Is Fingerprint-Based Time and Attendance Tracking of Employees Lawful? Biometric Data and the GDPR – an ANSPDCP Case Study

Biometric time and attendance systems for employees and the limits on the processing of biometric data

The use of a fingerprint-based biometric time and attendance system is an increasingly common technical solution among organisations seeking to control access to their premises and to keep records of employees’ working time.

From a data protection perspective, however, the question is not merely whether the technology is effective, but whether the processing of employees’ fingerprints is lawful under the GDPR, whether there is an appropriate legal basis and, above all, whether the use of biometric data is necessary and proportionate.

A recent case examined by the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) is relevant in this respect. Following an investigation, the Authority found an infringement of Article 5(1)(c) in conjunction with Article 9 of Regulation (EU) 2016/679 and imposed a fine of RON 26,236, the equivalent of EUR 5,000. The investigation concerned the use of employees’ fingerprints for time recording and access control.

The case provides a useful starting point for analysing the obligations of an employer that intends to use biometric data in the workplace.

1. What is biometric data and why does it enjoy special protection?

Under Article 4(14) GDPR, biometric data means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that person.

A fingerprint is one of the forms of data that may fall within this category where it is processed for the purpose of identifying a person or verifying their identity.

It is subject to a special legal regime.

Article 9(1) GDPR lays down, as a general rule, a prohibition on processing biometric data for the purpose of uniquely identifying a natural person, unless one of the conditions set out in Article 9(2) applies.

Consequently, in the case of a fingerprint time and attendance system, the employer cannot rely solely on the fact that it wishes to verify employees’ attendance.

A further assessment of the lawfulness of processing biometric data is required.

2. Fingerprint time recording and the GDPR: why a single legal basis is not enough

Where biometric data is concerned, the general conditions for lawful processing under Article 6 GDPR and the specific conditions under Article 9 GDPR must be assessed together.

Article 6 GDPR sets out the circumstances in which the processing of personal data is lawful, whereas Article 9 GDPR establishes an additional regime for special categories of personal data.

Accordingly, for a biometric time and attendance system for employees, the controller must be able to identify:

  • the legal basis for the processing;
  • the applicable special condition under Article 9(2) GDPR;
  • the specific purpose of the processing;
  • the necessity of using biometric data;
  • the proportionality of the measure;
  • whether or not less intrusive alternatives exist.

The mere existence of a legitimate purpose, such as recording working time or controlling access to the employer’s premises, does not in itself resolve the question of lawfulness.

3. The data minimisation principle – Article 5(1)(c) GDPR

One of the central principles in assessing a fingerprint time and attendance system is the principle of data minimisation.

Article 5(1)(c) GDPR provides that personal data must be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed”.

This principle is of particular importance where biometric data is concerned.

The fact that a biometric system is high-performing, fast or difficult to circumvent does not automatically mean that the processing of fingerprints is necessary.

The controller must assess whether the intended purpose can be achieved by means that entail a lesser interference with employees’ private lives.

In the case of electronic time recording, consideration should be given, for example, to the use of:

  • individual access cards;
  • personal codes;
  • time-recording software applications;
  • other identification mechanisms that do not involve the processing of biometric data.

The relevant question is therefore not merely “Is fingerprint time recording effective?” but rather “Is the processing of fingerprints necessary to achieve the intended purpose?”

4. The existence of a less intrusive alternative

This is one of the most important conclusions to be drawn from the case examined by the ANSPDCP.

According to the Authority’s findings, the purposes pursued through the biometric system – access control and the recording of working time – could have been achieved by alternative means that are less intrusive to employees’ privacy. Accordingly, the Authority ordered the biometric system to be replaced with an alternative solution capable of achieving the same purposes without processing biometric data.

This approach is relevant to any employer intending to introduce a biometric time and attendance system.

Before implementation, an assessment of the available alternatives should be documented. It is not sufficient for the employer to assert that a fingerprint system is more convenient or more secure.

It must be assessed whether a non-biometric solution can adequately perform the same functions.

If so, the use of biometrics may raise serious concerns in light of the data minimisation principle.

5. Is it lawful to use employees’ fingerprints for time and attendance purposes?

The question cannot be answered in the abstract with a simple “yes” or “no”.

The lawfulness of a fingerprint time and attendance system must be assessed in light of the specific circumstances of the processing and of whether the conditions laid down by the GDPR are met.

Nevertheless, the fact that processing is intended to record working time does not, in itself, mean that the employer may use biometric data.

In such a situation, the following must be assessed cumulatively: legal basis + Article 9 GDPR condition + necessity + proportionality + data minimisation + availability of alternatives.

This assessment is all the more important given that a fingerprint is a biometric characteristic permanently linked to the individual.

6. Can the employer rely on employees’ consent?

A problem frequently encountered in practice is the attempt to justify biometric time recording by obtaining employees’ written consent.

Consent, however, should not be regarded as an automatic solution.

The GDPR provides that, in order to be valid, consent must be freely given, specific, informed and unambiguous. Moreover, Recital 43 of the Regulation draws attention to situations in which there is a clear imbalance between the data subject and the controller.

In employment relationships, the existence of a relationship of subordination therefore calls for careful scrutiny of whether consent is genuinely freely given.

