What the law requires
- Biometric identification data is special-category data (Art. 9): processing is prohibited unless an exception applies — in employment, explicit consent is the usual basis, and it must be freely given with a real alternative offered. Note: several member-state regulators (e.g. Spain’s AEPD, France’s CNIL, the Dutch AP) consider workplace biometrics disproportionate even with consent — assess necessity and proportionality per country.
- A data-protection impact assessment (DPIA) before deployment (Art. 35 — large-scale processing of special categories).
- Data minimisation, storage limitation and security of processing (Art. 5 and 32): encryption, access controls, no keeping data longer than needed.
- Transparency and rights: a clear privacy notice, records of processing, and honouring access, erasure and consent-withdrawal requests.
- Transfers outside the EU/EEA require safeguards (adequacy decision or standard contractual clauses).
How NCheck supports it
- Full on-premises deployment — biometric data never leaves your servers or your country; the cloud option is EU-hosted — see on-premise attendance software.
- Encrypted, non-reversible templates — raw face, fingerprint or iris images are not retained.
- Consent capture at enrolment, with RFID, barcode or manual check-in as a genuine alternative for staff who decline.
- Retention limits and deletion tools, plus a full audit trail for accountability.
Practical checklist
- Run and document a DPIA before go-live.
- Offer a non-biometric alternative and record consent (use our free template).
- Set retention periods and automatic deletion for leavers.
- Add the system to your records of processing and update the privacy notice.
- Prefer on-premises deployment where data residency is critical.
Free templates: Download the free consent-form and retention-policy templates →
This page is general information, not legal advice. Laws change — confirm current requirements with your counsel.
Where this matters most
See how NCheck handles attendance in the sectors where these rules bite hardest: Manufacturing · Healthcare · Government · Enterprise · all industries.
Deploy it the compliant way
Run NCheck fully on your own server — data never leaves your network — or in our EU-hosted cloud. Either way, only encrypted templates are stored, never raw images. About on-premises → · Security & compliance →