BIPA and Daycare Biometric Check-In Systems 2026
Fingerprint and face-scan pickup kiosks at daycare and childcare centers collect biometric data from two separate groups at once — the parents doing the scanning and the children enrolled alongside them. That dual collection is exactly the fact pattern that has already produced real BIPA class actions against childcare providers.
Why Daycare Check-In Is a Distinct BIPA Fact Pattern
Childcare centers adopted fingerprint and face-scan check-in kiosks to solve a real safety problem: verifying that only an authorized parent or guardian picks up a specific child, without relying on staff memory or a sign-out clipboard. The system works by enrolling a biometric template for every adult authorized for pickup — and, in many implementations, for the child as well, to match them to the correct guardian record.
That design choice is what creates concentrated BIPA exposure. A single kiosk enrollment event captures data from a population — young children and their parents — that is rarely covered by any BIPA-specific consent process, because most childcare enrollment paperwork was written around health, emergency contacts, and payment, not biometric data collection.
Two Data Subjects, Two Consent Obligations
The Child
HIGH RISKFace or fingerprint template collected to match the child to an authorized pickup record; consent must come from a parent or legal guardian, since a minor cannot provide binding consent
The Parent or Guardian
HIGH RISKOwn fingerprint or face geometry captured at every pickup and drop-off; requires separate written consent naming the parent as the data subject, not just a general enrollment signature
Authorized Alternate Pickups
MEDIUM RISKGrandparents, babysitters, or other approved adults enrolled after the fact, often without any consent paperwork at all
Check-In App Vendor
MEDIUM RISKHosts and may retain biometric templates across many unrelated centers' families on shared infrastructure
Why "The Parent Signed the Enrollment Form" Isn't Enough
BIPA requires a written release that specifically discloses the biometric identifier being collected, the purpose of collection, and the length of time it will be stored — presented before collection, not folded into a broader childcare enrollment packet. A parent's signature on a general intake form that mentions a "secure check-in system" without naming the biometric data type or retention terms is unlikely to satisfy BIPA's specificity requirement.
This matters twice over at a daycare: once for the adult's own biometric enrollment, and again for the guardian's consent on behalf of the child. Centers that built a single generic consent line into their handbook, rather than a standalone form for each data subject, carry the compliance gap for both classes of claimants at once.
BIPA Compliance Checklist for Daycare Biometric Check-In
Review before enrolling the next family at any Illinois center, or any center serving Illinois residents.
Audit your AI product's compliance exposure
RatedWithAI helps tech teams understand their compliance posture across accessibility, privacy, and AI regulation requirements. Start with a free scan.
Scan Your Product for Free →Frequently Asked Questions
Can a parent sue a daycare over biometric check-in without proving any actual harm or data breach?
Yes. Illinois courts treat a bare procedural violation — collecting a biometric identifier without the required written notice and consent — as sufficient standing to sue under BIPA. Neither the parent nor a guardian suing on a child's behalf needs to show identity theft, a breach, or other concrete injury.
Does using a third-party check-in app instead of building the kiosk in-house shift BIPA liability away from the daycare?
No. Licensing a check-in platform does not remove the daycare's own BIPA obligations as the entity that enrolls families and controls the collection at the point of use. The vendor may carry additional exposure of its own, but that is separate from, not a substitute for, the center's compliance responsibilities.
Is there a compliant way to keep using biometric check-in at a childcare center in Illinois?
Yes, through proper consent rather than avoidance: a standalone written release for each parent and each child (signed by a guardian), a published retention and destruction policy, and no sale or profit from the biometric data. Centers that build this into enrollment from day one carry substantially less risk than those retrofitting it after years of unconsented collection.