
This page is for HR, admin and facilities heads and the teams funding a credential rollout in 2026. It is general information for procurement planning, not legal advice — employers should confirm their obligations with their own counsel.
What changed in November 2025, and why do two dates matter?
Two instruments landed eight days apart. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 under Gazette reference G.S.R. 846(E), starting an 18-month runway with full compliance due 13 May 2027. On 21 November 2025, India's four Labour Codes came into force. Read together, they create a specific problem for attendance.
The Labour Codes — the Code on Wages 2019, the Industrial Relations Code 2020, the Code on Social Security 2020 and the Occupational Safety, Health and Working Conditions Code 2020 — require you to maintain registers, and all four permit those registers to be kept digitally. The DPDP framework regulates the identifier you use to generate them. You now have a record-keeping duty on one side and a regulated collection method on the other, meeting at the same device on the wall.
Put one interim milestone in the plan: the Consent Manager framework becomes operational on 13 November 2026, six months before the compliance date. And the reason boards are paying attention is the ceiling — penalties under the DPDP Act run up to Rs 250 crore per violation or breach incident.
Is biometric attendance still legal in India in 2026?
Yes. Biometric attendance is legal in India and the DPDP Rules, 2025 did not ban it. Nothing in the framework tells an employer to stop using fingerprint, face or iris readers. What it does is attach the highest compliance obligations to that data and give the individual a right you must honour operationally. Be precise: much of what circulates online overstates the case. The defensible chain has three links, and it is narrower than the claim that "the Rules require employers to offer RFID".
- (a) Biometric templates are the highest-liability data class an employer can hold under the DPDP framework — explicit, informed, purpose-specific consent, purpose clearly communicated, encrypted storage rather than raw images.
- (b) Because consent can be refused or withdrawn, and the employer cannot compel the individual or deny them the service, a working non-biometric fallback is effectively required.
- (c) A card, wristband or fob UID is a revocable, reissuable identifier that is not biometric data, so both the consent burden and the breach exposure collapse.
That is the whole case, and it does not survive exaggeration. Where consent is withdrawn or refused, a reasonable alternative must be provided, and published compliance guidance names an RFID card or manual sign-in as that alternative. Treat that as commentary rather than text lifted from G.S.R. 846(E) — no rule numbers are quoted here, and your policy note should not quote any without pulling the gazette text first.
What do the DPDP Rules change for biometric attendance data?
Biometric data — fingerprint, face, iris — carries the highest compliance obligations in the framework. For an attendance deployment that becomes duties you must be able to evidence, not merely assert.
- Consent must be explicit, informed and purpose-specific. A line buried in the appointment letter is not a consent record you can produce later.
- The purpose must be clearly communicated — for example, attendance only. If the same template later drives canteen entitlement and a productivity dashboard, that is a different purpose.
- Templates must be stored encrypted, not as raw images. Ask your biometric vendor in writing what sits on the device, what sits in the database, and in what form.
- Refusal and withdrawal must be handled without penalty. The individual cannot be compelled or denied the service for saying no, so the answer cannot be an argument with a supervisor.
- Retention has to be deliberate. When someone leaves, the template should not sit in a reader at a side gate for years because nobody owns deletion.
What attendance records do the Labour Codes require you to keep?
Wage registers, attendance muster rolls, overtime records and leave registers are mandatory under the Labour Codes and must be retained for at least three years. All four Codes permit these registers to be maintained digitally — so a paper fallback is a weak answer to a refusal.
This is what quietly breaks the "we'll just have them sign a sheet" plan. If an employee declines biometric enrolment and your fallback is a register at the security desk, you maintain two parallel attendance truths — a digital muster roll for most staff, signed sheets for the rest — reconciled by hand at every audit, overtime dispute or wage claim. One system with two credential types avoids that; our guide to RFID attendance management in India covers the architecture.
What actually happens when an employee refuses to give a fingerprint?
Consent can be refused at enrolment or withdrawn later, and the employer cannot compel the individual or deny them the service. The gap most Indian employers have is operational, not legal: no second credential is wired into the same attendance system, so one refusal becomes a manual exception living outside the digital register.
Walk the sequence through your own site. An employee withdraws consent and HR accepts it. Which device do they punch on the next morning? Who tells payroll their hours now come from elsewhere? Who deletes the template from every reader it was pushed to, and what proves it was deleted? In most organisations the honest answer to at least two of those is "nobody has decided yet".
