Skip to content
Free for up to 5 employees — face check-in in minutes.Start free →·Book a demo →
Compliance · EU

Biometric attendance under the GDPR

Biometric data used to identify a person is special-category data under Article 9 GDPR. Here is what that means for attendance systems — and how NCheck is built for it.

What the law requires

  • Biometric identification data is special-category data (Art. 9): processing is prohibited unless an exception applies — in employment, explicit consent is the usual basis, and it must be freely given with a real alternative offered. Note: several member-state regulators (e.g. Spain’s AEPD, France’s CNIL, the Dutch AP) consider workplace biometrics disproportionate even with consent — assess necessity and proportionality per country.
  • A data-protection impact assessment (DPIA) before deployment (Art. 35 — large-scale processing of special categories).
  • Data minimisation, storage limitation and security of processing (Art. 5 and 32): encryption, access controls, no keeping data longer than needed.
  • Transparency and rights: a clear privacy notice, records of processing, and honouring access, erasure and consent-withdrawal requests.
  • Transfers outside the EU/EEA require safeguards (adequacy decision or standard contractual clauses).

How NCheck supports it

  • Full on-premises deployment — biometric data never leaves your servers or your country; the cloud option is EU-hosted — see on-premise attendance software.
  • Encrypted, non-reversible templates — raw face, fingerprint or iris images are not retained.
  • Consent capture at enrolment, with RFID, barcode or manual check-in as a genuine alternative for staff who decline.
  • Retention limits and deletion tools, plus a full audit trail for accountability.

Practical checklist

  • Run and document a DPIA before go-live.
  • Offer a non-biometric alternative and record consent (use our free template).
  • Set retention periods and automatic deletion for leavers.
  • Add the system to your records of processing and update the privacy notice.
  • Prefer on-premises deployment where data residency is critical.

Free templates: Download the free consent-form and retention-policy templates →

This page is general information, not legal advice. Laws change — confirm current requirements with your counsel.

← All regulations

Where this matters most

See how NCheck handles attendance in the sectors where these rules bite hardest: Manufacturing · Healthcare · Government · Enterprise · all industries.

Deploy it the compliant way

Run NCheck fully on your own server — data never leaves your network — or in our EU-hosted cloud. Either way, only encrypted templates are stored, never raw images. About on-premises → · Security & compliance →

Start free Talk to us