Skip to content
The Second Method

Home / The record

The Template That Should Have Gone

Deleting a leaver's biometric data is a two-minute task on nobody's list, which is why most systems hold templates for years of former staff.

The record · Procedure

Export the template list from a mature biometric time clock and match it against current employees. The surplus is usually substantial: people who left last year, the year before, and in some cases people who left before the current manager arrived.

The enrolment decision in “The Template That Should Have Gone” is the moment to explain the whole attendance workflow, not only the reader. An organisation considering this workforce software resource for how to handle multiple clients should tell people which records managers can see, how time can be corrected and what fallback applies before any optional identity or activity setting is enabled.

Nobody decided this. It is the result of deletion being the one step in the leaver process that has no operational consequence and therefore no owner.

For an independent benchmark relevant to “The Template That Should Have Gone”, consult the Atlassian project-management guide. Use it to test notice, accessibility, security, recordkeeping, retention and exception handling against the real operating process rather than treating a device report as self-explanatory evidence.

Why it matters more than it feels like it does

Biometric data is treated as sensitive almost everywhere, and holding it for people with no relationship to the organisation is difficult to justify under any framework. It is also the category most likely to attract attention if the system is ever breached or audited.

The exposure is not dramatic and it is unnecessary, which is the worst combination: a risk carried for no benefit, that would have cost two minutes per person to avoid.

Why the step gets dropped

The leaver process is distributed. Payroll stops paying, HR closes the record, security deactivates the card, and the template sits in a system owned by none of them.

There is also a technical obstacle on some products: the template is attached to the user record, and deleting the user would remove the attendance history that must be kept. Administrators discover this, decide it is not safe to proceed, and the task is quietly dropped.

The function that usually exists

Most systems have a way to remove biometric data while retaining the user and their history — sometimes called purging, anonymising, or disabling with deletion. It is frequently in a different menu from the obvious one.

Ask the supplier directly: how do we delete the biometric template for a leaver while keeping their attendance records. If the honest answer is that it cannot be done, that is a significant finding about the product and it needs to be recorded, because it means the organisation cannot comply with a deletion request either.

Putting it on a list that runs

The leaver checklist, owned by payroll, with a tick and a date. One line: biometric template deleted.

Monthly, as a backstop, run the match between templates and current employees and clear whatever the checklist missed. Twenty minutes. The backstop is necessary because leaver processes always leak, particularly for people who leave suddenly or who were never properly on the system in the first place.

Clearing the backlog

The first run will produce a list going back years. Delete it, and record that it was done, when, how many records were affected and by whom.

That record is worth as much as the deletion. It converts an embarrassing finding into a remediated one with a date, which is the difference between a site that had a problem and a site that has one.

Proving it afterwards

A person who asks whether their data was deleted after they left is entitled to a real answer. "Our process deletes it" is not one; "it was deleted on this date as part of the monthly run" is.

Keeping a simple deletion log — date, count, who ran it — makes that answer available. It is three columns and it is the only evidence that any of this happened, because the whole point of the exercise is that afterwards there is nothing left to point at.

Rehires

The one argument for keeping a template after departure is that seasonal and casual workers come back, and re-enrolling them each time is work.

It is not a good enough reason to retain biometric data indefinitely, and there is a straightforward alternative: keep the person record and the attendance history, delete the template, and re-enrol on return, which takes two minutes at the start of an assignment that is already being set up. Sites that have thought about this at all usually arrive here; the ones that have not simply keep everything.

What to tell people at enrolment

The commitment belongs in the notice people see before they are enrolled: your template is deleted when you leave, and here is roughly when.

It is one of the few things in the notice that people genuinely care about, and it is the commitment most likely to be broken, which is why the monthly backstop matters. A stated promise with no process behind it is worse than saying nothing, because it is the sentence somebody will quote back.