Mandatory Biometric Attendance in India: Can Employees or Students Lawfully Refuse Facial or Fingerprint Authentication?

Jurisdiction: India (Union law, with reference to Delhi and Odisha/Orissa High Court and Supreme Court proceedings)

Research cut-off date: 19 September 2026

Format: Gray-area legal research article

What Is the Short Answer on Refusing Biometric Attendance in India?

Indian law does not settle this question; the answer changes with who is asking. A government employer may introduce biometric attendance without prior consultation, though a privacy challenge on other facts stays open. A private employer’s scanner is governed today by older consent-based rules, not a newer no-consent ground, since that provision has not commenced. Law students challenging Bar Council-mandated biometric attendance have a matter pending before the Supreme Court.

Why Is Mandatory Biometric Attendance a Legal Gray Area in India?

India has no single statute that says “biometric attendance is mandatory” or “an individual has the right to refuse it.” The legal position has to be pieced together from at least five sources that were not designed to work together: the constitutional right to privacy, the Aadhaar Act, 2016, the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and its 2025 Rules, the older IT Act framework that has not yet fully exited the field, and a set of ongoing court proceedings over biometric attendance in law colleges. These sources point in different directions depending on who is imposing the requirement — a government office, a private employer, or an educational regulator — and what kind of biometric system is used.

The result is that “can I refuse?” does not have one answer. That is what makes this a live, unsettled question rather than a settled proposition capable of a one-line answer.

What Does Indian Law Already Settle About Biometric Attendance?

  1. Privacy is a fundamental right, but it is not absolute.

In Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, a nine-judge Bench held that the right to privacy is intrinsic to Article 21. As multiple secondary accounts of the plurality opinion (authored by Chandrachud, J., for himself and three other judges, with Kaul, J. concurring in substance) confirm, the test articulated for State action restricting privacy has three limbs: legality (a law must exist), legitimate aim (“need”), and proportionality (a rational nexus between the means and that aim). This is the formulation properly attributed to the 2017 judgment. The additional, more granular four-part proportionality inquiry — legitimate goal, rational nexus, necessity/least-intrusive-alternative, and balancing — traces to the Constitution Bench’s decision in Modern Dental College & Research Centre v. State of Madhya Pradesh, (2016) 7 SCC 353, and was applied and elaborated by Sikri, J. (writing for the majority) in the 2018 Aadhaar judgment reported as Justice K.S. Puttaswamy (Retd.) v. Union of India, (2019) 1 SCC 1 — not in the 2017 privacy judgment itself. (Resolved: this is a verifiable, secondary-source-confirmed distinction, not a single-paragraph pinpoint from the primary reporter available through this research process; the SCC headnote/paragraph citation should still be confirmed against the official reporter before publication if a direct quotation is used.)

Note on a claim that has been dropped: an earlier draft flagged the assertion that biometric data was “expressly recognised as a specially sensitive category because it is permanent, unique, and cannot be reset.” No specific paragraph in either Puttaswamy judgment stating this in those terms could be located through this research process. Rather than assert it on the strength of general secondary commentary, it has been removed from the article. If the editorial team has access to the full 1,448-page judgment text and wants to reinstate a version of this point, it should be sourced to a specific paragraph before it goes back in.

  1. Aadhaar-based authentication cannot be forced by private parties.

In the companion Aadhaar judgment, Justice K.S. Puttaswamy (Retd.) v. Union of India, (2019) 1 SCC 1, the Court struck down Section 57 of the Aadhaar Act to the extent it allowed private entities to seek Aadhaar-based authentication on a contractual basis. Aadhaar authentication otherwise survives principally for delivery of subsidies, benefits and services debited to the Consolidated Fund of India (Section 7), a threshold private employers and most private colleges do not meet. The Aadhaar Authentication for Good Governance (Social Welfare, Innovation, Knowledge) Rules have since carved out limited categories in which specified private entities may seek UIDAI permission to use Aadhaar authentication — a narrow, permission-based exception that does not disturb the core 2019 holding.

