An employer asks for a fingerprint to operate the attendance system, installs a camera that "recognises" faces, or uses artificial intelligence software to score applicants and employees. The technology may promise speed and security, but that alone does not make it lawful. The employment relationship involves dependency, biometric data are particularly sensitive, and an error or breach cannot be remedied as easily as changing a password.
The short answer: Biometric timekeeping does not become lawful merely because it is convenient or because everyone has signed a form. The employer must demonstrate a specific purpose, a lawful basis, an exception permitting the processing of special-category data, strict necessity, proportionality, and the absence of a less intrusive means. Access to an exceptionally high-security area must be assessed differently from routine clocking in and out. Emotion recognition in the workplace is prohibited in principle under the AI Act, while other AI tools used for recruitment or workforce management may qualify as high-risk systems without being automatically prohibited.
1. What is biometric data, and what is not
The General Data Protection Regulation defines biometric data as data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a person, which allow or confirm that person's unique identification. This category may include fingerprints, facial templates, iris patterns, voice, or even gait when they are used for unique identification.
A simple identity photograph or footage from a camera does not automatically become "special-category biometric data." The decisive step is the technical processing that extracts features and compares them in order to identify or verify a particular person. This does not mean that an ordinary image is left unprotected; it remains personal data and is subject to the requirements of lawfulness, purpose limitation, data minimisation, and security.
The distinction has practical significance. A photograph in a company register, a security camera, and a system that converts a face into a numerical template in order to search for it in a database are three different things. In the last scenario, the strict protection afforded by Article 9 GDPR also applies.
2. The two legal "keys" that must be present together
When a system processes biometric data for unique identification, a general assertion that there is a "legitimate interest" is not enough. There must first be a lawful basis under Article 6 GDPR and, in addition, a specific exception to the prohibition in Article 9. The exception must correspond to the actual purpose and, where required, be grounded in EU or national law that provides appropriate safeguards.
In employment relationships, Article 27 of Law 4624/2019 permits processing when it is strictly necessary for a decision on entering into an employment contract or for the performance of that contract. It is not a general authorisation to install any system whatsoever. The employer must explain why the same purpose cannot be achieved with a card, PIN, physical access control, incident logging, or another less intrusive solution.
- Purpose: it must be specific and declared before processing begins.
- Necessity: the system must address a real, documented problem, not merely offer theoretical convenience.
- Proportionality: the interference with rights must not outweigh the benefit.
- Data minimisation: only what is needed may be collected, and only for as long as it is needed.
- Accountability: the employer must be able to demonstrate, rather than merely assert, compliance.
3. Timekeeping and access control are not the same
There are usually simpler means of recording routine arrival and departure. The argument that a fingerprint prevents "a colleague clocking in for someone else" does not, by itself, establish strict necessity. There must be real evidence of the risk, an assessment of alternatives, and documentation explaining why those alternatives fail.
By contrast, entry to a military installation, a laboratory containing extremely hazardous materials, or premises subject to a specific statutory security requirement may call for a different balancing exercise. The Hellenic Data Protection Authority describes this possibility narrowly: specific security requirements, the absence of another means, and a specific legal basis. It does not automatically extend to offices, shops, hotels, or warehouses.
Opinion 4/2026 of the Authority is illustrative. The Authority found that indiscriminate biometric identification of all public-sector employees for access and attendance, without sufficient proof of strict necessity and without ruling out less intrusive solutions, was incompatible with the data protection framework. The Opinion does not say that every biometric system is always unlawful; it says that generalised use without closely reasoned justification is not enough.
4. Why employee consent usually does not solve the problem
Valid consent must be freely given, specific, informed, and capable of being withdrawn without adverse consequences. There is an imbalance of power in the employer-employee relationship: an employee may reasonably fear that refusal will affect recruitment, shift allocation, or performance appraisal. For this reason, European and Greek authorities regard consent as a problematic basis in most employment contexts.
A form headed "I consent" does not cure a lack of necessity. Even when a card is offered as an alternative, it must be genuinely equivalent, with no delay, stigmatisation, additional monitoring, or risk of adverse treatment. Withdrawal must work in practice and lead to erasure where there is no other lawful basis for retention.
5. Cameras, facial recognition, and the difference between 1:1 and 1:N
A camera that records an area, a system that verifies whether the person standing before a sensor is the holder of a particular card, and a system that searches for a face across an entire database do not perform the same function. In 1:1 verification, a claimed identity is compared with a template. In 1:N identification, the system searches among many people to determine who the person is.
This distinction affects the level of risk and certain classifications under the AI Act, but it does not amount to automatic "authorisation." Even 1:1 verification must have a lawful basis, an Article 9 exception when it involves unique identification, a clear purpose, appropriate security, and limited retention.
