A privacy-first checklist for attendance devices
Biometric and RFID attendance can save time, but the rollout creates new identity, device and retention decisions. Schools should settle those decisions before enrolling the first student.
Attendance devices sit at the boundary between physical presence and the digital student record. That makes them useful and sensitive. A procurement form that asks only about accuracy, price and warranty misses the data lifecycle.
Map what is collected, where matching occurs, which identifiers travel, who can access templates or event logs, how long they remain and how a person uses the service when the primary method fails.
Attendance-device data lifecycle
Privacy decisions exist at enrolment, capture, matching, transfer, retention and deletion.
Minimise the identity payload
A reader usually does not need the full student profile. Use a scoped identifier that the attendance system can resolve through a controlled service. Avoid copying names, contact details and academic data to every device.
For biometrics, document whether the system stores images or mathematical templates, where matching occurs and whether the vendor can use data for another purpose. The answers affect risk and contract terms.
Make retention an automatic rule
Raw capture data, biometric templates, device logs and official attendance events may need different retention periods. Define each one and implement expiry rather than relying on occasional manual cleanup.
Deletion must cover devices, central services, backups and vendor systems according to the agreed policy. Keep enough evidence to prove the action without retaining the sensitive data itself.
Provide a dignified alternative
A learner or staff member may be unable to use a biometric method, may forget a card or may be caught by a device failure. The alternative should be accessible, quick and non-stigmatising.
Manual correction needs the same controls as automated capture: a named actor, reason, timestamp and link to the original exception.
Questions to settle before configuration.
- Map every data element and destination.
- Document the legal and institutional basis for collection.
- Minimise what devices store.
- Separate template, log and attendance-event retention.
- Restrict vendor secondary use in contract terms.
- Provide an accessible alternative and controlled correction path.
- Test device loss, breach, outage and cohort offboarding.
Sources behind this field guide
These links explain the standards, regulations or evidence referenced above. Product choices should still be tested against your institution's own policy and jurisdiction.
- FERPA regulationsDefinitions include biometric records and set requirements for education-record handling.
- NIST Privacy FrameworkA voluntary tool for identifying and managing privacy risk.
- NIST facial recognition implementation frameworkPrivacy, proportionality and human-rights considerations for live facial recognition.
