Biometric attendance records presence by verifying a physical characteristic, such as a fingerprint or a face, at a device placed where people work. Its purpose is identity: it makes a punch difficult to delegate. Everything else about it, including cost, exception handling and privacy obligation, follows from that single design decision.
Proxy punching, and very little else. A card or a code can be handed to a colleague; a physical characteristic is much harder to lend. In workplaces where attendance drives pay directly, and where the population is large enough that supervisors cannot vouch for presence personally, that difference is the entire justification. Where neither condition holds, the same result is available from far cheaper methods, and employers deploying devices for reasons other than identity verification usually discover they have bought an expensive way of recording a time nobody was disputing in the first place.
Time, and it recurs. Every employee has to be enrolled in person, which is straightforward at one site and a project across many. New joiners need enrolling before their first shift, or the first day generates an exception before anything else happens. Contractors and visitors need a policy of their own. And a proportion of any population cannot enrol reliably at all: worn fingerprints from manual work, conditions affecting the relevant feature, or simply a template that keeps failing to match. That group needs a documented alternative from the start, not an improvised one at the door.
Anywhere the work is not performed at a fixed point. Field sales, service engineers, drivers, site supervisors moving between locations and anyone working remotely all sit outside the model, and adding devices does not bring them into it. Forcing the fit produces the worst outcome available: a population routinely marked absent, correcting their own records every week, and a register nobody believes. The right answer for those roles is a different capture method entirely, chosen for the way they actually work, with the device reserved for the population it was designed to serve.
Biometric information identifies a person and cannot be reissued if it is compromised, which is why it is treated more strictly than a badge number nearly everywhere it is regulated. The recurring themes across jurisdictions are a stated purpose and a lawful basis, notice to employees about what is captured and why, limited retention, restricted access, and appropriate security. Some places require explicit consent, some require an alternative for anyone who declines, and some restrict moving the templates across borders at all.
The specific requirements differ by country and sometimes by state, and they have been changing quickly. That makes this one of the few attendance decisions where the legal position should be established before procurement rather than after deployment, with advice from someone qualified in the applicable data protection law for each location. Practical consequences follow from the answer: whether templates may be held centrally or must remain on the device, whether a raw image may be kept at all, and what has to happen to a template when the person leaves.
By deciding in advance what happens on each failure mode. The device is down: who records presence, on what, and how does it reach the system. An individual cannot enrol: what is their permanent alternative, and does using it flag them in any report. A read fails repeatedly for one person: how many attempts before they switch to the alternative, and who gets told. Answering these before go-live is the difference between a controlled process and a supervisor with a notebook that nobody else can read.
The alternative path also has to be dignified. Someone who cannot use the device for a physical reason should not have to explain it at a queue every morning, and should not appear on an exception list managers read as suspicion. Assigning them a standing alternative, recorded once, removes both problems at once. Where that alternative is a manual entry, it needs the same approval discipline as any other correction, which is what stops the exception route becoming the convenient route for everybody else.
Placement, throughput and hygiene, in roughly that order of neglect. A device positioned where a queue forms at shift change will be blamed for lost minutes that are really a layout problem, and the usual response is to buy a second device rather than move the first. Throughput determines how many readers a site needs, and it is a function of how synchronised the arrivals are rather than of headcount alone, which is why two sites with identical populations can need very different provision.
Contact-based readers carry a maintenance and hygiene burden that touchless ones do not, and the choice between them has consequences for accuracy in dusty or wet environments. Both need network reliability planned rather than assumed, because a reader that cannot reach the server has to buffer locally and reconcile later, and one that silently stops buffering produces a gap nobody notices until payroll. Feeding readings into [attendance management software](/attendance-management-software) that flags a device which has stopped reporting is worth more in practice than any accuracy specification.
Sparingly, and for a stated purpose. The temptation with a precise arrival record is to extend it into performance judgement, monitoring of movement between areas, or measurement of time away from a station. Each extension goes beyond the purpose the capture was justified on, and in several jurisdictions that alone creates a problem. It also changes what the workforce believes the device is for, and that belief determines whether the deployment is accepted or quietly resisted.
The narrow use is the defensible one: establishing presence for pay and for statutory registers, feeding a roster, and surfacing exceptions that need a human decision. Keeping the biometric layer confined to identity, and letting the [HRIS](/hris) hold the employment record it attaches to, also limits the blast radius of any incident, since a compromised attendance system holding only timestamps and identifiers is a far smaller problem than one holding the full personnel file alongside them.
Pitch N Hire is an applicant tracking system built for recruiters and hiring teams. Everything on this page — sourcing, screening, interviewing, offers — runs in one pipeline.
Free for 1 user · No credit card · Talk to a real hiring expert
Pitch N Hire unifies sourcing, screening and hiring decisions on one AI-native platform. Book a quick demo on your real roles.
Prefer to talk? Book a demo · Talk to sales · View pricing
Free 1-user plan · No credit card · Talk to a real hiring expert
See your true cost-per-hire and how much Pitch N Hire could save you — our free Recruitment ROI Calculator gives you the numbers in under a minute. No signup required.
Open the free ROI calculatorPrefer a tailored walkthrough on your real roles? Drop your work email:
★ Free 1-user plan · No spam · Talk to a real hiring expert