POLICY

GPS Attendance Policy for Employees: Rules, DPDP Consent and a Full Sample Policy

How to write a GPS attendance policy that survives a dispute: scope, what location data is collected and when, geofence radius, mock-location rules, consent and retention under DPDP, correction process, disciplinary clauses and a complete sample policy you can adapt.

Field employee marking GPS attendance inside a geofenced client site on a mobile app

Why a written GPS attendance policy is not optional

Most companies switch on GPS attendance by sending a WhatsApp message: 'From Monday everyone will mark attendance on the app.' Three months later a sales executive disputes a loss-of-pay deduction because his punch landed 300 metres outside the client's premises, and nobody can point to a document that says what the acceptable radius was, who approves exceptions, or whether he was told his location would be recorded at all. The written policy is what turns a software setting into an enforceable rule.

There are three separate reasons to write it down. The Digital Personal Data Protection Act 2023 treats location as personal data and expects notice, purpose limitation and reasonable security; a policy is the simplest way to evidence all three. Trust matters because employees who believe they are being tracked all day resist the app, share fake locations and lobby supervisors for manual marking. Disputes over LOP, late marks and overtime are settled far faster when both sides can read the same clause. The legal background is covered in is employee GPS tracking legal in India.

The policy should be short enough to read in ten minutes and specific enough to answer the four questions employees actually ask: when is my location captured, how far from the site can I be, what happens if the app fails, and who sees this data. Everything else is supporting detail.

  • A policy converts an app setting into a rule you can enforce and defend
  • DPDP notice, purpose limitation and security are easiest to prove with a written document
  • Answer the four employee questions: when, how far, what if it fails, who sees it

Scope: who is covered, which shifts, field versus office

Define coverage by role and work pattern, not by a blanket 'all employees'. A back-office accountant who sits at one desk needs web or kiosk attendance, and requiring a GPS punch from her adds data collection with no operational purpose, which is exactly what purpose limitation under DPDP tells you to avoid. A medical representative who visits eight clinics a day, a security guard rotating between three client sites, and a housekeeping supervisor covering four housing societies have a genuine reason for location-verified punches.

Specify the shifts and locations to which the policy applies. For a security agency, that might read: 'all guards and supervisors deployed at client sites, for every rostered shift including night posts from 20:00 to 08:00'. For a field-sales team: 'first and last punch of the day and each client visit check-in'. Name the roles that are exempt and the method they use instead, so the exemption is a rule rather than a favour.

Cover contract and third-party staff explicitly. If your housekeeping contractor's staff mark attendance on your app, your policy must say so and the contractor must issue the notice to them, because you are collecting their data even though they are not your employees. The principal employer's obligations on records are described in contract labour compliance for principal employers.

  • List covered roles by work pattern: field, multi-site, deployed at client premises
  • List exempt roles and the attendance method they use (web, kiosk, biometric)
  • Include contract staff and make the contractor responsible for issuing the notice

What is collected and when: punch-only versus continuous

This is the clause employees care about most and the one most policies leave vague. There are two fundamentally different designs. Punch-only collection records a single coordinate, timestamp and accuracy reading at check-in and check-out (and optionally at each client-visit event the employee initiates). Continuous tracking records the device location at intervals throughout the shift, typically every few minutes, to produce a route or to confirm a guard stayed at the post.

Punch-only is sufficient for most attendance and payroll purposes and is far easier to justify under data minimisation. Continuous tracking is defensible only for roles where presence throughout the shift is the service being paid for, such as security guards at a client post or delivery riders on a route, and even then it should stop automatically at check-out. The policy must state which design applies to which role, the interval if continuous, and that no location is collected outside working hours or when the employee is checked out.

State precisely what accompanies each punch: coordinates, timestamp, GPS accuracy in metres, device identifier, whether a selfie or face verification was taken, and whether mock-location was detected. Employees should be able to see their own punch history in the app; transparency reduces the suspicion that fuels resistance.

  • Default to punch-only collection; justify continuous tracking role by role
  • Continuous tracking must stop at check-out and never run outside shifts
  • List every field captured with a punch, including accuracy and selfie status
  • Give employees self-service visibility of their own punch history

Geofence radius, exceptions and device rules

A geofence is the boundary within which a punch counts as on-site. The radius has to match the physical site and the accuracy of consumer GPS, which in a dense urban area with tall buildings can drift by 30 to 50 metres and in a basement may fail entirely. A 100-metre radius around a standalone factory gate is tight and workable. The same 100 metres around a ground-floor shop inside a mall will produce constant failures; you may need 150 to 250 metres or a second geofence at the staff entrance. Large campuses can have multiple geofences, one per gate or block.

