C.H. Robinson Warehouse Worker and Visitor Policy
BIOMETRIC DATA POLICY
PURPOSE: C.H. Robinson ("Company") has adopted this Biometric Data Policy and Notice (this "Policy") to provide guidelines for how it, its vendors, and/or the licensor of C.H. Robinson collect, store, or use Biometric Data solely for Covered Individual identity verification purposes. Protecting the confidentiality and integrity of Biometric Data is a critical responsibility that must be taken seriously at all times. Compliance with this Policy is mandatory.
SCOPE: Applicable to Covered Individuals whose Biometric Data is collected, stored, used, disclosed, retained, or otherwise processed by or on behalf of the Company in jurisdictions with applicable biometric data privacy requirements, including but not limited to Illinois and California. This Policy applies only to Company employees, temporary employees, contingent workers, contractors, independent contractors, interns, visitors to Company facilities, and other individuals whose Biometric Data is processed in connection with Company employment, engagement, access, safety, security, identity verification, or facility-related purposes.
DEFINITIONS:
As used in this Policy, “Biometric Data” includes “Biometric Identifiers” and “Biometric Information” as defined in the Illinois Biometric Information Privacy Act (“BIPA”), 740 ILCS § 14/1, et seq., and includes biometric information or similar biometric data elements regulated under other applicable biometric data privacy laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), Cal. Civ. Code § 1798.140, where applicable.
“Biometric Identifier” means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. Biometric Identifiers do not include writing samples, written signatures, photographs, human biological samples used for valid scientific testing or screening, demographic data, tattoo descriptions, or physical descriptions such as height, weight, hair color, or eye color. Biometric Identifiers do not include donated organs, tissues, or parts as defined in the Illinois Anatomical Gift Act or blood or serum stored on behalf of recipients or potential recipients of living or cadaveric transplants and obtained or stored by a federally designated organ procurement agency. Biometric Identifiers do not include biological materials regulated under the Genetic Information Privacy Act. Biometric Identifiers do not include information captured from a patient in a healthcare setting or information collected, used, or stored for healthcare treatment, payment, or operations under the federal Health Insurance Portability and Accountability Act (“HIPAA”) of 1996. Biometric Identifiers do not include an X-ray, roentgen process, computed tomography, MRI, PET scan, mammography, or other image or film of the human anatomy used to diagnose, prognose, or treat an illness or other medical condition or to further validate scientific testing or screening.
“Biometric Information” means any information, regardless of how it is captured, converted, stored, or shared, based on an individual’s Biometric Identifier used to identify an individual. Biometric Information does not include information derived from items or procedures excluded under the definition of Biometric Identifiers.
“Covered Individual” means Company employees, temporary employees, contingent workers, contractors, independent contractors, interns, visitors to Company facilities, and other individuals whose Biometric Data is collected, stored, used, disclosed, retained, or otherwise processed by or on behalf of the Company in connection with Company employment, engagement, access, safety, security, identity verification, or facility-related purposes in a jurisdiction with applicable biometric data privacy requirements.
“Written Release” means an informed written or electronic acknowledgment, including an electronic signature, sound, symbol, or process attached to or logically associated with a record, by which the Covered Individual acknowledges receipt of notice regarding the Company’s collection, storage, use, disclosure, retention, or other processing of Biometric Data as described in this Policy.
AUTHORIZATION:
To the extent that the Company, its vendors, and/or the licensor of the Company’s identity verification software collect, capture, or otherwise obtain Biometric Data relating to a Covered Individual, the Company will provide notice and obtain any consent, written release, authorization, acknowledgment, or other permission required by applicable law before collecting, storing, using, disclosing, retaining, or otherwise processing such Biometric Data. Where required, the Company will first:
- Inform the Covered Individual in writing that the Company, its vendors, and/or the licensor of the Company’s identity verification software are collecting, capturing, or otherwise obtaining the Covered Individual’s Biometric Data and that the Company is providing such Biometric Data to its vendors and the licensor of Company’s identification verification software;
- Inform the Covered Individual in writing of the specific purpose and length of time for which the Covered Individual’s Biometric Data is being collected, stored, and used; and
- Receive a written release signed (electronically, as set out in 740 ILCS 14/10, or otherwise) by the Covered Individual (or the Covered Individual’s legally authorized representative) acknowledging receipt of notice regarding the Company’s collection, storage, use, disclosure, retention, and other processing of the Covered Individual’s Biometric Data for the specific purposes disclosed by Company, including disclosure to the Company’s vendors and the licensor of Company’s identification verification software, where applicable.
The Company, its vendors, and/or the licensor of the Company’s identification verification software will not sell, lease, trade, or otherwise profit from Covered Individuals’ Biometric Data; provided, however, that the Company’s vendors and the licensor of the Company’s identification verification software may be paid for products or services used by the Company that utilize such Biometric Data.
JURISDICTION-SPECIFIC REQUIREMENTS: The Company will comply with applicable biometric data privacy requirements in the jurisdictions where Covered Individuals’ Biometric Data is collected, stored, used, disclosed, retained, or otherwise processed. These requirements may include, depending on the jurisdiction, providing clear notice of the categories of Biometric Data collected, the purposes for collection and use, the length of time the Biometric Data will be retained, the categories of service providers or other recipients to whom the Biometric Data may be disclosed, and the rights or choices available to Covered Individuals. Where a jurisdiction imposes requirements that are more protective than this Policy, the Company will apply the more protective requirement to the applicable Covered Individual.
DISCLOSURE:
The Company will not disclose, disseminate, sell, lease, trade, or otherwise profit from any Covered Individual’s Biometric Data except as permitted or required by applicable law and this Policy. The Company may disclose Biometric Data to its authorized vendor(s), service providers, and/or licensor of the Company’s identification verification software where necessary to support the disclosed purpose for collection and use, subject to appropriate confidentiality, security, and data protection obligations. The Company will not otherwise disclose or disseminate Biometric Data without/unless:
- Obtaining written Covered Individual acknowledgment of such disclosure or dissemination, where required by applicable law;
- The disclosed Biometric Data completes a financial transaction requested or authorized by the Covered Individual;
- Disclosure is required by state or federal law or municipal ordinance; or
- Disclosure is required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction.
RETENTION AND DESTRUCTION SCHEDULE:
The Company will have access to Biometric Data only for as long as necessary to satisfy the disclosed purpose for collection, use, or processing, or as otherwise permitted or required by applicable law. Where Biometric Data is processed by the licensor of the Company’s identification verification software or another authorized service provider, the Company will require retention and deletion practices consistent with this Policy and applicable law. Unless a shorter retention period is required by applicable law, any Covered Individual’s Biometric Data in the Company’s possession will be retained only until the first of the following occurs:
- The initial purpose for collecting or obtaining such Biometric Data has been satisfied, such as the termination of the Covered Individual’s employment, engagement, visit to a Company facility, or other purpose for which the Biometric Data was collected, or the Covered Individual moves to a role for which the Biometric Data is not used; or
- Within 1 year of the Covered Individual’s last interaction with the identification verification software.
PRIVACY PROTECTION: The Company will use a reasonable standard of care to store, transmit, and protect any paper or electronic Biometric Data collected from disclosure. Such storage, transmission, and protection from disclosure shall be performed in a manner that is the same as or more protective than how the Company stores, transmits, and protects other confidential and sensitive information, and in accordance with applicable law, internal policies, and the Company’s Privacy Notices.