Skip to main content
CampusTrack — staff HRMS and operations for campuses
Security

Security & Compliance

Built with UAE data protection requirements in mind.

UAE PDPL Compliance

The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) sets requirements for processing personal data, including biometric data. CampusTrack is designed with these requirements in mind.

Biometric data (face embeddings) classified as sensitive personal data
Consent tracking for face verification enrollment
Data minimisation — only embeddings stored, not raw face photos
Support for Data Protection Officer (DPO) requirements
Breach notification readiness with complete audit trails
GPS and biometric consent dialogs before data collection
Full data export (JSON) per employee on request
Employee anonymization — right to be forgotten compliance

How we protect data

industry-standard encryption at rest and in transit
Face embeddings stored — not raw photos
Audit photos retained per a configurable retention policy
No biometric data stored on local devices
Row-level data isolation per branch
Complete audit trail for all data access

GPS & Device Security

Multiple layers of security protect the integrity of GPS-based attendance.

GPS spoofing detection and prevention
Velocity anomaly detection (impossible travel alerts)
Device binding and fingerprint enforcement
Account lockout after failed authentication attempts
Session management with configurable timeout controls
Check-in cooldown periods to prevent rapid re-entry
Max travel speed validation between check-ins
Six-layer GPS integrity verification framework

School Inspection & Education Governance

CampusTrack helps schools maintain the operational governance and staff management practices that support strong inspection outcomes. While Dubai school inspection's direct attendance focus is on students, staff attendance data supports operational readiness during Dubai school evaluations.

Attendance reporting aligned with operational governance best practices
Inspection-ready reports exportable to Excel and PDF
Staff-only system — no student personal data collected
Branch-level reporting for individual campus audits

UAE Labour Law & WPS Compliance

Schools are employers under UAE Labour Law. Federal Decree-Law No. 33 of 2021 requires accurate record-keeping of working hours, overtime, and leave. The Wage Protection System (WPS) requires payroll accuracy, which depends directly on attendance data.

Working hour tracking aligned with Federal Decree-Law No. 33/2021
Overtime calculation matching Labour Law provisions (25–50% premiums)
Payroll-ready attendance exports for WPS compliance
Leave tracking and record-keeping per Labour Law requirements
UAE Labour Law inspection readiness with exportable attendance records
Ramadan working hour adjustments built in

Safeguarding & Emergency Accountability

In school environments, knowing who is on campus is a safeguarding requirement — not just an administrative convenience.

Real-time staff presence data — know who is on campus at any moment
Emergency evacuation support — GPS-verified accountability register
Duty of care compliance — track staff responsible for students at all times
Post-incident auditing — timestamped, location-verified attendance records

GDPR Alignment

CampusTrack incorporates data protection principles informed by GDPR best practices. CampusTrack is not GDPR-certified. Schools with GDPR obligations should assess their specific requirements independently.

Data minimisation — only necessary data collected and retained
Purpose limitation — data used exclusively for attendance management
Employee data export on request (right of access)
Data anonymization and deletion capabilities
Clear consent mechanisms for biometric enrollment
Built to support UAE PDPLInspection-Ready ReportsEncrypted at restEnterprise-grade cloud hosting
CampusTrack compliance dashboard with device management and GPS fraud detection

Compliance-ready reporting dashboard

What we deliberately do not do

Security pages list what a vendor does. For anyone doing due diligence, the more useful half is usually what the vendor has decided not to do.

We do not track staff outside check-in

Location is checked at the moment of check-in against the campus geofence. There is no continuous tracking through the working day, and that is a design decision rather than a feature we have not built yet.

We do not keep biometric images indefinitely

The retention window is configurable, and the attendance record survives without the face image. Keeping the record is a legitimate need; keeping the face forever is rarely one.

We do not sell or share school data

Staff data is not an input to anything we sell, is not shared with advertisers or data brokers, and is not used to train models.

We do not make leaving expensive

Export in open formats is available on request, including at the point you decide to stop using us. A platform that makes exit difficult is charging a switching cost the school never agreed to.

We do not grant blanket internal access

Support access to school data is restricted rather than open to anyone employed here. Being the vendor is not itself a reason to read a staff record.

We do not require staff to accept biometrics

Consent to face verification is separable. Attendance can be recorded without it for staff who decline, so consent stays a genuine choice rather than a condition of employment.

For procurement and governance review

What school leadership and governors typically ask before signing, and what to expect:

Can we sign a Data Processing Addendum?

Yes. Ask and we will provide one covering the processing described on this page, the roles of controller and processor, and the obligations on each side.

Who else processes our data?

Infrastructure and email delivery providers, bound by contract, and we will name them on request rather than asking you to accept an unnamed list.

What happens if there is a breach?

You are notified. Notification obligations under UAE law run to the school as controller, and we would rather tell you about something minor than have you hear it elsewhere.

Can our IT team run a security review?

Yes. Send your questionnaire and we will answer it directly, including where the honest answer is that something is planned rather than in place.

What happens to our data if we leave?

You export it in open formats and we delete it according to the terms agreed. Neither should require negotiation at the point you have decided to go.

Can we set our own retention periods?

Biometric retention is configurable. Attendance and working-hour records are retained for the period required under UAE Labour Law, which is a floor rather than a preference.

This page describes our approach to data protection and is not legal advice. For a Data Processing Addendum or a completed security questionnaire, please get in touch.

Questions about security?

Get in touch with our team to discuss compliance requirements for your school.

Request Demo