© meeboonstocker on canva.com

Processing biometric data in the company

Note: This article has been machine translated and may therefore contain translation errors.

A contribution from

Alexander Brittner LL.M.

Salary Partner, Attorney at Law

Topics and keywords

Two-factor authentication (2FA) can go hand in hand with the processing of biometric data. It is useful for ensuring data security in the company, but raises the question of whether biometric information may also be compared in the employment relationship. Separate from 2FA, fingerprint scanners, Face ID or video surveillance provide security and convenient access, but raise legal questions. In this newsletter, we shed light on the conditions under which such procedures are permissible in the employment relationship and what additional obligations will arise in future from the AI Act(Regulation (EU) 2024/1689).

Legal framework according to GDPR and BDSG

Biometric data – such as fingerprints, facial geometry, iris or voice – are considered special categories of personal data under data protection law. Their processing is generally prohibited under Art. 9 GDPR and is only justified in narrowly defined exceptional constellations. In the employment context, explicit, voluntary consent is the main form of permission. § Section 26 BDSG sets high hurdles: Biometric procedures must be absolutely necessary for the respective purpose under employment law. Where milder means such as chip cards or transponders are available, these should be offered as an alternative.

However, the distinction is important: a photo or video only becomes a special category of biometric data if it is processed using special technical procedures for automated comparison. A pure visual inspection without automated recognition (e.g. video surveillance) does not fall under Art. 9 GDPR, but remains fully regulated as “normal” personal data processing.

Typical application scenarios and pitfalls

Labor courts have made it clear, for example, that there is generally no need to process biometric data for time recording using fingerprints. Even if consent has been given, the measure could therefore be unlawful.

Other measures such as access controls or 2FA solutions (e.g. Face ID or Windows Hello) can be designed to be more data protection-friendly if the biometric comparison takes place exclusively locally on the end device (“on-device”) and no central biometric databases are set up. However, a viable balancing of interests and the offer to use alternative login methods (PIN, password, FIDO2 token) remain essential.

Impact of the AI Act on the workplace

With the new AI regulation, the use of AI-supported biometric systems in the workplace has been given an additional level of regulation. Three areas are particularly relevant: prohibited practices, high-risk systems and transparency obligations.

However, unlike emotion recognition, untargeted biometric categorization or performance evaluation systems, pure 1:1 verification systems to confirm an identity for the purpose of access, to unlock a device or for security clearances do not fall under the strict requirements. GDPR obligations, in particular the necessity test, must also be complied with.

Practical recommendations

In practice, it is advisable to avoid processing biometric data of employees as far as possible. Where enrolment is necessary, alternatives (chip card, transponder, app) should be offered.

At the same time, experimental HR AI systems should be classified as potential high-risk systems at an early stage and subjected to a legal assessment. This could require risk management, technical documentation, logging or human monitoring procedures.

In any case, the internal data protection organization must be strengthened: Updated records of processing activities, a data protection impact assessment for systematic access controls, clearly communicated data subject rights and appropriate technical and organizational measures (access concepts, encryption, erasure concepts) must be implemented.

Conclusion

Biometric processes can increase security and convenience, but are highly sensitive from a legal perspective in the employment relationship. Mandatory fingerprint or Face ID solutions without alternatives entail considerable risks under labor and data protection law. At the same time, the AI Act tightens the regulatory framework, in particular by banning certain biometric AI practices. Close cooperation between management, data protection, IT, HR and co-determination bodies is essential for the design and implementation of these steps.

Downloads

Share this page

Similar posts


Contact

Client Login