Biometric employee clock-in: what Argentine law requires
Keeping a record of your employees' working hours is a legal obligation, and biometric clock-in is a valid way to meet it, with conditions: fingerprints and faces are personal data protected by Law 25.326, so you must state the purpose, document consent and handle the data with care. The cleanest alternative: run the biometric check on the employee's own phone, so no central biometric database ever exists.
Recording working hours is not optional
Before discussing fingerprints or faces, set the baseline: recording the working day is an employer obligation, not a convenience. When the record is missing, the company is the one that loses.
| Rule | What it requires | If missing |
|---|---|---|
| Law 11,544, sec. 6 (working hours) | Display start, end and shift times for staff | Labor fines on inspection |
| Decree 16,115/33 | Keep a record of hours worked | No evidence against a claim |
| Law 20,744, sec. 52 (special book) | Certified book with each employee's data | Presumption in the worker's favor |
The point that hurts most in practice: in an overtime claim, the burden of proof flips. Without a reliable time record, the employee's account tends to outweigh yours. A paper sheet filled in at the end of the month is not a reliable record, and courts know it.
Fingerprints and faces are personal data
Argentina's personal data law (25.326) fully covers biometric clock-in: a fingerprint template or face pattern uniquely identifies a person, and depending on context can qualify as sensitive data.
Four concrete obligations follow:
| Obligation | In practice |
|---|---|
| State the purpose | Written notice: what is captured, why, who has access, how long it is kept |
| Document consent | Employee signature, plus a reasonable alternative (PIN, card) for anyone who declines |
| Register the database | A central biometric database belongs in the AAIP national registry |
| Proportionality | Capture no more than needed: a mathematical template, never the raw image |
None of this is exotic: it is what any company already does with customer data, applied to the team's data.
The architecture that avoids most problems
There are two ways to do biometric clock-in, and the legal difference is enormous.
Central biometric clock: the device or server stores templates for the whole staff. You are now the administrator of a biometric database, with everything that implies: registration, security, retention, access control.
Verification on the employee's own phone: the app uses the phone's own biometric unlock (the fingerprint or face the employee already set up for themselves). The biometric data never leaves the device: the system only receives the identity confirmation, the time and the location. There is no central biometric database to manage or register.
That second architecture is what our staff management system uses: strong identity validation for the time record, without the company ever touching a biometric data point. Cost changes too: no hardware to buy, break or maintain.
Checklist for doing it right
If you are adding biometric clock-in, this is the short list a labor lawyer would ask for:
| Step | Why |
|---|---|
| Written notice covering purpose, access and retention | Information duty under Law 25.326 |
| Signed consent, with an alternative available | Forced consent is not consent |
| Prefer on-device verification | Avoids the central database and its obligations |
| If a central database exists: templates only, encryption, restricted access, AAIP registration | What the data protection regime requires |
| Offboarding policy: delete templates on exit | Keeping data without purpose is an infraction |
| Monthly export of worked hours, signed and archived | Your evidence in an hours claim |
Honest note: this is a practical guide, not legal advice. For a specific case, talk to a labor lawyer; to implement the system right from day one, this list covers what the rules and practice demand.