What the law requires
- Biometric data is special-category (Art. 6): processing generally requires explicit consent, and Board guidance expects biometrics to be used only where less intrusive means are insufficient (necessity & proportionality).
- A privacy notice (aydınlatma yükümlülüğü) at collection, in clear Turkish.
- VERBIS registration for controllers above the thresholds, with processing purposes kept up to date.
- Security measures aligned with the Board’s biometric-data guidance (encryption, access control, logging).
- Cross-border transfers are tightly controlled — explicit consent or approved safeguards.
How NCheck supports it
- On-premises deployment keeps biometric data in Türkiye — avoiding the transfer problem entirely.
- A genuine alternative (RFID, barcode, manual check-in) supports the proportionality analysis for staff who decline.
- Encrypted, non-reversible templates; raw images are not retained.
- Retention limits, deletion tools and audit logs matching Board guidance.
Practical checklist
- Document a necessity & proportionality assessment before go-live.
- Prepare the aydınlatma notice in Turkish and capture explicit consent (use our free template).
- Register or update VERBIS entries.
- Keep biometric data local — prefer on-premises deployment.
- Set retention periods and deletion for leavers (use our free template).
Free templates: Download the free consent-form and retention-policy templates →
This page is general information, not legal advice. Laws change — confirm current requirements with your counsel.
Where this matters most
See how NCheck handles attendance in the sectors where these rules bite hardest: Manufacturing · Construction · Retail · Hospitality · all industries.
Deploy it the compliant way
Run NCheck fully on your own server — data never leaves your network — or in our EU-hosted cloud. Either way, only encrypted templates are stored, never raw images. About on-premises → · Security & compliance →