A fingerprint or face scanner that recognises an employee at a door, a time clock or a computer processes biometric data (Article 4(14) GDPR). When the purpose is to uniquely identify a person, this is special category data, which may not be processed unless one of the exceptions in Article 9(2) GDPR applies (Article 9(1) GDPR). In employment a suitable exception is hard to find: neither the Law on Legal Protection of Personal Data (ADTAĮ) nor the Labour Code mentions biometric data, and an employee’s consent is rarely freely given.
So the practical answer is this: for time and attendance and access control, biometrics is almost never necessary. If it is used anyway on the basis of employee consent, the employee must have a real alternative without biometrics, and the employer must have a data protection impact assessment (DPIA) carried out before starting and a reasoned explanation of why a simpler measure did not work.
When it is biometric data
Biometric data is personal data resulting from specific technical processing relating to physical, physiological or behavioural characteristics that allow or confirm the unique identification of a person, such as facial images or dactyloscopic data (Article 4(14) GDPR). A photograph is not biometric data in itself: it becomes biometric data only when it is processed through specific technical means allowing identification (Recital 51 GDPR). A photo on an employee ID card is not biometrics. A face template in a terminal, against which the face of the person arriving is compared, is biometrics.
The European Data Protection Board (EDPB), in its Guidelines 3/2019 on video devices, sums this up in three criteria: the nature of the data (physical, physiological or behavioural characteristics), the means and way of processing (specific technical processing) and the purpose (to uniquely identify a person) (section 5.1). Ordinary video footage that is not technically processed for identification is not, in itself, biometric data. Video surveillance, GPS and call recording at work are covered in our article on employee monitoring.
Why an employer struggles to find a legal basis
The law does not provide for biometrics. Article 9(2)(b) GDPR allows special category data to be processed only where this is necessary to carry out obligations or exercise rights in employment law, and only as far as Union or national law, or a collective agreement under national law with appropriate safeguards, allows. The Labour Code requires working time records, but they are kept in timesheets in a form approved by the employer, which may be filled in and stored electronically (Article 120(1) and (3) DK). The law does not prescribe the method, let alone a biometric one. Member States may introduce further conditions for biometric data (Article 9(4) GDPR), but biometric data is not mentioned in either ADTAĮ or the Labour Code. In our view, without such a clause in a collective agreement, point (b) does not justify biometrics for time and attendance or access control, and even with one the employer would have to show that biometrics are necessary.
Consent is rarely free. What remains is explicit consent (Article 9(2)(a) GDPR). But an employee who depends on the employer can rarely refuse freely – see our article on employee consent. Consent can only be free when nothing happens to the person who refuses.
If you rely on consent, an alternative is essential. In its guidelines on video devices, in an example on entering a building by face recognition on the basis of consent, the EDPB says that “the controller must always offer an alternative way to access the building, without biometric processing, such as badges or keys” (section 5.1, example 3). Where consent is required, the alternative must come without restrictions or additional cost, and it is also needed for people whose biometric data the device cannot read and for when the device fails (paragraph 86). The guidelines concern video devices, but in our view the same applies to fingerprints: without a real alternative, consent is not free. A card, a PIN code or a key must be a real choice, not a penalty for refusing.
The Article 29 Working Party, in an opinion on data processing at work adopted before the GDPR applied, said that time and attendance systems, including biometric ones, pose risks because they give the employer too much knowledge of and control over the employee’s activity (WP 249, section 5.5), and, on video analytics, that employers should not use facial recognition technologies; exceptions are possible only in extreme cases (section 5.6).
Proportionality: can the same be achieved more simply?
Even with a legal basis, only what the purpose needs may be collected (Article 5(1)(c) GDPR). The EDPB recommends assessing the impact on rights before deploying biometrics and considering less intrusive means (section 5.1 of the guidelines). The same question is a mandatory part of a DPIA: an assessment of the necessity and proportionality of the processing (Article 35(7)(b) GDPR).
For one organisation handling sensitive data, its IT supplier proposed confirming staff logins to its system with biometrics, including fingerprints. Our lawyer replied that processing employees’ biometric data here carried a particularly high risk, that a lawful basis was hard to see, and that to defend itself before VDAI the organisation would have to show all the alternatives it had considered. The supplier then proposed an alternative: two-factor confirmation with a one-time code in an app, with no biometric data at all.
