data after employment ends, nor does it establish a timeline for retention. The EEOC enforces ADA compliance; the FTC enforces FCRA compliance. Most private-sector biometric regulation occurs at the state level, leaving South Carolina employers without state-mandated restrictions unless they process EU resident data.
South Carolina Law: What's Different
South Carolina has enacted no comprehensive biometric data privacy statute comparable to Illinois (Biometric Information Privacy Act, 740 ILCS 14/1), Texas (S.B. 1523), or Washington (H.B. 1071). This means South Carolina employers operate under a permissive regime: biometric collection is generally lawful absent explicit employee objection, provided federal law is observed.
However, South Carolina's data breach notification law, S.C. Code § 40-99-30, requires any person or entity that maintains biometric data to notify affected individuals and the South Carolina Attorney General if a breach occurs. The law defines "biometric data" as fingerprints, iris scans, voiceprints, and other unique biological identifiers used for authentication or identification. The notification must be made without unreasonable delay, and if the breach involves more than 250 South Carolina residents, notice to the AG is mandatory.
South Carolina Code § 40-99-10 also requires any entity collecting sensitive personal information (which may include biometric data) to implement and maintain reasonable security procedures and practices. Employers are not explicitly required to obtain written consent before collecting biometric data under South Carolina law, unlike Illinois or Texas, but they must comply with FCRA if using a third party, which effectively mandates consent. There is no South Carolina statute of limitations for civil suits related to biometric data misuse; the general three-year statute of limitations for contract and tort claims (S.C. Code § 15-3-430) likely applies. South Carolina employers benefit from the absence of a state biometric law but face greater federal compliance burden and potential multi-state liability if they operate in Illinois, Texas, Washington, or other states with strict biometric laws.
Key Numbers & Thresholds
South Carolina breach notification law applies to any breach involving biometric data; notice to SC Attorney General required if breach affects 250+ South Carolina residents. No South Carolina employer size threshold applies. Federal FCRA requires written authorization before third-party biometric collection for background checks. No state-mandated deletion deadline for biometric data in South Carolina.
Exceptions & Special Cases
South Carolina law contains no explicit exceptions or safe harbors for biometric collection. However, employers can rely on federal law exceptions to comply generally: (1) Employers collecting biometric data for law enforcement purposes (though limited in private sector), (2) data collected with explicit, informed written consent is generally protected from privacy claims under FCRA, (3) biometric data used solely for IT security (e.g., phone unlock authentication) falls outside FCRA because it is not used for background checks or adverse employment decisions, (4) data collected and used only by the employer internally (not sold to third parties or processed by vendors) may not trigger FCRA if it does not constitute a "consumer report," (5) employers providing notice of retention and deletion policies may argue they complied with reasonable security standards under S.C. Code § 40-99-10.
Common employer defenses: (1) Employee consented in writing to collection, (2) biometric data is not accessible or does not fall within the statutory definition (e.g., not stored as digital identifier), (3) the employer deleted the data within a reasonable timeframe consistent with business purpose, (4) no unauthorized access occurred, so no breach notification duty triggered. ADA exception: if biometric collection is required by law (e.g., DOD contractor fingerprinting), the employer may be protected from ADA claims. At-will employment doctrine does not create an exception; employees can still sue for breach of contract or FCRA violation even if at-will. Union employees may have collective bargaining protections requiring consent before biometric collection, overriding default at-will rules.
What to Do If Your Rights Are Violated
Step 1: Document the biometric data collection practice. Retain copies of any consent forms signed, emails or notices sent to employees, the vendor agreement if a third party collects data, and records of what biometric data was collected (fingerprints, facial scans, etc.), when, and for what stated purpose (background check, timekeeping, security access). Keep screenshots of any company policy or handbook language describing collection. Maintain evidence of storage location, security measures, and retention timeline. Document any incident in which data was accessed or transmitted.
