Skip to content
CompliancePublished 16 August 2026 · Updated 6 September 2026 · 2 min read

Biometric attendance privacy: EU, UK and Illinois questions

A scoped starting point for reviewing biometric workforce processing, with official sources and no blanket compliance guarantee.

By Attendify Vision · Product-led guidance with sources and labeled examples.

Start with the proposed processing

Document the purpose, people affected, data collected, storage, recipients, decisions and alternatives. Distinguish a photograph, a reference template, one-to-one verification and one-to-many identification. A numeric template does not make unique-identification processing legally insignificant.

This is an educational issue map, not a determination that your deployment is lawful. The relevant law depends on territorial scope and the actual parties and processing.

European Union: check both grounds and safeguards

The official GDPR text defines territorial scope in Article 3, lawful bases in Article 6, special-category conditions in Article 9 and impact assessment duties in Article 35. Where those rules apply, identifying a general lawful basis is not the end of the analysis for biometric unique identification.

Consent should not be assumed valid simply because a worker tapped a button. Assess the specific condition relied on, necessity, alternatives and consequences of refusal. EU and UK requirements should not be treated as one interchangeable jurisdiction.

United Kingdom: use the regulator’s current guidance

The ICO’s biometric attendance guidance addresses alternatives, worker information and impact assessment. It currently notes that it is under review following the Data (Use and Access) Act. Recheck it before relying on a deployment decision.

A product consent screen is one interaction in the process. It does not establish the employer’s complete legal grounds or make an unusable fallback acceptable.

Illinois: inspect the actual statute

BIPA Section 15 includes requirements concerning a public retention/destruction policy, notice and written release. Its destruction rule uses the earlier of satisfaction of the initial purpose or three years after the individual’s last interaction, subject to the statutory context.

Section 20 includes amended recovery provisions from 2024. Do not reuse older per-scan liability summaries or confuse a proposed bill with enacted law. Obtain jurisdiction-specific review of applicability and implementation.

Turn questions into deployment decisions

Scroll the table sideways to read all columns.

TopicEvidence to establish
NecessityDefined problem and considered alternatives
NoticeActual purposes, data, recipients and worker route
Error handlingUsable alternative and review of genuine work
RetentionSeparate periods for hours, selfies, templates and logs
Transfers and processorsActual infrastructure and contractual arrangements
Change controlReassessment when purpose or system changes

Attendify’s current boundary

Face verification and kiosk identification are controlled features. Templates are stored server-side; accepted attendance selfies remain in private storage. Kiosk notice, calibration and fallback decisions remain relevant before wider deployment. The product is not a GDPR/BIPA certification or a guarantee of lawful processing.

Use the DPIA worksheet and the security overview as factual preparation for the appropriate review.

Keep reading