The Lobby Kiosk Enrolled a Stranger.
"Welcome back, Dana — your badge is printing" is the feature every visitor management vendor demos. It is also proof that the system stored a measurement of a courier's face, and that nobody obtained a written release from a person who does not work there.
Illinois BIPA excludes photographs but covers a scan of face geometry derived from one. A private entity may not collect a biometric identifier without first informing the subject in writing that it is being collected and stored, informing them in writing of the specific purpose and length of term, and obtaining a written release — and it must maintain a publicly available retention and destruction policy. Damages are liquidated at $1,000 per negligent and $5,000 per intentional or reckless violation, plus fees. A visitor management kiosk that recognises returning guests is doing the covered thing, to a population that signed nothing, at the moment they walk through the door.
A Badge Photo Is Not the Problem. The Template Is.
Facilities teams hear "the kiosk takes a picture" as one thing. Legally it is two, and the boundary is sharp: capturing an image is expressly outside the statutory definition, while deriving a measurement of facial geometry from that image is inside it. Nearly every feature that makes a modern visitor system worth its subscription sits on the wrong side of that line, because frictionless check-in requires the system to know who arrived.
Visitors Are the Hardest Consent Population There Is
Employee biometric compliance has a natural home: onboarding, where a written release fits alongside the tax forms and the handbook acknowledgement. A visitor has no equivalent moment. The person at the kiosk is a stranger to the organisation, is often late, is holding a package or a laptop bag, and has no relationship that would make reading a disclosure feel reasonable. Everything the statute requires has to happen in the seconds before they touch the screen.
That constraint is why the durable answer for most buildings is configuration rather than consent engineering. A check-in flow that never derives a template does not need a release at all, and it costs one convenience feature that primarily benefits people who visit often — a group better served by a separate non-biometric lane anyway.
No relationship exists with this person and no prior document has been signed. Every consent mechanism has to fit into the next forty seconds.
Written notice of collection, purpose and retention term must come before capture. Most stock kiosk flows put a privacy link in a footer instead.
If the release was not executed first, collection has occurred without consent. This is a single moment and it is not recoverable afterwards.
Comparison against enrolled visitors, a watchlist or an ID photo converts an image into an identification. This is the step that BIPA is about.
Visitor data flows into access control, security video and the tenant's own logs, each with different retention defaults and different owners.
Vendor defaults commonly retain enrolments indefinitely to make the returning-visitor feature work. Absence of a published destruction schedule is a standalone violation.
Multi-Tenant Buildings Diffuse the Obligation Until Nobody Holds It
A single lobby check-in can involve a property manager who selected and installed the system, a landlord who owns the space, a tenant whose employee is being visited and receives the record, and a vendor who stores the templates and runs the match. Each of them can accurately describe the compliance obligation as belonging to one of the others, and in most portfolios all four do.
BIPA does not resolve this by picking one. It attaches to the private entity that collects or possesses, which on these facts is more than one party, so plaintiffs name everyone and the allocation gets decided by contracts that were never drafted with biometric identifiers in mind. The moment of leverage is before installation — in the lease amendment or the property management agreement — and it is almost never used, because the kiosk is procured as a facilities purchase rather than a data one.
Six Controls Worth Having
One question decides the entire compliance posture: does the system derive, store or compare any measurement of facial geometry? Sales engineers answer this casually and inconsistently. Put it in the order form as a representation, because it is the fact you will need to produce two years later.
Returning-visitor matching and watchlist screening are usually optional modules sold as differentiators. Disabling them during evaluation costs a demo feature. Disabling them after a demand letter concedes that they were running against every guest who walked in.
In a multi-tenant building, three parties touch the same check-in and none of their agreements mention biometric identifiers. Decide before installation who provides notice, who holds the consent record, who publishes the retention policy and who indemnifies, then write it into the lease or the property management agreement.
It is required whenever biometric identifiers are possessed, regardless of how briefly, and its absence is checkable from outside by anyone with a browser. This is the cheapest defect to fix and the most frequently pleaded.
The highest-frequency visitors are the ones with no onboarding and the most repeat exposure. A non-biometric lane for deliveries and recurring contractors removes the largest block of per-person risk without touching the guest experience anyone is measuring.
Loading docks, garage gates, after-hours doors and the tablet at reception are frequently different systems bought by different budgets. A compliant lobby and a face-matching side entrance produce exactly one compliant surface and several that are not.
Related Reading
- Facial recognition in apartment and property management — the same landlord-tenant allocation problem with residents instead of guests.
- The section 15(a) retention policy requirement — the violation that can be pleaded without any discovery at all.
- Texas CUBI and AI systems — Attorney General enforcement with no class action required.
Start With What Your Own Site Admits
Before the vendor confirms anything, your building's own pages have already described the feature — "touchless check-in", "recognises returning guests", "instant badge on arrival". Those sentences are exhibits, and so is a privacy page that never mentions a retention schedule.
See what your public pages are claiming in one pass. Run a free scan and reconcile every check-in claim against your consent flow and published policy.
This article is general information and not legal advice. Biometric privacy statutes differ substantially by state in scope, consent mechanics, enforcement and damages, and whether a particular check-in system derives a scan of face geometry is a fact-specific technical question. Consult qualified counsel before deploying or continuing to operate face-capture systems in visitor areas.