Engage Logo

Biometric Attendance

Last verified

Biometric attendance records presence by matching a physical characteristic such as a fingerprint or face against a stored template. It removes proxy punching, and it makes the employer the custodian of sensitive personal data, with the obligations that follow from that.

What it is and what it fixes

A biometric system stores a representation of a physical characteristic for each employee and, at the point of attendance, matches a fresh reading against it. Fingerprint and face are the common ones in Indian workplaces; iris and palm vein appear in higher-security settings.

The specific problem it solves is proxy attendance: one employee marking another present. Cards, PINs and registers are all transferable, and in workplaces where attendance drives pay directly, they get transferred. A characteristic that cannot be handed over closes that.

It is worth being honest that the other benefits usually cited do not require biometrics. Accurate timestamps, integration with payroll, exception reporting and shift compliance are all available from card readers, mobile capture or web check-in. If proxy punching is not a real problem in a given workplace, the case for biometrics is weaker than it is usually presented, and the obligations that come with it are the same either way.

The data obligations that follow

Collecting biometric data makes the employer the custodian of sensitive personal information about every employee, and that is a different posture from holding their address.

India's data protection regime places obligations on anyone processing personal data, and biometric information is treated as a sensitive category. The practical requirements an employer should be able to satisfy are these.

  • A stated purpose. Attendance, and not repurposing the same data for access control, surveillance or performance monitoring without saying so.
  • Notice and consent, obtained meaningfully rather than buried in a joining form, with a route for an employee who objects.
  • Storage limitation. A template rather than a raw image where the technology allows, and confirmation from the vendor about which is stored and where.
  • Retention limits, including deletion when an employee leaves. Biometric templates of former employees sitting on a device years later is the most common finding in any review of this.
  • Security, including encryption at rest and in transit, and control over who can export the data.
  • Vendor position. If the templates sit with a third party or on a device the vendor administers, the employer is still accountable for them.

Verify the current obligations under the applicable data protection law and rules before relying on any of this, since the regime and its rules have been evolving.

Consent, refusal and alternatives

Employees do sometimes object, on privacy grounds or religious ones, and an employer that has not thought about it in advance handles it badly.

Two things make the objection easier to deal with.

  • An alternative that is not punitive. A card, a supervisor-attested register or mobile capture achieves attendance for the small number who object. An alternative that requires the employee to seek permission daily is a refusal dressed as an accommodation.
  • A clear position on whether consent is genuinely being sought. Consent obtained under a condition of employment is doing less work than it appears to, which is a reason to be able to justify the collection on its own terms rather than resting the whole thing on a signature.

Aadhaar-based biometric authentication is a separate matter from biometric attendance generally. Its use is subject to specific statutory restrictions on who may authenticate and for what purpose, and a private employer cannot assume it may use it for attendance simply because the employee has an Aadhaar number. That question should be taken on its own facts.

Where it is the wrong mechanism

A fixed reader at a door assumes the employee passes that door twice a day. Where they do not, the system generates corrections rather than data.

  • Field staff, who are at client sites, on the road, or at locations with no reader.
  • Hybrid and remote employees, who have nothing to present a finger to.
  • Multi-site staff who move between locations during the day.
  • Contract and daily-wage workers at sites where enrolment is impractical and turnover is high.
  • Anyone whose fingerprint reads poorly, which is a real and under-acknowledged problem for manual workers and older employees, and which produces failures the employee experiences as being accused of not turning up.

The diagnostic is regularization volume. A population that regularizes constantly is telling you the capture method does not match how they work, and no amount of process tightening around approvals will change that. Geotagged mobile capture, supervisor attestation or work-output-based recording are better answers for those groups than a stricter policy about the reader.

What goes wrong

  • Templates retained for former employees indefinitely, because deletion was never part of the exit process.
  • Raw images stored rather than templates, usually because nobody asked the vendor which it was.
  • Attendance data repurposed for monitoring or disciplinary use beyond the stated purpose.
  • A device that fails for a subset of employees, whose absences then look like attendance problems rather than hardware ones.
  • Enrolment treated as a one-off, so joiners work for weeks before being enrolled and their attendance is reconstructed by hand.
  • The device clock drifting or the network dropping, so timestamps are wrong in ways that only surface in the payroll run.
  • Biometrics deployed to solve a problem the workplace did not have, taking on sensitive data obligations for no operational gain.

