Skip to main content
Security

Security & Compliance

Built with UAE data protection requirements in mind.

UAE PDPL Compliance

The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) sets requirements for processing personal data, including biometric data. CampusTrack is designed with these requirements in mind.

Biometric data (face embeddings) classified as sensitive personal data
Consent tracking for face verification enrollment
Data minimisation — only embeddings stored, not raw face photos
Support for Data Protection Officer (DPO) requirements
Breach notification readiness with complete audit trails
GPS and biometric consent dialogs before data collection
Full data export (JSON) per employee on request
Employee anonymization — right to be forgotten compliance

How we protect data

AES-256 encryption at rest and in transit
Face embeddings stored — not raw photos
S3 lifecycle: 60-day auto-delete of audit photos
No biometric data stored on local devices
Row-level data isolation per branch
Complete audit trail for all data access

GPS & Device Security

Multiple layers of security protect the integrity of GPS-based attendance.

GPS spoofing detection and prevention
Velocity anomaly detection (impossible travel alerts)
Device binding and fingerprint enforcement
Account lockout after failed authentication attempts
Session management with configurable timeout controls
Check-in cooldown periods to prevent rapid re-entry
Max travel speed validation between check-ins
Six-layer GPS integrity verification framework

School Inspection & Education Governance

CampusTrack helps schools maintain the operational governance and staff management practices that support strong inspection outcomes. While KHDA's direct attendance focus is on students, staff attendance data supports operational readiness during DSIB evaluations.

Attendance reporting aligned with operational governance best practices
Inspection-ready reports exportable to Excel and PDF
Staff-only system — no student personal data collected
Branch-level reporting for individual campus audits

UAE Labour Law & WPS Compliance

Schools are employers under UAE Labour Law. Federal Decree-Law No. 33 of 2021 requires accurate record-keeping of working hours, overtime, and leave. The Wage Protection System (WPS) requires payroll accuracy, which depends directly on attendance data.

Working hour tracking aligned with Federal Decree-Law No. 33/2021
Overtime calculation matching Labour Law provisions (25–50% premiums)
Payroll-ready attendance exports for WPS compliance
Leave tracking and record-keeping per Labour Law requirements
MOHRE inspection readiness with exportable attendance records
Ramadan working hour adjustments built in

Safeguarding & Emergency Accountability

In school environments, knowing who is on campus is a safeguarding requirement — not just an administrative convenience.

Real-time staff presence data — know who is on campus at any moment
Emergency evacuation support — GPS-verified accountability register
Duty of care compliance — track staff responsible for students at all times
Post-incident auditing — timestamped, location-verified attendance records

GDPR Alignment

CampusTrack incorporates data protection principles informed by GDPR best practices. CampusTrack is not GDPR-certified. Schools with GDPR obligations should assess their specific requirements independently.

Data minimisation — only necessary data collected and retained
Purpose limitation — data used exclusively for attendance management
Employee data export on request (right of access)
Data anonymization and deletion capabilities
Clear consent mechanisms for biometric enrollment
Built for UAE PDPLInspection-Ready ReportsAES-256 EncryptedCloud Hosted in AWS
CampusTrack compliance dashboard with device management and GPS fraud detection

Compliance-ready reporting dashboard

Questions about security?

Get in touch with our team to discuss compliance requirements for your school.