Cameras installed to monitor staff performance or behaviour continuously are generally disproportionate. The Hellenic Data Protection Authority expressly states that cameras used for the purpose of monitoring employees are unlawful. Protecting a cash desk or a critical facility may be assessed differently, but even then the field of view, camera angle, audio capture, access, and retention period must be strictly limited.
6. AI that "reads" emotion, recruitment, or performance
The AI Act prohibits in principle the use of AI systems to infer emotions in the workplace, except where they are intended for medical or safety reasons. A tool claiming that it can detect from a face or voice whether an employee is angry, dishonest, anxious, or "uncooperative" lies at the heart of the prohibition. According to the consolidated text, the relevant provisions of Chapter II have applied since 2 February 2025.
Not every detection of a physical condition constitutes emotion recognition. Measuring fatigue or pain may be assessed differently, particularly when linked to a genuine safety purpose. The label chosen by the supplier is not decisive; what matters is what the system infers, from which data, and how the result is used.
AI tools that filter CVs, score applicants, recommend dismissal, allocate tasks, or evaluate behaviour and performance may fall within the high-risk systems listed in Annex III. This does not mean that they are all prohibited. It means that strict governance is required and that the GDPR, employment law, and anti-discrimination law already apply. Following the 2026 amendment, the principal obligations in Sections 1 to 3 of Chapter III for Annex III systems apply from 2 December 2027; they should not be presented as fully applicable in August 2026.
7. Impact assessment: scrutiny before deployment, not justification afterwards
The systematic processing of employees' biometric data for unique identification is included in the Greek list of processing operations that require a Data Protection Impact Assessment (DPIA). The assessment must take place before the system becomes operational. It describes the purpose and data flow, tests necessity and proportionality, assesses risks, and specifies technical and organisational measures.
A DPIA is neither an authorisation nor a certificate of lawfulness. If the underlying processing has no legal basis or a less intrusive solution is available, a well-drafted document does not make it lawful. If a high risk remains despite the measures, the controller must seek prior consultation with the Hellenic Data Protection Authority before starting the processing.
For security purposes, it matters whether the system stores a fingerprint image or a non-reversible template, whether the template remains locally on a card or in a central database, who has access, who the supplier is, whether cloud services outside the EEA are involved, when data are erased, and what happens after employment ends. Encryption reduces risk, but it does not cure an unlawful purpose.
8. Twelve questions the employer must be able to answer
- What is the system's precise purpose?
- What is the lawful basis under Article 6 GDPR?
- Which Article 9 exception permits biometric identification?
- What factual evidence demonstrates strict necessity?
- Which less intrusive solutions were considered, and why were they rejected?
- Does the system perform 1:1 verification or a 1:N search?
- Does it store an image, a template, a score, video, or an event history?
- How long are the data retained, and when are they permanently erased?
- Which recipients, technical providers, and cloud services are involved?
- Is there a transfer outside the European Economic Area?
- Was a DPIA completed before deployment, and what measures resulted from it?
- How can employees exercise their rights, and what non-biometric procedure is available in the event of a malfunction or dispute?
The answers must be set out in a clear privacy notice, not hidden in the supplier's general terms of use. The information must be provided before collection and be available in language that staff can understand.
9. What an employee can do, step by step
- Request written information. Ask about the purpose, lawful basis, Article 9 exception, categories of data, retention, recipients, supplier, cloud services, and any transfer.
- Request a genuine alternative. Ask whether you may use a card or another method without adverse consequences or additional inconvenience.
- Exercise your rights. Depending on the legal basis and circumstances, you may have rights of access, rectification, restriction, or objection. There is no general right to receive the entire DPIA, but you may request meaningful information about the processing and its risks.
- Request human review. If a solely automated decision produces legal effects or similarly significantly affects you, request human intervention, an opportunity to express your point of view, and a means of challenging the decision.
- Keep evidence lawfully. Retain notices, emails, forms, screenshots of company policy, and evidence of an adverse decision. Do not gain unauthorised access to company systems or copy colleagues' data.
- Contact the controller or DPO first. For a complaint alleging an infringement of your rights, retain your request and the response, or evidence that the usual one-month time limit has expired.
- Lodge a complaint with the Hellenic Data Protection Authority. Describe the employment relationship, the system, and the right you exercised, and attach the relevant documents. Employment-law or discriminatory treatment may also require a parallel referral to the competent labour authorities or a lawyer.
Useful model request: "Please inform me of the system's precise purpose and lawful basis, the applicable exception under Article 9 GDPR, the type of biometric template, the retention period, the recipients and processor, the non-biometric alternative, and the procedure for exercising my rights."
10. Four practical examples
Example A: a fingerprint instead of an attendance card
A company installs a fingerprint reader because it wants faster timekeeping. It documents no incidents of fraud, does not consider a card with a PIN, and asks everyone to "consent." Convenience and uniform application are not enough. The system presents a serious risk of failing the necessity and freely given consent requirements.
