Most companies deploying a biometric system hit the same question at the same moment: several employees decline to give consent. From there a practical question follows - is attendance without biometric data possible?
This piece is not legal advice. It is about the principle of data minimisation and its practical consequences.
What happens when consent is declined
The scenario develops almost identically every time.
If the company has no alternative method, those employees' records are entered by hand by a manager. That produces two consequences.
First, part of the record becomes imprecise, because a manually written entry is created after the fact rather than at the moment of the event.
Second, two different regimes appear inside one team. For one group the record is automatic; for the other it depends on a manager's memory. That raises a fairness question at month end and is, in practice, the case that causes the most disputes.
So the main conclusion is this: the alternative route has to be planned before rollout - not afterwards.
What a non-biometric model stores
The difference lies in what is stored.
In a model based on codes and a mobile app, what is stored is: the time of the record, the point it was made at, and the device it came from. No physical characteristic - a fingerprint template or face geometry - is stored.
The practical consequence is twofold. The internal obligation around data handling gets considerably lighter, and the consent question disappears - no physical characteristic is asked of the employee.
This does not mean biometrics is bad. The two models simply have different obligation profiles, and that difference should be weighed at the selection stage. Full comparison: biometric attendance system.
Where control moves to
The most common objection: if no biometric data is stored, how is the owner of a record confirmed?
The answer is that control moves from inside the record to around it and is assembled from several layers:
- the device the record came from is stored, and device history is kept;
- device changes appear as separate events and the relevant people can be notified;
- two devices of the same make and model can be identified as distinct devices;
- the record is matched against the location of the entry point;
- a mismatch reaches the responsible person as a notification.
In practice the value of these layers is in their combination: two independent signals coinciding on the same day make a case worth reviewing, while a single signal usually has an ordinary explanation.
What should be written internally
Whichever model is chosen, one document is needed and it fits on a single page.
What is recorded: the start and end of the working day, the point the record was made at, the device it came from.
What is not recorded: movement between records, personal locations, time outside working hours.
What the employee sees: their own records, schedule, lateness and leave balance.
The third point is the most often skipped and the biggest factor in reducing resistance. When transparency runs both ways, the system is read as a shared record rather than a monitoring tool.
What to do in a mixed team
In some companies a biometric terminal is already installed and running. What is the practical decision then?
The approach that works best is to separate the problems: the terminal stays in place as physical access control, while attendance is recorded in one system for all employees.
Splitting the record - one group on the terminal, another in a different system - means reconciling two files at month end. In practice that eats most of the gain automation was meant to deliver.
Where to start
- Check with an actual number how many people in the team have smartphones.
- Choose the alternative for the rest: an NFC point or a manual record.
- Write the one-page document: what is recorded, what is not, what the employee sees.
- Circulate it before the rollout - not after.
A worked example: the five who declined
A manufacturing company rolled out a fingerprint system for 120 employees. Five declined to give consent.
Because no alternative had been planned, their records were kept by hand by the shop supervisor. In the first month nothing seemed wrong. In the second, two things surfaced.
The first was technical: the five people's records were written in a batch at the end of the day and did not reflect actual times. The second was human - a view formed in the team that "there is a different rule for them".
The situation was resolved in month five: attendance recording moved to mobile check-in for all employees, while the terminal stayed at the production-area door as physical access control. Keeping two parallel records was not considered - reconciling two files at month end would have been a bigger problem than the original one.
Three facts to establish before asking the question
When choosing a model it helps to collect three concrete numbers from the team - they move the discussion from opinion to fact.
How many people have a suitable smartphone? This usually comes out higher than assumed and shows the size of the alternative needed for the rest.
How many entry points exist and how many will be added over three years? This number determines the most volatile line in the cost calculation.
Is the internal personal-data rule ready? If biometric data is stored, that document is required, and preparing it usually takes longer than the technical setup.
Once the three numbers are collected, the decision more or less makes itself.
The next step
A model that stores no biometric data is not the right choice for every company - at a fixed entrance with phone restrictions a terminal may fit better. But the existence of an alternative has to be planned either way.
See the alternative setup, look at what QRGate does, or calculate the price.