The first question in most conversations about biometric timeclocks is not about speed or accuracy. It is about the data, and the consideration is justified. A payroll number can be reissued. A badge can be replaced. But a fingerprint? It’s a permanent link to a person’s identity.
So it stands to reason that both employers and the employees that are asked to present one at the start of every shift want to know what is being kept, where it goes and who is able to reach it.
It’s not the same answer for every timeclock manufacturer, and it begins with a distinction that is not widely understood: what the device stores is not what it captured.
What The Timeclock Captures
Our biometric timeclocks, like the GT8 or GT4, do not store a photograph of a face or an image of a fingerprint. At the point of capture, the device identifies a set of key points – on a face, features such as the eyes, the bridge of the nose and the corners of the mouth – and records their positions as XYZ coordinates, like a map. Those coordinates are converted into binary, so what is saved to storage is a string of ones and zeros. This code, when inspected on its own, carries no visual meaning.
But for users, it’s the outcome that matters more than the process. This ‘template’ cannot be used to reproduce a usable image of the person it came from. It is not a photograph held under lock, and there is no stored library of faces and fingerprints on the terminal or in the software behind it.
“We don’t actually retain the original biometrics. We convert it, either a finger or a face, into a binary template. The key point is you can’t re-engineer your face. So even if someone’s got access to that template, they can’t turn it into someone’s face.”
Paul Smith, Head of Compliance, Grosvenor Technology
Both fingerprint and facial recognition is available on the GT8 and GT10, while the GT4 uses a fingerprint reader. The template principle is the same in each case.
Protection On The Device
Template files are encrypted where they sit, on the terminal as well as in the cloud, and access is limited to enabled accounts.
It’s questions about physical access to the clock that we hear most often. Attacking a GT8 or GT10 directly would require someone to remove it from the wall and connect specialist equipment to it. They would then be met with an encrypted file system, secure boot, which prevents an unauthorised device from being started at all, and a hardware-backed keystore holding the encryption keys. Data is encrypted again as it moves to the cloud platform, and once more at rest when it arrives.
Enrolment Happens With The Employee, Not To Them
A timeclock cannot capture the face of someone who walks past it. The employee must already exist in the HR system, so biometric data is added to a profile created when they joined the company rather than creating a record of its own. Anyone not enrolled in that system, a visitor, a contractor, a member of the public, is simply not recognised.
They must also act. Enrolment requires the employee to interact with the terminal directly and confirm on screen that they agree to the conditions displayed. Nothing is captured passively. The same design makes movement between sites straightforward: if someone transfers, their template can be distributed to the terminal at the new location without re-enrolment and without a second copy being created.
Retention, Deletion and Subject Access
When someone leaves a business, the employer notifies Grosvenor Technology and the template is removed from the terminals and from the database. It remains within backup for continuity purposes but is not accessible from that point. Most of this happens automatically: the HR platform records a leaving date, the synchronisation runs, and the registration is removed without anyone raising a request.
A retention policy governs everything that remains, on the principle that data is not held longer than there is reason to hold it. Employees can also approach us directly. A data subject access request (DSAR) may ask for data to be corrected, for processing to stop, or for a record to be deleted. Each is verified with the employer, then acted on. These are legal obligations rather than discretionary services.
Who Verifies Data Security Claims?
Claims about security are worth very little without someone independent testing them. Grosvenor Technology terminals are tested by an independent laboratory to confirm the cybersecurity features are present and working. Separately, an external firm is paid once a year to attack the infrastructure and attempt to get in, looking both for the unglamorous failures, patching left undone, default passwords still in place, and for any weakness that could be exploited to reach data.
“Our devices are tested by an independent laboratory to confirm we’ve got the cybersecurity features in place. We also pay an external company to try and attack us to see if they can penetrate our defences. That has to be done yearly and it’s all part of the requirements.”
Paul Smith, Head of Compliance, Grosvenor Technology
CE and UKCA marking covers the devices themselves, including obligations under the Radio Equipment Directive. Grosvenor Technology holds ISO 27001 along with SOC 1 and SOC 2. These are audited regularly rather than awarded once, and they cover a great deal more than biometrics: what they describe is the overall risk position of the business.
The Regulatory Position
The design starting point is compliance with UK and EU data protection law, adapted where other jurisdictions require it rather than approached separately. It is the more demanding baseline, and building to it first means the US position becomes a matter of adaptation rather than redesign for our clocks deployed in North America. State legislation there follows similar principles with local variations, most visibly in Illinois, where the Biometric Information Privacy Act (BIPA) sets a demanding standard and has generated substantial litigation. What matters most is consistent across both regimes: was the use of biometrics explained clearly, was consent obtained properly, and can both be demonstrated afterwards.
Why The Security Case Comes First
The argument for biometrics is that it is quick. An employee walks up to a GT8, is identified in under a second, confirms and moves on. A badge or a fob is slower and can be lost, shared or forgotten. But that case is only available once the security case has been made. Employees are entitled to decline biometric identification, and organisations are entitled to ask hard questions before deploying it. The controls described here exist so that those questions have answers.
“There’s so much time and effort goes into being compliant with the regulations, and they’re not simple to achieve. There are years of work gone into making sure our processes and systems are robust and secure.”
Paul Smith, Head of Compliance, Grosvenor Technology
Find out more
To discuss biometric timeclocks and how they would work in your organisation, contact our team on 01202 621700 or at hcmsales@grosvenortechnology.com.
This article is provided for general information only and does not constitute legal advice. Organisations deploying biometric technology should take their own advice on their obligations under applicable data protection and biometric privacy legislation.