Employee Privacy: Remote Work Biometric Data

At some point in the last few years, using your face to unlock your laptop or your fingerprint to log into a system stopped feeling futuristic and just started feeling normal. But the normalization of biometric data in remote work has quietly moved past device unlocking. It’s now in the meeting tools that analyze your voice to see who’s talking most, or the software that uses your keystroke patterns to verify your identity. The Illinois Biometric Information Privacy Act already recognizes voiceprints as a biometric identifier requiring written consent, which puts a lot of common remote work tools into a legally gray area most employees don’t know exists.

Employee Rights Privacy Law Biometric Data

Heads up — this post may include links to things I use or like, and I might earn a little something if you shop through them. Doesn’t cost you anything extra, and I only mention stuff I’d actually recommend.

Your Body as a Password: The Biometric Shift in Remote Work

Biometric data isn’t just fingerprints anymore. Under laws like BIPA, it includes information “regardless of how it is captured, converted, stored, or shared,” so long as it’s based on a biometric identifier and used to identify an individual. That means your voice patterns from a Zoom call, your keystroke dynamics, or even your gait analysis from a video could qualify. The practical meaning for remote workers is that the tools you use every day might be collecting legally protected data without you ever signing a consent form.

😰The “wait, what?” moment

Most people I talk to who work remotely have no idea their voice is being analyzed by the meeting tools their company requires. It’s not paranoia to feel uncomfortable about it — it’s your body being used as a data point, and the laws protecting it are still catching up.

The definition matters because the law doesn’t care whether the data is stored on a server in your office or in a cloud vendor’s system. If the tool distinguishes you as an individual based on a unique physical or behavioral characteristic, that data is likely biometric. The Office of the Privacy Commissioner of Canada finalized guidance under PIPEDA that makes this even clearer: biometric information includes data extracted from physical or behavioral characteristics such as fingerprints, facial geometry, voice patterns, iris scans, keystrokes, or gait. If any of that can be linked back to you as an identifiable individual, it’s considered sensitive personal information.

A lot of remote workers assume biometric data only applies to the fingerprint scanner on their laptop or the face ID on their phone. That assumption is the gap companies are falling through. The meeting software that tracks engagement, the productivity tool that monitors activity patterns, the time-tracking app that uses facial recognition to confirm you’re at your desk — all of these can generate biometric data. And most of them don’t come with a clear disclosure about what they’re doing with it.

If you work for a company based in Illinois, or even one that handles Illinois residents’ data, BIPA requires a publicly available retention and destruction policy and a written release before any biometric data is collected. That’s not a checkbox buried in terms of service. It’s a separate, signed document that tells you what data is being collected, why, and how long it will be kept. In Canada, the OPC guidance raises the bar even higher: consent must be express, in plain language, and renewed if the use of the data expands beyond the original scope.

The tricky part is that most employers are operating across multiple jurisdictions. A remote worker in Toronto might be using a tool procured by a U.S.-based company that stores data on servers in Ireland. The OPC’s guidance makes clear that U.S. employers screening Canadian job candidates must comply with PIPEDA when handling biometric data. The legal obligation follows the data, not the company’s headquarters.

⚠️ The mistaken assumption about consent

People often assume that if their employer enabled the tool, the consent is taken care of. But BIPA’s scope can apply to vendors who merely facilitate collection without possessing the data, and the OPC’s four-part test requires a legitimate business need, minimal intrusiveness, and proportionality. The company’s IT department might not even know the tool is collecting biometric data.

The patchwork nature of these laws creates real practical problems. Illinois has amended the Illinois Human Rights Act to address the use of proxies, such as zip codes, in AI models when those proxies may correlate with protected characteristics. Quebec requires filing a notice with the Commission d’accès à l’information before launching any biometric program. Other provinces may follow suit. For a remote worker, this means the protections you have depend heavily on where you live, where your employer is based, and where the data is processed. That’s a lot of uncertainty for something as personal as your voice or face.

