A recent ANSPDCP case shows that not every security technology is legally justified.
Using modern technologies to secure access to an organisation's premises is becoming increasingly common. However, when these solutions involve processing biometric data, such as facial recognition, significant risks arise from a personal data protection perspective.
A recent case examined by the National Supervisory Authority for Personal Data Processing (ANSPDCP) clearly highlights the legal limits on using such technologies and the importance of complying with the fundamental principles of Regulation (EU) 2016/679 (GDPR).
The authority opened an investigation following complaints regarding an organisation's intention to implement a facial-recognition-based access control system for employees.
Although the system had not yet been deployed, the analysis focused on how the biometric data would have been processed and whether this complied with the requirements of the GDPR.
The organisation was already using a card-based access system, and the new biometric solution was intended to prevent unauthorised access and the misuse of these cards.
Biometric data, such as a facial image used for identification, is considered sensitive because it allows a person to be uniquely identified.
Under the GDPR, processing such data is subject to strict conditions and must respect essential principles such as:
Following its analysis, the authority found that the use of facial recognition did not meet the requirements of necessity and proportionality.
More specifically:
In this context, the use of biometric data would have been excessive in relation to the purpose pursued.
Although the system was not yet operational, the authority issued a warning, stressing that such processing could breach the provisions of the GDPR, in particular:
At the same time, it recommended using alternative, less intrusive solutions to achieve the security objective.
This case is a clear example that the intention to implement a technology is not enough — its compliance with the GDPR must also be demonstrated before use.
To avoid the risks, organisations should:
It is essential to demonstrate that the chosen solution is truly necessary and that no less intrusive alternatives exist.
The impact on private life must be proportionate to the purpose pursued.
Biometric data should be used only in exceptional and well-justified situations.
For this type of processing, a data protection impact assessment is essential.
Technologies such as facial recognition can bring security benefits, but their use must be carefully analysed from a GDPR perspective.
This case clearly shows that not every technological solution is legally justified, even if the purpose is legitimate. Choosing less intrusive methods and respecting the core principles of data protection remain essential to avoiding penalties and protecting the rights of data subjects.
Not automatically. A facial image used for identification is a special category of data (Art. 9 GDPR), and processing it is allowed only under strict conditions. At the workplace, the authority (ANSPDCP) checks necessity and proportionality: if the security purpose can be achieved through less intrusive methods, facial recognition becomes excessive and breaches the GDPR, even if the system has not yet been deployed.
Yes. Biometric data used to uniquely identify a person, such as a facial image, is a special category of data under Art. 9 GDPR. Its processing is prohibited as a rule and allowed only by way of exception, with a solid legal basis, plus compliance with the principles of lawfulness, necessity, proportionality and data minimisation.
As a rule, no. Employee consent is not a solid basis because of the power imbalance between employee and employer — an employee cannot truly refuse freely. For time-keeping there are almost always less intrusive alternatives (cards, PIN codes, sign-in sheets), so biometric processing fails the test of necessity and proportionality.
Less intrusive solutions that achieve the same security purpose: access cards, PIN codes, physical keys or tokens, or a combination of these. Before choosing biometrics, carry out a data protection impact assessment (DPIA) and document why the alternatives are not sufficient — without that justification, facial recognition remains disproportionate.
We help you assess necessity and proportionality and carry out a DPIA before implementation.