  1. Government departments can introduce biometric attendance without prior employee consultation — on that narrow point.

In Union of India v. Dillip Kumar Rout, Civil Appeal No. 13572 of 2015, decided 29 October 2025, the Supreme Court set aside an Orissa High Court ruling that had invalidated Biometric Attendance System (BAS) circulars for want of consultation. At paragraphs 9–10, the Court held that where the introduction of a Biometric Attendance System is for the benefit of all stakeholders, the mere fact that employees were not consulted before implementation does not render the introduction of the system illegal. This settles the narrow procedural question. It does not hold that biometric attendance can never be challenged on privacy or proportionality grounds; that broader question was not before the Court.

  1. Biometric data is treated as legally significant.

Whether under the older SPDI Rules, 2011 (biometric information is expressly listed as “sensitive personal data or information”) or the newer DPDP framework once its substantive provisions commence, biometric data attracts a materially higher standard of care than an ordinary attendance register.

Where Does the Law Genuinely Conflict or Remain Unresolved?

1. Two data-protection regimes, on a collision course that has not yet arrived

Resolved and pinpointed: By commencement notification G.S.R. 843(E), issued by the Ministry of Electronics and Information Technology alongside the DPDP Rules, 2025 (notified 13 November 2025), only Section 1(2), Section 2, Sections 18–26, Section 35, Sections 38–43, and Section 44(1) and (3) of the DPDP Act came into force on 13 November 2025. Section 6(9) and Section 27(1)(d) commence on 13 November 2026. Section 7 — the “certain legitimate uses” provision — Sections 3–5, 6(1)–(8) and (10), 8–17, 27 (other than clause (1)(d)), 28–34, 36–37, and Section 44(2) (which would omit Section 43A of the IT Act) all commence eighteen months after the notification, a date computed as 13 May 2027. This is corroborated independently by the Internet Freedom Foundation’s contemporaneous statement on the notification and by Wikipedia’s infobox for the Act (itself sourced to the same notification), in addition to specialist compliance trackers. The editorial team should still pull G.S.R. 843(E) itself from the e-Gazette before publication, since that is the only fully authoritative text, but the three-tranche structure and dates above are now corroborated by more than one independent source and can be stated with confidence.

Practical consequence: today, there is no live conflict between a consent-based standard and a no-consent “legitimate use” ground, because the no-consent ground is not yet law. The SPDI Rules, 2011 currently govern collection of biometric data as sensitive personal information, requiring written consent, and Section 43A of the IT Act currently remains the operative compensation route for negligent handling of that data — both continue to apply until the DPDP omission provision commences on 13 May 2027.

What does apply now is Section 38 of the DPDP Act (already in force). Section 38(1) provides that the Act’s provisions are in addition to, not in derogation of, other laws in force. Section 38(2) separately provides that where a provision of the Act conflicts with another law, the Act’s provision prevails to the extent of the conflict. Today, Section 38(2) has nothing to bite on with respect to Section 7, because Section 7 is not yet in force. The real question this raises is prospective — once Section 7 commences, whether a permissive processing ground and a stricter consent requirement will be treated as being “in conflict” at all.

Resolved per instruction: the earlier draft claimed that named commentators disagree on whether Section 7(i) reaches the initial collection of biometric data or only its downstream processing. No two specific, identifiable commentators taking opposing published positions on that narrow question could be located through this research process. Per the instruction to name two or delete, that sentence has been removed. The underlying compliance-cliff point stands on the text of the Act alone and does not need commentator support.

This is the compliance question worth flagging for private employers — not as a live, unresolved conflict today, but as a compliance cliff with a fixed runway: employers relying on informal justifications for biometric collection now should not assume that a future “legitimate use” exemption will retroactively validate current practice, and should continue to meet the SPDI consent standard until 13 May 2027.

