Biometric time clocks are legal in most jurisdictions, but they are regulated — and the regulation is about the biometric identifier itself, not about timekeeping. Two things decide your exposure: whether you obtained informed written consent before enrolling anyone, and where the biometric template is stored. A clock that keeps the template on the terminal leaves you with no biometric database to secure, migrate or hand over. It does not, on its own, make you compliant.
Almost every time clock vendor will tell you biometric data is "encrypted" and stored as a "mathematical template, not an image". That is true of essentially all of them and tells you very little. The question that actually separates one system from another is where that template ends up: matched and stored on the terminal in front of the employee, or uploaded to the vendor's servers and matched there. That single architectural choice determines what exists to be breached, subpoenaed, exported in a data subject request, or destroyed when someone leaves.
"If the template never leaves the terminal, there is no biometric database to protect — the vendor cannot lose what it was never sent."
The device or app captures the face or finger and sends it to the vendor's cloud, where the template is stored and the match is performed. You now have a biometric database — held by a third party, replicated across their infrastructure, and in scope for every breach notification, DPIA, vendor security review and deletion request you will ever handle. Your retention schedule depends on the vendor actually destroying data on request.
Enrolment happens at the terminal. The scan is converted to an encrypted template and written to the device's own storage, where the match also takes place. Over the ADMS connection ClockIt receives an employee ID, the punch timestamp, the in/out state and a job code where one is used. No image and no template crosses the wire, so the cloud record is attendance data rather than biometric data.
The biometric identifier stays inside equipment you own, on your premises. Deprovisioning becomes a device action: delete the enrolment and the template is gone, while the attendance history stays in ClockIt for payroll and audit, because a log of employee IDs and timestamps is not biometric data. A vendor breach notification exercise no longer has to consider biometric identifiers. And because EU and UK regulators have consistently treated centralised biometric databases as the highest-risk configuration in employment settings, a decentralised design is materially easier to justify in a DPIA than shipping templates to a third-party cloud.
It reduces the surface area; it does not discharge your duties. You are still the controller of the biometric data your terminals hold, and every obligation below applies whether the template sits on a device in your lobby or in a vendor's data centre. Treat any vendor that markets its product as making you "BIPA compliant" or "GDPR compliant" with suspicion — compliance is a property of your programme, not of a product.
The specifics vary by jurisdiction, but these four obligations recur almost everywhere biometrics are regulated.
Tell employees in writing what is being collected, the specific purpose (timekeeping), and how long it will be kept — then get a signed release before anyone touches the scanner. Consent gathered after the fact does not cure the original collection. In the EU and UK, consent is a weak basis in employment because of the power imbalance, so most employers rely on a different Article 9 condition and must document that reasoning.
Illinois requires a publicly available written policy setting out when biometric data is destroyed: at the earlier of the purpose being satisfied or a set period after the individual's last interaction with you. Write the schedule down, publish it, and make sure it matches what actually happens on the terminals.
Several jurisdictions require it and it is good practice everywhere. ClockIt terminals accept PIN codes and RFID or NFC badges alongside face and fingerprint, so an employee who refuses biometric enrolment can clock in on the same device under the same attendance rules — no separate process, no visible penalty.
Under the GDPR and UK GDPR, biometric processing for unique identification is special category data and a DPIA is expected. Record what you considered, why a less intrusive method was rejected, and where the templates are stored. Enforcement action in Europe has repeatedly turned on employers being unable to show they assessed alternatives.
The strictest US regime and the only one with a private right of action, which is why the class action volume is concentrated there. Requires a written release before collection and a publicly available retention schedule. Statutory damages are $1,000 for negligent and $5,000 for reckless or intentional violations. A 2024 amendment clarified that repeatedly scanning the same person by the same method counts as a single violation, ending the per-scan multiplication that drove earlier settlements — the exposure is smaller than it was, not gone.
Both require notice and consent before capturing a biometric identifier for a commercial purpose, and both are enforced by the state attorney general rather than by private plaintiffs. Texas provides for civil penalties of up to $25,000 per violation. Several other states have added biometric provisions to their comprehensive privacy statutes.
Biometric data processed to uniquely identify someone is special category data under Article 9 and needs a lawful basis plus an Article 9 condition. Consent is fragile in the employment context. Regulators have taken action against employers using biometric attendance systems where a less intrusive method would have worked — the UK ICO ordered an employer to stop using facial recognition and fingerprint scanning for staff attendance in 2024. Necessity and proportionality, documented in a DPIA, are the crux.
Australia's Privacy Act treats biometric information as sensitive information, which generally requires consent and cannot be collected unless reasonably necessary. Canadian PIPEDA and provincial equivalents apply a similar necessity-and-consent test. India's DPDP Act, the UAE and Saudi regimes broadly follow a notice-and-purpose-limitation model. The common thread: you must be able to explain why a badge or PIN would not have been sufficient.
