The Practice |
The organisation uses biometric attendance systems (fingerprint or facial recognition) at office locations, and a geo-tagged mobile app for field or hybrid employees to log check-in/check-out locations. This data is used for attendance, payroll processing, and in some cases informal monitoring of employee movement during work hours.
Questions Raised for Compliance Review |
- Does the collection of biometric and geo-location data for attendance purposes require a distinct consent basis under DPDP?
- What breach risks arise from the storage and downstream use of biometric templates and location trails?
- What is the compliant approach to deploying biometric and geo-tagged attendance systems?
Is This Permitted Under DPDP? |
Permissible — but only under a narrowly scoped, well-disclosed consent basis.
Biometric data (fingerprint templates, facial geometry) and precise geo-location are both categories of personal data that carry heightened sensitivity. Their collection for attendance is a legitimate operational purpose, but DPDP requires that employees be specifically informed of what is captured, how the biometric template is stored, how long location trails are retained, and whether the data is used for any purpose beyond attendance — such as productivity monitoring or disciplinary action.
Where the Breach Risks Sit |
- Function creep beyond attendance — Biometric and geo-tagged systems often generate rich behavioural data — arrival patterns, time spent at client sites, deviation from expected routes. If this data is used for performance review or disciplinary action without having disclosed that possibility, the organisation has processed data for a purpose beyond what was declared.
- Irrevocable nature of biometric data — Unlike a password, a fingerprint or facial template cannot be reset if compromised. A breach of the biometric database carries a materially higher consequence for the employee than a typical data breach, and DPDP's security obligations apply with corresponding weight.
- Vendor-hosted biometric templates — Many attendance systems are cloud-hosted by a third-party vendor. If the vendor stores raw biometric templates (rather than encrypted, non-reversible hashes) without a data processing agreement addressing this specifically, the organisation has limited assurance over how that data is protected or whether it is used for the vendor's own purposes.
- No opt-out or alternative mechanism — Employees who are uncomfortable providing biometric data — for personal, religious, or other reasons — are often not offered an alternative attendance method, effectively making consent involuntary rather than freely given.
The Ideal Compliant Approach |
- Disclose scope and purpose explicitly at rollout. Before deployment, issue a specific notice covering what biometric or location data is captured, how it is stored, retention period, and confirmation that it will not be used for performance monitoring unless separately disclosed.
- Use hashed or templated biometric storage only. Confirm with the vendor that raw fingerprint or facial images are not stored — only irreversible mathematical templates — and that this is contractually guaranteed in the vendor agreement.
- Offer a non-biometric alternative. Provide an ID-card or PIN-based alternative for employees who decline biometric enrolment, so that consent to the biometric method remains genuinely optional.
- Cap location data retention. Geo-tagged check-in data should be retained only as long as needed for payroll reconciliation, with automatic purging thereafter — indefinite retention of movement history has no lawful basis.
DPDP Risk Summary
| Element | Status | Recommended Action |
|---|---|---|
| Biometric enrolment without specific disclosure | Needs consent basis | Issue a dedicated biometric data notice before rollout |
| Raw biometric images stored by vendor | Needs verification | Confirm hashed/templated storage in vendor DPA |
| Location trails used beyond attendance | Purpose not declared | Restrict use to attendance/payroll; disclose any secondary use |
| No non-biometric attendance alternative | Consent not freely given | Offer PIN/card-based alternative for opt-out employees |
| Indefinite retention of movement history | No policy defined | Define and enforce retention and auto-deletion period |