Insights

Regulation Is Now the Decision Maker on Biometric Time Capture

For most of the period in which biometric verification has been available in workforce management, the questions asked of it were technical. How fast is it, how often does it fail, and how does it cope with a wet finger or a changed appearance. Those questions have largely been answered by the technology improving.

 

The question that now determines whether a biometric system can be deployed at all is a different one, and it is not answered by better hardware. It is whether the employer can demonstrate that using biometric data was necessary in the first place.

 

The Information Commissioner’s Position

On 23 February 2024 the Information Commissioner’s Office issued enforcement notices against Serco Leisure, Serco Jersey and seven associated community leisure trusts, ordering them to stop using facial recognition and fingerprint scanning to monitor employee attendance. The processing covered more than 2,000 employees across 38 leisure facilities. The ICO found breaches of Articles 5(1)(a), 6 and 9 of the UK GDPR, and gave three months to cease processing and destroy the data.

 

The reasoning is the part worth attention. The ICO did not find that the technology was inaccurate or that the data was inadequately protected. It found that the employer had not established why biometric data was necessary when less intrusive methods, including identity cards and fobs, were available for the same purpose. It also found that employees had not been proactively offered an alternative, and that biometric sign-in had been presented as a requirement in order to be paid.

 

That second finding is the one with the widest application. Where an employer relies on consent, the imbalance of power in the employment relationship makes it unlikely that a worker could meaningfully refuse. An employer that offers no alternative has therefore not obtained consent at all, whatever the enrolment screen records.

 

Why Templates Are Not The Answer

Vendors commonly explain, correctly, that a biometric terminal does not retain a photograph or a fingerprint image. What is stored is a mathematical representation derived from the original capture, from which the original cannot practically be reconstructed.

 

This matters a great deal for security, but it does not change the legal classification. Biometric data processed for the purpose of uniquely identifying a person is special category data under Article 9 of the UK GDPR, and a template used to identify someone is exactly that. While converting an image into a numerical representation reduces the consequences of a breach, it does not remove the requirement to identify an Article 9 condition, and it does not answer the necessity question the ICO asked of Serco.

 

An employer relying on the template explanation as its compliance position has answered a question the regulator did not ask.

 

Biometrics In The US

In the US, Illinois has regulated this area since 2008 under the Biometric Information Privacy Act, which requires written consent before biometric identifiers are collected and provides a private right of action.

 

The exposure peaked with the Illinois Supreme Court’s 2023 decision in Cothron v. White Castle System, which held that a separate claim accrues each time biometric data is collected or transmitted. For an employer running fingerprint timekeeping, that meant one claim per scan per employee. The court noted the potential for ruinous liability and invited the legislature to revisit the question.

 

It did. Senate Bill 2979, enacted as Public Act 103-0769 and effective 2 August 2024, provides that repeated collection of the same identifier from the same person by the same method constitutes a single violation, with one recovery available. The Seventh Circuit has since held that the amendment applies retroactively.

 

The damages exposure has therefore narrowed considerably. The underlying obligations have not. Notice and written consent before collection remain the substance of most claims, and an employer that never obtained consent properly is in the same position it was before, with a smaller number attached.

 

Building Systems That Answer The Question

Two constraints emerge from the two jurisdictions, and they point the same way.

 

Biometric verification must be genuinely optional. And that doesn’t mean optional in the sense that a policy document mentions an alternative, but optional in the sense that any employee who declines biometric verification can still record their hours via another method at the same terminal, without disadvantage and without having to ask. This is what the ICO found missing at Serco, and it is the difference between consent and compliance.

 

Where templates are held is the other design decision that carries legal weight. A system that retains templates on the device, or that holds them in a form tied to a single site, presents a different risk profile from one that centralises a template library. The obligations are the same. The consequences of failing them are not.

 

Accuracy, by contrast, has become the least interesting property of a biometric system. It makes the day-to-day of users easier but it was never the objection of regulators.

 

Grosvenor Technology’s Position

Grosvenor Technology builds time capture systems for employers with shift-based and site-based workforces. Biometric verification is available on its terminals as an option an employer selects rather than a default, and an employee who declines can record their hours by another method. Systems are designed against UK and EU data protection requirements and adapted where other jurisdictions impose different ones, which reflects the fact that the more demanding baseline is the more useful one to build to.

 

The practical position for any employer is that the choice of verification method is a data protection decision before it is a procurement decision, and it should be documented as one.