RatedWithAI

RatedWithAI

Accessibility scanner

AI RegulationJuly 19, 2026

BIPA and Daycare Biometric Check-In Systems 2026

Fingerprint and face-scan pickup kiosks at daycare and childcare centers collect biometric data from two separate groups at once — the parents doing the scanning and the children enrolled alongside them. That dual collection is exactly the fact pattern that has already produced real BIPA class actions against childcare providers.

2 Classes
Parents and children are each independent BIPA claimants under the same kiosk enrollment
$5,000
Per intentional or reckless BIPA violation, with no aggregate cap
No Age Floor
BIPA's biometric-identifier definition has no minor carve-out or age exemption

Why Daycare Check-In Is a Distinct BIPA Fact Pattern

Childcare centers adopted fingerprint and face-scan check-in kiosks to solve a real safety problem: verifying that only an authorized parent or guardian picks up a specific child, without relying on staff memory or a sign-out clipboard. The system works by enrolling a biometric template for every adult authorized for pickup — and, in many implementations, for the child as well, to match them to the correct guardian record.

That design choice is what creates concentrated BIPA exposure. A single kiosk enrollment event captures data from a population — young children and their parents — that is rarely covered by any BIPA-specific consent process, because most childcare enrollment paperwork was written around health, emergency contacts, and payment, not biometric data collection.

Two Data Subjects, Two Consent Obligations

The Child

HIGH RISK

Face or fingerprint template collected to match the child to an authorized pickup record; consent must come from a parent or legal guardian, since a minor cannot provide binding consent

The Parent or Guardian

HIGH RISK

Own fingerprint or face geometry captured at every pickup and drop-off; requires separate written consent naming the parent as the data subject, not just a general enrollment signature

Authorized Alternate Pickups

MEDIUM RISK

Grandparents, babysitters, or other approved adults enrolled after the fact, often without any consent paperwork at all

Check-In App Vendor

MEDIUM RISK

Hosts and may retain biometric templates across many unrelated centers' families on shared infrastructure

Why "The Parent Signed the Enrollment Form" Isn't Enough

BIPA requires a written release that specifically discloses the biometric identifier being collected, the purpose of collection, and the length of time it will be stored — presented before collection, not folded into a broader childcare enrollment packet. A parent's signature on a general intake form that mentions a "secure check-in system" without naming the biometric data type or retention terms is unlikely to satisfy BIPA's specificity requirement.

This matters twice over at a daycare: once for the adult's own biometric enrollment, and again for the guardian's consent on behalf of the child. Centers that built a single generic consent line into their handbook, rather than a standalone form for each data subject, carry the compliance gap for both classes of claimants at once.

BIPA Compliance Checklist for Daycare Biometric Check-In

Review before enrolling the next family at any Illinois center, or any center serving Illinois residents.

Confirm every enrolled parent and every enrolled child has a standalone, biometric-specific written release on fileDiscovery
Draft a separate consent form for child biometric enrollment, signed by a parent or legal guardianRequired
Draft a separate consent form for each adult (parent, guardian, authorized alternate pickup) enrolled in the kioskRequired
Publish a written retention and destruction schedule tied to disenrollment from the centerRequired
Confirm the check-in app vendor does not pool or cross-reference biometric templates across unrelated centersVendor
Set technical deletion of templates when a child leaves the program or a pickup authorization is revokedOperations
Train front-desk and enrollment staff to present biometric consent as a distinct step, separate from health and emergency-contact paperworkTraining

Audit your AI product's compliance exposure

RatedWithAI helps tech teams understand their compliance posture across accessibility, privacy, and AI regulation requirements. Start with a free scan.

Scan Your Product for Free →

Frequently Asked Questions

Can a parent sue a daycare over biometric check-in without proving any actual harm or data breach?

Yes. Illinois courts treat a bare procedural violation — collecting a biometric identifier without the required written notice and consent — as sufficient standing to sue under BIPA. Neither the parent nor a guardian suing on a child's behalf needs to show identity theft, a breach, or other concrete injury.

Does using a third-party check-in app instead of building the kiosk in-house shift BIPA liability away from the daycare?

No. Licensing a check-in platform does not remove the daycare's own BIPA obligations as the entity that enrolls families and controls the collection at the point of use. The vendor may carry additional exposure of its own, but that is separate from, not a substitute for, the center's compliance responsibilities.

Is there a compliant way to keep using biometric check-in at a childcare center in Illinois?

Yes, through proper consent rather than avoidance: a standalone written release for each parent and each child (signed by a guardian), a published retention and destruction policy, and no sale or profit from the biometric data. Centers that build this into enrollment from day one carry substantially less risk than those retrofitting it after years of unconsented collection.

Related Guides