On-device template storage describes ClockIt's biometric terminals connected over ADMS. The ClockIt Kiosk app, which turns a tablet into a shared time clock, works differently: it captures a photo on each punch and stores it in your ClockIt account so managers can review flagged punches. That is a deliberate design difference, not an oversight — but if your reason for choosing biometrics is to avoid holding employee images in the cloud, the terminals are the product that does that. This page is general information about how these systems are built and regulated, not legal advice; check your obligations with counsel in each jurisdiction where you operate.
Yes, in most jurisdictions, provided you meet the conditions attached to collecting biometric identifiers. In practice that means informed written consent obtained before enrolment, a published retention and destruction schedule, and an alternative clock-in method for employees who decline. No jurisdiction bans workplace biometric timekeeping outright, but several — Illinois in particular — attach real financial consequences to getting the process wrong.
No. On ClockIt biometric terminals the scan is converted to an encrypted template on the device and stored there, and the match happens there too. ClockIt receives an employee ID, the punch timestamp, the in/out state and a job code where one is used. There is no biometric database on ClockIt's servers. The Kiosk tablet app is the exception — it captures a photo on each punch which is stored in your account.
No, and no product can. Keeping templates on the terminal removes a large part of your exposure — there is no vendor-held biometric database to breach or to account for — but you remain the controller of the data on your devices. Written consent before enrolment and a publicly available retention schedule are still required under BIPA regardless of where the template lives.
In several jurisdictions yes, and offering an alternative is good practice everywhere. ClockIt terminals support PIN codes and RFID or NFC badges on the same device as face and fingerprint, so an employee who declines biometric enrolment clocks in on the same terminal with the same rules applied. Building the alternative in from the start is considerably easier than retrofitting it after someone objects.
Delete their enrolment on the terminal and the template is destroyed on the device. Their attendance history stays in ClockIt for payroll and audit purposes, because a record of employee IDs and timestamps is not biometric data. If you retire or resell a terminal, clear its enrolments before it leaves your premises.
No. The sensor converts the scan into a mathematical representation and discards the image. The template cannot be reversed into a usable fingerprint or photograph, and a template from one vendor's algorithm is not portable to another's. It is still biometric data in the legal sense, which is why consent and retention obligations attach to it — but the practical consequences of losing one are far narrower than losing a set of images.
Awards & Recognition
Recognized by industry leaders for value, ease of use, and performance.

Capterra
2026
Software Advice
2026
Software Advice
2026
Capterra
2026
Software Advice
2026
Software Advice
2025
Capterra
2025
Get App
2025
Capterra
2025
Capterra
2025
Capterra
2024
Software World
2023
Software World
2023
Capterra
2019
Get App
2018“The mobile app time clock has revolutionized how we manage our remote team. It's intuitive, accurate, and has saved us countless hours in payroll processing. The GPS feature ensures accountability without being intrusive. It's a game-changer for businesses with a mobile workforce.”
“As a small business owner, I was skeptical about implementing a new time tracking system. But this mobile app has exceeded all my expectations. It's user-friendly, reliable, and the reporting features have given me invaluable insights into our productivity.”
“The integration capabilities of this mobile time clock app are outstanding. It seamlessly connects with our existing HR and payroll systems, creating a streamlined workflow that has significantly reduced errors and improved our overall efficiency.”
“What we love most is the real-time data and reports, which provide clear insights into employee attendance and payroll expenses. Plus, the ease of use means less administrative burden, allowing our HR team to focus on more strategic initiatives. If you’re looking for a reliable payroll solution that enhances efficiency and accuracy, clockit.io is the perfect choice! Highly recommended!”
“ClockIt.io cut our timesheet corrections by more than half. Exports line up perfectly with payroll and the GPS clock-ins keep our field crews honest without creating friction.”
“Geofencing and kiosk mode at each site solved our late punches. Managers love the late alerts and I love closing payroll on Friday in minutes.”
“ClockIt’s overtime rules and approvals gave us immediate savings. Clear audit trails and clean timesheets mean finance isn’t chasing people anymore.”
“We schedule across multiple locations and roles. ClockIt.io handles PTO, availability, and publishes updates to everyone’s phones instantly—no more group chats.”
“Our trainers swap shifts right in the app and confirm attendance. Attendance and payroll line up perfectly—ClockIt just works.”
“Setup was fast and the support team was outstanding. We rolled out ClockIt to 120 staff in a week and adoption was near 100% on day one.”
“The reports in ClockIt.io make our monthly reviews painless. We finally have visibility into attendance trends and actual hours by department.”
“Time‑off requests, approvals, and balances are all in one place. Doctors see who’s off at a glance and we avoid coverage gaps.”
“For crews on the move, ClockIt’s GPS punch-ins and site-based rules keep things accurate. It’s the reliability we were missing before.”
“We tried three tools before ClockIt.io. This is the first one our team actually likes using—and it saves my admin two hours every payroll run.”
“Implementing ClockIt's biometric kiosks eliminated buddy punching overnight. The facial recognition is instant and works perfectly even in our warehouse environment. It's the most secure time tracking decision we've made.”