Why Fixing Buddy Punching Got Employers Sued
A framework for the five ways employers verify someone actually showed up, and why the one method that actually stops a coworker from clocking in for someone else is also the one that has cost White Castle, BNSF, and ADP nine figures combined in Illinois courts.
In this article7 sections
A colleague clocking in for someone who’s running late, or who never shows up at all, is old enough to predate the time clock itself: a foreman signing a paper roster for an absent hand is the same act as a coworker tapping a badge against a reader for someone still in the parking lot. What’s changed since roughly the mid-2010s is that a meaningful share of employers switched to a verification method that makes the old trick physically impossible, and in doing so walked directly into the single most litigated employment-privacy statute in the country.
What actually makes a fingerprint scanner different from everything before it
Every attendance-verification method an employer has ever used falls into one of two categories: something a worker has (a badge, a time card, a PIN), or something a worker is (a fingerprint, a face, an iris). The first category has a flaw no policy memo has ever fully closed: anything a worker has can be handed to somebody else. A badge can sit in a friend’s pocket. A PIN can be read off a sticky note. A signed paper sheet can be signed by whoever’s holding the pen. Every generation of “something you have” technology has been adopted to close the gap the previous generation left open, and every generation has left a new gap of the same shape, because the object doing the verifying is still separable from the person it’s supposed to verify.
A fingerprint or a face doesn’t have that flaw. It can’t be lent, borrowed, or left in a friend’s pocket, which is precisely why timekeeping vendors and large employers started installing biometric terminals: not to save money on the badges, but to close the one gap “something you have” could never close on its own. The tradeoff nobody priced into that decision at the time is that a fingerprint isn’t just harder to lend than a badge. It’s a different legal category of information entirely, and one state built a law to police exactly that category, part of a much broader shift toward employers asking workers to prove things that used to be taken on faith, a trend covered more fully elsewhere on this site, of which the fingerprint clock is the single most expensive cautionary tale.
The Punch-Clock Spectrum
Line up the methods employers have actually used to catch a late or absent worker, and they sit on one continuum, not a random pile of options. Call it the Punch-Clock Spectrum: as verification moves from something a worker has toward something a worker is, spoofability drops in a straight line, and legal exposure rises in almost the same line.
- A paper sign-in sheet or a supervisor’s roll call. Spoofable by anyone holding a pen or answering to a name. Collects no personal data beyond a signature, and carries no legal exposure beyond ordinary payroll-fraud law.
- A mechanical or magnetic-stripe time card. Spoofable by handing the card to a coworker on the way in. Still collects nothing about the body, so the exposure here is limited to the same wage-and-hour disputes paper always created.
- A badge swipe or a shared PIN. Marginally harder to spoof than a bare card, since a badge can be deactivated, but functionally identical in practice: lend the badge, share the code, and the reader has no way to tell the difference. This is the rung where most large employers sat for two decades, and the rung “buddy punching” as a named problem usually describes.
- A fingerprint scan. The spectrum turns a corner here. A fingerprint can’t be handed off the way a badge can, so buddy punching as a physical act becomes close to impossible. It’s also the exact rung where Illinois’s Biometric Information Privacy Act (BIPA), passed in 2008 as 740 ILCS 14, draws its line: a fingerprint is a “biometric identifier” under the statute’s own definition, and collecting one without a written policy, advance notice, and signed consent is a violation regardless of whether anyone was actually harmed by it.
- Facial recognition. The newest rung, and the one liveness-detection features got added to because early facial readers could sometimes be fooled by a photo held up to the camera. Legally, it sits in the same exposed category as a fingerprint: BIPA defines “biometric identifier” to include a scan of face geometry, and a growing list of other states, including Texas’s Capture or Use of Biometric Identifier Act and Washington’s biometric privacy law, cover it in a looser but real form too.
The pattern across all five rungs is not subtle. The two methods that actually solve buddy punching, fingerprint and face, are the only two that pull a body of privacy law into play built around exactly the property that makes them work: the data can’t be changed, reissued, or separated from the person it belongs to. An employer cannot buy the strongest available defense against a coworker clocking in for someone else without also buying the sharpest liability category in American employment law today.
Illinois wrote the law before most employers noticed they’d triggered it
BIPA’s mechanics are unusually precise for a state privacy statute, which is exactly why it has generated so much litigation, and its precision draws a much narrower line than a reader might assume: an ordinary, unanalyzed photo falls outside BIPA’s own definition of biometric data entirely, which is exactly why the fingerprint and face-geometry scans below sit in such a differently exposed category. Section 15(b) requires written notice and signed consent before collecting a fingerprint or face scan. Section 15(a) requires a public written policy with a retention and destruction schedule, biometric data has to be destroyed within three years of an employee’s last interaction with the employer or when the purpose for collecting it ends, whichever comes first. And the statute gives an ordinary employee, not just a regulator, the right to sue directly: $1,000 per negligent violation, $5,000 per intentional or reckless one, with no need to show any actual harm beyond the violation itself.