Step 2: Initiate internal complaint process if you are an employee. Contact your HR department in writing (email is acceptable) and state that you object to or question the legality of biometric data collection. Request written explanation of the business purpose, identification of who will access the data, how long it will be retained, and how it is secured. Do not sign any biometric collection authorization unless you understand the scope. Request a copy of the company's biometric data retention and deletion policy. This creates an internal record and may prompt compliance review before escalation becomes necessary. Some employers will cease collection or modify practices after written notice.
Step 3: File a complaint with the relevant federal agency. For FCRA violations (if a third-party vendor was used for background check), file a complaint with the Federal Trade Commission (FTC) at www.reportidentitytheft.ftc.gov or file a private right of action lawsuit under 15 U.S.C. § 1681p within 2 years of discovery. For ADA violations (if biometric collection reveals disability), file a charge with the U.S. Equal Employment Opportunity Commission (EEOC) at www.eeoc.gov or call 1-800-669-4000 within 180 days (or 300 days in a deferral state, though SC does not defer). For data breach involving unauthorized access to biometric data, file a complaint with the South Carolina Attorney General at www.scag.gov or call 803-734-3888. For GDPR violations (if you are an EU resident), file a complaint with your home country's data protection authority (DPA) or the U.S. subsidiary's state DPA representative.
Step 4: Expect the investigation process to vary by agency. EEOC charges are assigned to an investigator who will contact the employer within 30 days and request documentation; the investigation typically takes 2-4 months, and the EEOC will issue a determination letter closing the charge or recommending mediation. FTC complaints do not trigger formal investigation in all cases; the FTC prioritizes patterns of violation but may decline to investigate a single incident. Your private FCRA lawsuit will follow standard discovery; the employer must produce the consent form, the biometric data collected, the vendor agreement, and evidence of compliance (or non-compliance) with notice requirements. Data breach complaints to the SC AG may result in civil investigation or referral to local law enforcement if criminal conduct is suspected.
Step 5: Consult an employment attorney if the employer refuses to clarify practices, if you suffer adverse employment action (termination, demotion, wage cut) after raising concerns, or if your biometric data was breached. Retain an attorney specializing in privacy law or employment law with FCRA experience; they can send a demand letter citing specific federal violations, file a civil lawsuit if the employer does not respond, or negotiate a settlement. An attorney can also determine if you have a class action claim if other employees' biometric data was similarly mishandled. Do not delay if you believe retaliation occurred; consult counsel within 30 days to preserve claims under whistleblower laws (though South Carolina has limited statutory protection for privacy complaints).
Relevant Agency
Federal Trade Commission (FTC) — Consumer Sentinel
https://reportidentitytheft.ftc.gov1-877-438-4338
Consult a South Carolina employment attorney who specializes in privacy law to review your employer's biometric policies and ensure federal compliance.
Get notified when employment law changes
Laws change every year. We'll email you when something changes that affects this topic.
Frequently Asked Questions
Does my employer in South Carolina have to ask permission before collecting my fingerprints or facial recognition data?
South Carolina law does not explicitly require employer consent before biometric collection, but federal law does if the data is used for background checks. Under the Fair Credit Reporting Act (FCRA), 15 U.S.C. § 1681, if your employer uses a third-party vendor to collect biometric data for a background check, they must provide written notice and obtain your written authorization before collection. If your employer collects biometric data in-house for timekeeping, access control, or IT security without selling or sharing it, FCRA does not apply, and South Carolina has no state law requiring consent. However, the absence of a legal requirement does not mean employers typically collect without consent; best practice is for employers to provide notice and allow opt-out. If you were not informed and did not consent, you may have a claim under FCRA if the data was used for an adverse employment decision.
What happens if my employer's biometric data system is hacked or breached in South Carolina?
