Employee Privacy Rights for Biometric Attendance Systems

Quick answer

A Philippine employer may use fingerprints, facial images, iris scans, or similar biometric data for attendance, but not merely because the technology is convenient or common. The employer must have a lawful basis, explain the system before or at the next practical opportunity, collect only what is necessary, protect it properly, limit access and sharing, set a defensible retention period, and respect employees’ rights under the Data Privacy Act of 2012 and its Implementing Rules and Regulations.

Employees do not have an absolute right to reject every biometric attendance system. Conversely, an employer cannot cure an unnecessary, excessive, insecure, or undisclosed system by simply requiring employees to sign a consent form. Whether a particular system is lawful depends on what it collects, why biometrics are needed, what alternatives exist, how the data is used and secured, and whether it will affect pay or discipline.

Why biometric attendance data is legally protected

Biometrics can identify or verify a particular person through characteristics such as a fingerprint, face, voice, or iris. The National Privacy Commission (NPC) has treated uniquely identifying biometric information as personal information. A biometric template may still be personal information even if it is converted into numbers or stored separately from an employee’s name, as long as it can still be linked to or used to distinguish that employee.

Biometric data is not automatically classified as “sensitive personal information” simply because it is biometric. That classification depends on the actual information being processed. A system may also contain sensitive personal information—for example, birth dates, health or disability information, or government-issued identifiers. This distinction matters because legitimate interest under Section 12 of the Data Privacy Act applies only to personal information, not sensitive personal or privileged information. The latter must have a lawful basis under Section 13.

Biometric information nevertheless carries unusual risk. Unlike a password, a face or fingerprint cannot simply be replaced after exposure. NPC breach rules expressly recognize biometric data as information that may enable identity fraud.

When an employer may lawfully use biometrics

The employer ordinarily acts as the personal information controller because it decides why and how attendance data will be processed. A biometric-system provider normally acts as its personal information processor when it handles the data only on the employer’s instructions.

Processing must satisfy both a lawful basis and the principles of transparency, legitimate purpose, and proportionality.

Possible lawful bases

Depending on the facts, an employer may rely on one or more of the following:

  • Processing necessary to perform obligations under the employment contract;
  • Processing necessary to comply with a legal obligation;
  • Processing necessary for a legitimate interest that is not overridden by employees’ constitutional rights and freedoms; or
  • Valid consent, where consent is genuinely appropriate.

Employers have legitimate reasons to maintain accurate attendance and working-time records. The Omnibus Rules Implementing the Labor Code require covered employers to keep individual time records and recognize several recording methods. That recordkeeping obligation does not, by itself, prove that biometric collection is necessary in every workplace. The employer must still justify the particular method chosen under data-privacy law.

If the employer relies on legitimate interest

Under NPC Circular No. 2023-07, the employer must conduct and document a legitimate-interest assessment covering three matters:

  1. Purpose: There must be an actual, clearly defined and lawful interest, such as preventing proxy attendance or maintaining reliable time records.
  2. Necessity: The chosen processing must be adequate, relevant, suitable, necessary and not excessive. The employer should consider whether a less intrusive method can reasonably accomplish the same purpose.
  3. Balancing: The employer must weigh its interest against the effect on employees’ rights, the availability of alternatives, employees’ reasonable expectations, and safeguards that reduce the risk.

A vague assertion that biometrics are “more efficient” is not the same as a documented necessity and balancing assessment. Legitimate interest also cannot be used as the lawful basis for sensitive personal or privileged information.

Consent is not always required—or sufficient

Consent is unnecessary when another lawful basis under Sections 12 or 13 properly applies. A privacy notice is still required even when consent is not.

If an employer chooses to rely on consent, NPC Circular No. 2023-04 requires consent to be freely given, specific, informed, expressly indicated, and evidenced by written, electronic, or recorded means. Consent is not freely given when refusal carries pressure, intimidation, or possible adverse consequences.

The NPC has also observed in its 2024 advisory opinion on employee monitoring that consent may be unsuitable in an employment relationship because employees are seldom in a position to freely refuse or withdraw it. An employer should therefore identify the real lawful basis instead of using a compulsory consent form as a blanket waiver.

Signing an employment contract or handbook acknowledgment does not authorize every possible use of biometric information. Consent cannot be vague, bundled across unrelated purposes, or inferred merely from continued reporting for work.

What the employer must disclose

Employees should receive a clear privacy notice or policy stating:

  • What is collected—for example, a raw fingerprint image, facial photograph, facial geometry, or mathematical template;
  • The specific attendance, security, payroll, or other purposes;
  • The lawful basis for each purpose;
  • How enrollment, matching, storage and deletion work;
  • Whether the system performs profiling or automated decision-making;
  • Who may access the data;
  • The identity of the vendor and other recipients;
  • Whether data will be stored in the Philippines or transferred abroad;
  • The retention period or the criteria used to determine it;
  • The employer’s identity and the contact details of its data protection officer or representative;
  • Available employee rights and how to exercise them; and
  • How to report an error, security incident, or suspected breach.

