The law, named by jurisdiction · 3.2
Fingerprint and face clocks
Fingerprint and face clocks. What decides it, what it costs, and what usually goes wrong. For a practical comparison point, see Monitask's EdTech time tracking.
The most litigated corner of this industryWhere the risk actually is
Fingerprint and facial recognition clocks are convenient, they eliminate one person clocking in for another, and they have generated more legal exposure than anything else a time tracking system does.
The reason is that biometric data is treated differently from other personal data in a growing number of places, with specific requirements attached and, in some, a right for individuals to sue directly. For related guidance and industry context, see CIPD.
The United States
Illinois has a biometric privacy statute requiring, among other things, informed written consent before collection and a published retention and destruction policy, and it provides a private right of action with damages set by statute. Fingerprint time clocks have been a principal subject of litigation under it.
Texas and Washington have biometric statutes enforced by their attorneys general rather than by individuals. Other states have considered or adopted provisions, and the position moves.
The practical consequence is that a clock deployed uniformly across sites in several states may be lawful in most of them and expensive in one.
Europe
Biometric data used to identify somebody is a special category under European data protection law, which requires a specific condition for processing beyond the ordinary basis.
Several supervisory authorities have taken the view that biometric clocks are disproportionate for ordinary attendance recording where a card or a code would achieve the same purpose. The question they ask is whether a less intrusive means was available, and for attendance it usually was.
The question to ask before deploying one
What problem is this solving that a card cannot?
If the answer is one person clocking in for another, that is a real problem and there are less intrusive answers: a photograph at the moment of clocking, a supervisor confirmation, a device tied to a location. Each addresses the same problem without collecting a biometric identifier.
Regulators ask this question, and an organisation that has considered it and documented the answer is in a substantially better position than one that has not.
Biometric capture is not offered by us. Where a client needs identity assurance at a clock, the alternatives above are what we support, and this is a deliberate position rather than a gap.
If you already have one
Establish what was collected, on what basis, with what consent, and what the retention and destruction policy says. In several jurisdictions the existence of a written policy is itself a requirement rather than good practice.
Then take advice covering every place your staff are, because the answer genuinely differs and a uniform deployment is the arrangement most likely to be wrong somewhere.
Templates
Consent forms circulate widely and are usually written for one jurisdiction. A form drafted for one statute may fail another's requirements entirely, and the fact that it looks thorough is not evidence about the place you are using it.
Not advice
This entry names statutes and describes their general shape. It states no rule, quotes no threshold and should not be relied on for any deployment. Biometrics are the one area in this field where specialist advice before acting is not optional.
Retention of biometric templates
Where biometrics are used, several regimes require a published policy on how long the data is kept and when it is destroyed, and in some the absence of the policy is itself the breach rather than the retention.
The practical failure is a template stored indefinitely for somebody who left three years ago, which is both a violation and an unnecessary risk.
Vendors and the template
Ask where the biometric template is stored, whether it leaves the device, whether the vendor holds a copy, and what happens to it when the contract ends. Storage on the device with nothing transmitted is a materially different arrangement from a central database, both technically and legally.
What tends to trigger a claim
Not usually a data breach. Usually the paperwork: consent not obtained in the required form, a policy that was never published, or a vendor holding data nobody disclosed.
Which means the exposure is largely avoidable by administration rather than by technology, and it is largely avoided by not deploying biometrics where a card would do.
The alternative that usually works
A card or code plus a photograph captured at the moment of clocking, retained briefly. It addresses the same problem, it is not a biometric identifier in most regimes, and it is considerably easier to explain to everybody involved.
Where biometrics are genuinely justified
High-security areas, controlled substances, and settings where identity assurance is the point rather than a convenience. Those exist and the analysis is different, because the less intrusive alternative genuinely does not achieve the purpose.
Attendance recording is almost never in that category, which is why it is the deployment regulators and claimants have concentrated on.
A short summary
Ask what problem it solves that a card cannot. Document the answer. Take advice for every jurisdiction involved. Publish a retention and destruction policy if you proceed. And consider the photograph alternative first.
The position in one line
Biometrics for attendance carry the largest legal exposure and the smallest advantage over the alternatives, which is why we do not offer them.
The question this entry exists to prompt
If your organisation already runs a biometric clock, does anybody know what the retention policy says? In most cases the answer is that there is no policy, which in some jurisdictions is the exposure rather than a step toward it.
Also in the law, named by jurisdiction
Why timesheets are left blank
A timesheet asks somebody to reconstruct a fragmented day hours later. The reconstruction is a guess and everybody knows it.
Choosing the categories
The list somebody picks in week one governs everything the record can later answer.
Reminders, nudges and escalation
Reminders, nudges and escalation. What decides it, what it costs, and what usually goes wrong.
What a manager should do with it
What a manager should do with it. What decides it, what it costs, and what usually goes wrong.