2. Educational institutions: an active challenge, with more decided already than the previous draft credited

  • On 24 September 2024, the Bar Council of India (BCI) issued Notification BCI:D:5186/2024 (LE Circular No. 13/2024), titled “Implementation of Criminal Background Check System, Declaration Regarding Simultaneous Degree and/or Regular Academic Programs, Employment Status, Attendance Compliance, Biometric Attendance, and Installation of CCTV Cameras in Law Colleges,” directing all Centres of Legal Education to implement mandatory biometric attendance and CCTV surveillance. This precise number is corroborated by an open letter addressed directly to the BCI Chairman quoting it verbatim, and independently by LawBeat’s and LawChakra’s contemporaneous reporting. It has not been possible to load bci.gov.in directly through this research process to confirm against the Council’s own posted copy; the editorial team should do that final check, but the number can otherwise be stated with reasonable confidence given three independent, mutually corroborating citations of the identical string.
  • Two final-year law students — Prakruthi Jain (NALSAR University of Law) and Keyur Akkiraju (Symbiosis Law School) — filed separate writ petitions before the Supreme Court challenging the circular, later tagged together as P.(C) No. 31/2025, arguing, among other grounds, that there are no disclosed safeguards for how the biometric data will be stored and that it is being outsourced to private intermediaries without a clear legal basis, and that the circular exceeds the BCI’s statutory mandate under the Advocates Act, 1961.
  • A related strand arose from a suo motu Delhi High Court proceeding, Courts on its Own Motion in Re: Suicide Committed by Sushant Rohilla, P.(CRL) 793/2017 (Prathiba M. Singh and Amit Sharma, JJ.), judgment dated 3 November 2025. At paragraph 249, the Court directed the BCI to re-evaluate mandatory attendance norms and held that no student could be debarred from examinations solely for an attendance shortfall.
  • Confirmed against the primary judgment and a tier-one reporter. The Delhi High Court’s own judgment text (accessed via Indian Kanoon) records, at paragraph 128 of the “Analysis and Findings” section, the BCI’s own affidavit defending Circular BCI:D:5186/2024 as consistent with “digital governance and accountability” — confirming the biometric circular was squarely in issue before the Court, not a side comment. SCC OnLine’s own case report of the judgment — reported as Courts on its Own Motion in Re: Suicide Committed by Sushant Rohilla, 2025 SCC OnLine Del 7920 — states directly that “the Court suspended the operation of the BCI’s Biometric Attendance Circular (BCI:D:5186/2024), holding that technological surveillance in classrooms could aggravate psychological distress among students.” This is now corroborated by a tier-one legal reporter, not just the secondary outlets that first raised it, and the judgment’s own text confirms the circular was live before the Court. This can now be stated as fact rather than flagged as unconfirmed. The judgment’s index shows “Directions With Respect to Mandatory Attendance Norms” spans paragraphs 249–252; the Supreme Court’s 26 May 2026 stay order, by its own text, stays only “paragraph no. 249.” Since the biometric-suspension direction addresses a distinct subject (surveillance/data protection) from the debarment-from-exams direction that paragraph 249 self-evidently addresses, it is more likely housed in a different sub-paragraph (250–252) — meaning it is not obviously covered by the Supreme Court’s stay and may currently stand as good law within Delhi, independent of the attendance-debarment litigation still before the Supreme Court. The one remaining gap is the exact paragraph number (250, 251, or 252) for a precise pinpoint citation; the substance of the holding is no longer in doubt.
  • On 26 May 2026, a Supreme Court Bench of Justices Vikram Nath and Sandeep Mehta stayed the operation of paragraph 249 prospectively, while leaving other High Courts free to decide connected attendance disputes on their own merits. At the same hearing, petitioner Prakruthi Jain raised the absence of data-security safeguards in the biometric-attendance mandate; the Court stated it had not decided that petition and listed it for 21 July 2026.
  • At the 21 July 2026 hearing, the Court clarified its interim order: students who had acted under a bona fide belief (formed after the Delhi High Court’s ruling) that an attendance shortage would not bar them from that session’s examinations were entitled to appear in the final examination for the ongoing academic session as a one-time measure, and to a supplementary examination if they had missed all or part of it. The order sheet records that the matter was listed again for 25 August 2026 “for final disposal.” Reporting located through this research process covers the 21 July clarification in detail but does not confirm what occurred at the 25 August 2026 hearing, including whether it addressed the biometric-attendance safeguards question specifically. The Supreme Court’s cause list and order sheet for 25 August 2026 onward, up to the current date, must be checked directly before publication — this is the second-highest-priority verification item.
  • A related, more recent development worth noting for context (not directly dispositive of the biometric question): in early September 2026, the Supreme Court ruled in a separate matter that the BCI has no disciplinary jurisdiction over law students before their enrolment as advocates, quashing directions issued by the BCI Chairman against NALSAR University of Law’s 2026 graduating batch, and converting earlier interim protection into permanent relief. This does not resolve the biometric-attendance question, but it is a second, very recent instance of the Supreme Court curbing the BCI’s asserted regulatory reach over students, and is relevant background for anyone assessing whether the BCI’s 2024 circular was validly issued under its statutory powers.

