Fingerprint and facial clocking: read the Serco notice first
Biometric clocking is sold as the answer to buddy punching. In February 2024 the Information Commissioner ordered an employer to switch it off and destroy the data. Here is what that decision actually says.
What happened
On 19 February 2024 the ICO issued an enforcement notice to Serco Leisure Operating Limited and associated trusts, as joint controllers. Facial recognition was in use at 38 leisure facilities, with fingerprint scanning at two more, for staff attendance, since 2017. It affected 2,283 people. The ICO found contraventions of Articles 5(1)(a), 6 and 9 of the UK GDPR, ordered the processing to stop within three months, and ordered the biometric data destroyed — including instructing the software supplier to delete what it held.
The reasoning, which is the part that matters to you
- Necessity fails. The notice says processing biometric data cannot be considered necessary to verify attendance when less intrusive means are available, and names them: RFID cards or fobs, and manual sign-in sheets.
- Legitimate interests fail too, for the same reason, plus the substantial privacy impact and the fact that staff were not clearly told how to object or what the alternative was.
- Consent is fragile at work. The ICO pointed to the imbalance of power between employer and employee, and to a standard operating procedure telling staff that refusal might escalate to disciplinary action.
- "The law requires us to keep records" does not carry it. Serco cited the Working Time Regulations. The ICO answered that the Article 9(2)(b) condition does not cover purely contractual employment obligations, that the legal basis had not been identified when the processing began, and that no appropriate policy document existed as Schedule 1 of the Data Protection Act 2018 requires.
Read the last point twice. The duty is to keep adequate records — not biometric ones. Citing the record-keeping duty is what made the necessity argument collapse, because a card would have satisfied the same duty.
If you still want biometrics
It is not banned, and we are not going to tell you it is. On the ICO’s own reasoning you would need, at minimum: a lawful basis under Article 6 and a separate Article 9 condition; a data protection impact assessment completed before deployment, not after; an appropriate policy document if you rely on Schedule 1; a real, proactively offered, detriment-free alternative for anyone who objects; and evidence that the alternative genuinely would not work. Serco had a real problem with the old system and still lost, because it had not tried discipline against the few people abusing it.
Why we use PIN and card
We do not offer fingerprint or facial clocking. It is a product decision, and this is the reasoning:
- A card is as quick as a finger and works when the internet does not.
- No special category data means no Article 9 condition to find and no impact assessment to defend.
- A lost card is reissued in a minute. A compromised fingerprint is for life.
- If the rules tighten again, there is nothing on our customers’ systems to switch off and destroy.
Against buddy punching, the honest answer is that a card is not perfect either — it can be handed over. What a card does give you is the device and the exact time of every punch, which is enough to spot a pattern. How the terminal works.
Questions we get
Is fingerprint clocking illegal in the UK?
Not illegal as such, but it is treated as special category data, and the ICO has already ordered an employer to stop. You would need both a lawful basis under Article 6 and a separate condition under Article 9, a data protection impact assessment before you start, and a genuine alternative for anyone who objects. In the Serco case the ICO found none of that was in place.
What exactly did the ICO decide?
In February 2024 it issued an enforcement notice to Serco Leisure over facial recognition and fingerprint scanning used for attendance at 38 sites, affecting 2,283 staff. It found breaches of Articles 5(1)(a), 6 and 9 of the UK GDPR and ordered the processing to stop and the biometric data to be destroyed. Its central reasoning: biometric data cannot be "necessary" to check attendance when cards, fobs or a sign-in sheet would do.
Can we just ask staff to consent?
The ICO addressed that directly and was sceptical. It pointed to the imbalance of power between employer and employee, and to Serco’s own procedure, which said staff were expected to use the system and that refusal might escalate to disciplinary action. Consent that carries a consequence is not freely given.
What do you use instead?
A PIN or a physical card. A card is as fast as a finger at the door, works with no connection, and collects no biometric data at all — so there is no special category condition to find, no impact assessment to defend and nothing to destroy if the rules change.
Sources, retrieved 23 September 2026: ICO enforcement notice to Serco Leisure Operating Limited, 19 February 2024, issued under section 149 of the Data Protection Act 2018 (ico.org.uk); ICO guidance on biometric recognition; UK GDPR Articles 5, 6 and 9; Data Protection Act 2018 Schedule 1.
Free for up to 3 employees, forever
Thirty days with everything included, AI assistant and all, no card and no automatic renewal. When the trial ends, companies with up to 3 employees simply keep working for free. And within the first 60 days you get your money back if it does not fit.
Questions? Write to time@irot.com. We answer on working days, usually by the next one.