Biometric Time Clocks & Privacy Law: Where the Data Lives

The Verdict

Biometric time clocks are legal in most jurisdictions, but they are regulated — and the regulation is about the biometric identifier itself, not about timekeeping. Two things decide your exposure: whether you obtained informed written consent before enrolling anyone, and where the biometric template is stored. A clock that keeps the template on the terminal leaves you with no biometric database to secure, migrate or hand over. It does not, on its own, make you compliant.

The question buyers should be asking vendors

Almost every time clock vendor will tell you biometric data is "encrypted" and stored as a "mathematical template, not an image". That is true of essentially all of them and tells you very little. The question that actually separates one system from another is where that template ends up: matched and stored on the terminal in front of the employee, or uploaded to the vendor's servers and matched there. That single architectural choice determines what exists to be breached, subpoenaed, exported in a data subject request, or destroyed when someone leaves.

The real test

"If the template never leaves the terminal, there is no biometric database to protect — the vendor cannot lose what it was never sent."

Two architectures, two risk profiles

Server-side matching (most cloud time clocks)

The device or app captures the face or finger and sends it to the vendor's cloud, where the template is stored and the match is performed. You now have a biometric database — held by a third party, replicated across their infrastructure, and in scope for every breach notification, DPIA, vendor security review and deletion request you will ever handle. Your retention schedule depends on the vendor actually destroying data on request.

On-device matching (ClockIt biometric terminals)

Enrolment happens at the terminal. The scan is converted to an encrypted template and written to the device's own storage, where the match also takes place. Over the ADMS connection ClockIt receives an employee ID, the punch timestamp, the in/out state and a job code where one is used. No image and no template crosses the wire, so the cloud record is attendance data rather than biometric data.

What this changes in practice

The biometric identifier stays inside equipment you own, on your premises. Deprovisioning becomes a device action: delete the enrolment and the template is gone, while the attendance history stays in ClockIt for payroll and audit, because a log of employee IDs and timestamps is not biometric data. A vendor breach notification exercise no longer has to consider biometric identifiers. And because EU and UK regulators have consistently treated centralised biometric databases as the highest-risk configuration in employment settings, a decentralised design is materially easier to justify in a DPIA than shipping templates to a third-party cloud.

On-device storage is not compliance

It reduces the surface area; it does not discharge your duties. You are still the controller of the biometric data your terminals hold, and every obligation below applies whether the template sits on a device in your lobby or in a vendor's data centre. Treat any vendor that markets its product as making you "BIPA compliant" or "GDPR compliant" with suspicion — compliance is a property of your programme, not of a product.

What the law still requires of you

The specifics vary by jurisdiction, but these four obligations recur almost everywhere biometrics are regulated.

1

Informed written consent, obtained before enrolment

Tell employees in writing what is being collected, the specific purpose (timekeeping), and how long it will be kept — then get a signed release before anyone touches the scanner. Consent gathered after the fact does not cure the original collection. In the EU and UK, consent is a weak basis in employment because of the power imbalance, so most employers rely on a different Article 9 condition and must document that reasoning.

2

A published retention and destruction schedule

Illinois requires a publicly available written policy setting out when biometric data is destroyed: at the earlier of the purpose being satisfied or a set period after the individual's last interaction with you. Write the schedule down, publish it, and make sure it matches what actually happens on the terminals.

3

A genuine alternative for employees who decline

Several jurisdictions require it and it is good practice everywhere. ClockIt terminals accept PIN codes and RFID or NFC badges alongside face and fingerprint, so an employee who refuses biometric enrolment can clock in on the same device under the same attendance rules — no separate process, no visible penalty.

4

A data protection impact assessment where required

Under the GDPR and UK GDPR, biometric processing for unique identification is special category data and a DPIA is expected. Record what you considered, why a less intrusive method was rejected, and where the templates are stored. Enforcement action in Europe has repeatedly turned on employers being unable to show they assessed alternatives.