A notice is not meaningful if it only says that data will be used for “company purposes.” Attendance data should not quietly be reused for employee profiling, facial-recognition surveillance, marketing, product development, or artificial-intelligence training without a compatible lawful purpose, proper notice, and any additional legal basis that the new processing requires.

Proportionality and less intrusive alternatives

Biometric processing is more likely to be defensible when the employer can show a concrete problem that ordinary timecards, authenticated applications, ID badges, or supervised logs cannot reasonably address.

Relevant questions include:

  • Is the system used only to verify attendance, or does it continuously track location and movement?
  • Does the device store a full image or only a protected template?
  • Is the central storage of templates necessary, or can verification occur locally on the device?
  • Is biometric enrollment required for every employee regardless of risk?
  • Can employees with injuries, worn fingerprints, disabilities, religious concerns, or repeated matching failures use another reliable method?
  • Will a supervisor review questionable records before deductions or discipline?
  • Are unrelated features—such as emotion analysis, age estimation, or continuous facial tracking—disabled?

Philippine law does not give every employee an automatic right to a non-biometric alternative. Still, the availability of a less intrusive and equally effective method is directly relevant to whether biometric processing is necessary and proportionate. A reasonable alternative is especially important when the system cannot reliably enroll or recognize a particular employee.

Security, vendors and retention

Under NPC Circular No. 2023-06, employers and their processors must implement reasonable organizational, physical and technical safeguards. Among other obligations, they must:

  • Conduct and update a privacy impact assessment for the processing system;
  • Maintain an inventory of processing activities and data repositories;
  • Apply privacy by design and privacy by default;
  • Disable functions that lack a lawful basis or are inconsistent with privacy principles;
  • Restrict access to authorized personnel on a need-to-know basis;
  • Use formal contracts governing the vendor’s access and security duties;
  • Monitor threats and vulnerabilities;
  • Maintain incident-response and breach-management procedures; and
  • Securely erase or destroy data when retention is no longer justified.

Hiring a vendor does not transfer the employer’s accountability. The employer must ensure that the provider follows documented instructions, applies appropriate safeguards, assists with employee requests and breaches, and does not repurpose the data for its own business.

There is no universal Data Privacy Act retention period for biometric attendance data. The employer must establish and document a period tied to the declared purpose, applicable recordkeeping laws, legitimate business needs, and the establishment or defense of legal claims. Data cannot be retained indefinitely for an unspecified future use.

Separation from employment does not always require immediate deletion of every attendance record. Records may still be needed for payroll, audits, labor claims or another lawful purpose. However, continuing to retain reusable biometric templates after they are no longer necessary requires a separate and defensible justification. Secure deletion should cover live systems, devices, vendor copies and backups, subject to lawful backup-retention cycles.

Your rights as an employee

As the data subject, you may exercise the following rights, subject to lawful limitations:

  • To be informed: Know whether and how your biometric and attendance data is processed.
  • To object: Object where processing is based on consent or legitimate interest. If another lawful basis applies, the employer must identify and explain it.
  • To access: Request your data, its sources, purposes, recipients, processing method, retention period, access or modification dates, and information about significant automated decisions.
  • To rectification: Dispute an incorrect attendance entry or biometric match and require correction within a reasonable period.
  • To erasure or blocking: Seek suspension, blocking or deletion when data was unlawfully obtained, used for an unauthorized purpose, is no longer necessary, or is otherwise unlawfully processed.
  • To data portability: In qualifying cases, obtain electronically processed data in a commonly used structured format.
  • To damages: Seek indemnity for legally compensable injury caused by inaccurate, unlawfully obtained, or unauthorized processing.

Under NPC Advisory No. 2021-01 on data-subject rights, a private-sector controller should act on a rights request without undue delay and within 30 working days after receiving the request and any necessary supporting documents. A complex or numerous request may be extended by up to 15 additional working days, but the employee must be notified of the reason. Different government-service timelines may apply to government employers.

These rights do not guarantee deletion or cessation in every case. An employer may retain or continue processing data where necessary for a legal obligation, the employment relationship, a legitimate business purpose consistent with applicable standards, or the establishment or defense of legal claims. It must be able to explain and support that conclusion.

What to do if you have concerns

1. Obtain the policy and identify the responsible person

Ask HR for the biometric-attendance privacy notice, employee monitoring policy, retention policy, and the contact details of the data protection officer. Do this in writing.