More importantly, even where valid consent exists, it does not remove the other obligations laid down by the GDPR.

The controller must still comply with the principles set out in Article 5 GDPR and be able to justify the necessity and proportionality of the processing.

Therefore, an employee’s signature on a consent form does not automatically render a fingerprint time and attendance system lawful.

7. The employer’s accountability obligation

The GDPR requires the controller not only to comply formally with the rules but also to be able to demonstrate compliance.

Article 5(2) GDPR enshrines the principle of accountability, under which the controller is responsible for compliance with the data processing principles and must be able to demonstrate such compliance.

Where a biometric system is used for employee time and attendance, the internal documentation should make it possible to justify the decision to implement it.

Depending on the circumstances, this may include:

  • identification of the purpose of the processing;
  • determination of the legal basis;
  • identification of the applicable Article 9 GDPR condition;
  • an assessment of the necessity of the processing;
  • a proportionality assessment;
  • an assessment of alternative solutions;
  • determination of the retention period;
  • determination of the persons authorised to access the data;
  • determination of the technical and organisational measures;
  • provision of information to employees;
  • a risk assessment;
  • documentation of the security measures.

Depending on the specific characteristics of the processing, the need to carry out a data protection impact assessment (DPIA) under Article 35 GDPR must also be considered.

8. Biometric data and the risk of a personal data breach

Another important aspect concerns the risks associated with processing biometric data.

A password can be changed.

An access code can be reset.

A card can be blocked and replaced.

A person’s biometric characteristics, however, cannot be replaced in the same way.

For this reason, any compromise of a biometric database may give rise to significant risks for the data subjects.

This feature must be taken into account when the employer assesses whether it is appropriate to use a fingerprint access control system or a biometric time and attendance system.

The GDPR requires the controller to implement technical and organisational measures appropriate to the risks of the processing.

Accordingly, the assessment must not be confined to the moment the fingerprint is collected but must cover the entire data lifecycle: collection, use, storage, access, transfer, erasure and eventual destruction.

9. What did the ANSPDCP find in this case?

In the case under review, the ANSPDCP found that a controller was using employees’ biometric data for access control and working-time recording without an appropriate legal condition under Article 9 GDPR and in breach of the data minimisation principle laid down in Article 5(1)(c) GDPR.

The Authority also held that the purposes pursued could have been achieved by alternative, less intrusive means.

As a result, a fine of RON 26,236, the equivalent of EUR 5,000, was imposed, together with a corrective measure requiring the biometric system to be replaced with an alternative solution.

The case is significant not only for the amount of the penalty but, above all, for the legal reasoning underlying the measure: the existence of a legitimate purpose is not sufficient where the controller chooses a means of processing that is more intrusive than necessary to achieve that purpose.

10. What should an employer check before implementing biometric time recording?

Before introducing a fingerprint time and attendance system, the employer should complete at least the following steps:

1. Define the purpose

It must be clearly established whether the system is used for time recording, access control, premises security or several distinct purposes.

2. Identify the legal basis

The applicable legal basis under Article 6 GDPR must be identified.

3. Assess Article 9 GDPR

For biometric data, the specific condition permitting the processing under Article 9(2) GDPR must also be identified.

4. Test necessity

It must be assessed whether the use of biometric data is genuinely necessary to achieve the intended purpose.

5. Assess the alternatives

Available non-biometric solutions must be identified, and it must be assessed whether they can adequately achieve the same purpose.

6. Assess proportionality

The employer’s needs must be weighed against the impact of the processing on employees’ rights and freedoms.

7. Comply with the data minimisation principle

It must be verified that the data collected and the way it is used are limited to what is necessary.

8. Set the retention period

It must be determined how long the data is retained and on what grounds that period is justified.

9. Implement security measures

Biometric data must be protected by technical and organisational measures appropriate to the risks.

10. Document the decision

The entire process must be documented so that the controller can demonstrate compliance with the GDPR.

11. Conclusions: biometric time recording must be necessary, not merely convenient

The case examined by the ANSPDCP sends an important message to employers: the use of modern technology is not, in itself, a legal justification for processing biometric data.

A fingerprint time and attendance system may be efficient, fast and accurate. However, these features must be weighed against the special nature of the data processed and the availability of alternative solutions.

Where biometric data is concerned, the GDPR assessment must start from one fundamental question:

Is the use of the employee’s fingerprint necessary to achieve the intended purpose, or can the same purpose be achieved by less intrusive means?

The answer to this question must be supported by a documented legal and technical assessment.

For employers, the implementation of a biometric time and attendance system, a fingerprint access control system or any technology involving the processing of employees’ biometric data should not be treated as a mere IT or administrative decision.

It is, first and foremost, a decision to process personal data, subject to the requirements of the GDPR and, in particular, to the rules applicable to special categories of personal data.

Consequently, before installing a biometric system, the controller must be able to provide documented answers to three essential questions:

Is there a legal basis?

Is a condition under Article 9 GDPR met?

Is the use of biometric data necessary and proportionate, having regard to whether less intrusive alternatives exist?

If these questions cannot be given a sound legal answer, the mere practical usefulness of a fingerprint time and attendance system is not sufficient to ensure compliance with the GDPR.

Author: P.A.

Post Views: 10