Jurisdiction quick reference

Illinois — BIPA

The strictest US regime and the only one with a private right of action, which is why the class action volume is concentrated there. Requires a written release before collection and a publicly available retention schedule. Statutory damages are $1,000 for negligent and $5,000 for reckless or intentional violations. A 2024 amendment clarified that repeatedly scanning the same person by the same method counts as a single violation, ending the per-scan multiplication that drove earlier settlements — the exposure is smaller than it was, not gone.

Texas (CUBI) and Washington (HB 1493)

Both require notice and consent before capturing a biometric identifier for a commercial purpose, and both are enforced by the state attorney general rather than by private plaintiffs. Texas provides for civil penalties of up to $25,000 per violation. Several other states have added biometric provisions to their comprehensive privacy statutes.

EU and UK — GDPR

Biometric data processed to uniquely identify someone is special category data under Article 9 and needs a lawful basis plus an Article 9 condition. Consent is fragile in the employment context. Regulators have taken action against employers using biometric attendance systems where a less intrusive method would have worked — the UK ICO ordered an employer to stop using facial recognition and fingerprint scanning for staff attendance in 2024. Necessity and proportionality, documented in a DPIA, are the crux.

Australia, Canada and elsewhere

Australia's Privacy Act treats biometric information as sensitive information, which generally requires consent and cannot be collected unless reasonably necessary. Canadian PIPEDA and provincial equivalents apply a similar necessity-and-consent test. India's DPDP Act, the UAE and Saudi regimes broadly follow a notice-and-purpose-limitation model. The common thread: you must be able to explain why a badge or PIN would not have been sufficient.

A note on scope

On-device template storage describes ClockIt's biometric terminals connected over ADMS. The ClockIt Kiosk app, which turns a tablet into a shared time clock, works differently: it captures a photo on each punch and stores it in your ClockIt account so managers can review flagged punches. That is a deliberate design difference, not an oversight — but if your reason for choosing biometrics is to avoid holding employee images in the cloud, the terminals are the product that does that. This page is general information about how these systems are built and regulated, not legal advice; check your obligations with counsel in each jurisdiction where you operate.

Frequently Asked Questions

Are biometric time clocks legal?

Yes, in most jurisdictions, provided you meet the conditions attached to collecting biometric identifiers. In practice that means informed written consent obtained before enrolment, a published retention and destruction schedule, and an alternative clock-in method for employees who decline. No jurisdiction bans workplace biometric timekeeping outright, but several — Illinois in particular — attach real financial consequences to getting the process wrong.

Does ClockIt store our employees' fingerprints or face scans?

No. On ClockIt biometric terminals the scan is converted to an encrypted template on the device and stored there, and the match happens there too. ClockIt receives an employee ID, the punch timestamp, the in/out state and a job code where one is used. There is no biometric database on ClockIt's servers. The Kiosk tablet app is the exception — it captures a photo on each punch which is stored in your account.

Does on-device storage make us BIPA compliant?

No, and no product can. Keeping templates on the terminal removes a large part of your exposure — there is no vendor-held biometric database to breach or to account for — but you remain the controller of the data on your devices. Written consent before enrolment and a publicly available retention schedule are still required under BIPA regardless of where the template lives.

Can employees refuse to use a biometric time clock?

In several jurisdictions yes, and offering an alternative is good practice everywhere. ClockIt terminals support PIN codes and RFID or NFC badges on the same device as face and fingerprint, so an employee who declines biometric enrolment clocks in on the same terminal with the same rules applied. Building the alternative in from the start is considerably easier than retrofitting it after someone objects.

What happens to biometric data when an employee leaves?

Delete their enrolment on the terminal and the template is destroyed on the device. Their attendance history stays in ClockIt for payroll and audit purposes, because a record of employee IDs and timestamps is not biometric data. If you retire or resell a terminal, clear its enrolments before it leaves your premises.

Is a biometric template the same as a fingerprint image?

