At some point in the last few years, using your face to unlock your laptop or your fingerprint to log into a system stopped feeling futuristic and just started feeling normal. But the normalization of biometric data in remote work has quietly moved past device unlocking. It’s now in the meeting tools that analyze your voice to see who’s talking most, or the software that uses your keystroke patterns to verify your identity. The Illinois Biometric Information Privacy Act already recognizes voiceprints as a biometric identifier requiring written consent, which puts a lot of common remote work tools into a legally gray area most employees don’t know exists.
Employee Rights Privacy Law Biometric Data
Heads up — this post may include links to things I use or like, and I might earn a little something if you shop through them. Doesn’t cost you anything extra, and I only mention stuff I’d actually recommend.
Your Body as a Password: The Biometric Shift in Remote Work
Biometric data isn’t just fingerprints anymore. Under laws like BIPA, it includes information “regardless of how it is captured, converted, stored, or shared,” so long as it’s based on a biometric identifier and used to identify an individual. That means your voice patterns from a Zoom call, your keystroke dynamics, or even your gait analysis from a video could qualify. The practical meaning for remote workers is that the tools you use every day might be collecting legally protected data without you ever signing a consent form.
Most people I talk to who work remotely have no idea their voice is being analyzed by the meeting tools their company requires. It’s not paranoia to feel uncomfortable about it — it’s your body being used as a data point, and the laws protecting it are still catching up.
The definition matters because the law doesn’t care whether the data is stored on a server in your office or in a cloud vendor’s system. If the tool distinguishes you as an individual based on a unique physical or behavioral characteristic, that data is likely biometric. The Office of the Privacy Commissioner of Canada finalized guidance under PIPEDA that makes this even clearer: biometric information includes data extracted from physical or behavioral characteristics such as fingerprints, facial geometry, voice patterns, iris scans, keystrokes, or gait. If any of that can be linked back to you as an identifiable individual, it’s considered sensitive personal information.
A lot of remote workers assume biometric data only applies to the fingerprint scanner on their laptop or the face ID on their phone. That assumption is the gap companies are falling through. The meeting software that tracks engagement, the productivity tool that monitors activity patterns, the time-tracking app that uses facial recognition to confirm you’re at your desk — all of these can generate biometric data. And most of them don’t come with a clear disclosure about what they’re doing with it.
✦
The Legal Patchwork: What BIPA and PIPEDA Actually Mean for You
If you work for a company based in Illinois, or even one that handles Illinois residents’ data, BIPA requires a publicly available retention and destruction policy and a written release before any biometric data is collected. That’s not a checkbox buried in terms of service. It’s a separate, signed document that tells you what data is being collected, why, and how long it will be kept. In Canada, the OPC guidance raises the bar even higher: consent must be express, in plain language, and renewed if the use of the data expands beyond the original scope.
The tricky part is that most employers are operating across multiple jurisdictions. A remote worker in Toronto might be using a tool procured by a U.S.-based company that stores data on servers in Ireland. The OPC’s guidance makes clear that U.S. employers screening Canadian job candidates must comply with PIPEDA when handling biometric data. The legal obligation follows the data, not the company’s headquarters.
People often assume that if their employer enabled the tool, the consent is taken care of. But BIPA’s scope can apply to vendors who merely facilitate collection without possessing the data, and the OPC’s four-part test requires a legitimate business need, minimal intrusiveness, and proportionality. The company’s IT department might not even know the tool is collecting biometric data.
The patchwork nature of these laws creates real practical problems. Illinois has amended the Illinois Human Rights Act to address the use of proxies, such as zip codes, in AI models when those proxies may correlate with protected characteristics. Quebec requires filing a notice with the Commission d’accès à l’information before launching any biometric program. Other provinces may follow suit. For a remote worker, this means the protections you have depend heavily on where you live, where your employer is based, and where the data is processed. That’s a lot of uncertainty for something as personal as your voice or face.