Another case is sobriety checks. An employer must suspend an employee who comes to work intoxicated (Article 49(1) DK), so checking sobriety serves a legitimate purpose. But the law does not provide that this is done by face recognition. We were asked by an employee whose workplace breathalyser scans the face, with no alternative, and anyone who is not tested is not allowed to work. In such a set-up consent is not free, and the lack of an alternative runs against the EDPB’s requirement. Where the face is scanned only to confirm who took the test, the employer must be able to explain why a simpler method, such as a result recorded by a responsible person, would not work.
DPIA and informing employees
Processing biometric data intended to identify a person for monitoring or control purposes is on VDAI’s list of operations that require a DPIA (point 4 of the VDAI list). The same list includes monitoring of employees’ behaviour, location or movement (point 10). The assessment is carried out before processing starts (Article 35(1) GDPR). In practice, organisations also come to us for a DPIA when the equipment, for example breathalysers with face recognition, is already installed. At that point the assessment no longer helps choose a solution, it only tests one already chosen, and if the conclusion is negative the equipment has to be changed or switched off. What the assessment consists of and how long it takes is covered in a separate article on DPIAs.
If the system also records employees’ location or behaviour, employees must be informed of this against signature or in another way that proves they were informed (Article 5(4) ADTAĮ).
Security: what the EDPB recommends
In a controlled environment, the EDPB recommends keeping the template on a device held and controlled only by the user, such as a card, and in a central database only where objectively needed, encrypted, with a key held only by the person. Templates and identity data should be kept in separate databases and encrypted, and raw data, such as facial images, should be deleted (section 5.2 of the guidelines). General security requirements are covered in our article on Article 32.
What happens when biometrics is used without a basis
The first risk is a fine. Infringing Article 9 and the basic principles falls in the highest tier of fines: up to twenty million euros or, for an undertaking, up to 4 % of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(5)(a) GDPR). Infringing the controller’s obligations, including the duty to carry out a DPIA, can lead to up to ten million euros or, for an undertaking, up to 2 % of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(4)(a) GDPR).
The second risk is a ban on the system. VDAI can impose a temporary or definitive limitation on processing, including a ban (Article 58(2)(f) GDPR). The investment in equipment is then lost, and working time records have to be organised again.
The third risk is damage. An employee who has suffered material or non-material damage as a result of an infringement has the right to compensation (Article 82(1) GDPR). If biometric data leaks, unlike a password, it cannot be changed.
When to call a lawyer
- before buying or deploying fingerprint or face recognition equipment;
- when a supplier says its system “complies with the GDPR” but you do not know where the templates are stored;
- when an employee refuses to use a biometric system;
- when biometrics is already in use and no DPIA has been done;
- when VDAI has asked about your processing of biometric data.
Frequently asked questions
Can we use fingerprints for time and attendance if employees agree?
Only if the consent is truly free: an employee can refuse and use a card or a code with no consequences. The Labour Code does not require biometrics for working time records (Article 120(3) DK), so you must justify why a simpler measure is not enough and carry out a DPIA.
Is an employee’s photo on an ID card biometric data?
No. A photograph becomes biometric data only when it is processed through specific technical means that allow a person to be uniquely identified (Recital 51 GDPR). A photo that a security guard compares with a face by eye is not biometric processing.
Do we need a DPIA if biometrics is used only for entry to the premises?
Yes. On VDAI’s list a DPIA is required when biometric data is processed for monitoring or control purposes (point 4), and access control is control. The assessment is carried out before processing starts.
Is a breathalyser with face recognition lawful?
The purpose of checking sobriety can be legitimate, because an employer must suspend an intoxicated employee (Article 49(1) DK). But face recognition needs an exception under Article 9(2), and if consent is relied on, the employee must have an alternative without biometrics. Without an alternative and without a DPIA, such a system is risky.
How to start
List every place where fingerprints or faces are used: doors, terminals, logins, breathalysers. Next to each, write what alternative is offered and where the templates are stored. Send us this list and the supplier’s description – we will assess whether the system can be defended before VDAI and what the DPIA is missing.
You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).
Email: info@linden.lt
More about this service: Data protection impact assessment.