No. The sensor converts the scan into a mathematical representation and discards the image. The template cannot be reversed into a usable fingerprint or photograph, and a template from one vendor's algorithm is not portable to another's. It is still biometric data in the legal sense, which is why consent and retention obligations attach to it — but the practical consequences of losing one are far narrower than losing a set of images.

Biometric time tracking without a biometric database

ClockIt terminals keep face and fingerprint templates on the device and send only an employee ID and a timestamp to the cloud.

14‑day free trial • No credit card required • All features included

Emily RodriguezOperations Manager, TechNova Solutions
★★★★★
“The mobile app time clock has revolutionized how we manage our remote team. It's intuitive, accurate, and has saved us countless hours in payroll processing. The GPS feature ensures accountability without being intrusive. It's a game-changer for businesses with a mobile workforce.”
Michael ChangFounder & CEO, Innovative Designs Co.
★★★★★
“As a small business owner, I was skeptical about implementing a new time tracking system. But this mobile app has exceeded all my expectations. It's user-friendly, reliable, and the reporting features have given me invaluable insights into our productivity.”
Sarah JohnsonHR Director, Global Tech Enterprises
★★★★★
“The integration capabilities of this mobile time clock app are outstanding. It seamlessly connects with our existing HR and payroll systems, creating a streamlined workflow that has significantly reduced errors and improved our overall efficiency.”
S MitchellHR Operations Manager, NexaTech Solutions
★★★★★
“What we love most is the real-time data and reports, which provide clear insights into employee attendance and payroll expenses. Plus, the ease of use means less administrative burden, allowing our HR team to focus on more strategic initiatives. If you’re looking for a reliable payroll solution that enhances efficiency and accuracy, clockit.io is the perfect choice! Highly recommended!”
Priya NairHead of HR, BlueWave Retail
★★★★★
“ClockIt.io cut our timesheet corrections by more than half. Exports line up perfectly with payroll and the GPS clock-ins keep our field crews honest without creating friction.”
David KimOperations Director, FreshBite Kitchens
★★★★★
“Geofencing and kiosk mode at each site solved our late punches. Managers love the late alerts and I love closing payroll on Friday in minutes.”
Laura BennettCFO, Meridian Logistics
★★★★★
“ClockIt’s overtime rules and approvals gave us immediate savings. Clear audit trails and clean timesheets mean finance isn’t chasing people anymore.”
Ahmed Al MansooriGeneral Manager, Desert Care Clinics
★★★★★
“We schedule across multiple locations and roles. ClockIt.io handles PTO, availability, and publishes updates to everyone’s phones instantly—no more group chats.”
Sofia GarciaStore Manager, UrbanFit Gyms
★★★★★
“Our trainers swap shifts right in the app and confirm attendance. Attendance and payroll line up perfectly—ClockIt just works.”
Tom O'ConnorIT Manager, GreenLeaf Services
★★★★★
“Setup was fast and the support team was outstanding. We rolled out ClockIt to 120 staff in a week and adoption was near 100% on day one.”
Jing WeiHR Business Partner, Sunrise Manufacturing
★★★★★
“The reports in ClockIt.io make our monthly reviews painless. We finally have visibility into attendance trends and actual hours by department.”
Hannah BrooksClinic Coordinator, BrightSmile Dental
★★★★★
“Time‑off requests, approvals, and balances are all in one place. Doctors see who’s off at a glance and we avoid coverage gaps.”
Roberto SilvaOperations Manager, Pacifica Transport
★★★★★
“For crews on the move, ClockIt’s GPS punch-ins and site-based rules keep things accurate. It’s the reliability we were missing before.”
Grace ThompsonCEO, Willow & Co. Interiors
★★★★★
“We tried three tools before ClockIt.io. This is the first one our team actually likes using—and it saves my admin two hours every payroll run.”
James WilsonPlant Manager, Apex Manufacturing
★★★★★
“Implementing ClockIt's biometric kiosks eliminated buddy punching overnight. The facial recognition is instant and works perfectly even in our warehouse environment. It's the most secure time tracking decision we've made.”