Quick answer
A Philippine employer may use fingerprints, facial images, or other biometric data for attendance, but it does not have an unlimited right to do so. The system must have a lawful basis, serve a specific and legitimate workplace purpose, collect only what is necessary, provide employees with clear notice, protect the data with appropriate safeguards, and retain it only as long as justified.
Employee consent is not automatically required in every case. An employer may rely on another lawful basis under the Data Privacy Act of 2012, such as necessity for an employment contract, compliance with a legal obligation, or a properly established legitimate interest. However, the employer cannot use “consent” as a shortcut where employees have no genuine choice, and legitimate interest does not excuse excessive, undisclosed, or insecure processing.
Employees may ask what biometric data is collected, whether the system stores a raw fingerprint or facial image or only a mathematical template, who receives it, how long it is kept, and what happens after employment ends. They may object, seek access or correction, and request erasure or blocking when the legal conditions are met. These rights do not always require immediate deletion if the employer still has a valid legal ground or must preserve attendance records for a lawful claim or obligation.
Why biometric attendance raises special privacy concerns
A password or identification card can usually be changed. A fingerprint or facial characteristic cannot be replaced in the same way after compromise.
Biometric attendance may involve several kinds of personal data:
- The original fingerprint scan, facial image, voice sample, or other bodily characteristic
- A biometric template generated from the scan
- The employee’s name, number, department, schedule, and device identifier
- Time-in, time-out, location, shift, absence, and overtime records
- Logs of failed matches, attempted entries, corrections, and administrator access
Biometric identifiers and templates that can identify or single out an employee are personal information. Depending on the information collected, its purpose, and what it reveals or is combined with, the processing may also involve sensitive personal information governed by the stricter rules in Section 13 of the Data Privacy Act.
Calling a record “encrypted,” “hashed,” “anonymized,” or “just a template” does not automatically remove it from privacy law. If the employer or its provider can still link the record to an employee, authenticate that employee, or reasonably restore the link, it remains personal data.
The legal standards an employer must satisfy
The principal law is Republic Act No. 10173, the Data Privacy Act of 2012, together with its Implementing Rules and Regulations and binding National Privacy Commission issuances.
There must be a lawful basis
For ordinary personal information, Section 12 of the Data Privacy Act permits processing under specified grounds, including:
- The employee’s valid consent
- Necessity for performing a contract with the employee or taking requested pre-contractual steps
- Compliance with a legal obligation
- Protection of vitally important interests
- Necessity for a public authority’s mandate
- A legitimate interest that is not overridden by the employee’s fundamental rights and freedoms
An employer relying on legitimate interest should be able to identify the concrete interest, show that biometric processing is necessary for it, and balance that interest against the effect on employees. The governing requirements appear in NPC Circular No. 2023-07 on Legitimate Interest.
If the system processes sensitive personal information, the employer must identify a basis permitted by Section 13. The lawful grounds for ordinary personal information cannot simply be assumed to authorize sensitive-personal-information processing.
Consent must be genuine when it is the chosen basis
Valid consent must be freely given, specific, informed, and evidenced by written, electronic, or recorded means. It must relate to declared and legitimate purposes and may be withdrawn.
The employment relationship creates an obvious power imbalance. A signature on an onboarding form does not necessarily establish freely given consent if refusing would automatically cost the employee a job or benefit and no other lawful justification or reasonable choice exists. Bundled consent—such as one signature authorizing attendance, security, marketing, profiling, and unrelated future uses—is also questionable.
The employer should identify its actual legal basis rather than telling employees that biometric processing is “mandatory because you consented.” Detailed consent requirements are set out in NPC Circular No. 2023-04 on Consent.
The system must be necessary and proportionate
All processing must follow the principles of transparency, legitimate purpose, and proportionality.
The employer should be able to explain why the attendance objective cannot reasonably be achieved with less intrusive measures, such as an identification card, PIN, signed log, mobile check-in without biometric identification, or supervisor-certified attendance.
This does not mean biometrics are always unlawful whenever another method exists. It means the employer must make a defensible, fact-based assessment of necessity, effectiveness, risks, and available alternatives. A system collecting full facial images, location histories, or continuous surveillance data when a limited attendance template would suffice may be disproportionate.
Function creep is particularly risky. Data collected to record attendance should not quietly be reused for employee profiling, productivity scoring, disciplinary surveillance, law-enforcement disclosure, marketing, or training an unrelated facial-recognition product without a separate lawful basis and proper notice.
What employees should be told
Before collection, the employer should provide a clear privacy notice that employees can understand. It should identify:
- The employer or other personal information controller
- The exact biometric and related attendance data collected
- The purpose of each processing activity
- The lawful basis relied upon
- Whether raw images are retained or converted into templates
- Whether matching happens on the device, on company servers, or in a vendor’s cloud
- The recipients or categories of recipients
- Any overseas storage, access, or processing
- The retention period or objective criteria used to determine it
- The consequences of refusing or being unable to enroll
- The employee’s privacy rights and how to exercise them
- The employer’s Data Protection Officer and contact details
A vague statement that data will be used for “company purposes,” “security,” or “future business needs” is not a substitute for a specific notice.
