A logistics company in Pune moved three warehouses to fingerprint attendance back in 2023, mainly to kill buddy-punching on the night shift. It worked. Disputes over hours dropped within a month. Nobody in HR asked what happens to the fingerprint data itself, because at the time nobody had to.
That changed on 13 November 2025, when the Ministry of Electronics and Information Technology notified the final Digital Personal Data Protection Rules, 2025 (Gazette notification G.S.R. 846(E)), bringing the Digital Personal Data Protection Act, 2023 into force in stages from 14 November 2025. If your biometric attendance system in India still runs on a fingerprint or face scanner with no consent trail behind it, this is the piece to read before your next audit, not after.
Biometric attendance compliance in India starts with one word: consent
Under the DPDP Act, biometric identifiers, fingerprints, face geometry, iris scans, count as personal data the moment they’re captured, and the law expects a lawful basis before you touch them. For an employer, that basis is almost always consent, and it has to be a specific kind of consent: informed, given for a stated purpose (“attendance and time tracking,” not a blanket HR clause buried in the offer letter), and capable of being withdrawn without the employee facing a penalty for withdrawing it.
Two things trip up Indian employers here. First, implied consent, the idea that showing up to a scanner every day counts as agreeing to it, does not hold under the Act. Second, an employee who withdraws consent still has to be able to clock in. If your fallback for a refused scan is “then don’t get paid,” that fallback itself is a compliance problem, not just an HR one.
What the Rules actually require you to do
Three enforcement dates matter, staggered by the Rules: 14 November 2025 for the foundational provisions and the Data Protection Board’s constitution, 14 November 2026, and 14 May 2027 for the remaining obligations including breach-reporting timelines and the more detailed consent-manager framework. Practically, an employer collecting biometric attendance data today should already have:
- A documented, purpose-specific consent notice for biometric capture, in a language the workforce actually reads, not just English.
- A working opt-out that doesn’t dock the employee’s ability to mark attendance, an app-based or manual fallback is the usual answer.
- A retention limit. Biometric templates kept indefinitely on an old attendance server, sometimes even after the employee has left, are one of the most common gaps we see when reviewing a client’s existing setup.
- Encryption and access control on wherever the biometric templates sit, whether that’s on-device, on a local server, or in the cloud.
The number that gets HR’s attention
The DPDP Act’s own schedule sets penalties running up to ₹250 crore for failing to take reasonable security safeguards around personal data, biometric data included. That figure is why this has moved from “something legal will handle eventually” to a line item CFOs are now asking HR about directly. It is worth saying plainly: the risk isn’t that biometric attendance is illegal in India. It isn’t. The risk is running it the way most companies still do, capture first, consent as an afterthought, no retention policy, no access log.
A practical audit, not a legal one
You don’t need outside counsel to do the first pass. Pull up your attendance system and check five things this week: whether a consent record exists for every employee currently scanning in biometrically; whether that consent notice names the purpose and names DPDP by reference; whether an employee who says no today has a real alternative tomorrow morning; who, by name or role, can access the raw biometric database; and whether templates for anyone who exited in the last two years have actually been deleted or are still sitting in a table nobody looks at.
Most SMB and mid-market HR teams we talk to fail at least two of those five on the first pass, usually the consent-notice wording and the exit-data deletion. Neither is expensive to fix. Both are expensive to explain to a regulator after the fact.
Where geo-attendance changes the picture
Field staff, sales teams, and site engineers on geo-attendance apps face a related but separate question: location data isn’t biometric, but it’s still personal data under the Act, and continuous location tracking outside working hours is the kind of “purpose creep” the DPDP Act is specifically written to catch. If your geo-attendance app pings location around the clock rather than only during check-in and check-out windows, that’s worth narrowing, both for compliance and, frankly, for how it lands with employees.
The IntelloHRM angle
We get asked, fairly often, why IntelloHRM pairs biometric and geo-attendance capture with a built-in consent log and a configurable retention window instead of leaving that to a separate compliance tool. The honest answer is that attendance and data protection stopped being separate problems on 14 November 2025. A system that clocks people in but can’t show you a consent trail for that data is now an incomplete system, not just a lean one. We’ve covered the broader case for structured attendance tracking in our piece on the benefits of attendance management software; this is the compliance layer that piece didn’t yet need to cover.
What to do this month
Don’t wait for the 14 November 2026 milestone to start. Get the consent notice rewritten and re-collected if your current one predates the Rules, put a deletion job on exited-employee biometric data, and write down, in one page, who can access the raw scanner database and why. That one page is usually the difference between a routine audit and a bad one.
Published 6 August 2026. Verified against MeitY’s gazette notification (G.S.R. 846(E), 13 November 2025) and legal-industry summaries of the Digital Personal Data Protection Rules, 2025, on that date.
