Skip to main content
CampusTrack — staff HRMS and operations for campuses
Back to BlogMarch 2026

By CampusTrack Team

What the UAE PDPL Means for School Attendance Records

CampusTrack face data privacy notice demonstrating UAE PDPL-compliant data handling for school attendance

The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) established a comprehensive framework for how organisations collect, process, and store personal data. For schools operating attendance systems, several provisions are directly relevant.

What counts as personal data?

Under PDPL, personal data includes any information that can identify a person — directly or indirectly. For attendance systems, this includes employee names, ID numbers, GPS coordinates, timestamps, and biometric data such as facial features or fingerprints.

Consent for biometric data

Biometric data is classified as sensitive personal data under PDPL. Schools using face verification or fingerprint recognition for attendance must obtain explicit consent from employees before collecting this data. The consent must be informed (employees understand what is collected and why), specific (for the stated purpose only), and freely given (not a condition of employment).

GPS location tracking

Collecting GPS coordinates at check-in falls under personal data processing. Schools should inform staff that location is recorded at the point of check-in and check-out, explain that it is used to verify presence within the school geofence, and confirm that continuous tracking does not occur outside check-in events.

Data minimisation

PDPL requires that only necessary data is collected. An attendance system should collect the minimum data needed to verify presence and identity — not continuous location tracking, not browsing history, and not personal device information beyond what is strictly required.

Storage and retention

Personal data should not be retained longer than necessary. Schools should define retention periods for attendance records (typically aligned with academic years), automatically delete temporary data like face verification photos, and ensure proper data disposal when an employee leaves.

Employee rights

Under PDPL, employees have the right to access their attendance data, request corrections to inaccurate records, request deletion (subject to legitimate retention needs), and withdraw consent for optional features like face verification. These rights exist alongside the employer's UAE Labour Law obligations to maintain accurate attendance records.

What a school should actually document

Compliance is largely a documentation exercise, and the documents are ones most schools can produce in an afternoon if they know which ones are needed:

  • A record of what personal data is collected through attendance, and why each item is necessary.
  • The lawful basis relied on for each category, with biometric data treated separately from the rest.
  • Evidence of consent where consent is the basis — including what staff were told at the time.
  • Retention periods for each category, and evidence that deletion actually happens.
  • Who has access to what, and how that is reviewed.
  • A route for a member of staff to ask what is held about them and to have it corrected.

Where schools most often get consent wrong

The single most common failure is bundling. Consent to biometric processing folded into an employment contract or a general IT policy is not specific, and specificity is exactly what a special category of data requires. It has to be separable, which in practice means a distinct step a member of staff can decline without declining everything else.

The second failure follows from the first: a deployment that cannot function unless every member of staff consents has not obtained consent, it has obtained compliance. If declining means being unable to record attendance at all, the choice is not real. There has to be a path that works without biometrics — and having one is what makes the consent from everyone else meaningful.

Retention is where good intentions quietly fail

Most schools set a retention period and never verify that anything is deleted. The distinction that matters is between the attendance record and the biometric template: the record of who checked in, when and where has a long and legitimate retention need under employment law, while the face data used to verify it does not. Keeping the two together means the stricter obligation governs both, and the school ends up holding biometric data for years because it needed the attendance record.

Separating them is the practical fix. The audit trail survives; the biometric template expires on its own schedule. Worth confirming that your system can actually do this rather than assuming it, because many cannot.

CampusTrack is built with PDPL compliance in mind

Consent-based face enrolment, configurable photo auto-deletion policy aligned with UAE PDPL retention principles, role-based data access, and full data export on request.

See our security practices

Frequently asked questions

Do we need consent for biometric attendance?

Yes — explicit, recorded, and with a genuine alternative for anyone who declines. Consent presented as unavoidable is not consent, and the existence of a real alternative path is what makes it meaningful.

Can we store photographs of staff faces?

Store a mathematical template rather than an image wherever the system allows it, and document what is stored, where it lives and for how long. “We keep the photos in case” is the answer that becomes a problem later.

What do organisations most often get wrong?

Retention. Consent is usually collected carefully at enrolment and then nothing ever deletes anything, so records for people who left years ago are still sitting there because no schedule was set.

This article is for informational purposes only and does not constitute legal, regulatory, or compliance advice.

Request Demo