Security duties of the employer and provider
The employer remains accountable for personal data under its control even if a third-party vendor supplies or hosts the attendance system. The vendor normally acts as a personal information processor when it handles data only on the employer’s documented instructions.
The employer should conduct and document a privacy impact assessment before implementation and when material changes are introduced. Under NPC Circular No. 2023-06 on Security of Personal Data, organizations must adopt reasonable and appropriate organizational, physical, and technical safeguards.
For a biometric attendance system, appropriate controls commonly include:
- Collecting templates rather than retaining raw images where feasible
- Encrypting data at rest and in transit
- Separating biometric templates from names and payroll records
- Strict role-based access and prompt removal of former administrators
- Multi-factor authentication for privileged accounts
- Access, enrollment, deletion, and export logs
- Protection against copying templates between systems or devices
- Procedures for false matches, failed scans, and manual corrections
- Regular vulnerability testing, patching, backups, and secure disposal
- Written limits on the vendor’s use, disclosure, subcontracting, retention, and return or deletion of data
- Incident-response and business-continuity procedures
An employer should also verify whether its Data Protection Officer and relevant data processing system must be registered with the NPC under NPC Circular No. 2022-04. Registration, where required, does not by itself prove that the processing is lawful.
Retention and deletion
Biometric data must not be kept indefinitely merely because storage is inexpensive.
The employer should establish a documented retention period tied to attendance administration, payroll, audit, dispute resolution, or another identified legal purpose. When the data is no longer necessary, it should be securely deleted, destroyed, anonymized, or returned, including copies held by vendors, subject to lawful retention requirements.
An employee’s resignation or termination does not invariably require the immediate destruction of every attendance record. The employer may still need non-biometric attendance information for payroll, labor, tax, audit, or legal-claim purposes. That does not automatically justify retaining a reusable biometric template for the same period. The employer should evaluate the template separately and keep only what remains necessary.
Your rights as an employee
Section 16 of the Data Privacy Act and the IRR recognize rights that include:
- Right to be informed: You may ask for meaningful information about the collection and use of your data.
- Right to object: You may object to processing, particularly when it is based on consent or legitimate interest. The effect depends on whether another lawful ground applies or an overriding legitimate ground is established.
- Right of access: You may request the personal data processed about you and information about its sources, recipients, purposes, manner of processing, and relevant retention period.
- Right to correction: You may dispute and seek correction of inaccurate or erroneous attendance information.
- Right to erasure or blocking: You may seek suspension, blocking, removal, or destruction when, for example, data was unlawfully obtained, used for an unauthorized purpose, is no longer necessary, or is being processed unlawfully. Exceptions may apply for legal obligations, legitimate business retention, or the establishment, exercise, or defense of legal claims.
- Right to damages: You may seek compensation for damage caused by inaccurate, incomplete, outdated, unlawfully obtained, or unauthorized use of personal data, subject to proof and the proper proceedings.
- Right to data portability: This may apply to electronically processed data in a structured and commonly used format under the conditions stated in the law and IRR.
A request for erasure is therefore not an automatic right to delete every employment record on demand. The answer depends on the type of record, the legal basis, the purpose, applicable retention duties, and any pending dispute.
What to do if you are concerned
1. Ask the employer in writing
Write to Human Resources and the Data Protection Officer. Keep the request factual and specific. Ask for:
- The employee privacy notice and biometric attendance policy
- The lawful basis for collection and processing
- The data fields collected and whether raw scans are retained
- The retention and deletion rules
- The names or categories of service providers and recipients
- The location of storage and any overseas processing
- The procedure for access, correction, objection, or deletion
- The available alternative if a disability, injury, religious concern, technical failure, or privacy objection prevents reliable biometric use
Request a written answer and preserve proof that the employer received your letter or email.
2. Document attendance disputes separately
If the system records a false absence, late arrival, or missing time-out, report it immediately through the company’s correction process. Attach supporting material such as:
- Work emails or system-login records
- Gate, building, or transport records lawfully available to you
- Approved schedules and overtime forms
- Messages to a supervisor
- Witness names
- Payslips and time records
- Screenshots showing the failed scan or system error
Do not secretly access restricted systems or obtain another employee’s records.
3. Use internal channels
Raise the matter with the Data Protection Officer, HR, grievance committee, union, or procedure under the collective bargaining agreement. A privacy complaint and an attendance or disciplinary dispute may involve different decision-makers and deadlines, so address both.
4. Escalate to the National Privacy Commission when appropriate
Before filing an NPC complaint, a complainant generally must first inform the respondent in writing of the claimed violation or personal data breach and allow it to act. The NPC’s published complaint mechanics state that proof should be attached showing that the respondent failed to take timely or appropriate action, or did not respond within 15 calendar days after receiving the written notice.
Use the NPC’s current complaint mechanics and Complaint-Affidavit form. A complaint must be complete and supported by evidence; incomplete complaints may be dismissed. Check the NPC website before filing because forms, addresses, and accepted filing channels can change.
