Few everyday technologies pack in as much regulatory density as a fingerprint reader on a company door. It looks like a clocking-in formality; it's processing of biometric data — a special category under Article 9 GDPR when used to uniquely identify a person — over the most protected group in the whole legal framework, the workforce, under an authority — the Spanish Data Protection Agency (AEPD) — that has spent years raising the bar, and under an AI Regulation that reserves some of its harshest boxes for biometrics. And yet the whole analysis falls into place around a single prior distinction.
The distinction: 1:1 versus 1:N
Verification (one-to-one): the system compares the person's biometric trait against their own stored template, to confirm they are who they say they are. The question is "is this you?" It's fingerprint clocking-in checked against your own record, facial unlock checked against your own profile.
Identification (one-to-many): the system compares the trait against a database of templates to work out who the person is. The question is "who are you, out of everyone?" It's the camera that recognises anyone who walks through the door.
The difference isn't technical — it's about the nature of the risk: identification requires a centralised biometric database covering the whole workforce and, in practice, functions as permanent scanning. That's why the entire regulatory framework treats it more severely: data protection doctrine demands justifications that verification doesn't need, and the AI Act reserves some of its toughest boxes for it — biometric identification has its own entry in the high-risk Annex III, and, in the workplace, the prohibition that matters is Article 5(1)(f) — inferring employees' emotions — rather than the real-time remote biometric identification of Article 5(1)(h), which is aimed at law enforcement in publicly accessible spaces. 1:1 verification, by contrast, sits explicitly on a much lower rung of that scheme.
The immediate consequence for any company: if verification solves your case, don't deploy identification. It's the first design decision, and the cheapest one to get right early.
The test the AEPD applies: was biometrics necessary?
With the "how" settled, the "whether" remains. AEPD doctrine on workplace biometrics turns on a test of necessity and proportionality that's worth running before buying the reader: is there a less invasive alternative that reasonably achieves the same purpose? For attendance control, there almost always is — a card, a PIN, an app. That doesn't rule biometrics out; it turns it into something that has to be justified in writing: why the alternatives fall short in your specific case (documented clocking-in fraud, specific security requirements), what safeguards you're adding, and why the balance comes out in favour.
That reasoning lives in the document this scenario demands almost by definition: the Data Protection Impact Assessment (DPIA). Special-category processing, involving workers, carried out systematically — the DPIA here isn't a prudent option — it's the starting point. And its absence is, precisely, one of the patterns that generates the most enforcement files.
The rest of the file
With the distinction made and proportionality reasoned through, the file is rounded out with the familiar pieces: a reinforced legal basis under Article 9 (in the employment context — delicate ground, where employee consent rarely holds up because of the imbalance in the relationship, so the applicable exception has to be identified carefully, not assumed); clear information for the workforce and, where one exists, its representatives; technical measures matched to the data (encrypted templates, local or distributed storage rather than a central database, defined erasure periods); and a record of all of it.
One final reading rule, because this is ground where generalisations fail in both directions: "workplace biometrics is prohibited" is false; "workplace biometrics is high-risk" as a blanket statement is false too. The correct answer is more demanding: the specific use decides — 1:1 verification for clocking in, properly justified and documented, is defensible; 1:N identification demands reasons of a different order; and certain remote uses simply have no defence. The work of a serious company isn't memorising the slogan — it's classifying its own case, justifying it, and being able to show the justification.
This article is for informational purposes only and does not constitute legal advice.