Under South Carolina Code § 40-99-30, your employer must notify you without unreasonable delay if biometric data is breached. If the breach involves more than 250 South Carolina residents, your employer must also notify the South Carolina Attorney General. The law requires notification to the AG at www.scag.gov, though no specific timeline is mandated beyond "without unreasonable delay" (typically interpreted as 30-60 days). You have the right to file a complaint with the SC Attorney General and request investigation. You may also pursue a private civil lawsuit for negligence or violation of the duty to maintain reasonable security practices under S.C. Code § 40-99-10, though South Carolina courts have not yet established a clear statutory damages amount for biometric breaches. Consult an attorney if you incur identity theft losses; you may recover actual damages and potentially attorney fees if you can prove negligence or willful misconduct.
Can my South Carolina employer use facial recognition or fingerprint data to monitor me during work?
South Carolina law does not prohibit employers from using facial recognition, fingerprints, or other biometric data for monitoring or timekeeping purposes. This is one area where South Carolina is significantly more permissive than states like Illinois (which prohibits collection without consent and requires written retention policies). An employer may use biometric timekeeping, access control, or security monitoring if the system is described in the employee handbook or notice is provided at hire. However, the data must be stored securely under S.C. Code § 40-99-10 and destroyed within a reasonable time after employment ends or when no longer needed. If the employer uses facial recognition in a way that reveals disability (e.g., to detect fatigue or health conditions) without your consent, the Americans with Disabilities Act (ADA) may be violated. Additionally, some South Carolina employers in federally regulated industries (e.g., banking, healthcare) may face additional restrictions under industry-specific privacy rules. If you believe monitoring is excessive or violates your privacy, document the system, request the data retention policy, and consult an attorney.
How long can my employer keep my biometric data after I resign or am fired in South Carolina?
South Carolina law does not mandate a specific deletion timeline for biometric data. Unlike Illinois, which requires employers to delete or anonymize biometric data within 3 years of employment end or when the purpose is satisfied (whichever is first), South Carolina imposes no statutory deadline. However, S.C. Code § 40-99-10 requires that any biometric data held be stored with "reasonable security procedures and practices." This may imply an obligation to delete outdated data to minimize breach risk, though no court has clarified this. Best practice for employers is to delete biometric data within 1-2 years of employment end, consistent with federal FCRA recommendations. If you request deletion in writing and the employer refuses without legitimate business reason (e.g., ongoing litigation hold), you may argue breach of the duty to maintain reasonable security. Additionally, if biometric data is retained longer than necessary and is subsequently breached, the extended retention period may increase employer liability. Request written deletion confirmation from HR; if denied, consult an attorney to determine if breach of contract or negligence claims apply.
If I work for a South Carolina employer that operates across multiple states, which biometric privacy law applies to my data?
If your employer operates in states with strict biometric laws—such as Illinois (740 ILCS 14/1), Texas (H.B. 1523), Washington (H.B. 1071), or California (A.B. 375)—your employer is likely required to comply with those state laws even if you work in South Carolina. Employers typically standardize biometric practices across all states rather than maintaining separate policies per state. This means if your employer collects biometric data from any Illinois employee and requires written consent and 3-year retention limits under Illinois law, the employer may extend these protections to all employees, including you in South Carolina. Federal law (FCRA, ADA, GDPR if applicable) also applies uniformly nationwide. You should request your employer's biometric data policy in writing and ask which state laws they follow. If the employer claims to follow only South Carolina law (which is permissive), you may still have claims under federal law if your data is misused. Consult an employment attorney if you suspect your employer is not complying with multistate biometric regulations.
Related Topics in South Carolina
Sources & References
- 15 U.S.C. § 1681 (Fair Credit Reporting Act) — Regulates background checks including biometric screening.
- 29 U.S.C. § 552a (Privacy Act of 1974) — Protects federal employee biometric records.
- Regulation (EU) 2016/679 (GDPR) — Applies to biometric data of EU residents processed by US employers.
Informational only. Not legal advice. Laws change — always verify with a licensed attorney.
Editorial standards: This guide is reviewed against primary government sources and cites 3 statutes. Last reviewed September 2026. Scheduled for re-verification by September 2027.
See our editorial policy for how content is created and verified, or report an inaccuracy.