The Meeting Tool Blind Spot: Voiceprints, Facial Analysis, and Consent

AI meeting tools that analyze who spoke, for how long, and with what emotional tone are increasingly common. BIPA explicitly recognizes voiceprints as biometric identifiers. The Illinois Artificial Intelligence Video Interview Act adds another layer for employers using AI to analyze video interviews, requiring notice and consent. The Salinas v. Arthur Schuman Midwest, LLC case clarified that entities that merely facilitate collection without possessing the data aren’t liable, but the vendor and the employer might be.

4-part test
The OPC’s framework for appropriate biometric collection: legitimate need, effective technology, minimal intrusiveness, and proportional benefit.

What does this mean for the average remote worker sitting through a Tuesday morning standup? If your employer uses a tool that records the meeting and then analyzes who spoke, how long they spoke, and whether their tone was positive or negative, that tool may be collecting biometric data. If the tool uses your voiceprint to identify you as a specific individual, BIPA’s requirements likely apply. The same goes for facial analysis tools that track whether you appeared engaged or distracted.

The complicating factor is that many of these tools are marketed as productivity or engagement enhancers, not biometric data collectors. The vendor might not even mention biometric data in their marketing materials. But the legal definition doesn’t depend on what the vendor calls it. It depends on what the technology actually does. If a system relies on biometric characteristics to identify a person, the resulting information may fall within the scope of existing privacy laws, regardless of how the method of processing is described.

The Four-Part Test: A Framework for Asking Hard Questions

The OPC’s guidance gives employees a useful framework for evaluating their own workplace. First, is there a legitimate, bona fide business need for the biometric data? Second, is the technology effective and accurate in real-world conditions, including for diverse demographic groups? Third, are there less privacy-invasive alternatives? Fourth, do the operational benefits justify the privacy risks? These questions aren’t just for lawyers — they’re for you to ask your HR department.

🛠️ Questions to ask your employer
  • What biometric data does this tool collect, and where is it stored?
  • Is there a written consent process and a published retention/destruction policy?
  • Has the tool been tested for accuracy across different demographic groups?
  • Who has access to the data — the vendor, the platform, or just the company?

The accuracy requirement is worth pausing on. The OPC guidance specifically mentions that biometric systems must be tested for error rates, spoofing, and performance disparities across demographic groups. This is not a theoretical concern. Facial recognition systems have been shown to have higher error rates for people with darker skin tones. Voice analysis tools can struggle with accents or speech patterns. If your employer is using a biometric tool that hasn’t been tested for demographic bias, the tool itself might be making decisions based on flawed data.

Critical decisions that involve biometric data must also involve human oversight. This is a non-negotiable part of the OPC framework. An automated system cannot be the final decision-maker on something like hiring, promotion, or disciplinary action based on biometric analysis. The human element is required to avoid discriminatory effects.

What to Do When the Vendor Controls the Data

When a vendor provides the tool, an employer enables it, and a platform hosts the interaction, determining who actually controls biometric data becomes murky. The OPC requires that third-party vendors adhere to the same standards. U.S. employers screening Canadian candidates must comply with PIPEDA when handling biometric data. Illinois has even amended the Human Rights Act to address AI models that use proxies like zip codes that correlate with protected characteristics. The legal obligation follows the data, not the company’s headquarters.

The Salinas case in Illinois gives some clarity on liability. The court held that liability under Section 15(b) of BIPA turns on whether the defendant actually collected or obtained biometric data. Entities that merely facilitate collection without possessing, accessing, or controlling the biometric data are not liable. But this also means that the entity that does possess, access, or control the data is liable. If your employer’s vendor holds the biometric data, the vendor is responsible. But so is the employer if they had any role in directing the collection.

This creates a shared responsibility model that most remote workers don’t know about. If a tool collects biometric data without proper consent, both the vendor and the employer could face legal consequences. The practical implication is that employers have a strong incentive to verify that their tools comply with applicable laws. But they don’t always do that verification, and the employee is left holding the privacy risk.

🤔 Pause and ponderIf your employer asked you to sign a biometric consent form tomorrow, would you feel informed enough to say yes or no — or would you just sign it to keep your job?
🔍 So what actually changes?

Start treating biometric data like the sensitive information it is. Read the consent forms, ask about retention policies, and push back on tools that don’t have a clear privacy framework. You have more rights than you think — but only if you exercise them. The laws are a patchwork, but they exist, and they apply to the tools on your laptop right now.

