Popeyes Prevails in Biometric Data Lawsuit Over Fingerprint Scans

Popeyes Louisiana Kitchen Inc. defeated a class action lawsuit alleging the company violated employees' privacy rights by collecting their fingerprints...

Popeyes Louisiana Kitchen Inc. defeated a class action lawsuit alleging the company violated employees’ privacy rights by collecting their fingerprints without proper consent. In a ruling issued March 27, 2026, the U.S. District Court for the Northern District of Illinois dismissed the lawsuit brought by employee Brunettea Jones, finding that while she had the right to sue, she failed to establish that Popeyes itself—rather than a franchise operator—was responsible for the biometric data collection. The case centered on whether Popeyes violated the Illinois Biometric Information Privacy Act (BIPA) when it implemented fingerprint-based time clocking systems at franchise locations between September 2019 and at least January 2020.

The lawsuit highlighted a growing tension between workplace efficiency and employee privacy rights. Many employers have turned to biometric authentication systems—fingerprint scans, facial recognition, and iris scanning—to streamline timekeeping and access control. While these systems offer security and convenience benefits, they also collect sensitive personal data that cannot be changed like a password. BIPA, one of the nation’s strictest biometric privacy laws, requires employers to be transparent about how they collect, use, store, and destroy biometric information. The Popeyes case illustrates how courts interpret these obligations and where liability may fall when large companies use franchised operations to implement technology policies.

Table of Contents

What Was the Fingerprint Scanning Requirement at Popeyes?

Between September 2019 and at least January 2020, Popeyes required employees at certain locations to use fingerprint scans to clock in and out for their shifts. Rather than swiping a card or entering a PIN, workers had to place their finger on a biometric scanner. The system stored fingerprint data to authenticate workers and track their hours. For many employees, this was their first experience with mandatory biometric data collection at work, and some did not fully understand what information the company was capturing or how long it would be retained. Brunettea Jones, the lead plaintiff, worked at a franchise location operated by Diamond Jubilee Enterprises Inc. and was required to provide her fingerprints as a condition of employment.

The lawsuit alleged that Popeyes failed to meet BIPA’s transparency requirements when rolling out this system. Specifically, the complaint claimed that Popeyes did not provide employees with a written policy explaining what biometric data was being collected, how it would be stored, how long it would be kept, and when and how it would be destroyed. Without these disclosures, employees could not make an informed decision about providing their biometric information. BIPA mandates that employers obtain informed written consent before collecting biometric data and must have clear data retention and destruction policies. The plaintiff argued that by failing to provide these details, Popeyes violated the law regardless of whether the system functioned properly or whether any data was actually misused.

What Was the Fingerprint Scanning Requirement at Popeyes?

Why Did the Court Rule in Popeyes’ Favor?

The court’s ruling focused on a critical legal distinction: who was actually responsible for implementing the biometric system. The plaintiff alleged that Popeyes violated BIPA, but the evidence showed that the fingerprint scanning system was implemented at a franchise location operated by Diamond Jubilee Enterprises, a separate legal entity. While Popeyes does establish brand standards and policies for franchisees, franchisees retain significant operational control over their individual locations. The court determined that the plaintiff failed to allege sufficient facts showing that Popeyes itself—the parent company—made the decision to collect fingerprints or that Popeyes was directly responsible for the alleged BIPA violations.

This is an important limitation in class action law: a plaintiff must establish that the defendant actually caused the alleged harm. However, this ruling does not mean that franchisees are automatically liable for BIPA violations, either. Had the lawsuit proceeded and gone to trial, the plaintiff would have needed to prove that Diamond Jubilee Enterprises collected fingerprints without proper consent and without the required written policies. The decision does clarify that if a franchise operation collects biometric data, the franchise operator—not necessarily the parent franchisor—bears primary responsibility for complying with BIPA. This has important implications for future cases: employees harmed by biometric data practices at a franchise location may need to name the specific franchise entity as the defendant rather than the national brand, which can be more challenging in class action litigation since franchisees are typically separate corporate entities.

State Biometric Privacy Laws Enacted by Year20081number of states20152number of states20173number of states20195number of states2023+8number of statesSource: National Conference of State Legislatures

What Are the Facts of the Case?

Brunettea Jones worked as an employee at a Popeyes franchise operated by Diamond Jubilee Enterprises. As part of her job duties, she was required to use a fingerprint scanner to clock in and out of her shifts. The biometric system was in place from at least September 2019 through January 2020, though it may have extended beyond that date. During this period, her fingerprint data was collected, stored, and processed by the company’s time-tracking system. Jones had no choice in the matter: providing her fingerprint was a condition of employment.

She was not given a detailed written explanation of what data was being collected, how long it would be stored, or when and how it would be destroyed. Jones filed the lawsuit as a representative of all employees who had their fingerprints scanned at Popeyes locations during the relevant time period. She sought damages for the alleged BIPA violations and asked the court to certify the case as a class action so that potentially thousands of other affected workers could join the lawsuit. The court allowed her to proceed as an individual plaintiff with standing to sue—meaning she had personally suffered an injury and had the right to bring the claim. However, the court found that she did not allege enough facts to show that Popeyes (not just the franchisee) was liable for the biometric data collection, which prevented the case from moving forward against Popeyes as the defendant.

