01

Why Biometric Clocking Raises Legal Questions

Biometric data (like fingerprints or facial templates) is classified as special personal information under POPIA. That doesn’t make it illegal… it just means employers must handle it more carefully than ordinary employee data.

02

What POPIA Expects From Employers Using Biometric Clocking

To remain compliant, employers should be able to show that:

  1. 01
    There Is a Lawful and Reasonable Purpose

    Time and attendance tracking, payroll accuracy, overtime control, and access security are all considered legitimate business purposes.

  2. 02
    Employees Are Clearly Informed

    Employees must understand:

    • what biometric data is collected
    • why it’s collected
    • how it’s stored
    • who has access to it
    • how long it’s kept

    This should be explained in writing — not buried in fine print.

  3. 03
    Data Collection Is Proportionate

    Only collect what is necessary.

    Modern systems store biometric templates, not raw fingerprint images or photos, which significantly reduces privacy risk.

  4. 04
    Security Safeguards Are in Place

    This includes:

    • restricted admin access
    • encrypted storage
    • secure servers or devices
    • audit trails

    If you can’t explain how data is protected, you’re exposed.

  5. 05
    Data Isn’t Kept Forever

    Biometric data should be deleted when:

    • the employee leaves
    • it’s no longer needed for the stated purpose

    Retention should be defined — not open-ended.

A Common Misconception

“We Just Need Consent”

Consent alone is not enough in an employment relationship. POPIA recognises that employees may feel pressured to consent.

That’s why transparency, fairness, and alternatives matter just as much as a signed form.

Discuss Your Requirements