I know it’s awkward to be the one asking questions about privacy. The technology is moving fast, and the laws are trying to catch up. But your body isn’t just another data point for a software dashboard. You’re not being difficult — you’re being smart about protecting something that belongs to you.— Marianne
Facebook
Twitter
LinkedIn
Email

Marianne Foster

Hi, I’m Marianne! A mom who knows the struggles of working from home—feeling isolated, overwhelmed, and unsure if I made the right choice.At first, the balance felt impossible. Deadlines piled up, guilt set in, and burnout took over. But I refused to stay stuck. I explored strategies, made mistakes, and found real ways to make remote work sustainable—without sacrificing my family or sanity.Now, I share what I’ve learned here at WorkFromHomeJournal.com so you don’t have to go through it alone. Let’s make working from home work for you. 💛
Table of Contents

Work From Home Recruitment Bias Impacts Employee Rights

The shift to work from home has brought multiple benefits, such as flexibility and increased productivity. Yet, it also introduces recruitment biases that can impact employee rights in significant ways. This article dives deep into these biases, outlining their consequences and potential solutions for fostering a more equitable work environment. Understanding Recruitment Bias in Remote Work In the age of remote work, recruitment bias manifests in several subtle yet pervasive ways. For instance, many companies use automated applicant tracking systems (ATS) that might favor candidates from specific educational backgrounds or locations. These systems often learn from existing data, which

Read More »

Why Remote Work Dependent Care Stipends Matter for You

Remote work has become a lifeline for many employees, especially during times of global uncertainty. But for those juggling work from home duties alongside dependent care, the need for stipends specifically aimed at easing these child or elder care responsibilities cannot be overstated. If you’re balancing the demands of your job with those of caregiving, understanding and advocating for remote work dependent care stipends is vital for your well-being and productivity. Understanding Dependent Care Stipends Dependent care stipends are financial allowances provided by employers to help cover the costs associated with caring for dependents, such as children or elderly

Read More »

Protecting Employee Rights With Ergonomic Telecommuting Tips

As remote work continues to rise globally, understanding how to protect employee rights in telecommuting environments has never been more crucial. This article offers actionable ergonomic tips that not only enhance productivity but also safeguard your well-being while working from home. Your workspace matters, and implementing practical solutions can help you avoid common telecommuting pitfalls. The Importance of Ergonomics in Remote Work Ergonomics is all about creating a workspace that fits you, which can significantly affect your health and productivity. When you work from home, it’s easy to overlook your work environment. According to the World Health Organization, improper

Read More »

Employee Rights on Telecommuting Equipment Depreciation

With more and more companies jumping on the remote work bandwagon, it’s super important to know your rights as an employee when it comes to stuff like computers and equipment wearing out. When you’re working from home, you might be using your own stuff or gear that the company gives you. This brings up the big question: who pays when things start to break down or become outdated? This article is all about breaking down your rights when it comes to your work-from-home equipment losing value. We’ll keep it simple and friendly! Understanding Depreciation in the Context of Telecommuting

Read More »

Telecommuting Lawsuit Risk Management For Employee Rights

As remote work continues to rise, understanding telecommuting lawsuit risk management is crucial for protecting employee rights. When employees work from home, their rights and obligations can become less clear. This article is dedicated to navigating the specific landscape of employee rights in remote work environments and minimizing potential legal risks for all parties involved. Here’s how you can stay informed and proactive. Understanding Remote Work Dynamics The shift to working from home has brought significant changes to the traditional workplace. Employers have to adapt to new habits and technologies, while employees encounter unique challenges associated with remote work.

Read More »

What Are Your Rights Against Telework Harassment?

You might assume that sliding into your home office each morning puts you outside the reach of workplace harassment law. The physical distance, the lack of co-workers in the same room — it can feel like the rules that govern in-office behavior don’t quite apply. But that assumption is wrong, and it’s dangerous. In April 2024, the EEOC issued enforcement guidance making explicit that virtual harassment violates Title VII just as squarely as harassment in a physical office, and it doesn’t matter whether the conduct happens during scheduled work hours or on an official company platform. Rights & Policy

Read More »