5. Seek labor assistance for employment consequences
The NPC addresses data-privacy violations; it does not replace labor remedies. If the biometric policy leads to withheld wages, suspension, dismissal, discrimination, or another employment dispute, promptly consult a union representative, labor lawyer, or the Department of Labor and Employment. Labor claims may have different procedures and prescriptive periods.
Evidence worth preserving
Keep lawful copies of:
- Privacy notices, consent forms, policies, memoranda, and enrollment instructions
- Emails and messages sent to HR, the DPO, supervisors, or the vendor
- Proof of delivery and all responses
- Time records, payslips, schedules, and disputed deductions
- Screenshots or photographs of notices displayed near the device
- Dates and descriptions of failed scans, false matches, or unauthorized access
- Notices of a security incident or data breach
- Disciplinary notices and your written explanations
- The relevant handbook and collective bargaining agreement
- Names of witnesses and a contemporaneous timeline
Preserve original electronic files and metadata when possible. Avoid posting biometric records, employee lists, internal screenshots, or allegations publicly, because doing so may expose other people’s data or complicate the dispute.
Common mistakes
- Assuming biometric attendance is automatically illegal
- Assuming an employer may collect biometrics merely because attendance monitoring is legitimate
- Treating a signed form as conclusive proof of freely given consent
- Failing to distinguish a raw biometric image from a template and ordinary attendance logs
- Collecting more data than the stated attendance purpose requires
- Reusing attendance data for undisclosed monitoring or profiling
- Allowing the vendor to retain or reuse biometric data for its own purposes
- Keeping former employees’ templates without a documented reason
- Ignoring accessibility needs, worn fingerprints, facial-recognition errors, or device failures
- Making only an oral complaint and keeping no proof
- Refusing a workplace instruction without first requesting the policy, legal basis, and available alternative
- Filing an NPC complaint without first completing the required written notice or attaching evidence
When help is urgent
Seek prompt assistance if:
- You receive a notice of termination, suspension, wage deduction, or disciplinary hearing
- The system repeatedly identifies you incorrectly or attributes another person’s attendance to you
- Someone appears to have copied, exported, sold, or publicly disclosed biometric records
- A lost device, hacked account, ransomware event, or vendor breach may involve employee biometrics
- You are pressured to sign a backdated or blank consent form
- The employer refuses to identify its Data Protection Officer or explain where the data goes
- The system disadvantages you because of disability, injury, facial difference, religious practice, or another protected circumstance
- A deadline in a company grievance procedure, collective bargaining agreement, labor case, or NPC proceeding is approaching
If a personal data breach is suspected, notify the employer’s DPO immediately and retain the notice. The legal duty to assess and, when required, report the breach generally rests on the personal information controller; employees should not delay reporting internally while trying to determine whether every notification requirement has been met.
Frequently asked questions
Can my employer require fingerprint or facial attendance?
Possibly. A requirement may be lawful if it has a valid legal basis, is necessary and proportionate to a legitimate purpose, is transparently implemented, and includes appropriate safeguards. Its validity depends on the actual design, policy, alternatives, employment terms, and effects—not simply on the employer owning the device.
Must my employer obtain my consent?
Not always. Another lawful ground may apply. If the employer relies on consent, however, it must satisfy the legal requirements for valid consent, including that it is freely given, specific, and informed. Withdrawal of consent does not necessarily stop processing supported by a different lawful basis.
Can I refuse to enroll?
You may object and request an explanation or alternative, but refusal does not automatically invalidate a lawful and reasonable workplace rule. Conversely, an employer should not assume that any refusal justifies discipline. The result depends on the policy’s legality, necessity, proportionality, notice, employment rules, available accommodations, and observance of disciplinary due process. Obtain advice before taking a step that may affect your employment.
Can the company send my biometric data to a vendor?
It may engage a service provider, but the employer remains accountable for data under its control. The arrangement must have a lawful purpose, proper contractual and security controls, restricted vendor use, and appropriate transparency. Overseas access or storage should also be disclosed and protected in accordance with Philippine law.
Can I demand deletion after resignation?
You may request it. A biometric template that is no longer needed should not be kept indefinitely. Some ordinary attendance and payroll records may lawfully be retained for obligations or claims. Ask the employer to explain separately why it retains the biometric template, raw image, attendance logs, and payroll records.
Can biometric attendance be used to dismiss an employee?
Attendance records may form part of an employment investigation, but a machine record is not automatically conclusive. Errors, device failures, schedule changes, authorized leave, identity mismatches, and manual alterations must be considered. Any disciplinary action must have a valid labor-law basis and follow applicable due process.
Where can I read the official rules?
Start with the Data Privacy Act of 2012, its Implementing Rules and Regulations, and the NPC’s official collection of advisories and circulars. The NPC also provides official guidance on data-subject rights and complaint procedures.
This article provides general legal information, not legal advice for a particular employee, employer, system, or dispute. Outcomes depend on the documents, data design, workplace rules, contractual arrangements, and specific facts. Official sources and procedures were checked as of 1 September 2026.