Skip to main content

GPS tracking and employee consent: what security companies should know

Tracking a security guard's location touches three separate bodies of law: employee electronic-monitoring statutes that require advance written notice, biometric privacy laws that can apply to photo-based identity verification, and general state privacy laws that now cover employee data. Obligations depend on where your guards physically work, not where your company is registered. This post is an orientation to the categories, not legal advice.

· Sayed Qureshi

Three separate bodies of law apply

Operators often think of this as one question, "can I track my guards?", when it is three, and they can have different answers in the same state.

  1. Employee electronic monitoring. Some states require employers to give notice before monitoring employees electronically. Connecticut (Gen. Stat. § 31-48d) and New York (Civil Rights Law § 52-c*2) are the commonly cited examples; both require prior written notice and both carry a civil penalty ladder of $500, $1,000, then $3,000 per offence, enforced by the state.
  2. Biometric privacy. If your clock-in uses a photo of a guard's face for identity verification, a biometric privacy statute may apply. Illinois (BIPA) and Texas (CUBI) are the two that most often bite in an employment setting.
  3. General state privacy law. California's CCPA, as amended by the CPRA, has applied to employee and applicant data since 1 January 2023, when the HR and B2B exemptions expired. That brought ordinary HR records into a regime originally written for consumers.

It follows the guard, not the head office

The obligations generally attach to where the employee works, not where the company is incorporated. A company registered in one state with contracts in three others may be dealing with three different sets of requirements at once, which is a common situation in guarding, where the sites are wherever the clients are.

Why photo verification catches operators out

Operators tend to assume location is the sensitive part and a photo is trivial. Depending on the jurisdiction and how the photo is processed, the reverse can be closer to the truth: biometric statutes can carry notice, written-consent, retention-schedule, and destruction requirements.

The enforcement model is what makes Illinois different from everywhere else, and it is worth understanding before you compare states:

StatuteRequirementWho enforces
Illinois BIPA (740 ILCS 14)Written release before collecting a biometric identifier (§ 15(b)), plus a published retention and destruction schedulePrivate right of action (§ 20): individuals can sue directly
Texas CUBI (§ 503.001)Inform the individual and obtain consent before capture for a commercial purposeTexas Attorney General only, up to $25,000 per violation
A private right of action is why Illinois generates the litigation volume it does; Texas depends on the AG choosing to act.

Whether a given implementation falls in scope turns on details: whether a facial template is generated and stored, or whether the image is simply retained for a human to look at. That distinction is exactly the kind of thing worth putting in front of counsel rather than reasoning about from a blog post.

Practices that narrow the question

None of these are a legal opinion, and none of them substitute for checking your obligations. They are simply the choices that leave less to argue about.

  • Collect location during active, scheduled shifts only, never off the clock. Continuous tracking is far harder to justify than shift-bounded tracking.
  • Give notice in writing, before deployment rather than after, and keep a record that it was given.
  • Say plainly what is collected, when collection starts and stops, who can see it, and how long it is kept.
  • Have a retention and deletion schedule rather than keeping everything indefinitely.
  • Train supervisors to answer guards' questions consistently, because an inconsistent answer from a supervisor is itself a risk.
  • Revisit the position when you take on work in a new state.

What GuardOps does and does not collect

So you can describe the system accurately to your own counsel:

  • Location is recorded at clock-in and clock-out and during active, scheduled shifts. Guards are not tracked off the clock.
  • Each site has a geofence, and clock-in is compared against that boundary.
  • A selfie can be captured at clock-in and is stored with the timestamp and device information.
  • Photos are held in private storage accessible only to authorised users in the same company.
  • Consent and notice to guards are the employer's responsibility. GuardOps does not obtain consent on your behalf.

Exactly what GuardOps collects and retains.

Read the privacy policy

Sources

Frequently asked

Do I need written consent to track guards by GPS?

It depends on where your guards work. Connecticut and New York both require prior written notice of electronic monitoring, and photo-based verification may trigger separate biometric consent requirements in states such as Illinois and Texas. Confirm your specific obligations with an employment attorney licensed in each state where you operate.

Which state law creates the most risk for employee biometric data?

Illinois, because the Biometric Information Privacy Act gives individuals a private right of action under section 20, so they can sue directly rather than waiting for a regulator. Texas has comparable notice-and-consent duties under CUBI but enforcement rests solely with the state Attorney General.

Is tracking guards off the clock ever acceptable?

Continuous off-duty tracking of employees is substantially harder to justify than shift-bounded tracking and is restricted in some jurisdictions. GuardOps records location during active scheduled shifts only.

Does GuardOps handle compliance for me?

No. GuardOps limits collection to active shifts and documents what it stores, but notice, consent, and policy obligations to your guards remain the employer's responsibility.

Prove every shift on your own sites

GPS-verified clock-ins, DAR and incident reports, and client-ready exports. 30-day free trial, no credit card.

More guides