Write the exception path into the policy. If a punch falls outside the geofence, the app should still record it as an out-of-range punch and route it to the manager for approval rather than silently rejecting it. The employee should not be left with no record at all. Official outdoor duty, a client meeting away from the base, or a site with known GPS problems should be pre-approved reasons, each requiring a comment from the employee and a decision from the manager within a fixed number of days.

Device rules close the obvious loopholes. Fake-GPS apps on Android can place a phone anywhere on the map; the policy should state that mock-location flags will be recorded, that developer-mode spoofing is a disciplinary matter, and that attendance must be marked from the employee's registered device. Explain what happens when a phone is lost or changed: a new device registration approved by HR, not an informal switch. The technical side is covered in how to prevent GPS spoofing in attendance.

  • Set the radius per site after a test walk, not one number for the whole company
  • Record out-of-range punches and send them to approval; never discard them
  • Pre-define approved exception reasons: outdoor duty, client visit, known GPS dead zone
  • Register one device per employee; treat mock-location detection as a disciplinary trigger

Consent, notice, retention and access under DPDP

Location data collected for attendance is personal data. Whether you rely on consent or on the employment-purpose basis under the DPDP Act, you still owe the employee a notice that explains what is collected, why, how long it is kept, who can see it, and how they can raise a grievance. Issue the notice before the first punch, in a language the employee reads, and keep a record of acknowledgement. For workers who are not comfortable reading, a supervisor-led briefing with a signed attendance sheet of the briefing itself is a reasonable approach.

Retention should be tied to a purpose. Attendance records that feed payroll and statutory registers need to be kept for the periods the labour laws require; raw location coordinates behind those punches usually do not need to live as long. A workable rule is to retain raw location data for the period needed to close payroll disputes and audits (many companies choose the current financial year plus one), then delete or anonymise it, while the attendance record itself (present, late, hours) is kept as long as the wage register.

Access should be restricted to named roles: the employee sees their own data, the reporting manager sees their team, HR and payroll see what they need for processing, and nobody else. Log every access to location history. If a client under a security or facility contract asks for guard location data, provide site-level attendance and man-hour reports, not raw GPS trails, unless the contract and the notice to the guard specifically cover that sharing.

  • Issue a plain-language notice before the first punch and keep proof of acknowledgement
  • Retain raw coordinates only as long as disputes and audits require; keep the attendance outcome longer
  • Restrict access by role and log every view of location history
  • Share site-level reports with clients, not raw GPS trails, unless expressly covered

Corrections, regularization and disciplinary clauses

Every GPS attendance policy needs a correction process, because devices fail, networks drop and people forget. Define what an employee must do when a punch is missing or out of range: raise a regularization request in the app within a set window, typically 3 to 7 days, with a reason and any supporting evidence such as a client visit confirmation or a supervisor's note. Define who approves (reporting manager, with HR review for repeated requests), and the monthly cap beyond which requests are escalated. The full process is described in attendance regularization process and policy.

Be explicit about what counts as misconduct. Marking attendance for someone else, using a mock-location app, marking from outside the site without an approved exception, and repeatedly leaving the site after punching in are all different acts and deserve graded consequences: a warning, a recorded late or half-day, LOP for the day, and formal disciplinary action for deliberate fraud. Tie the grading to your existing standing orders or HR manual so the GPS policy is not a parallel legal system.

Make clear that the manager's decision on a punch affects pay. If an out-of-range punch is rejected, the day is treated per the late coming policy or as LOP, and the payroll cutoff date is the deadline after which corrections flow into the next month. Employees will accept strict rules far more readily when the rules are known in advance and applied uniformly.

  • Set a regularization window (3–7 days), an approver chain and a monthly cap
  • Grade consequences: warning, late mark, LOP, disciplinary action for deliberate fraud
  • Link the policy to existing standing orders rather than creating a separate code
  • State the payroll cutoff after which corrections move to the next cycle

Sample GPS attendance policy clauses and how to roll them out

The clauses below are written to be adapted. Replace the bracketed items with your own values, remove clauses that do not apply, and have the final version reviewed against your state's Shops and Establishments Act, your standing orders and your DPDP notice. The wording is deliberately plain so that a supervisor can explain each clause in Hindi or a regional language without losing the meaning.

