Straight answer: Indian employers have long been required to maintain attendance and wage registers under labour legislation, and since 2023 the biometric data many use to generate those registers is separately regulated under the DPDP Act. Two obligations, two different logics — one says keep records, the other says do not keep biometrics longer than you need.
This is a practical summary, not legal advice, and the details genuinely vary by state and by which statute covers your establishment. Verify specifics with your compliance advisor before acting.
Obligation one: keep the register
Maintaining attendance and wage registers is standard requirement under Indian labour legislation — the Factories Act for factories, the relevant state shops and establishments legislation for commercial establishments, and equivalents for contract labour and construction. The labour codes consolidate much of this.
Three things follow that matter operationally:
Registers must be produced on demand. Inspections happen. A system that cannot export a clean register per employee per month is a compliance risk regardless of how sophisticated it looks.
Contract labour usually counts. Where you engage contract workers, obligations attach to the principal employer as well as the contractor in many situations. Whether contract labour appears in your attendance system is therefore a compliance question, not just an operational one.
State rules differ. Register formats, overtime limits and retention periods are not uniform across India. A Punjab factory and a Karnataka office do not necessarily face identical requirements.
Obligation two: the DPDP Act, and why it pulls the other way
A face image or fingerprint template is personal data under the Digital Personal Data Protection Act, 2023. If you run biometric attendance, you are processing personal data as an employer, and the core duties are straightforward in principle:
Notice. Tell employees what is collected, why, and how long it will be held. A short written notice at rollout, in a language people actually read.
Purpose limitation. Data collected for attendance is for attendance. Repurposing it for something else needs its own basis.
Storage limitation. Do not keep biometric templates longer than the purpose requires. When someone leaves, their template should go.
Security. Reasonable safeguards, and a plan for what happens if there is a breach.
Children. Stricter obligations apply, including verifiable parental consent — which is exactly why student-facing biometric attendance in schools deserves far more caution than vendors typically suggest.
The tension worth understanding
Labour law says keep the attendance record. Data protection law says do not keep the biometric longer than needed.
These are not in conflict once you separate the two things. The attendance record — who was present, when, for how many hours — is a business record you retain per statutory requirement. The biometric template that produced it is a means to an end, and should be purged when the employment relationship ends.
Systems that conflate them, storing raw biometric data indefinitely as part of the attendance archive, create exposure with no compliance benefit.
A five-line checklist
- A written employee notice covering collection, purpose and retention, issued at rollout.
- Clarity on which statute and state rules govern your establishment's registers.
- Contract labour included in the attendance record where obligations attach.
- Biometric templates deleted on exit, separately from the retained attendance register.
- A clean per-employee register export you can produce during an inspection.
Get those five in place and the compliance question stops being the reason to delay a decision.