The Meeting Tool Blind Spot: Voiceprints, Facial Analysis, and Consent
AI meeting tools that analyze who spoke, for how long, and with what emotional tone are increasingly common. BIPA explicitly recognizes voiceprints as biometric identifiers. The Illinois Artificial Intelligence Video Interview Act adds another layer for employers using AI to analyze video interviews, requiring notice and consent. The Salinas v. Arthur Schuman Midwest, LLC case clarified that entities that merely facilitate collection without possessing the data aren’t liable, but the vendor and the employer might be.
What does this mean for the average remote worker sitting through a Tuesday morning standup? If your employer uses a tool that records the meeting and then analyzes who spoke, how long they spoke, and whether their tone was positive or negative, that tool may be collecting biometric data. If the tool uses your voiceprint to identify you as a specific individual, BIPA’s requirements likely apply. The same goes for facial analysis tools that track whether you appeared engaged or distracted.
The complicating factor is that many of these tools are marketed as productivity or engagement enhancers, not biometric data collectors. The vendor might not even mention biometric data in their marketing materials. But the legal definition doesn’t depend on what the vendor calls it. It depends on what the technology actually does. If a system relies on biometric characteristics to identify a person, the resulting information may fall within the scope of existing privacy laws, regardless of how the method of processing is described.
✦
The Four-Part Test: A Framework for Asking Hard Questions
The OPC’s guidance gives employees a useful framework for evaluating their own workplace. First, is there a legitimate, bona fide business need for the biometric data? Second, is the technology effective and accurate in real-world conditions, including for diverse demographic groups? Third, are there less privacy-invasive alternatives? Fourth, do the operational benefits justify the privacy risks? These questions aren’t just for lawyers — they’re for you to ask your HR department.
- What biometric data does this tool collect, and where is it stored?
- Is there a written consent process and a published retention/destruction policy?
- Has the tool been tested for accuracy across different demographic groups?
- Who has access to the data — the vendor, the platform, or just the company?
The accuracy requirement is worth pausing on. The OPC guidance specifically mentions that biometric systems must be tested for error rates, spoofing, and performance disparities across demographic groups. This is not a theoretical concern. Facial recognition systems have been shown to have higher error rates for people with darker skin tones. Voice analysis tools can struggle with accents or speech patterns. If your employer is using a biometric tool that hasn’t been tested for demographic bias, the tool itself might be making decisions based on flawed data.
Critical decisions that involve biometric data must also involve human oversight. This is a non-negotiable part of the OPC framework. An automated system cannot be the final decision-maker on something like hiring, promotion, or disciplinary action based on biometric analysis. The human element is required to avoid discriminatory effects.
✦
What to Do When the Vendor Controls the Data
When a vendor provides the tool, an employer enables it, and a platform hosts the interaction, determining who actually controls biometric data becomes murky. The OPC requires that third-party vendors adhere to the same standards. U.S. employers screening Canadian candidates must comply with PIPEDA when handling biometric data. Illinois has even amended the Human Rights Act to address AI models that use proxies like zip codes that correlate with protected characteristics. The legal obligation follows the data, not the company’s headquarters.
The Salinas case in Illinois gives some clarity on liability. The court held that liability under Section 15(b) of BIPA turns on whether the defendant actually collected or obtained biometric data. Entities that merely facilitate collection without possessing, accessing, or controlling the biometric data are not liable. But this also means that the entity that does possess, access, or control the data is liable. If your employer’s vendor holds the biometric data, the vendor is responsible. But so is the employer if they had any role in directing the collection.
This creates a shared responsibility model that most remote workers don’t know about. If a tool collects biometric data without proper consent, both the vendor and the employer could face legal consequences. The practical implication is that employers have a strong incentive to verify that their tools comply with applicable laws. But they don’t always do that verification, and the employee is left holding the privacy risk.
✦
Start treating biometric data like the sensitive information it is. Read the consent forms, ask about retention policies, and push back on tools that don’t have a clear privacy framework. You have more rights than you think — but only if you exercise them. The laws are a patchwork, but they exist, and they apply to the tools on your laptop right now.