What Are the Facts of the Case?

What Is the Illinois Biometric Information Privacy Act (BIPA)?

The Illinois Biometric Information Privacy Act is one of the most comprehensive state biometric privacy laws in the United States. Enacted in 2008, BIPA applies to any private entity that collects, stores, or uses biometric information from Illinois residents. Biometric information includes fingerprints, voiceprints, scans of the iris or retina, DNA records, or other biological markers. Under BIPA, employers cannot collect, use, or disclose a person’s biometric information without first providing detailed written notice of the collection practices and obtaining the person’s written consent. The law also requires employers to have a specific policy regarding the retention and destruction of biometric data.

Importantly, BIPA allows employees to sue their employer for violations and recover actual damages, liquidated damages of $1,000 to $5,000 per violation, and attorney’s fees. Unlike many employment laws that require proving the employer intended to harm the employee, BIPA violations can occur even if the employer acted in good faith or took reasonable precautions. For example, simply failing to disclose a biometric data retention policy in writing is a violation, even if the employer actually has a policy in practice. This strict liability approach reflects the legislature’s judgment that biometric data is uniquely sensitive because it cannot be changed like a password. Employers in Illinois who use fingerprint scanners, facial recognition systems, or other biometric authentication systems must carefully document their policies and obtain explicit written consent. The Popeyes case shows that large national companies cannot assume that standards set at corporate headquarters automatically satisfy BIPA when those practices are implemented through franchisees at individual locations.

What Are the Privacy Risks of Fingerprint Data Collection?

Fingerprints are permanent, unchangeable biological identifiers. Unlike a password or PIN that can be reset if compromised, your fingerprint remains the same throughout your life. If an employer’s biometric database is breached and your fingerprint is stolen, you cannot simply change your fingerprint and move on. This makes biometric data uniquely sensitive and irreplaceable. Additionally, fingerprints can be used for purposes far beyond timekeeping: law enforcement agencies maintain fingerprint databases, background check companies use fingerprints for vetting purposes, and in theory, stolen fingerprints could be used to create fake identities or to impersonate someone in other biometric systems.

Another concern is data retention: if an employer collects fingerprints but does not have a clear policy for destroying that data after an employee leaves, the employer may retain the information indefinitely. This increases the window of opportunity for data breaches or misuse. Also, employees often feel pressure to consent to biometric collection because it is presented as a condition of employment. However, BIPA explicitly states that employers cannot condition employment on consent to biometric data collection. Despite this requirement, many workers are unaware of their rights and do not realize they can refuse to provide fingerprints. The Popeyes lawsuit underscores why BIPA requires clear written disclosure: employees deserve to know what biometric data is being collected and what safeguards protect it before they are required to provide that data.

What Are the Privacy Risks of Fingerprint Data Collection?

How Do Franchise Operations Complicate Liability?

The Popeyes ruling highlights a structural issue in franchise businesses: corporate liability versus franchisee liability. When a national company like Popeyes franchises its brand, individual franchise operators run their own restaurants while adhering to brand standards and company policies. However, franchisees are typically independent entities with their own management, hiring, and operational decisions. This creates ambiguity about who is legally responsible for violations that occur at the franchise level.

In the Popeyes case, the court found that Brunettea Jones failed to allege that Popeyes corporate made the decision to implement fingerprint scanning; she only showed that it happened at a specific franchise location. This distinction matters for employees suing over privacy violations. If a franchisee implements a biometric system without proper BIPA compliance, the harmed employee must name the franchisee as the defendant to hold them accountable. However, proving that a specific franchise operator is liable is more challenging than suing a large national corporation, which may have deeper pockets to pay settlements or judgments. This framework can create a gap in accountability: the national brand benefits from the efficiency of biometric systems but may escape direct liability for violations if franchisees are the ones implementing the technology.

What Does This Ruling Mean for Workers and Employers Going Forward?

The Popeyes decision clarifies that corporate parent companies cannot be held liable for biometric data collection practices at franchise locations unless the evidence shows that the parent company itself directed or required those practices. This places the burden on employees to identify the correct entity to sue—the franchisee operator rather than the national brand. For workers concerned about biometric data collection, this reinforces the importance of knowing who actually employs you and operates your workplace, since that is the entity that must comply with BIPA. For employers considering biometric systems, the ruling underscores that BIPA compliance is non-negotiable.

Even if a company believes biometric timekeeping improves efficiency and security, it must implement it carefully: provide written notice before collection, obtain written consent, establish and disclose data retention policies, and ensure that employees understand their rights. Companies that delegate biometric system implementation to franchisees or third-party contractors should ensure those partners understand and comply with BIPA requirements. The cost of non-compliance—potential class action lawsuits, liquidated damages, and reputational harm—far outweighs the savings from cutting corners on privacy disclosures. As biometric technology becomes more common in workplaces, BIPA and similar state laws will likely generate more litigation, making proactive compliance the safer choice.

You Might Also Like

Open Settlements You Can Claim Now

Browse current class action settlements accepting claims — several require no proof of purchase:


Leave a Reply