What the law requires
- •Biometric identification data is special-category data (Art. 9): processing is prohibited unless an exception applies — in employment, explicit consent is the usual basis, and it must be freely given with a real alternative offered. Note: several member-state regulators (e.g. Spain’s AEPD, France’s CNIL, the Dutch AP) consider workplace biometrics disproportionate even with consent — assess necessity and proportionality per country.
- •A data-protection impact assessment (DPIA) before deployment (Art. 35 — large-scale processing of special categories).
- •Data minimisation, storage limitation and security of processing (Art. 5 and 32): encryption, access controls, no keeping data longer than needed.
- •Transparency and rights: a clear privacy notice, records of processing, and honouring access, erasure and consent-withdrawal requests.
- •Transfers outside the EU/EEA require safeguards (adequacy decision or standard contractual clauses).
How NCheck supports it
- •Full on-premises deployment — biometric data never leaves your servers or your country; the cloud option is EU-hosted — see on-premise attendance software.
- •Encrypted, non-reversible templates — raw face, fingerprint or iris images are not retained.
- •Consent capture at enrolment, with RFID, barcode or manual check-in as a genuine alternative for staff who decline.
- •Retention limits and deletion tools, plus a full audit trail for accountability.
Practical checklist
- ✓Run and document a DPIA before go-live.
- ✓Offer a non-biometric alternative and record consent (use our free template).
- ✓Set retention periods and automatic deletion for leavers.
- ✓Add the system to your records of processing and update the privacy notice.
- ✓Prefer on-premises deployment where data residency is critical.
Download the free consent-form and retention-policy templates →
This page is general information, not legal advice. Laws change — confirm current requirements with your counsel.
← All regulations