Do Employees Have a Right to Refuse Enrollment in a #Biometric System?

biometric time clockBiometrics is a Growing Identification Technology 

It’s no secret that biometric technology deployments are on the rise.  Increasingly, retailers are catching on to the unique benefits and security that biometric technology offers to positively identify an individual by their physiological characteristics instead of through ID cards, personal identification numbers or passwords.  The rapid growth of biometric technology seemed to begin shortly after we shifted into a society aggressively focused on safety and security in the wake of the rise in global terrorism.  Biometrics was soon recognized as the only technology that could tell with near absolute certainty that someone was who they claimed to be.  Governments were the first to actively use biometric identification to secure their intellectual and physical property and then slowly expanded to border control and public safety.

employee's rights to enroll in a biometric identification system

Federal Courthouse

The progression of biometric technology didn’t stop solely with security deployments though; it kept on growing and progressing.  As price points dropped and the technology became more refined, deployments began to shift to the private sector as companies took notice that biometrics had strong potential to help them with problems like employee time theft, inventory shrink, identity theft, compliance and fraud.  Widespread adoption by the private sector fueled the growth of biometric systems designed to positively identify individuals to prevent these problems and with this growth came increased scrutiny of the technology (specifically how individual biometric data was stored and what it may be used for other than identification) by Privacy advocates and proponents of civil liberty protection.  Their feelings are that biometric technology violates individual privacy without a 100% guarantee that templates are safely stored and unable to be stolen and governments are not using the data to track citizens interacting with a system and subsequently disseminating the information collected to external bodies.

These arguments are strong but perhaps a closer look at how the technology works would help uncover some answers to these concerns and clear up some misconceptions about biometric technology.

The Privacy Issue – How Does Biometric Technology Actually Work?

Most people believe that when an individual places their finger on a fingerprint reader to register their identity in a biometric system, an image of their fingerprint(s) is stored somewhere on a server or a computer.  In actuality this is typically not the case.  Instead, the biometric matching software extracts and stores what is known as an identity template.  This is a mathematical representation of data points that a biometric algorithm extracts from the scanned fingerprint.  The biometric identity template is simply a binary data file, a series of zeros and ones.  The algorithm then uses the template to positively identify an individual during subsequent fingerprint scans.  No image is ever stored or transmitted across a network.  In addition, the algorithm is “one way” which means that it is nearly impossible to recreate the original biometric image from the template.  In other words, it is nearly impossible to reverse engineer the data that is sent to positively identify an individual and successfully “steal” their biometric identity.

Understanding these processes is central to realizing how the danger of identity theft or a security breach is significantly lessened, if not completely eliminated, through the use of a proprietary algorithm with no stored image and data encryption.  Biometric templates are also not linked to anything in a closed system that can positively identify an individual outside of that system.

However, privacy advocates strongly feel that the idea of capture, storage and use of biometric data (specifically by governments either through mandated deployments for social services/social issues or request of data and records from private business) to assemble a comprehensive citizen knowledge base and thus exercise covert control of society in general is a violation of individual privacy and proves to be a valid point.

fingerprint readerCan an Employee Claim that using Biometric Technology is a Violation of Their Privacy?

If you adopt biometric technology for time and attendance, access control or another deployment within a business, do employees have a right to refuse participation on the grounds that it violates their privacy and/or individual civil liberties?   It brings up an interesting question.  Without irrefutable proof that a biometric database can’t be hacked into and the templates reverse engineered into images, if an employee did decide to decline participation, would they be able to prove their claim that the technology did in fact violate their civil liberties?

There have not been any known cases here in the U.S. of an employee taking their employer to court for their refusal to enroll in a biometric identification system that resulted in wrongful termination or a violation of their equal opportunity rights.  However, shouldn’t biometric information be treated as any other personally identifiable data that an employer keeps on file like social security numbers, pictures, or bank information if you request a direct deposit?  Information that, if stolen, could be used to recreate you as a person?  Most companies already have policies in place that govern the safe protection of this data and biometrics should arguably be included and not treated any differently.  It should be treated the same way as the data you have already given up and is stored just by being an employee of the company.

