employee-biometric-data
Employee Biometric Data
Overview
Biometric data is classified as a special category of personal data under Art. 9(1) GDPR when processed for the purpose of uniquely identifying a natural person. Processing biometric data for employee timekeeping and access control is one of the most frequently scrutinised activities by European supervisory authorities. The general prohibition on processing special category data under Art. 9(1) means that employers must identify a specific exception under Art. 9(2), satisfy the proportionality requirement, demonstrate that no less intrusive alternative exists, and implement robust safeguards. National DPAs have issued substantial fines for biometric processing that fails these tests, including the landmark Clearview AI enforcement actions and sector-specific decisions on workplace fingerprint systems.
Legal Framework
Art. 4(14) — Definition of Biometric Data
"Biometric data means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data."
Art. 9(1) — General Prohibition
"Processing of [...] biometric data for the purpose of uniquely identifying a natural person [...] shall be prohibited."
Critical distinction: Biometric data processed for purposes other than unique identification may not be classified as special category data under Art. 9(1). However, in the employment context, biometric processing for timekeeping and access control is almost always for identification purposes.