In short: the Delhi High Court has already ruled against the BCI’s biometric-attendance mandate on privacy grounds, and — unlike the attendance-debarment portion of the same judgment — that ruling has not been shown to be stayed. What remains genuinely open is narrower than the previous draft suggested: whether the Supreme Court, in the still-pending Prakruthi Jain proceedings, will take a different view of the BCI’s statutory authority to mandate biometric attendance nationally, and whether the stay of paragraph 249 will be read to extend further than its text suggests. A categorical claim that “biometric attendance in colleges is legal” nationwide would now be the harder position to defend; a claim that it is currently unenforceable in Delhi, on privacy grounds, is well-supported.

3. The distinction between a one-time scan and ongoing surveillance

Neither Puttaswamy nor Dillip Kumar Rout squarely addresses facial recognition attendance as opposed to fingerprint attendance, even though the privacy concerns are arguably sharper: a facial recognition system can, in principle, continue to identify a person in a camera feed well beyond the moment of “marking attendance.” No reported Indian decision located through this research process has drawn a clear line between a one-time authentication scan and a continuously operating recognition system used for attendance, even though a proportionality analysis would plausibly treat them differently.

4. Employees or students with reasonable accommodation needs

Where a person’s fingerprints cannot be reliably captured — a recognised issue for manual labourers, some elderly persons, and persons with certain disabilities or skin conditions — the DPDP Rules, 2025 contain protective provisions referencing children and persons with disabilities. There is, however, no settled, publicly tested framework specifically addressing a right to a non-biometric alternative for attendance purposes in the Indian workplace or classroom. Employers and institutions are, in practice, left to devise their own fallback procedures.

Who Is Affected, and What Remedies Are Available?

Stakeholder Typical exposure Possible remedy, as the law currently stands
Government employee Mandatory BAS/AEBAS, sometimes linked to salary release Departmental representation. The consultation argument from Dillip Kumar Rout is foreclosed for that narrow point, but proportionality/privacy arguments on specific facts remain open and were not decided by that case.
Private-sector employee Employer-installed fingerprint/face scanner for payroll/attendance Internal grievance to HR citing SPDI consent requirements (currently the operative consent standard); complaint to the Data Protection Board once its complaint mechanism for this subject is operational; civil remedy for data misuse currently lies under Section 43A of the IT Act, which remains in force until 13 May 2027.
Law/other college student BCI-mandated biometric attendance and CCTV Track the pending Supreme Court proceedings (tagged petitions including Prakruthi Jain’s, W.P.(C) 31/2025) and confirm whether the Delhi High Court’s biometric-specific ruling (see verification flag above) currently stands; institution-level representation citing absence of disclosed data-security safeguards.
University teaching staff AEBAS linked to salary disbursement Representation to the university/UGC; collective bargaining through teachers’ associations; constitutional challenge if salary is withheld solely for non-compliance.
Person unable to enrol biometrically No reliable fingerprint/face capture Request a manual/alternative attendance mechanism; the DPDP Rules, 2025 contain disability-related protections, though their application to attendance-capture failures specifically is untested.

What Should Employers and Institutions Do Now?

