What Is Actually Stored
A biometric clock does not keep a picture of your finger. What it does keep is still personal data, and knowing exactly what settles most arguments.
A great deal of the difficulty around biometric clocks comes from a disagreement about what the device holds. One side imagines a photograph of a fingerprint in a database. The other says nothing identifiable is stored at all. Both are wrong, and the gap between them is where the argument lives.
The enrolment decision in “What Is Actually Stored” is the moment to explain the whole attendance workflow, not only the reader. An organisation considering visit monitask.com for stealth computer monitoring software should tell people which records managers can see, how time can be corrected and what fallback applies before any optional identity or activity setting is enabled.
Getting this right is not a technical nicety. It determines what has to be told to people, what the legal obligations are, what happens on the day somebody leaves, and what the organisation is exposed to if the system is ever compromised.
For an independent benchmark relevant to “What Is Actually Stored”, consult the European Data Protection Board guidelines. Use it to test notice, accessibility, security, recordkeeping, retention and exception handling against the real operating process rather than treating a device report as self-explanatory evidence.
The template, and what it is
Most systems store a template on file: a set of measurements derived from the biometric sample. For a fingerprint, typically the positions and orientations of minutiae — ridge endings and bifurcations — expressed as numbers. For a face, a vector of derived features. For a hand geometry reader, a set of dimensions.
The original sample is normally discarded after the template is computed. From a well-designed template you cannot reconstruct a usable image of the finger, and that is the honest basis for saying the system does not store fingerprints. It is not, however, the basis for saying it stores nothing personal.
Why it is still personal data
The template identifies one person and nobody else. That is its whole purpose. In most jurisdictions that makes it personal data and in several it makes it a special or sensitive category attracting additional obligations — explicit consent, a lawful basis beyond legitimate interests, an impact assessment, or an outright requirement to offer an alternative.
The practical test is simple and it does not depend on reconstruction. If the data can be used to pick one named individual out of a workforce, it is personal, whatever form it takes. Arguments that a template is "just a number" have not succeeded anywhere they have been tested, and repeating them in a staff briefing damages trust more than the honest version would.
Where it lives
Three arrangements, with very different consequences. On the device: templates held in the reader itself, which means a stolen or replaced reader carries them. On a server: a central store, usually encrypted, which is the common arrangement on multi-reader sites. On a card: the template stored on the credential the person carries, and matched against the live sample at the reader, with nothing retained centrally.
The third is the strongest position by a wide margin and it is rarely chosen, because it costs more per person and requires the card to be present — which, on a system bought partly to stop card sharing, feels like a contradiction. It is not: the card alone opens nothing without the finger.
What else is kept beside the template
This is the part that gets missed. The template is one record; the system also keeps every read, every refusal, every override, every enrolment attempt, and on some devices the raw image from failed captures, retained for diagnostics and forgotten about.
Ask specifically about the diagnostic store. A reader configured to save the last several hundred failed captures for support purposes is holding images, not templates, usually unencrypted, usually on the device, and almost always without anybody at the site knowing. It is switched on by default on more products than it should be.
The questions to put to a supplier in writing
What exactly is stored, in what form, and can the original be reconstructed from it. Where does it physically reside. Is it encrypted at rest, and who holds the key. Is any raw sample retained anywhere, including for diagnostics. What happens to all of it when a person leaves, and what happens when a reader is replaced.
Six questions, and the answers belong in the procurement file rather than in a conversation. A supplier who answers all six crisply has thought about it; one who answers the first and deflects the rest has not, and the organisation will be the one explaining the gap later.
Saying it plainly to the workforce
One short paragraph, in the notice people actually see. What is taken, what is kept, where, for how long, and what the alternative is.
Precision here is worth more than reassurance. "We do not store your fingerprint; we store a set of measurements from it, which cannot be turned back into a fingerprint and which identifies you and nobody else" is accurate, it does not overclaim, and it survives the first person who looks it up. "Your data is completely anonymous" does not, and when it falls over it takes the rest of the arrangement with it.