That last piece is what turned BIPA from a compliance checkbox into a litigation engine. In Rosenbach v. Six Flags Entertainment Corp., decided January 25, 2019, the Illinois Supreme Court held unanimously that a plaintiff need not allege any real-world injury to qualify as “aggrieved” under the statute; a bare technical violation, missing consent paperwork, no posted retention policy, is enough on its own to support a lawsuit and collect statutory damages. A fourteen-year-old whose thumbprint was scanned for a Six Flags season pass, with no allegation that anything bad happened to him as a result, was allowed to sue and win. Every fingerprint time clock case that followed built on that ruling.
What that actually cost, case by case
The employer-side litigation runs from mid-size settlements to the largest employment-privacy verdict in the country’s history, and it maps almost perfectly onto the Punch-Clock Spectrum’s high end.
Cothron v. White Castle System, Inc., decided by the Illinois Supreme Court on February 17, 2023, addressed a question that determines how large any BIPA time clock case can get: does a claim accrue once, at the first unauthorized scan, or every time an employee scans in without consent? The court held it accrues with every scan. White Castle’s own attorneys calculated that reading could expose the company to more than $17 billion in statutory damages across its workforce. The case ultimately settled; a federal judge granted final approval to a $9.39 million settlement on August 1, 2024, a fraction of the theoretical exposure, but real money over a single company’s fingerprint clocks.
Rogers v. BNSF Railway Co. is the case that showed a jury would enforce this just as hard as a judge would. BNSF used a third-party contractor, Remprex LLC, to fingerprint roughly 45,600 truck drivers at its Illinois rail yards through an automated gate, the same population already bound by a separate federal rulebook dictating exactly how many hours they’re legally allowed behind the wheel, long before BIPA ever entered the picture. In October 2022, a federal jury found BNSF had recklessly or intentionally violated BIPA on every one of those scans and set damages at $228 million, the first case of its kind to reach a jury verdict at all. A district judge later vacated that figure in June 2023, ruling that BIPA’s damages provision is discretionary rather than automatic and ordering a new trial limited to the amount. Rather than retry it, BNSF settled: a $75 million fund, final approval granted June 18, 2024, covering drivers fingerprinted at BNSF’s Illinois facilities between 2014 and 2024, at an average payout of roughly $1,000 per driver. BNSF itself never operated the fingerprint scanners; it was found liable anyway for equipment a contractor ran on its behalf.
ADP, the payroll and timekeeping vendor rather than an employer at all, settled its own BIPA case over the fingerprint clocks it supplied to other companies’ workforces for $25 million, with final court approval on February 10, 2021. Below that tier sits a longer list of vendor-side settlements that shows how far down the market this exposure reaches: Accu-Time Systems settled for $1.5 million over its finger-scan time clocks, iSolved for roughly $2.5 million covering scans collected between 2014 and 2022, WorkEasy Software (formerly EasyWorkforce) for $1.69 million over a class period running from 2016 to 2023, and two Enterprise Rent-A-Car franchise operators for a combined $505,000. None of these companies are competing for the same customers. What they share is a single rung on the Punch-Clock Spectrum.
The liability doesn’t stay with whoever owns the time clock
BNSF’s case carries a second lesson: the company that got sued wasn’t the company that ran the scanners. That detail generalizes across nearly every case on this list. ADP, Accu-Time, iSolved, and WorkEasy are vendors rather than employers, and they were sued directly over hardware and software they sold to somebody else’s workforce. BIPA’s language reaches anyone who “collects, captures, purchases, receives through trade, or otherwise obtains” a biometric identifier, a list broad enough to catch a staffing agency, a payroll processor, or a contractor running the equipment on an employer’s property. An organization further down the spectrum can end up on the hook for a decision a vendor made about how to build its product, which is a different liability shape than most workplace-technology risk carries.
Whatever the exact verification method, the underlying idea driving all of it is the same one behind any setup that proves a claim instead of accepting it on faith, whether that’s a fingerprint scanner an employer bought or a live photo an app asks a friend group to see, the way DontSnooze treats an alarm the same way a time clock treats a shift: proof rather than a self-report.
Why this risk is so lopsided by geography
This isn’t a national risk in the way it might sound. BIPA is an Illinois statute, and its combination of a private right of action, statutory damages that don’t require proving harm, and a three-year retention deadline is unusually aggressive even among the small number of states with biometric privacy laws at all. Texas and Washington have their own versions, but neither gives an ordinary worker the direct right to sue for money the way Illinois does; enforcement in both states runs primarily through the state attorney general instead. An employer running the exact same fingerprint clock in Ohio and Illinois is running two entirely different risk profiles on the same hardware, which is part of why so much of the national reporting on this topic keeps circling back to the same state.
What this actually means for an employer choosing a clock today
The Punch-Clock Spectrum doesn’t resolve into a clean recommendation, because the two things it measures move in opposite directions from an employer’s point of view: the rung that best stops buddy punching is the rung that carries the sharpest legal exposure, and no available technology solves both problems at once. A badge-based setup stays legally simple and keeps the exact vulnerability biometrics were built to close. A fingerprint or face reader closes that vulnerability and opens a different one, discovered fingerprint by fingerprint, one court filing at a time, over the decade since Illinois wrote a law for a problem most employers hadn’t yet realized they were creating.
None of BIPA’s exposure attaches to a voluntary, friend-to-friend version of the same proof-of-presence idea, since the legal categories that reach an employer’s verification tools stop at the edge of the employment relationship itself — a social contract with no employer on either end of it never triggers the statute in the first place.