  • Always offer a non-biometric alternative (ID-card swipe, manual register, OTP-based check-in). This defuses most SPDI consent objections today and will remain a reasonable practice once the DPDP transition occurs, regardless of how the Section 7/Section 38 question is ultimately resolved.
  • Issue a clear, separate notice describing what biometric data is captured, whether raw images/scans or only encrypted templates are stored, retention period, and who has access — this satisfies the current SPDI disclosure norms and anticipates the DPDP Rules’ notice requirements.
  • Prefer on-device template matching over centralised storage of raw biometric images, to reduce breach exposure.
  • Do not link Aadhaar-based authentication to non-subsidy purposes for private entities; if Aadhaar authentication is used at all, verify whether it falls within a specific UIDAI-permitted “Good Governance” category.
  • Build in a documented reasonable-accommodation pathway for individuals whose biometrics cannot be reliably captured.
  • Track the pending Supreme Court proceedings and Data Protection Board developments before finalising any institutional biometric policy, and specifically re-check the status of the Delhi High Court’s biometric-specific holding flagged above.

What Reform Would Resolve This?

A specific employment- and education-sector rule under the DPDP Act — clarifying, in advance of the Section 7 commencement date of 13 May 2027, whether the “legitimate use” ground extends to the initial collection of biometric data or only to its subsequent processing, and mandating a non-biometric alternative wherever biometric attendance is introduced — would resolve the conflict identified above before it becomes live, without requiring fresh primary legislation.

Frequently Asked Questions

Q1. Can my private employer force me to give my fingerprint for attendance? There is no single statute answering this directly, and the position is simpler today than it will become. The DPDP Act’s “legitimate use” ground (Section 7(i)) has not yet commenced — it is scheduled for 13 May 2027 under Notification G.S.R. 843(E). Today, the operative standard is the SPDI Rules, 2011, which require written consent from the individual before a body corporate collects biometric data as sensitive personal information. The safest practical position for an employer, now and after the transition, is to offer a non-biometric alternative, though no court has held that it is legally compelled to do so.

Q2. Does the Supreme Court’s ruling in the Dillip Kumar Rout case mean biometric attendance is always legal? No. That case held only that a government department’s failure to consult employees before introducing a BAS does not, by itself, make the circular illegal (paras 9–10). It did not decide — and was not asked to decide — whether biometric attendance can be challenged on privacy or proportionality grounds on particular facts.

Q3. Can a law college stop me from attending class or writing exams if I refuse biometric attendance? On the biometric-attendance mandate specifically, the Delhi High Court has already ruled against it: in Courts on its Own Motion in Re: Suicide Committed by Sushant Rohilla, 2025 SCC OnLine Del 7920, the Court suspended the BCI’s biometric-attendance circular on privacy grounds. That holding does not appear to be covered by the Supreme Court’s subsequent stay, which by its own text addresses only paragraph 249 (the separate question of exam debarment for attendance shortfalls). The exam-debarment question itself remains live before the Supreme Court in proceedings connected to Prakruthi Jain’s and Keyur Akkiraju’s challenges (W.P.(C) No. 31/2025 and connected matters), where students who relied in good faith on the Delhi High Court’s ruling have been given one-time protection for the ongoing session. Students should watch this litigation closely, and this section should be re-checked against the cause list immediately before publication, since the Supreme Court could still take up and rule on the biometric-mandate question itself in these proceedings.

Q4. Is Aadhaar-linked biometric attendance different from a private company’s own fingerprint scanner? Yes, and the distinction matters a great deal. Aadhaar-based authentication draws on the government’s UIDAI database and is governed by the Aadhaar Act and the 2019 Aadhaar judgment, which restricts its use largely to subsidy/benefit/service delivery funded from the Consolidated Fund of India. A stand-alone company-owned fingerprint or face scanner that never touches the UIDAI database is instead governed by ordinary data-protection law (the SPDI Rules today, the DPDP Act once its substantive provisions commence), not the Aadhaar Act.

Q5. What happens if my fingerprints simply don’t register on the scanner? There is no dedicated, tested Indian legal framework specifically guaranteeing a non-biometric fallback in every attendance context. The DPDP Rules, 2025 include provisions referencing persons with disabilities, but how these apply to attendance-capture failures has not been authoritatively settled. In practice, institutions typically resolve this administratively rather than through litigation.

