Biometric Access Control and GDPR: What Employers Can and Cannot Do
    Access Control2026-05-273 min read

    Biometric Access Control and GDPR: What Employers Can and Cannot Do

    A fingerprint reader at the server room door is the easiest part of the project from a technical standpoint. The harder question is whether you are allowed to install it there at all — biometric data is a special category of personal data and plays by different rules than a proximity card.

    What the law actually says

    GDPR treats biometric data processed for identification purposes as special category data (Article 9), where processing is prohibited as a rule, with narrow exceptions. In the employment context, Polish labour law adds detail: processing an employee's biometric data is permitted where it is necessary for controlling access to particularly sensitive information or to premises requiring special protection.

    The operative word is necessary — not convenient, not modern. Biometrics at the main office entrance used by every employee is very hard to defend on that basis. Biometrics at the door of a server room, a sensitive records archive or a laboratory is entirely justifiable.

    Relying on employee consent as the legal basis is risky in practice: supervisory authorities consistently point out that consent given within a relationship of subordination can hardly be considered freely given. It is far safer to design the system around necessity rather than around consent forms.

    How to implement it properly

    First, assess whether the same objective can be achieved by less intrusive means — a card with a PIN, or two-factor confirmation. If it can, GDPR requires you to choose the lighter measure. Second, run a data protection impact assessment (DPIA) — with biometrics it is effectively mandatory. Third, look at system architecture. Good systems never store the fingerprint image, only an irreversible mathematical template; better ones keep that template exclusively on the user's card rather than in a central database. That single decision changes the risk profile and makes the solution far easier to defend.

    Then the standard package: a record of processing activities, a retention rule (the template is deleted the day employment ends or authorisation is withdrawn), formal authorisations, and a data processing agreement with the company servicing the system.

    A practical recommendation

    In most facilities the optimal model is hybrid: a card or mobile credential as the primary identifier throughout the building, with biometrics reserved for the doors of critical zones — server rooms, executive areas, archives. That arrangement is easy to justify legally, cheaper to deploy, and avoids the employee pushback that "biometrics everywhere" almost always triggers.

    Access control should increase security, not create legal exposure. A well-designed system does both at once: it protects critical zones and stands up to any inspection.

    Cookies

    We use cookies to ensure proper website operation, analyze traffic and personalize content. By clicking "Accept all", you consent to their use in accordance with our Privacy Policy.