Most employers also monitor their employee’s activities while they are at work which could include video, email and telephone monitoring.  An employee is then asked to sign that they received and read the employee manual that explicitly states their acknowledgement that they will be monitored throughout their employment tenure.  Remember that this is not a request for permission to be monitored; it is an agreement that the employer will be doing it.

It is also important to note if you have a Twitter or Facebook account, purchase on the Internet, use credit cards at brick and mortar establishments, subscribe to publications on the Internet, have any form of insurance or bank account, etc. you no longer have any privacy. If you use one or more credit cards, the credit card company knows where you eat, what you eat, what kind of car you drive, where you live, what insurance you have, where you spend your vacations, what you read, how much you spend on shoes and more.  If you use most social media platforms, you have publicly given up every bit of privacy you ever had.    Although these are personal preferences, it makes the argument hard to justify that enrollment in a biometric system is any more egregious that most of the other daily online and offline activities that we participate in.

biometric time clock

John Trader (281 Posts)

John Trader is the Public Relations and Marketing Manager with M2SYS Technology, a recognized industry leader in biometric identity management technology. Headquartered in Atlanta, GA M2SYS Technology's mission is to pioneer the high-tech industry by delivering long-term value to customers, employees and partners through continued innovation and excellence in all aspects of our business. M2SYS continues to innovate, build and bring to market leading-edge biometrics solutions that revolutionize the industry and expand the applicability of biometrics technology in our marketplace. You can view their Web site at or contact them via e-mail at

  • James Baker

    I don’t think it is far to say that because you as an individual choose to share certain information on social network sites you have no privacy. When it comes to employer employee relations then it often makes sense to look after your staff. If staff feel you understand their concerns (whether well-founded or not) then that will surely lead to a better working environment. Having systems that allow for alternative verification e.g. smart card keeps everyone happy. 

    • Thank you for the comment James.  You are correct that employers have an obligation to protect their employees’ personal and confidential information and keep their best interests at heart.  That certainly leads to a more amicable working environment.  

    • Dianabhupaul

      does the us bank use bio metric systems

      • Thank you for the comment. Some elements of the US banking system use biometrics, but mostly for access control and network security. There has not yet been widespread adoption of biometrics for transactional based activities though. 

    • k7ben

      The problem is that smart cards and keys can be shared, stolen or copied. We without a fingerprint, we really don’t know who open the door or unlocked a piece of equipment or clocked in for work. As soon as you give one employee the alternative verification, they will go tell everyone at work and then you have lost any amount of control over who is accessing what.

  • Pingback: Biometric Technology to Replace Passwords()

  • We have a 0 tolerance policy on this blog for insults or vitriol. Please understand that this is unacceptable.

  • This blog promotes educational content to make information and views of biometric industry specialist available to the general people. We believe that if our effort can make a difference in your personal or public life, that would be our success. While carrying out these efforts, we maintain a zero tolerance policy for any degrading or insulting comments that might offend others.

  • k7ben

    I respectfully disagree with you. Your information is based on a lack of knowledge of how biometrics are stored and retrieved.

  • Raymond Coleman

    Mi supervisor checks my biometric gate readings to check when I leave but he has to ask another person to actively check it for him as he does not have the position to check it this legal. I work in construction in the uk

    • Thanks for your comment Raymond. although we are not sure what is your actual question. Could you please clarify a little bit.

      • Raymond Coleman

        I work as a tower crane operator I work in London on a construction site that’s has biometric fingerprint entry I have 4 hours downtime when I climb down the crane. I’m allowed off site during this time where I go to the gym to spend my time it usually takes 2 hours my supervisor /appointed person has been checking the data from the gate to see what time I’ve been leaving and coming back I also text him when I leave site and text him when I return however he checks the data by going through an authorised person to check it for him. Is he allowed to check the gate data to use against me,which seems to be the case,  he himself is not authorised to check the data. Thankyou

        Sent from Samsung Mobile on O2

        ——– Original message ——–

  • Aung htoo Linn

    I am staying at Office. I want to get attendance finger print of staff who are working onsite away from office. How can I do to get staff’s attendance finger print.