2. Ask focused questions

Request confirmation of:

  • The exact biometric elements collected;
  • Whether raw images are retained;
  • The declared purpose and lawful basis;
  • The reason a less intrusive method is insufficient;
  • The names and roles of vendors and recipients;
  • Storage locations and cross-border transfers;
  • Retention and deletion arrangements;
  • Access controls and security safeguards;
  • The procedure for correcting failed or incorrect matches; and
  • Whether an alternative attendance method is available.

You normally are not entitled to confidential source code or another employee’s information. You are entitled to meaningful information about your own data and how significant automated processing affects you.

3. Exercise the appropriate right in writing

State clearly whether you are requesting access, correction, objection, blocking, deletion, or a combination. Identify the disputed records and requested remedy.

A concise request may say:

I am exercising my rights under the Data Privacy Act concerning the biometric attendance system. Please provide the privacy notice, identify the biometric data processed and lawful basis, disclose the recipients and retention period, and provide my attendance records for the stated dates. I also dispute the entry dated ___ and request that no payroll deduction or disciplinary decision be finalized until it has been reviewed.

Keep proof that HR or the data protection officer received the request.

4. Preserve evidence

Keep copies of:

  • Enrollment forms, consent forms and privacy notices;
  • Employee handbooks and attendance policies;
  • Emails, memoranda and chat messages;
  • Screenshots of enrollment, errors and system warnings;
  • Daily time records, schedules, payslips and disputed deductions;
  • Written objections and the employer’s replies;
  • Names of witnesses to enrollment or system failures;
  • Breach notices or reports of unauthorized access; and
  • Dates when policies or system settings changed.

Preserve originals and metadata where possible. Do not obtain evidence by accessing another person’s account or restricted company systems.

5. Escalate internally before filing with the NPC

Ordinarily, the current NPC Rules of Procedure, as amended require you to inform the employer, vendor, or other concerned entity in writing and give it an opportunity to act. If it takes no timely or appropriate action, or does not respond within 15 calendar days from receipt, you may proceed with an NPC complaint. The NPC may waive this requirement for good cause or a serious violation, including circumstances involving grave and irreparable harm, the absence of an adequate remedy, or patently illegal action.

The complaint must be verified and supported by relevant correspondence, documents and witness affidavits. It may be filed personally, by registered mail, by accredited courier, or electronically when authorized by the NPC. Appropriate filing fees apply unless an exemption or waiver is available. Check the NPC’s current complaint instructions and forms before filing.

6. Use the proper labor remedy for employment consequences

The NPC addresses data-privacy violations. It is not a substitute for the labor process when the dispute concerns unpaid wages, an illegal deduction, suspension, retaliation, or dismissal.

For a labor issue, an employee may file a Request for Assistance through the DOLE Assistance for Request Management System or at an authorized Single Entry Assistance Desk. The Single Entry Approach generally provides a 30-day mandatory conciliation-mediation period before an unresolved matter proceeds to the appropriate labor forum.

If a union or collective bargaining agreement covers the workplace, consult the union and use the applicable grievance procedure as well.

If an attendance record affects pay or discipline

Biometric logs can be evidence of attendance, but they are not automatically conclusive. Devices may fail to enroll a fingerprint, record the wrong time, lose connectivity, duplicate an entry, or associate a scan incorrectly.

Dispute the record promptly and supply supporting evidence such as schedules, access logs, work emails, supervisor instructions, CCTV preservation requests, transport records or witness statements. Ask for a human review before payroll is finalized or discipline is imposed.

An employer relying on attendance data for disciplinary action must still comply with applicable substantive and procedural labor requirements. A privacy violation does not automatically invalidate every disciplinary action, and a valid attendance rule does not excuse unlawful biometric processing. The privacy and labor questions must be assessed separately.

Personal data breaches

A lost device, exposed database, unauthorized vendor access, malware incident, or disclosure of biometric templates may constitute a personal data breach.

Notification is not automatic after every security incident. Under the Data Privacy Act’s IRR and NPC Circular No. 16-03, the employer must notify the NPC and affected employees within 72 hours when the information is reasonably believed to have been acquired by an unauthorized person and the unauthorized acquisition is likely to create a real risk of serious harm. Biometric data is specifically recognized as information that may enable identity fraud. The employer remains responsible for notification even if the breach occurred at its vendor.

An affected employee should ask:

  • What biometric and other data was involved;
  • Whether raw images or templates were exposed;
  • When unauthorized access began and ended;
  • Who obtained or may have obtained the information;
  • What containment and deletion measures were taken;
  • What risks the employer identified; and
  • What assistance or protective steps are being offered.

Preserve the breach notice and suspicious messages or account activity. Do not publish your own biometric files or identifying numbers while seeking help.

Common mistakes

Mistakes by employers

  • Treating a privacy notice as employee consent;
  • Making consent compulsory without identifying another lawful basis;
  • Collecting full biometric images when a less intrusive template would suffice;
  • Using attendance data for surveillance, profiling or AI training without proper justification;
  • Assuming a vendor alone is responsible for compliance;
  • Keeping templates indefinitely after employees leave;
  • Allowing unrestricted HR, IT or vendor access;
  • Making automatic deductions without a correction and review process; and
  • Failing to reassess the system after a new feature, vendor or purpose is introduced.