Example B: entry to a high-risk laboratory
Access is restricted to a very small number of authorised employees, a specific security requirement applies, and it is demonstrated that a card or code is insufficient. The biometric solution does not automatically become lawful, but it may be considered where there is a narrowly defined purpose, a specific legal basis, a DPIA, local template storage, strict access rights, and a short retention period.
Example C: AI in a video interview
The tool scores "enthusiasm," "honesty," and "emotional stability" from the applicant's face and voice. Inferring emotions for recruitment purposes falls within the AI Act prohibition and also raises serious data protection and discrimination concerns. An "AI-assisted" notice on the screen does not cure the prohibition.
Example D: an algorithm recommends dismissal
The system combines productivity, absences, and corporate communications and classifies employees as being at "high risk of leaving." Even if it does not use biometric data, the employer must consider transparency, accuracy, purpose, proportionality, possible discrimination, and Article 22 GDPR. A decision with a significant impact should not be treated as neutral merely because it originated in software.
11. Frequently asked questions
Is every workplace fingerprint system unlawful?
No, not as an absolute rule. Use for routine timekeeping is very difficult to justify when less intrusive solutions are available. It may be considered in an exceptional high-security area, but only with closely reasoned justification, an appropriate legal basis, and strong safeguards.
If I sign a consent form, is the system lawful?
Not automatically. Employee consent is often not considered freely given because of the relationship of dependency. It does not replace necessity, proportionality, security, or the other requirements.
May my employer keep an image of my fingerprint?
Storing a complete image significantly increases the risk and requires specific justification. Even a mathematical template is personal data and will usually be special-category biometric data when used for unique identification. Ask exactly what is stored and where.
Can I request a copy of the entire DPIA?
There is no general right to obtain the entire internal document. You do, however, have the right to meaningful information and access to your own data. Merely saying "we have a DPIA," without answering questions about the purpose, basis, data, and retention, is not enough.
What happens if the biometric template is leaked?
The controller must assess the breach and, where the relevant conditions are met, notify the Hellenic Data Protection Authority and the data subjects. The employee should retain the notification and ask exactly what was exposed and what measures are being taken. A fingerprint or facial template cannot be changed like a password.
Where can I turn if I receive no answer?
For an infringement of your rights, you may lodge a complaint with the Hellenic Data Protection Authority, attaching your earlier request and the response or evidence that no response was provided. Because the same practice may also engage employment law or discrimination law, advice on the appropriate parallel action may be needed in the individual case.
12. The sound conclusion
Biometrics and artificial intelligence are not just another category of corporate software. They affect identity, access to work, and decisions that directly shape an employee's life. The proper assessment does not begin by asking whether the system is modern, but whether it is necessary, lawful, limited, and capable of being audited.
For an employee, the most useful response is documented and in writing: request information, do not treat consent as a cure-all, retain evidence lawfully, and use the available rights and competent authorities. For an employer, the prudent course is to examine the least intrusive solution first and not operate the system until the legal review, DPIA, and genuine safeguards have been completed.
Legal notice: This article provides general information based on the framework in force on 23 August 2026 and does not constitute individual legal advice. Lawfulness depends on the purpose, technical operation, legal basis, type of premises, available alternatives, and actual circumstances. Before lodging a complaint, refusing a procedure, or taking court action, seek an assessment of the specific documents.
Official sources
- General Data Protection Regulation, in particular Articles 4, 5, 6, 9, 12-15, 21, 22, 35, 36, and 88.
- Law 4624/2019, in particular Article 27 on data processing in the employment context.
- Hellenic Data Protection Authority: processing employees' biometric data.
- Hellenic Data Protection Authority: processing employee data and employment relationships.
- Hellenic Data Protection Authority: frequently asked questions on employment relationships.
- Hellenic Data Protection Authority: frequently asked questions on video surveillance.
- Hellenic Data Protection Authority, Opinion 4/2026 on the biometric identification of public-sector employees.
- Hellenic Data Protection Authority, Decision 65/2018 and the list of processing operations requiring a DPIA.
- Hellenic Data Protection Authority, Decision 42/2024 on biometric access control.
- Consolidated Regulation (EU) 2024/1689 on artificial intelligence, version of 27 July 2026.
- European Commission: official questions and answers on the AI Act.
- European Commission: guidelines on the transparency obligations under Article 50.
- European Data Protection Board, Guidelines 05/2020 on consent.
- European Data Protection Board, Guidelines 3/2019 on video devices.
- Hellenic Data Protection Authority: artificial intelligence legislation and Law 5321/2026.
- Hellenic Data Protection Authority: online submission of a complaint.
The sources and dates of application were checked on 23 August 2026.
Photo: panumas nikhomkhai / Pexels. The image is used for informational illustration.
Comments
Share your thoughts about this article.
No comments yet. Be the first to comment.
Submit a comment