The fix is cheap and boring in 2026, expensive and rushed in 2027. Issue every employee a card at joining, whether or not they also enrol biometrically. The card becomes the baseline credential; biometrics, where consented, sit on top as a second factor at high-value doors. A refusal then flips one flag on one record instead of changing the plumbing.
Why is a card UID a different liability from a fingerprint template?
Revocability. A compromised fingerprint template cannot be reissued — the employee has ten fingers and one face for life. A compromised card is voided in the reader database and reprinted the same morning. Say it once and let it carry the business case: you cannot reissue a fingerprint, and you can reissue a card before lunch. That puts the two credentials in completely different risk tiers.
| Dimension | Fingerprint or face template | RFID card, wristband or fob |
|---|---|---|
| Data class | Biometric — highest compliance obligations in the framework | A number linked to an employee record; not biometric data |
| Consent burden | Explicit, informed, purpose-specific; purpose must be communicated | Ordinary employment-record handling |
| If compromised | Cannot be reissued; exposure is permanent | Void it and print a replacement the same day |
| If consent is withdrawn | Template removed; the person needs another way to punch in | Nothing to withdraw; the credential keeps working |
"But cards get shared" — how do you stop buddy-punching?
This is the strongest argument the biometric vendors have, and it is fair: a card can be lent, shared or swiped by a colleague. Pretending otherwise loses the argument in the room. The honest answer is that buddy-punching is a solved problem — solved with layers at the door, not with the credential alone.
- Photo ID cards. A printed photograph and name turns a lent card into something a supervisor or guard spots immediately.
- Anti-passback. The reader refuses a second entry read from a credential that never registered an exit. One card cannot walk in twice.
- Card plus PIN. At sensitive doors, pair the credential with a keypad. Sharing the card now means sharing a secret too.
- Random supervisor verification against the live in-building list. Unpredictable spot checks change behaviour.
- Exception reporting on impossible sequences. Two reads from one credential at distant doors inside a window no human could walk — flag it, then investigate.
- CCTV paired with card reads. Timestamp-matched footage turns a disputed punch into a short review.
Layered like that, a card system is more than adequate for attendance and wage records while keeping the highest-risk data class out of your database — and where you want a biometric second factor, you can still have one.
Which credential should you choose — LF, HF/MIFARE or UHF?
HF/MIFARE at 13.56 MHz is the more common choice for door-level attendance in India. UHF at 865-867 MHz suits hands-free gates and long-range plant entry. LF at 125 kHz is legacy — specify it only to match readers you already own.
| Band | Best fit for attendance | Read style | Notes for Indian sites |
|---|---|---|---|
| LF 125 kHz | Legacy door readers already installed | Present at the reader | Robust, limited security options. Match existing hardware; avoid for new builds. |
| HF / NFC 13.56 MHz (MIFARE) | Office and factory doors, canteen, lockers, visitor passes | Tap | The workhorse. Supports secure-sector credentials and key diversification. |
| UHF 865-867 MHz | Gates, turnstiles, hands-free flow at shift change | Walk past without stopping | Excellent throughput. Needs read-zone design so you do not capture passers-by. |
On the India band: UHF RFID operates at 865-867 MHz, licence-free within WPC-notified limits. The 2021 SRD exemption rules, published 10 December 2021, set out interrogator channels at 865.7, 866.3, 866.9 and 867.5 MHz, 200 kHz each, up to 2 W e.r.p.; the exemption list was revised on 18 January 2024. That matters mainly at gates — at the door, 13.56 MHz HF/MIFARE is usually the better choice. For the full comparison see our UHF vs HF vs LF vs NFC frequency guide and the RFID cards buyer guide for India. India RFID Store stocks all three bands as RFID cards, so you can trial two credential types at one site before standardising.
Can an RFID card be cloned, and how do you prevent it?
Yes. A plain, low-security card that presents only an open UID can be copied with inexpensive equipment. That is a real risk, and any supplier who denies it is not worth buying from. It is also solved engineering: stop treating the UID as the secret and move to secure, key-based credentials.
- Encrypted or secure-sector credentials so the reader authenticates the card rather than reading a number off it.
- Key diversification — a per-card derived key, so one compromised card does not compromise the estate.
- Reader-side validation against your employee database, instead of blind acceptance of any well-formed number.
- Anti-passback and door rules that make a cloned credential behave visibly abnormally.
- Instant blacklisting of a lost or suspect card — precisely the control a biometric template can never offer.
Our write-up on RFID data security, cloning and encryption in India walks the attack surface honestly, including what encryption does and does not buy you.
How do you run both credentials in one system, and what should you budget?