Mistakes by employees

  • Refusing verbally without creating a written record;
  • Assuming every biometric requirement is automatically illegal;
  • Signing a form without requesting the underlying privacy notice;
  • Waiting until after a payroll or disciplinary deadline to dispute an error;
  • Demanding immediate deletion where a lawful retention obligation still exists;
  • Filing an NPC complaint without first writing to the employer or preserving proof of receipt; and
  • Treating an NPC complaint as the only remedy when wages or dismissal are also involved.

When help is urgent

Seek prompt assistance from the employer’s data protection officer, the NPC, your union, DOLE, or a Philippine lawyer when:

  • Raw biometric images or templates appear online or are sent to an unauthorized recipient;
  • The system has been compromised and the employer will not explain the incident;
  • A disputed match is about to cause a wage deduction, suspension or dismissal;
  • The employer threatens punishment solely for asking about privacy rights;
  • Biometrics are secretly reused for surveillance, profiling, law-enforcement disclosure, AI development or another undeclared purpose;
  • The employer or vendor refuses to preserve relevant records after receiving notice of a dispute; or
  • Immediate action may be needed to prevent grave and irreparable harm.

Frequently asked questions

Can my employer require fingerprint or facial attendance?

Possibly. There is no blanket prohibition, but the employer must establish a lawful basis, necessity, proportionality, transparency and adequate security. Legality depends on the actual system and circumstances.

Can I simply refuse to enroll?

You may object and request an alternative, but objection does not automatically stop processing where the employer can prove another lawful basis. Before refusing outright, ask for the policy, lawful basis, necessity assessment and available alternative. Employment consequences must still comply with labor law.

Is a signed consent form enough?

No. Consent must be valid, and all processing must remain necessary, proportionate, fair and secure. Consent obtained under pressure or with adverse consequences for refusal may not be freely given.

Must the employer offer a timecard or manual log?

There is no general statutory rule guaranteeing every employee a non-biometric option. However, the availability of an effective, less intrusive method weighs heavily in the proportionality assessment. An alternative may also be appropriate where enrollment fails or an employee has a documented condition affecting use.

Is a biometric template anonymous?

Not necessarily. If it can still be linked to an employee or used for verification, it remains personal information even if the raw image has been deleted or the template is stored under an employee number.

Can the vendor use employee biometrics to improve its product or train AI?

Not merely because it possesses the data. A processor must act under the employer’s documented instructions. Using the data for the vendor’s independent purpose may make the vendor a separate controller and would require its own lawful basis, transparency and compliance with privacy principles.

Can I have my biometric data deleted after resignation?

You may request deletion. The employer may retain necessary attendance records for legal obligations, claims or legitimate business purposes, but reusable biometric templates should not remain indefinitely without a specific justification. Ask separately about live systems, devices, backups and vendor copies.

What if the machine records me as absent?

Dispute the entry immediately, request access and correction, and provide other proof of work. Ask that no deduction or discipline be finalized until

Quick answer

A Philippine employer may use fingerprint, facial-recognition, iris, voice, or similar technology to record attendance, but it does not have unlimited freedom to collect or reuse employees’ biometric data. The system must have a valid legal basis, serve a specific and legitimate purpose, collect no more data than necessary, be properly disclosed to employees, and use reasonable security and retention controls.

Your consent is not automatically required if the employer can establish another lawful basis, such as a contractual or legal obligation or a properly documented legitimate interest. Consent is also not a cure for an excessive or insecure system. If the employer relies on consent, it must be freely given, specific, informed, and recorded; consent obtained through pressure or threatened adverse consequences may be invalid.

Employees do not have an automatic, absolute right to refuse every biometric attendance system. They may, however, object, seek access or correction, question whether biometrics are genuinely necessary, and request a less intrusive attendance method. Whether an employer may insist—and whether it may discipline an employee for refusing—depends on the system, the employer’s stated legal basis, the applicable workplace rules or collective bargaining agreement, any need for accommodation, and compliance with both privacy and labor law.

Why biometric attendance data is legally protected

Biometrics are measurements or characteristics used to identify or verify a person, such as a fingerprint, facial image or face template, iris scan, voice pattern, or signature. The definition used in Philippine legislation includes quantitative analysis that provides positive identification through features such as voice, photograph, fingerprint, signature, and iris.

A biometric identifier linked or linkable to an employee is personal information under the Data Privacy Act of 2012, or Republic Act No. 10173. This can include:

  • A raw fingerprint or facial image;
  • A digital biometric template extracted from the image;
  • The employee number linked to that template;
  • Time-in and time-out logs;
  • Device, branch, location, or access records; and
  • Reports generated from those records, such as tardiness or absence reports.

