What's Happening?
Dayforce, a company specializing in human capital management, has implemented a biometric identity verification process for certain employees. This process is primarily for individuals in elevated-risk positions and other employees when additional identity proofing
is required for security, fraud prevention, or access control. The company collects biometric information, specifically a facial scan derived from a live facial image or video selfie, along with an image of a government-issued identity document and its embedded photo. This data is used to verify the employee's identity, confirm liveness to prevent impersonation or fraud, and complete necessary identity proofing for designated access or roles. Dayforce utilizes HireRight’s Global ID with Biometrics service, which in turn uses Yoti for the biometric liveness check and comparison. The biometric information is retained only as long as needed for verification, with a maximum retention period of three months, and is then permanently destroyed. Dayforce explicitly states that this biometric data will not be used for timekeeping, monitoring performance, making automated employment decisions, or training AI models.
Why It's Important?
This implementation by Dayforce highlights a growing trend in corporate security and identity management, particularly for roles with heightened risk or requiring stringent access controls. The use of biometrics, such as facial recognition, offers a more robust method of identity verification compared to traditional methods, potentially reducing instances of fraud and unauthorized access. For employees, this means an enhanced level of security surrounding their professional identities and access privileges, but also raises considerations about data privacy and the handling of sensitive personal information. The explicit limitations on how Dayforce uses this data—excluding timekeeping or performance monitoring—are crucial for addressing employee concerns about surveillance and ensuring the technology serves its stated security purpose. This move could set a precedent for other companies in managing employee identities, especially as remote work and digital access become more prevalent, necessitating stronger verification protocols.
What's Next?
Dayforce's biometric identity verification process is now active for specified employee groups. Employees subject to this verification will undergo the process as required for their roles or access needs. The company has outlined a clear retention and destruction policy, ensuring that biometric data is not stored indefinitely. Dayforce also provides an alternative, non-biometric identity verification process for employees, depending on applicable laws, and encourages those who prefer not to provide biometric information to contact them for available alternatives. This indicates a commitment to compliance with varying privacy regulations and employee choice where legally mandated. Future developments may include further refinement of these processes based on employee feedback, evolving privacy laws, and advancements in biometric technology, potentially influencing how other organizations approach identity management in high-security contexts.
Beyond the Headlines
The adoption of biometric identity verification by companies like Dayforce delves into the broader societal discussion surrounding privacy, security, and the increasing digitization of personal information. While the stated purpose is enhanced security and fraud prevention, the collection of biometric data, even with strict retention policies, raises ethical questions about data ownership and potential misuse. The distinction between using biometrics for identity verification versus other applications like performance monitoring is critical, as it addresses concerns about 'function creep'—where technology initially deployed for one purpose is later expanded to others. The availability of alternative verification methods, where legally required, underscores the tension between security imperatives and individual privacy rights. This trend could lead to increased regulatory scrutiny and the development of more comprehensive legal frameworks governing biometric data in the workplace, shaping future employment practices and data protection standards across industries.











