Employee Biometric Data
Overview
Biometric data is classified as a special category of personal data under Art. 9(1) GDPR when processed for the purpose of uniquely identifying a natural person. Processing biometric data for employee timekeeping and access control is one of the most frequently scrutinised activities by European supervisory authorities. The general prohibition on processing special category data under Art. 9(1) means that employers must identify a specific exception under Art. 9(2), satisfy the proportionality requirement, demonstrate that no less intrusive alternative exists, and implement robust safeguards. National DPAs have issued substantial fines for biometric processing that fails these tests, including the landmark Clearview AI enforcement actions and sector-specific decisions on workplace fingerprint systems.
Legal Framework
Art. 4(14) — Definition of Biometric Data
"Biometric data means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data."
Art. 9(1) — General Prohibition
"Processing of [...] biometric data for the purpose of uniquely identifying a natural person [...] shall be prohibited."
Critical distinction: Biometric data processed for purposes other than unique identification may not be classified as special category data under Art. 9(1). However, in the employment context, biometric processing for timekeeping and access control is almost always for identification purposes.
Art. 9(2) — Exceptions Applicable to Employment
Key National Derogations
France — Art. L.1121-1 Labour Code + CNIL Framework:
- CNIL published dedicated guidance: "Règlement type biométrie" (Deliberation No. 2019-001, 10 January 2019)
- Biometric access control is permitted for access to premises, devices, and applications where justified by the context
- Storage preference hierarchy: (1) individual device held by employee (badge), (2) centralised database with employee control, (3) centralised database without employee control (requires strongest justification)
- The employee must be informed and provided an alternative non-biometric access method
Germany — Section 26(3) BDSG:
- Processing of special category data including biometrics is permitted for employment purposes where necessary for the exercise of rights or obligations under employment law, social security law, or social protection law
- Works council co-determination rights under Section 87(1)(6) BetrVG apply
Netherlands — UAVG Art. 29:
- Biometric processing is permitted for authentication or security purposes where necessary
- The Dutch DPA (Autoriteit Persoonsgegevens) has issued specific guidance restricting biometric processing to high-security contexts
Italy — Workers' Statute Art. 4 + Garante Guidance:
- Biometric access control requires trade union agreement or labour inspectorate authorisation
- The Garante has issued multiple decisions restricting biometric timekeeping to specific sectors
Sweden — Datainspektionen Decisions:
- The Swedish DPA fined a school SEK 200,000 for using facial recognition for attendance monitoring (DI-2019-2221), setting a strong precedent that biometric monitoring for attendance is disproportionate when simpler alternatives exist
Biometric Technologies in Employment
Fingerprint Recognition
Use cases: Timekeeping (clocking in/out), physical access control, device authentication.
Technical processing: Fingerprint scanner captures an image of friction ridges → image is processed to extract minutiae points → minutiae template is compared against stored templates → match/no-match result.
Privacy considerations:
- Template storage: Store templates on individual smart cards held by the employee (less intrusive) rather than in a centralised database (more intrusive)
- Revocability: Unlike passwords, fingerprints cannot be changed if compromised
- False acceptance rate (FAR) and false rejection rate (FRR) must be documented
- Employees with skin conditions, injuries, or disabilities affecting fingerprints must have an alternative access method
Atlas Manufacturing Group Example: Atlas installed fingerprint scanners for access to its R&D laboratory where proprietary formulations are developed. The DPO approved the deployment based on Art. 9(2)(b) (German BDSG Section 26(3)) for the R&D laboratory only, with the following conditions: (1) fingerprint templates stored on employee ID badges, not in a central database, (2) alternative PIN access available for employees who object or have medical conditions, (3) DPIA completed before deployment, (4) works council consulted and agreement obtained.
Facial Recognition
Use cases: Contactless access control, time and attendance, security zones.
Technical processing: Camera captures facial image → facial geometry is measured (distance between eyes, nose shape, jawline contour) → geometry data converted to mathematical template → template compared against enrolled images.
Privacy considerations:
- Facial recognition is significantly more intrusive than fingerprint scanning because it can operate without the employee's active cooperation or awareness (passive vs. active biometric)
- Continuous facial recognition in the workplace may constitute systematic monitoring, triggering additional DPIA requirements
- Risk of function creep: facial recognition deployed for access may be expanded to emotion detection, attention monitoring, or behavioural analysis
- Bias and accuracy: Facial recognition systems have documented higher error rates for certain demographic groups, creating discrimination risk
Supervisory Authority Position: Most European DPAs take the position that facial recognition for general time and attendance purposes is disproportionate when simpler alternatives (badge, PIN, fingerprint) are available. Facial recognition may be justified only for high-security access control where contactless verification is necessary (cleanroom environments, nuclear facilities).
Iris Scanning
Use cases: High-security access control, authentication in environments where hand-based biometrics are impractical (e.g., clean environments requiring gloves).
Privacy considerations:
- Among the most accurate biometric modalities (FAR below 0.0001%)
- Less affected by environmental factors than fingerprint
- Generally limited to high-security contexts where the heightened intrusion is justified
Voice Recognition
Use cases: Telephone-based authentication, call centre agent verification, voice-activated systems.
Privacy considerations:
- Voice data may reveal health information (fatigue, intoxication, emotional state), potentially creating additional Art. 9 issues
- Voice templates are more susceptible to spoofing than other biometric modalities
- Ambient noise and voice changes (illness, ageing) affect accuracy
Behavioural Biometrics
Use cases: Keystroke dynamics, gait analysis, mouse movement patterns.
Privacy considerations:
- Often collected passively without explicit employee action
- May reveal health conditions (tremor, cognitive impairment)
- The EDPB has not yet issued specific guidance on behavioural biometrics in employment, but existing principles on proportionality and transparency apply
Necessity Test Framework
Before deploying any biometric system, the employer must demonstrate that the biometric processing is genuinely necessary and that no less intrusive alternative would achieve the same purpose.
Step 1: Define the Specific Purpose
The purpose must be concrete, documented, and limited:
- "Controlling access to the R&D laboratory containing proprietary formulations" — acceptable
- "Improving workforce management" — too vague
- "Ensuring accurate time and attendance records" — biometric processing is unlikely to be necessary for this purpose