Converting a fingerprint or face into a template does not automatically make it anonymous. If the employer or its vendor can still link the template to an employee or use it to verify that person, it remains protected personal information.

Biometric information is not expressly listed as sensitive personal information merely because it is biometric. Its precise classification depends on the data and context. A record may include sensitive personal information when it also contains matters covered by Section 3(l) of the Data Privacy Act, such as health information or government-issued identifiers. Significantly, the NPC’s breach rules expressly recognize biometric data as information that may be used to enable identity fraud.

Keeping attendance records does not give an employer a blank check

Philippine labor rules require employers to maintain attendance or time records for covered employees. The Omnibus Rules Implementing the Labor Code identify methods such as a bundy clock, a timekeeper’s record, and employee-completed daily time records. Employers also need reliable records to calculate wages, overtime, undertime, leave, and attendance-related benefits.

That recordkeeping duty can support the legitimate purpose of accurate timekeeping. It does not, by itself, establish that a fingerprint or facial-recognition system is necessary in every workplace. The employer must still explain why its chosen biometric method is appropriate and proportionate—for example, whether it addresses substantiated buddy-punching, access-control, safety, or payroll-integrity concerns that cannot reasonably be handled through a less intrusive method.

What makes a biometric attendance system lawful

A compliant system should satisfy all of the following.

A specific lawful basis

For ordinary personal information, an employer may potentially rely on one of the criteria in Section 12 of the Data Privacy Act, including:

  • Consent;
  • Necessity in relation to an employment contract;
  • Compliance with a legal obligation; or
  • The employer’s or a third party’s legitimate interest, unless overridden by the employee’s fundamental rights and freedoms.

The correct basis must be determined for the particular activity. “Employment purposes” or “company policy” alone is too vague to explain every possible use of biometric data.

Legitimate interest applies only to personal information, not to sensitive personal or privileged information. Under NPC Circular No. 2023-07 on legitimate interest, an employer relying on it must conduct and document:

  1. A purpose test: the interest must be actual, lawful, clearly defined, and disclosed;
  2. A necessity test: the chosen processing must be adequate, relevant, suitable, necessary, lawful, and not excessive; and
  3. A balancing test: the employer must weigh its interest against the impact on employees’ rights, reasonable expectations, available safeguards, and less intrusive alternatives.

If sensitive personal information is involved, the employer must instead identify an applicable exception under Section 13 of the Data Privacy Act. Legitimate interest by itself is insufficient.

Necessity and proportionality

Even with a lawful basis, the system must be proportionate. The employer should be able to justify matters such as:

  • Why biometrics are needed instead of a card, PIN, manual daily time record, supervisor certification, or another method;
  • Why the selected biometric—such as facial recognition—is less intrusive or more suitable than alternatives;
  • Whether the device needs to retain a raw image or only a protected template;
  • Why centralized or cloud storage is necessary;
  • Whether continuous location tracking or access monitoring is needed in addition to attendance;
  • Whether attendance logs need to be linked to productivity, disciplinary, or surveillance tools; and
  • Whether the system creates a disproportionate burden on employees whose biometrics cannot be reliably captured.

The NPC Guidelines on Consent state, as a general rule, that personal data should be processed only if the purpose cannot reasonably be fulfilled by less intrusive means. Giving consent does not permit unnecessary or excessive collection.

Meaningful notice before enrollment

Employees must receive a clear privacy notice before their biometric data enters the system or, when legally allowed, at the next practical opportunity. The notice should identify:

  • The exact biometric and other data collected;
  • Whether the device stores a raw image, template, or both;
  • Each purpose of collection and use;
  • The lawful basis when processing is not based on consent;
  • How enrollment, matching, reporting, and correction work;
  • Whether automated processing or profiling is involved;
  • Who may receive or access the data;
  • The biometric-system vendor and the vendor’s role;
  • Whether data is stored locally, in the cloud, or outside the Philippines;
  • The retention period or the rule used to determine it;
  • The employer’s identity and its Data Protection Officer’s contact details; and
  • How employees may exercise their rights or complain.

A signature acknowledging receipt of a privacy notice is not necessarily consent. A privacy notice explains the processing; consent, where used, is a separate legal basis requiring an affirmative and informed choice. The NPC’s Data Subject Rights Advisory states that a privacy notice remains required even when consent is not the basis.

Appropriate security from enrollment to deletion

Under Section 20 of the Data Privacy Act and NPC Circular No. 2023-06 on security of personal data, employers and their service providers must implement reasonable organizational, physical, and technical safeguards.