One attendance system, two credentials, one muster roll. The employee record holds a credential-type flag and a consent status; the reader layer accepts either a biometric match or a card read; both produce identical punch events. Specify this at procurement, not during rollout.
- Mixed readers: wall-mount card readers at general doors, combination biometric-plus-card units where you want a second factor, a desktop enrolment reader in HR for issuing and voiding credentials, and an access-control panel treating both credential types as equal inputs.
- Consent status as a first-class field with timestamp and audit trail, so a withdrawal is a routine HR action, not an IT ticket.
- Export into the digital wage register, muster roll, overtime and leave records, with three-year retention configured and tested.
- Form factor by population: cards for office staff, RFID wristbands for shop floor, hospitals and sites where a pocket card is impractical, key fobs for drivers and contractors.
- In-house issuance with an RFID card printer, so a lost card is reprinted with a photo the same morning instead of waiting on a vendor batch.
Budget four line items rather than one: credentials, readers, door hardware and integration. Credentials are typically the smallest line and fall further with volume; readers, panels and door hardware are the larger capital spend; integration into payroll and the statutory registers is the line most often under-scoped.
What is your 2026 readiness checklist?
Work backwards from 13 May 2027 and you still have comfortable runway, with 13 November 2026 as a mid-point checkpoint.
- Inventory every biometric device on every site: what each stores, where, and in what form.
- Confirm in writing with your biometric vendor that templates are held encrypted and not stored as raw images.
- Rewrite the attendance consent notice so the purpose is explicit, informed and purpose-specific — attendance only, in a language your workforce reads.
- Write the refusal and withdrawal procedure before anyone needs it: who accepts it, what changes on the record, who deletes the template, what evidence is kept.
- Standardise the fallback credential — HF/MIFARE for doors, UHF for hands-free gates, LF only to match legacy readers.
- Issue a photo ID card to every employee, including those who did consent, and keep reprint capability in-house.
- Enable anti-passback and impossible-sequence exception reporting at the doors that matter.
- Verify that card and biometric punches produce identical muster roll rows, with three years of history retrievable on demand.
- Pilot at one site during 2026 rather than attempting a big-bang rollout in 2027.
Two cautions. This article is general information for procurement planning, not legal advice — confirm your obligations with counsel, and read the gazette text of G.S.R. 846(E) before citing any clause internally. And rules change: verify the current position on DPDP compliance, WPC frequency limits and Labour Code register formats with the official sources before finalising a specification or timeline.
Planning your fallback? Talk to an Indian manufacturer rather than a reseller. Identium Tech Solutions has built RFID hardware in India since 2015 — BIS and WPC certified, in-house manufacturing, bulk card personalisation with photo ID, pan-India shipping. Send your site count and headcount, and India RFID Store will put a card-based attendance fallback specification and samples in front of you before you commit budget.
Frequently asked questions
Is biometric attendance legal in India?
Yes. Biometric attendance is legal in India and was not banned by the Digital Personal Data Protection Rules, 2025. The framework attaches the highest compliance obligations to biometric data — explicit, informed, purpose-specific consent and encrypted templates rather than raw images — but does not prohibit it for attendance.
Do I have to offer an alternative to biometric attendance?
Where consent is refused or withdrawn, the employer cannot compel the individual or deny them the service, so a reasonable alternative has to be available. Published compliance guidance names an RFID card or manual sign-in as that alternative. That is not a rule to buy RFID, but you do need a working non-biometric option inside your digital register.
Is an RFID card UID personal data?
A card UID is not biometric data, though once linked to a named employee it sits inside an employment record and deserves the same care as any identifier. The difference that matters is revocability: the consent burden and breach exposure are far smaller than for a fingerprint template.
How long must I keep attendance records in India?
Wage registers, attendance muster rolls, overtime records and leave registers are mandatory under the Labour Codes and must be retained for at least three years. All four Codes permit digital registers, so a paper fallback for objectors creates a reconciliation problem rather than solving one.
What happens on 13 November 2026 and 13 May 2027?
The Consent Manager framework becomes operational on 13 November 2026, and full compliance with the Digital Personal Data Protection Rules, 2025 is due on 13 May 2027 — the end of the 18-month runway that began at notification on 13 November 2025. Penalties under the DPDP Act run up to Rs 250 crore per violation or breach incident.
Can we use RFID wristbands or fobs instead of cards?
Yes. Wristbands suit shop floors, hospitals and sites where a card is impractical or gets damaged; fobs suit drivers and contractors. All three are the same class of revocable credential, so choose by environment and keep the reader and software layer common.
Leave a Comment