Roll-out matters as much as drafting. Announce the policy at least two weeks before enforcement. Run a no-penalty pilot for one full pay cycle so employees learn the app and you learn where the geofences are wrong. Hold a fifteen-minute briefing per team, walk through the four employee questions, and collect acknowledgements. Publish the policy inside the app or the employee self-service portal so nobody can claim they never saw it. Attend Mitra supports this rollout with per-site geofences with configurable radius, punch-only GPS capture with mock-location flagging on Android, optional selfie or face verification on the punch, an in-app regularization workflow with approval and audit trail, and employee self-service visibility of punch history. The feature detail is on the GPS attendance software page and the GPS attendance glossary entry.

  • Clause 1 – Purpose: This policy governs the use of GPS-based attendance to record the presence of employees at their assigned place of work for the purpose of attendance, payroll and client reporting. Location data is not collected for any other purpose.
  • Clause 2 – Scope: Applies to [field sales staff, security guards and supervisors, housekeeping staff deployed at client sites] for all rostered shifts. [Head-office staff] are exempt and mark attendance via [web or kiosk].
  • Clause 3 – Data collected: At check-in and check-out the app records GPS coordinates, GPS accuracy, timestamp, device ID, geofence result and [selfie or face verification result]. No location is collected between check-out and the next check-in or outside working hours. [For guard roles: location is additionally recorded at [15]-minute intervals during the rostered shift only.]
  • Clause 4 – Geofence: Each site has a defined geofence of [100–250] metres set by [Operations/HR]. A punch inside the geofence is recorded as on-site. A punch outside is recorded as out-of-range and referred to the reporting manager.
  • Clause 5 – Devices: Attendance must be marked from the employee's registered device. A change of device requires HR approval. Use of mock-location or fake-GPS applications, developer-mode location overrides or another person's device is prohibited.
  • Clause 6 – Exceptions: Official outdoor duty, client visits away from the base site and documented GPS dead zones are approved exception reasons. The employee must submit the reason with the punch or within [3] working days.
  • Clause 7 – Corrections: Missed or incorrect punches must be regularized in the app within [5] working days with a reason. The reporting manager decides within [2] working days. More than [3] requests in a month are reviewed by HR. Requests after the payroll cutoff of the [25th] flow into the next cycle.
  • Clause 8 – Consequences: Out-of-range punches without approved reason are treated as [late mark/half day] per the attendance policy. Marking attendance for another person, spoofing location or leaving the site after check-in without permission is misconduct under [standing orders/HR manual, clause reference].
  • Clause 9 – Privacy: Location data is stored encrypted, accessible only to the employee, their reporting manager, HR and payroll. Raw location data is retained for [current financial year plus one year] and then deleted; attendance outcomes are retained per statutory register requirements. Employees may view their own history in the app and raise concerns with [HR contact].
  • Clause 10 – Acknowledgement: This policy takes effect on [date]. Each covered employee will receive a copy and a briefing and will acknowledge receipt in the app or on the briefing register.

Frequently Asked Questions

Can an employer legally use GPS attendance for employees in India?
Yes. Location collected for attendance is personal data under the DPDP Act 2023, so the employer needs a lawful basis, a clear notice explaining purpose, retention and access, and reasonable security. Collecting location only at check-in and check-out, and only during working hours, is the easiest design to justify. A written policy is how you evidence all of this.
Should GPS attendance track employees throughout the shift or only at punch time?
Default to punch-only. Continuous tracking is justifiable only for roles where presence throughout the shift is the service itself, such as guards at a client post or riders on a route, and it must stop at check-out. Write the design, the interval and the roles into the policy so employees know exactly when their location is recorded.
What geofence radius should a GPS attendance policy specify?
Set it per site, not company-wide. A standalone factory gate can work at around 100 metres; a shop inside a mall or an office in a dense high-rise area may need 150 to 250 metres or a second geofence at the staff entrance. Walk the site with the app before fixing the radius, and record out-of-range punches for approval rather than rejecting them.
How should the policy handle fake GPS or mock-location apps?
State that attendance must be marked from a registered device, that mock-location detection is recorded with the punch, and that using spoofing tools is misconduct under your standing orders. Pair the rule with technical controls: Android mock-location flagging, selfie or face verification and per-site geofences, so the policy is enforceable rather than aspirational.
How long should GPS attendance data be retained?
Separate the raw coordinates from the attendance outcome. Keep the attendance record (present, late, hours) as long as your wage and attendance registers require under labour law. Keep raw location data only as long as needed to close payroll disputes and audits, many companies choose the current financial year plus one, then delete or anonymise it.

Related guides

Ready to put this into practice?

Start your free trial or book a live demo with our team.