For a biometric system, this ordinarily calls for controls such as:

  • A privacy impact assessment before or during implementation and updates when the system, purpose, or vendor materially changes;
  • Collection of the minimum necessary biometric data;
  • Restricted, need-to-know access;
  • Strong authentication for administrators;
  • Encryption or comparable protection during storage and transmission where appropriate;
  • Access, modification, export, and deletion logs;
  • Separation of biometric templates from directly identifying employee records where feasible;
  • Testing, vulnerability management, backups, and incident-response procedures;
  • Controls against unauthorized copying, enrollment, re-enrollment, or template substitution;
  • Training and confidentiality obligations for HR, IT, payroll, security personnel, and vendor staff; and
  • Secure deletion from live systems, backups, devices, and vendor systems when retention is no longer justified.

The NPC requires a privacy impact assessment for every processing system involving personal data. The assessment need not routinely be filed with the NPC, but the employer must make it available if required during an investigation or compliance check.

Consent in the employment setting

An employer should not assume that an employee’s signature makes every biometric system lawful.

Under NPC Circular No. 2023-04, consent must be freely given, specific, informed, demonstrated through written, electronic, or recorded means, and tied to declared purposes. Consent is not freely given where pressure, intimidation, threatened adverse consequences, or another inability to exercise free will is present. Silence, failure to object, or mere enrollment cannot automatically be treated as implied consent.

The NPC has also recognized in its 2024 advisory opinion on employee monitoring that consent may be inappropriate in an employment relationship because employees are seldom in a position to freely refuse or revoke it. An employer may rely on another lawful basis when its requirements are actually met, but it must say which basis applies.

If consent is the stated basis, ask what happens if you decline or later withdraw it. A genuine alternative without punishment may support the claim that consent is voluntary. By contrast, “consent or lose your job” raises a serious question about whether the consent is freely given.

Your rights as an employee

Right to be informed

You may ask whether your biometric data is or has been processed and obtain the essential details of the processing. This includes its purposes, lawful basis, method, recipients, retention period, and any automated decision-making.

Right to access

You may request reasonable access to your own data, including:

  • The categories and contents of your personal data;
  • Enrollment and attendance records;
  • Sources of the data;
  • Purposes and manner of processing;
  • Recipients and reasons for disclosure;
  • Dates of access or modification;
  • Retention periods;
  • Information about automated processes that significantly affect you; and
  • The employer’s or DPO’s identity and contact details.

Your right normally covers your own information, not another employee’s biometric or attendance records.

Right to correct errors

You may dispute inaccurate attendance, identity matching, timestamps, or other personal data and request correction. This is especially important if a failed scan, duplicate record, device outage, or mistaken identity affects wages, leave, performance ratings, or discipline.

Request correction in writing before the payroll or disciplinary decision becomes final. Identify the specific entry, explain why it is wrong, and attach supporting evidence such as schedules, gate logs, work output, emails, supervisor confirmations, or system-error screenshots.

Right to object

You may object when processing is based on consent or legitimate interest. Explain the concrete impact—for example, recurring false rejections, an undisclosed new purpose, collection of raw facial images, or an unnecessary transfer to a vendor.

An objection does not automatically stop every employment-related processing. The employer may continue if another lawful basis or compelling reason applies, but it bears the responsibility of identifying and communicating that basis. If your concern can be addressed through a card, PIN, signed daily time record, or supervisor verification, request that alternative expressly.

Right to erasure or blocking

You may request suspension, blocking, removal, or destruction when the data was unlawfully obtained, is inaccurate, is being used for an unauthorized purpose, is no longer necessary, or the employer or vendor violated your data-subject rights.

Deletion is not absolute. The employer may retain necessary records to comply with law, complete a legitimate purpose, establish or defend legal claims, or satisfy a legitimate business need consistent with applicable standards. It should be able to state the particular justification and retention period rather than keeping biometrics indefinitely “just in case.”

Right to damages and to complain

A person who suffers damage from inaccurate, unlawfully obtained, or unauthorized use of personal data may seek indemnity through the processes allowed by law. Liability and the amount of any award depend on evidence and the facts established in the proceeding.

How long may biometric data be retained?

There is no single statutory retention period that applies to every employee biometric attendance system.

The employer must adopt and document a retention policy tied to the declared purpose. Identifiable data may be kept only as long as necessary for that purpose, an applicable legal duty, legitimate business requirements consistent with relevant standards, or the establishment, exercise, or defense of legal claims. It must then be securely deleted, destroyed, or irreversibly anonymized.

Different records may justify different periods. Payroll or attendance reports may need to be retained longer than the underlying biometric template. A former employee’s template should not be kept merely because the employer might find a use for it later. Ask whether deletion covers the attendance device, central database, vendor platform, backups, exports, and disaster-recovery copies.

The vendor does not replace the employer’s responsibility

When a third-party provider operates or hosts the system solely for the employer, the provider will commonly act as a personal information processor and the employer remains the personal information controller. Outsourcing does not transfer the employer’s accountability.

