Guides

    Biometric Clock-In (Fingerprint or Face): What the GDPR and AEPD Say

    RegulaKitAugust 11, 2026

    The Spanish DPA's shift on biometrics

    In November 2023 the Spanish Data Protection Agency (AEPD) issued guidance tightening the use of biometric data for attendance control. Biometric data is a special category under Article 9 of the GDPR, so processing it requires a reinforced legal basis and, as a rule, the worker's consent is not enough, given the imbalance in the employment relationship.

    Is fingerprint clock-in illegal?

    It is not automatically illegal, but the AEPD considers that, unless a law expressly authorises it, using biometrics for simple time tracking is disproportionate where less intrusive alternatives exist. The company must carry out a data protection impact assessment (DPIA) before deploying it.

    Employee consent alone is not a sufficient basis to process their fingerprint or face for clock-in purposes.

    Requirements if you still use it

    • Identify a valid legal basis under Article 9(2) GDPR.
    • Carry out a prior impact assessment.
    • Apply the principles of minimisation and proportionality.
    • Inform transparently and offer an alternative.

    Safe alternatives

    Most SMEs can comply with time tracking using non-biometric methods: PIN, card, a mobile app with one-off geolocation, or web clock-in. They are reliable, traceable and do not process special categories of data.

    With RegulaKit your staff clock in from a phone or browser without fingerprints, complying with the GDPR. Estimate the cost of non-compliance with our penalty calculator.

    Conclusion

    After the AEPD's criterion, the prudent move is to avoid biometrics for clock-in unless there is specific legal cover. Digital alternatives work just as well and cut the penalty risk.

    Frequently Asked Questions

    Can I use fingerprints for my staff to clock in?

    Only with a reinforced legal basis under Article 9 GDPR and a prior impact assessment; the AEPD deems it disproportionate where alternatives exist.

    Is employee consent enough?

    Not on its own. The employment relationship is imbalanced, so consent is not a sufficient basis.

    Is biometric clock-in illegal?

    Not automatically, but it demands strict requirements and, absent legal cover, is usually disproportionate.

    What alternatives do I have?

    PIN, card, mobile app or web clock-in are reliable methods that do not process biometric data.

    Do I need an impact assessment?

    Yes, a DPIA is mandatory before deploying a biometric attendance system.

    Does your company comply with time tracking law?

    Try RegulaKit. Digital time tracking, vacation management and full compliance.

    Request a Demo