What the law requires
- •Biometric data is special-category (Art. 6): processing generally requires explicit consent, and Board guidance expects biometrics to be used only where less intrusive means are insufficient (necessity & proportionality).
- •A privacy notice (aydınlatma yükümlülüğü) at collection, in clear Turkish.
- •VERBIS registration for controllers above the thresholds, with processing purposes kept up to date.
- •Security measures aligned with the Board’s biometric-data guidance (encryption, access control, logging).
- •Cross-border transfers are tightly controlled — explicit consent or approved safeguards.
How NCheck supports it
- •On-premises deployment keeps biometric data in Türkiye — avoiding the transfer problem entirely.
- •A genuine alternative (RFID, barcode, manual check-in) supports the proportionality analysis for staff who decline.
- •Encrypted, non-reversible templates; raw images are not retained.
- •Retention limits, deletion tools and audit logs matching Board guidance.
Practical checklist
- ✓Document a necessity & proportionality assessment before go-live.
- ✓Prepare the aydınlatma notice in Turkish and capture explicit consent (use our free template).
- ✓Register or update VERBIS entries.
- ✓Keep biometric data local — prefer on-premises deployment.
- ✓Set retention periods and deletion for leavers (use our free template).
Download the free consent-form and retention-policy templates →
This page is general information, not legal advice. Laws change — confirm current requirements with your counsel.
← All regulations