A written contract should restrict the vendor to the employer’s documented instructions, require confidentiality and appropriate security, regulate subcontractors and cross-border transfers, support data-subject requests and breach response, and require return or secure deletion when the service ends.

A vendor should not independently use employee fingerprints, face images, or templates to improve unrelated products, train artificial-intelligence models, build an identity database, market services, or serve other customers unless that separate processing has its own lawful basis and complies with transparency and other Data Privacy Act requirements. A vendor processing data for its own purposes may itself become a personal information controller.

Practical steps if you are concerned

1. Ask for the written documents

Request the biometric attendance policy, employee privacy notice, retention policy, and DPO contact details. If the system is already active, ask when and how the notice was issued.

2. Ask precise technical and legal questions

Useful questions include:

  • What biometric data is captured?
  • Is the original fingerprint or facial image retained?
  • Can the stored template be exported or reused on another system?
  • What is the exact lawful basis?
  • Why is biometrics necessary instead of a less intrusive method?
  • Who can access or modify the records?
  • Which vendor, cloud provider, or subcontractor receives the data?
  • Is any data stored outside the Philippines?
  • How long are templates and attendance logs kept?
  • What happens after resignation or vendor termination?
  • Is attendance data the sole basis for payroll or discipline?
  • How are device failures and false matches reviewed?
  • What alternative is available if enrollment or matching fails?

3. Make a written data-subject request

Address the request to HR and the DPO. State which right you are exercising, identify the data or entries involved, explain the requested action, and keep proof of delivery.

Under NPC Advisory No. 2021-01, a private-sector controller should act without undue delay and generally within 30 working days after receiving the request and necessary supporting documents. A complex or numerous request may be extended by up to 15 additional working days, provided the employee is notified of the reason. Different service-delivery rules may apply to government agencies.

4. Preserve evidence

Keep copies of:

  • Privacy notices, consent forms, policies, and enrollment instructions;
  • Emails, chat messages, memoranda, and acknowledgment receipts;
  • Screenshots or photographs of system errors and device notices;
  • Attendance reports, work schedules, payslips, leave records, and payroll adjustments;
  • Your written objection, access request, or correction request;
  • HR or DPO responses;
  • Names of witnesses to failed scans or disputed attendance;
  • Announcements about new vendors, purposes, or system features; and
  • Any breach alert or evidence that records were exposed or circulated.

Preserve originals and record dates. Avoid taking or distributing other employees’ personal data unnecessarily.

5. Escalate through the proper channel

For a privacy violation, write first to the employer, its DPO, or the concerned vendor and allow an opportunity to address the matter. Under the NPC Rules of Procedure, as amended, a complaint ordinarily requires proof that:

  1. You informed the respondent in writing; and
  2. It failed to take timely or appropriate action, or did not respond within 15 calendar days of receiving your written notice.

The NPC may waive these conditions for good cause or a serious violation, including grave and irreparable harm, lack of a plain and adequate remedy, or patently illegal action.

A formal NPC complaint must comply with the required form, verification, supporting evidence, correspondence, and certification against forum shopping. It may be filed personally, by registered mail, by accredited courier, or through electronic mail when authorized by the Commission. Appropriate filing fees apply unless an exemption or waiver is available. Check the NPC’s current complaint mechanics and forms before filing.

If the dispute also involves unpaid wages, deductions, suspension, dismissal, discrimination, or retaliation, privacy proceedings may not resolve the labor issue. A worker may seek assistance through the DOLE Assistance for Request Management System or an appropriate Single Entry Assistance Desk. SEnA provides a mandatory 30-day conciliation-mediation period for covered labor disputes before further proceedings, subject to applicable exceptions.

When help is urgent

Seek prompt advice from the DPO, a labor lawyer, a data-privacy lawyer, your union, DOLE, or the NPC when:

  • A fingerprint, facial-image, or biometric-template database may have been stolen, posted, emailed to unauthorized persons, or left publicly accessible;
  • An attendance error is about to cause a wage deduction, suspension, dismissal, or loss of benefits;
  • The system repeatedly rejects you and no manual correction process is offered;
  • You are ordered to sign a blanket consent form under threat of immediate punishment;
  • Biometric data is being used for an undisclosed purpose, such as continuous surveillance, profiling, AI training, or sharing with another company;
  • The employer refuses to identify its DPO, vendor, purpose, lawful basis, or retention period;
  • You face retaliation after making a privacy request or reporting a suspected breach; or
  • Continued processing presents a risk of grave and irreparable harm.

For a disputed payroll or disciplinary decision, immediately request preservation of the system logs and a human review. Do not wait until relevant records are routinely overwritten.

If biometric data is breached

Not every security incident triggers mandatory notice, but the employer must assess the incident under the Data Privacy Act and NPC Circular No. 16-03 on personal data breach management.

