Short answer
A university in England and Wales can lawfully monitor attendance and, in principle, use biometric systems or key-fob and card-swipe data, but only within tight limits set by data protection law. Biometric attendance in particular is legally difficult to justify because it involves special category data, and the Information Commissioner’s Office (ICO) has taken enforcement action against organisations that impose it without a proper basis or without offering a genuine alternative. Key-fob and card-swipe monitoring is generally easier to justify, but it still has to be proportionate, transparent and limited to a legitimate purpose. There is no absolute right for a university to require either method; each depends on whether the university can satisfy the relevant legal tests.
The legal framework
The main law is the UK GDPR together with the Data Protection Act 2018. Any personal data a university collects about students, including attendance records, swipe data and biometric identifiers, must be processed in line with the data protection principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; and security. The two principles that most often defeat over-intrusive monitoring are data minimisation (collect only what is necessary) and the requirement for a lawful basis.
To process any personal data the university needs a lawful basis under Article 6, such as consent, contract, legal obligation, or legitimate interests (public bodies must be careful relying on legitimate interests for their public tasks and may instead rely on public task). To process special category data it needs both an Article 6 basis and a separate Article 9 condition.
Biometric attendance
This is the harder case. Where biometric data such as a fingerprint or facial scan is used to uniquely identify an individual, it is special category data. ICO guidance is explicit that biometric data used for identification for timekeeping or access control is special category data and requires an additional condition for processing under Article 9, plus additional safeguards.
Two points follow from the ICO’s position, developed in its employment monitoring and biometric recognition guidance and reflected in enforcement action such as its intervention against a leisure group that used facial recognition on staff:
1. Necessity and proportionality. The university must be able to show that biometric identification is genuinely necessary for its purpose and that a less intrusive method would not achieve the same aim. If ordinary card swiping, key fobs, registers or app-based check-ins would work, it will be very hard to justify biometrics as necessary. Convenience or slightly better accuracy is unlikely to be enough.
2. A workable alternative and free consent. The ICO indicates that where a genuine, non-detrimental alternative is offered to those who opt out, consent is the most likely lawful basis for biometric access control. Consent must be freely given, specific, informed and as easy to withdraw as to give. If students are effectively forced to use biometrics, or are disadvantaged for refusing, consent is not valid, and the processing is likely to be unlawful. Because of the imbalance of power between an institution and its students, the ICO is sceptical of consent that is not truly optional.
The practical consequence is that a university can offer biometric attendance, but requiring it, with no realistic opt-out, is legally risky and likely to be unlawful unless the university can demonstrate a compelling necessity and an appropriate Article 9 condition. Before deploying any biometric system, the university must carry out a Data Protection Impact Assessment (DPIA), which is mandatory for this kind of high-risk processing, and be transparent about it.
Key-fob and card-swipe monitoring
Recording when a student enters a building or taps into a lecture using a card or fob is ordinary personal data, not special category data, so it does not carry the Article 9 burden. This kind of attendance monitoring is much more commonly accepted, and universities routinely use it. It still has to satisfy the data protection principles, which means:
The university needs a clear lawful basis, usually performance of its contract with the student and, for public universities, its public task, or legitimate interests. It must tell students in a privacy notice what data is collected, why, how long it is kept, who it is shared with and their rights. It must not collect more than needed, must keep the data secure, and must not repurpose location or movement data for unrelated surveillance without a fresh basis and fresh transparency.
There is an important distinction between recording attendance at teaching sessions, which is a legitimate academic and pastoral purpose, and tracking a student’s general movements around campus. Continuous location tracking of individuals, or building a detailed picture of where a student goes and when, is far more intrusive and would require strong justification and a DPIA. Using fob data narrowly to confirm presence at required sessions is easier to defend than using it as a general surveillance tool.
Immigration and international students
Universities that sponsor international students under the Student visa route have Home Office sponsor duties to monitor and record engagement and attendance and to report students who stop engaging. This gives a university a genuine legal and regulatory reason to monitor attendance for sponsored students, which strengthens the lawful basis and necessity argument for card or fob-based attendance systems. It does not, however, justify biometric monitoring specifically, because the sponsor duties can be met with non-biometric methods, and it does not remove the transparency and proportionality requirements.
University rules, contract and consultation
Whether a university can require a particular method also depends on its own regulations and the student contract. Attendance requirements are usually a legitimate part of academic regulations, and monitoring engagement is generally within the university’s contractual and public-task functions. But the method of monitoring must still comply with data protection law, and imposing a new intrusive system may need to be consistent with what students were told when they enrolled. A sudden, non-consensual switch to biometrics part-way through a course would be vulnerable to challenge on both data protection and fairness grounds.
What is unlikely to be lawful
Requiring biometric attendance with no genuine alternative and treating refusers detrimentally is unlikely to be lawful. Using card, fob or Wi-Fi data to build a general profile of a student’s movements beyond what attendance monitoring needs is likely to be disproportionate. Collecting the data without a clear privacy notice or without a DPIA for high-risk processing is a breach of the accountability and transparency requirements. Keeping detailed movement data for longer than necessary also breaches the storage limitation principle.
Practical steps if you are affected
1. Ask the university for its privacy notice and, for biometric or tracking systems, its Data Protection Impact Assessment and the lawful basis and Article 9 condition it relies on. It is required to be transparent about these.
2. Make a subject access request if you want to see exactly what movement or biometric data is held about you.
3. If biometrics are being imposed, ask in writing for the non-biometric alternative and object to biometric processing. If consent is the claimed basis, you can withdraw or refuse it.
4. Raise a data protection concern with the university’s Data Protection Officer first, in writing, setting out why you consider the processing unnecessary or disproportionate.
5. If the university does not resolve it, you can complain to the ICO, which regulates this area and has intervened against organisations imposing biometrics without a proper basis. You can also exercise your right to object and, for automated decisions with significant effect, rights around automated decision-making.
What would change the answer
The outcome turns on facts you have not yet supplied: whether the system is biometric or simply card and fob based; whether a genuine alternative is offered; whether you are a sponsored international student, which strengthens the university’s attendance-monitoring justification; what the privacy notice and student contract say; whether the data is used only for attendance or also for wider movement tracking; and whether a DPIA was done. A card-swipe register for teaching sessions is very likely lawful. Compulsory biometric identification with no opt-out is the scenario most likely to be challengeable.
This answer draws on broad legal knowledge and checks current law, guidance and procedure against relevant sources.
Can we use biometric data for time and access control and monitoring? | ICOico.org.ukBiometric data guidance: Biometric recognition | ICOico.org.ukHow do we process biometric data lawfully? | ICOico.org.ukICO orders leisure group to stop using facial recognition tech on employeeseversheds-sutherland.comKNOW WHERE YOU STAND
Ready to stop guessing?
The above is just an example answer. Sign up now to get personalised guidance and ask follow-up questions based on your own situation. Bring your legal issue, your contract, or your question. Lawyer Destroyer gives you clear, practical guidance so you can move forward with confidence.