The fingerprint terminal for clocking in, the facial recognition camera at the entrance turnstile: they are bought the way you would buy a time clock, and in legal terms they are nothing alike. A biometric system that does not fit properly within the GDPR is not a minor breach: it is the processing of special category data under a general prohibition, every day, across your whole workforce. And the decision to install it is usually taken by someone who has never heard of Article 9.
The good news is that the courts have mapped this out clearly. The leading decision is AAP Barcelona 72/2021, of 15 February, and its central distinction is the first question you should ask yourself.
The decisive question: does your system identify or only verify?
Not all biometrics carry the same weight. The criterion that separates the two regimes is technical, but it fits into one sentence. If the system compares the biometric data of the person presenting themselves against a database of templates in order to work out who they are (one-to-many), we are dealing with identification. If it compares that data against a single template already linked to that person, in order to confirm that they are who they say they are (one-to-one), we are dealing with verification or authentication.
In the light of that distinction, it may be understood that, under Article 4 GDPR, the concept of biometric data would cover both situations, both identification and verification/authentication. However, and as a general rule, biometric data will only be treated as special category data where it is subjected to technical processing aimed at biometric identification (one-to-many), and not in the case of biometric verification/authentication (one-to-one). [translation]
The practical consequence is enormous: one-to-many identification triggers the enhanced regime of Article 9; one-to-one verification, as a general rule, does not. Many clocking-in terminals run in identification mode because it is more convenient — the employee types no code, the system finds them in the database. That convenience of a few seconds changes the entire legal regime of the processing. In the case before it, the court had no doubt about the facial recognition system it examined: “This is not simple authentication but identification, and it therefore requires a dual legal basis”.
The legal starting point: a general prohibition
If your system carries out identification, its data falls within the special category of Article 9(1) GDPR, alongside health, political opinions and trade union membership. And the starting point of that provision is not authorisation subject to conditions: it is prohibition. AAP Granada 346/2019, of 20 May, and SAP Madrid 566/2019, of 17 July, say so in identical terms.
…Article 9(1) states that sensitive data deserves special protection, whether by reason of its nature or by reason of its connection with people's fundamental rights and freedoms. It therefore prohibits its processing, subject to certain exceptions. This means personal data revealing ethnic or racial origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data intended to identify a natural person uniquely, data concerning health, or data concerning a natural person's sex life or sexual orientation. [translation]
Why such severity over a fingerprint? Because the risk is of a different nature. A compromised password can be changed; a fingerprint or a face cannot. SAP Las Palmas 247/2020, of 6 November, ties this back to the recitals of the Regulation itself: “It refers to the latter [sensitive data] in recitals (51) and following, to which it affords special protection because the context of its processing could entail significant risks to fundamental rights and freedoms”.
Dual legal basis: one Article 6 ground is not enough
This is where most deployments fail. The company reasons: “I have a legal obligation to record working time, so the processing is justified”. That reasoning covers only half the ground. To process special category data you need two keys at once: a lawful basis under Article 6 and, in addition, one of the exceptions in Article 9(2) that lifts the general prohibition.
The existence of a public interest does not render lawful any and every kind of processing of personal data; regard must be had, first of all, to the conditions the legislature may have laid down, as Article 6 GDPR itself provides in paragraphs 2 and 3 (…). And where any of the personal data falling within the special categories of data referred to in Article 9(1) GDPR is to be processed, one of the circumstances set out in paragraph 2 must be present so as to lift the prohibition on processing such data, laid down as a general rule in paragraph 1. [translation]
And where the route chosen is consent, the court requires it to be explicit, not the tacit consent of someone who puts a finger on the reader because that is all there is: “for processing that requires special categories of data, as is the case with biometric data, the explicit consent of the data subject must be obtained as the basis for legitimising the uses and actions to be carried out with their information”. In an employment context, it is also worth remembering that consent is only valid if a real alternative exists: without one, it can hardly be freely given.
The last hurdle: the proportionality test
Even with both keys, the system has to pass a proportionality test: the intrusion involved in processing the biometric data of the whole workforce must be balanced against the purpose pursued and the safeguards in place. In the words of AAP Barcelona 72/2021, of 15 February, processing must observe “a minimum level of proportionality between the intrusion it entails and the safeguards accompanying it to remedy possible adverse effects”. If the same objective — knowing who comes in and when — can be achieved with a card, a code or one-to-one verification, imposing biometric identification on everyone is hard to defend.
The sensible decision is not always to remove the terminal: sometimes it is enough to reconfigure it to verification mode, document the proportionality test and put the legal bases in order. But that decision has to be taken on paper, not out of habit. You may also be interested in how the courts apply this same evidential logic in another area where companies lose avoidable cases: the five mistakes for which a company that registers a customer in a credit default register is found liable.
Does your company use biometric clocking in or access control?
Tell us what system you have — fingerprint, facial, identification or verification — and we will tell you, on the criteria the courts apply, whether it is properly grounded or what would need to change. No commitment.
Ask about my case by email