Notification to the NPC and affected employees is generally required within 72 hours after knowledge or reasonable belief of a notifiable breach when protected information has likely been acquired by an unauthorized person and the incident is likely to create a real risk of serious harm. Biometric data is expressly treated in the breach rules as information that may enable identity fraud. The applicable rule depends on what was accessed, whether the data was intelligible or usable, who obtained it, and the likely harm.

A request for postponement, exemption, or alternative notification does not automatically excuse compliance. NPC Advisory No. 2026-02 clarifies the current submission requirements for personal information controllers.

If notified, follow the employer’s protective instructions, watch for identity or account irregularities, and preserve the notice. Unlike a password, a fingerprint or face cannot simply be replaced, so unauthorized exposure warrants careful investigation even when no misuse has yet been proven.

Common mistakes to avoid

  • Assuming that all workplace monitoring is lawful because the device belongs to the company;
  • Assuming that biometric attendance is prohibited simply because an employee did not consent;
  • Signing without reading the purpose, vendor, retention, and sharing terms;
  • Treating a privacy notice as proof of valid consent;
  • Making only a verbal objection and keeping no proof;
  • Demanding deletion without addressing lawful payroll, recordkeeping, or litigation-retention needs;
  • Ignoring inaccurate attendance until after payroll or discipline is finalized;
  • Secretly taking other employees’ records to support a personal complaint;
  • Filing directly with the NPC without first documenting written notice to the employer, unless circumstances justify waiver; or
  • Treating an NPC privacy complaint as a substitute for a labor remedy involving wages, discipline, or dismissal.

Frequently asked questions

Can my employer require fingerprint or facial attendance?

Possibly. There is no blanket prohibition, but the employer must establish a lawful basis, necessity, proportionality, transparency, security, and appropriate retention. The legality depends on how the particular system operates, not merely on the label “attendance system.”

Can I refuse to enroll?

You may object and request an alternative, but refusal is not an automatic legal entitlement in every workplace. Ask the employer to state its lawful basis and why a less intrusive option cannot meet the purpose. Before refusing a direct instruction, obtain advice about the privacy policy, employment contract, collective bargaining agreement, accommodation needs, and possible labor consequences.

Must the employer obtain my consent?

Not always. Consent is only one possible lawful basis. If the employer relies on contract, legal obligation, or legitimate interest, it must meet the requirements of that basis and disclose it. If it relies on consent, the consent must be genuinely voluntary, specific, informed, and recorded.

Must the employer offer a manual or card-based alternative?

Philippine privacy law does not create a universal rule requiring an alternative in every biometric-attendance program. However, the availability of less intrusive methods is directly relevant to necessity and proportionality. An alternative may be particularly important where the system cannot reliably enroll an employee, an injury or disability affects scanning, or a documented objection requires individualized assessment.

May the device keep my full fingerprint or face photograph?

Only if retaining it is necessary and proportionate to the declared purpose and properly secured. An employer should assess whether a protected template can accomplish verification without retaining a reusable raw image. A template is still personal information if it remains linkable to you.

Can biometric logs be used for payroll or discipline?

They may be relevant evidence, but system results are not necessarily infallible. You may challenge false matches, missed scans, altered timestamps, device failures, or incorrect employee mapping and request correction and human review. Any disciplinary action must also comply with applicable labor-law requirements and workplace procedures.

Can the employer keep my biometrics after I resign?

Only for as long as a specific lawful need remains. The employer should distinguish the biometric template from payroll or attendance reports that may have separate retention justifications. Indefinite retention for an unspecified future use is inconsistent with the Data Privacy Act.

Can I ask who accessed my attendance record?

Yes. The right of access includes information about recipients and the date when personal data was last accessed or modified, subject to lawful limitations and the rights of other persons.

Can the vendor reuse my biometrics?

Not merely because it operates the attendance platform. A processor should act only under the employer’s lawful instructions. Use for the vendor’s independent product development, identity database, marketing, or AI training requires separate legal justification and compliance.

What if I previously signed a consent form?

A signature does not validate unlawful, excessive, misleading, or insecure processing. You may ask for a copy, identify the purposes covered, and determine whether consent was freely given. Consent may generally be withdrawn, but withdrawal does not necessarily stop processing supported by another lawful basis.

Where should I complain?

Start with the employer’s DPO or designated privacy contact and retain proof. If the response is absent or inadequate after the applicable 15-calendar-day period, consider an NPC complaint. Use DOLE, SEnA, the NLRC, a grievance mechanism, or voluntary arbitration as appropriate for employment consequences such as wage deductions, discipline, or dismissal.

Official sources

This article provides general legal information, not advice for a particular employee, employer, or dispute. Outcomes depend on the documents, system design, employment rules, and evidence. Official sources and procedures were checked as of 4 August 2026.

Disclaimer: This content is not legal advice and may involve AI assistance. Information may be inaccurate.