Q6. Can I get compensation if my biometric data is leaked from an attendance system? Potentially, but through a narrower route than is sometimes assumed. The Data Protection Board of India can impose monetary penalties on the entity responsible for a breach once its enforcement mechanism for this subject is fully operational — but those penalties are payable to the government, not compensation to the individual affected. An individual’s own compensation claim for negligent handling of sensitive personal data currently lies under Section 43A of the IT Act and the SPDI Rules, 2011, which remain in force until 13 May 2027. Whether and how individual compensation survives once Section 44(2) commences on that date is itself a question worth revisiting closer to the time.

Internal Links

The remaining suggested topics (Aadhaar Act Section 57 and private-sector authentication; employee data-privacy rights in India; an explainer on Section 43A, IT Act and SPDI Rules, 2011) do not appear to have matching published articles on the site as of this check, and have been dropped rather than left as placeholders.

Sources Consulted (for editorial verification)

  • Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 — privacy as a fundamental right; three-part test (legality, legitimate aim, proportionality) from the plurality opinion. Pinpoint paragraph still needed for direct quotation.
  • Modern Dental College & Research Centre v. State of Madhya Pradesh, (2016) 7 SCC 353 — source of the four-fold proportionality test later applied in the Aadhaar judgment.
  • Justice K.S. Puttaswamy (Retd.) v. Union of India, (2019) 1 SCC 1 — Aadhaar judgment; Section 57 struck down as to private-entity contractual use; four-fold proportionality test applied by Sikri, J.
  • Union of India v. Dillip Kumar Rout, Civil Appeal No. 13572 of 2015, decided 29 October 2025 (Supreme Court), paras 9–10.
  • Prakruthi Jain v. Bar Council of India, W.P.(C) No. 31/2025, and connected/tagged proceedings including SLP(Crl) No. 9450/2026 — Supreme Court, orders dated 26 May 2026 and 21 July 2026 (status: matter listed for final disposal 25 August 2026; outcome not confirmed as of this cut-off — re-verify against current cause list before publication).
  • Courts on its Own Motion in Re: Suicide Committed by Sushant Rohilla, W.P.(CRL) 793/2017, Delhi High Court, judgment dated 3 November 2025 (Prathiba M. Singh and Amit Sharma, JJ.), reported at 2025 SCC OnLine Del 7920 — paragraph 249 (exam-debarment directions, subsequently stayed by the Supreme Court) and a separate direction (paragraphs 250–252 by index position, exact paragraph to be pinpointed) suspending the BCI’s biometric-attendance circular on privacy grounds, confirmed by SCC OnLine’s case report and by the judgment’s own recitation (at paragraph 128) of the BCI’s affidavit defending the circular.
  • Bar Council of India, Notification BCI:D:5186/2024 (LE Circular No. 13/2024), dated 24 September 2024 — number corroborated by three independent secondary sources; final check against bci.gov.in still recommended.
  • [NALSAR 2026 batch matter] — Supreme Court, early September 2026, holding BCI has no disciplinary jurisdiction over students before enrolment (cited for context on BCI’s regulatory reach; case name/citation to be confirmed and added before publication).
  • Digital Personal Data Protection Act, 2023, ss. 1(2), 2, 6, 7, 18–26, 27, 35, 38, 44 — read with commencement Notification G.S.R. 843(E) dated 13 November 2025.
  • Digital Personal Data Protection Rules, 2025 (notified 13 November 2025), Rule 1 (phased commencement schedule).
  • Information Technology Act, 2000, s. 43A, and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
  • Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, ss. 7, 57.
  • Aadhaar Authentication for Good Governance (Social Welfare, Innovation, Knowledge) Rules — private-entity exception.
  • Internet Freedom Foundation, statement on notification of the DPDP Rules, 2025 (13 November 2025) — used to corroborate the commencement-tranche breakdown.
Dhanush Jaykar
Author: Dhanush Jaykar

⚖️ Law Student | Legal Researcher ✍️ Legal Writing • Research • Analysis Learning the law. Questioning it. Writing about it.