On November 24, the Spanish Data Protection Agency (AEPD) published its Guide on Attendance Tracking Using Biometric Systems. The truth is that, following several reports and guidelines from other supervisory authorities, the sector was eagerly awaiting the Agency’s definitive stance, as it had not previously issued such a comprehensive opinion on these processing activities. Specifically, we are referring to time-and-attendance systems (clocking in) and access control systems using biometric identification (such as clocking in with a fingerprint or gaining access via facial recognition, etc.).
The truth is that, after learning of the AEPD’s opinion, many would surely have preferred that it had not weighed in on the matter. The fact is that this guide is a direct blow to the very foundation of biometric identification systems in general, and particularly to attendance and access controls in the workplace. In it, the AEPD revises some of its previous criteria on the matter and clarifies some of the essential requirements that must be met when processing data.
We could oversimplify things and just say that, as of now, such activities cannot be carried out. But, even if only by a very small margin, that’s not exactly the case, so below we’ll outline the most important points from the Agency’s new guide. We promise to focus on what matters and explain it as simply as possible.
The General Data Protection Regulation (GDPR) generally prohibits the processing of special category data, which may be processed only in exceptional cases if any of the circumstances provided for in the Regulation itself apply. Biometric data constitutes special-category data when used to“uniquely identify a natural person.” Based on this mathematical concept of “uniqueness” associated with the purpose of identification, it appears that the AEPD initially interpreted that, if biometric data were used for identification purposes, it would be considered special-category data, but not if it were used in authentication systems. We will not delve further into this point, given that the European Data Protection Board has already clarified that, ultimately and to put it very simply, if an authentication process requires identification or if identification occurs simultaneously, the biometric data is being used to identify a specific natural person—and that is what matters in determining whether special-category data is being processed. This is one of the reassessments now being made by the AEPD.
It is therefore no longer possible to argue that what takes place during a time-and-attendance check or an access control check is authentication rather than identification, since it amounts to the same thing.
It is therefore necessary to determine whether the prohibition on the processing of biometric data can be waived under any of the exceptions set forth in the GDPR. Among the scenarios outlined in the Regulation for the processing of special-category data, only the following two would apply for the purposes discussed here:
- If the employees' consent has been obtained, which must be informed and given unequivocally, specifically, and freely.
- If necessary to fulfill obligations or exercise rights under labor law and social security and social protection laws. Note, however, that this is subject to authorization by a European or national regulation or a collective bargaining agreement that establishes adequate safeguards for the rights and interests—in this case, those of employees.
Limitations
And this is where the story starts to turn into such a horror movie that it puts “The Exorcist” or the entire “Saw” series to shame. Why? Because in this new guide, the AEPD practically, practically, practically shuts the door tight on these two options:
- I previously understood that these processing activities could be justified by the existence of a legal provision that addressed them: Article 20.3 of the Workers’ Statute regarding access control and Article 34.9 regarding time tracking, attendance monitoring, or clocking in for the workday—whatever we choose to call it. Now, echoing the position of other data protection supervisory authorities, it has revised its stance and determined that those articles are insufficient because they do not expressly mention the processing of biometric data and because they do not include the safeguards that must be applied to protect employees’ privacy.
- It also states that consent cannot serve as a legal basis for such processing either, since in an employer-employee relationship it must be presumed that the employee will not freely give consent, given the company’s dominant position.
- Even if free consent were possible, this would imply that an alternative must be provided for those employees who do not consent to the processing of their biometric data; and if that alternative is less invasive of employees’ privacy, this implies that the processing of biometric data is not indispensable and, therefore, pursuant to the principle of data minimization (not processing data that is not strictly necessary), it is not proportionate and cannot be carried out.
Conclusion: It becomes extremely difficult, if not impossible, to rely on biometric identification systems for these purposes within the company.
Is there no solution? We very much fear that, as long as there is no European or Spanish regulation specifically governing these biometric checks, the only way to process this type of data in the workplace is to negotiate it and expressly include it in a collective bargaining agreement, along with the safeguards that companies must implement when adopting these systems to ensure their employees’ rights.
Furthermore, if—with a great deal of luck—you manage to overcome this first hurdle, you would then have to meet the rest of the requirements set forth by the AEPD in this guide. And be warned: these requirements are neither few in number nor easy to meet, and they extend to other possible uses of biometric data outside the workplace.
So, if by any chance lawmakers were to decide to regulate these biometric control systems, please—while they’re at it—don’t skip the data protection impact assessment process, as that will ultimately save companies money when it comes to adopting these systems.
Ruth Benito Martín, of Counsel at ELZABURU