Statutory reference

Act
Digital Personal Data Protection Act, 2023, with the Occupational Safety, Health and Working Conditions Code, 2020
Section
Digital Personal Data Protection Act, 2023 and the rules made under it (obligations of a data fiduciary: notice, consent, purpose limitation, storage limitation, accuracy, security safeguards, and erasure when the purpose is served), together with the Information Technology Act, 2000 and the rules on sensitive personal data or information to the extent they continue to apply; Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016: Section 57, which had permitted use of Aadhaar by any body corporate or person under any law or contract, was omitted with effect from 25 July 2019 by the Aadhaar and Other Laws (Amendment) Act, 2019, so consent recorded in an employment contract is no longer a footing for anything. Section 4(4): an entity may perform authentication only if the Authority is satisfied it meets the specified privacy and security standards and is permitted to offer authentication services under a law made by Parliament, or is seeking it for a purpose the Central Government prescribes in the interest of State. Section 4(7): mandatory authentication for the provision of any service requires a law made by Parliament. Section 4(6): the entity must inform the individual of alternate and viable means of identification and may not deny any service for refusal or inability to authenticate. Section 4(3): the only route otherwise open is the holder's voluntary use, which the Explanation defines as use only with informed consent. Section 7, which does permit mandatory authentication, is a power of the Central or State Government tied to expenditure from the Consolidated Fund and is not available to an employer. Section 8(4): the Authority returns a positive or negative response and excludes any core biometric information, so Aadhaar authentication is not a means by which an employer acquires biometric data; Occupational Safety, Health and Working Conditions Code, 2020 and state shops and establishments legislation (the attendance records an employer must maintain, their particulars and retention)
Key limits
Biometric information is sensitive personal data. Collection requires a stated purpose, notice and consent, security safeguards, retention limits and erasure when no longer needed, including for former employees. Aadhaar-based attendance is closer to prohibited than restricted. Since Section 57 was omitted in 2019 there is no contractual route to it; An employer may authenticate only if the Authority permits it on a footing in a law made by Parliament, cannot make it mandatory without such a law, and cannot deny anything to an employee who refuses or fails. Aadhaar authentication also returns no biometric data to the employer, so it does not supply the biometric record such a system is usually assumed to build. Under notification G.S.R. 843(E) dated 13 November 2025, sections 3 to 17 - the grounds for processing, notice, consent, the general obligations of a data fiduciary and all of the data principal rights - take effect eighteen months from that date, on 13 May 2027. Only the definitions and the Data Protection Board and penalty machinery are in force now. Separately, processing for employment purposes runs on the section 7(i) legitimate use and not on consent, and the erasure duty in section 8(7) yields where retention is necessary for compliance with any law, which is the position for statutory payroll and register retention. Sections 3 to 17, which carry the duties described here, commence on 13 May 2027 under G.S.R. 843(E) of 13 November 2025. In force now are the definitions, the Data Protection Board and the penalty provisions. Aadhaar obligations are INDEPENDENT of the DPDP commencement timetable and apply now, which is the opposite of the DPDP position and easy to conflate. The load-bearing point, the omission of s. 57 by which private-sector authentication lost its statutory basis, is verified from the statute. The regulations made under the Act carry the operative detail and NONE was read, nor was Chapter VI on security and restrictions on sharing.

Source

Frequently asked questions

What is biometric attendance?

Recording attendance by matching a physical characteristic, usually a fingerprint or face, against a stored template for that employee. Its specific advantage is that the identifier cannot be handed to a colleague.

Is biometric attendance legal in India?

Collecting it is permissible, but biometric information is sensitive personal data, so the employer takes on obligations around notice, consent, purpose limitation, security, retention and erasure. Aadhaar-based authentication is a separate question with its own statutory restrictions.

Can an employee refuse to give biometrics?

Employees do object, and an employer should have a non-punitive alternative such as a card or supervisor-attested record. Consent obtained as a condition of employment does less work than it appears to, so the collection should be justifiable on its own terms.

How long should biometric data be kept?

Only as long as the purpose requires, which means templates for former employees should be deleted as part of the exit process. Retained templates of people who left years ago is the most common finding when this is reviewed.

Is biometric attendance suitable for field staff?

Usually not. A fixed reader assumes the employee passes it twice a day, and field, hybrid and multi-site staff do not. The result is constant regularization rather than accurate data, and geotagged mobile capture is the better mechanism for them.

How Engage handles attendance capture

Engage supports biometric devices alongside mobile and web capture, so field and hybrid staff are recorded by a method that matches how they actually work rather than generating corrections every month. Attendance flows into the same system as leave and payroll, so an exception is resolved once, and enrolment and removal sit inside joining and exit rather than being remembered separately.

See attendance handling in Engage
WhatsApp