What the law requires
- Free, specific, informed and unambiguous consent, preceded by a clear notice — available in English or any language in the Eighth Schedule.
- Purpose limitation and data minimisation: process only what the stated purpose needs, and delete data once the purpose is served or consent is withdrawn.
- Reasonable security safeguards, and breach notification to the Data Protection Board and affected individuals.
- Data-subject rights: access, correction, erasure and a grievance channel; Significant Data Fiduciaries face extra duties (DPO, audits, impact assessments).
- Employment exemptions are narrow — biometric attendance normally still runs on consent.
How NCheck supports it
- On-premises or in-country deployment keeps biometric data inside India.
- Encrypted, non-reversible templates — raw images are not retained.
- Consent capture at enrolment, with RFID, barcode or manual check-in as an alternative.
- Retention limits, deletion tools and an audit trail for erasure requests.
Practical checklist
- Publish a notice in the languages your workforce uses.
- Record consent at enrolment (use our free template).
- Name a grievance contact — and check whether you qualify as a Significant Data Fiduciary.
- Define retention and deletion for leavers.
- Prepare a breach-response plan naming the Board notification path.
Free templates: Download the free consent-form and retention-policy templates →
This page is general information, not legal advice. Laws change — confirm current requirements with your counsel.
Where this matters most
See how NCheck handles attendance in the sectors where these rules bite hardest: Manufacturing · Construction · Retail · Education · all industries.
Deploy it the compliant way
Run NCheck fully on your own server — data never leaves your network — or in our EU-hosted cloud. Either way, only encrypted templates are stored, never raw images. About on-premises → · Security & compliance →