"name": "ISO 27001 Readiness & Documentation", "url": "https://kooch.co/en/iso-27001-readiness-documentation" }, { "@type": "Service", "name": "Ongoing Compliance Management", "url": "https://kooch.co/en/ongoing-compliance-management" }, { "@type": "Service", "name": "Data Controller Representative in Türkiye", "url": "https://kooch.co/en/data-controller-representative-turkiye" } ] }

Türkiye’s KVKK Clarifies Employee Biometrics: What Employers Must Change

Türkiye’s KVKK Clarifies Employee Biometrics: What Employers Must Change

Türkiye’s Personal Data Protection Authority has drawn a clearer line between two uses of employee biometrics: using a fingerprint, palm scan or similar identifier to record working time, and using biometrics to control access to genuinely critical areas.

The practical conclusion is direct. Employers should not use biometric identification systems for ordinary attendance or timekeeping. The Personal Data Protection Board considers this use to lack an applicable processing condition under Article 6 of Law No. 6698 and to be disproportionate even where an employer believes it has obtained valid explicit consent.

Security-related access control is different, but it is not automatically lawful. A controller must still identify an applicable Article 6 condition, show that less intrusive measures are inadequate, restrict the system to the necessary people and locations, and apply the additional safeguards required for special-category personal data.

Decision map

How the 2026 position applies

Classification depends on what the system actually does and why—not the product name or the format in which the template is stored.

Use case Current position Practical response
Fingerprint or palm scan for attendance Replace
Decision No. 2026/921 finds no applicable Article 6 condition and says consent does not cure disproportionality.
Stop biometric timekeeping, deploy a card, PIN or another non-biometric method, and assess template deletion.
Biometric access to an ordinary office High scrutiny
A general security preference is unlikely to show necessity where less intrusive access controls work.
Use badges, mobile credentials, PINs or multilayered non-biometric controls unless a concrete case proves they are inadequate.
Biometric access to a genuinely critical area Case-specific
Outside the timekeeping decision, but not automatically lawful.
Document the Article 6 condition, threat, alternatives, restricted area and population, retention, safeguards and review cycle.
Security system also feeds HR attendance Separate uses
The routine HR output gives the biometric system a timekeeping purpose.
Block routine HR or payroll feeds and create working-time records through a separate non-biometric process.
Facial recognition for attendance Replace
Technical processing for unique identification is biometric processing. Ordinary CCTV is not automatically biometric.
Disable facial matching for timekeeping; assess any remaining CCTV or security use separately.

Important: “Outside Decision No. 2026/921” means a separate assessment is required. It does not mean the processing is approved.

What Principle Decision No. 2026/921 established

The Board adopted Principle Decision No. 2026/921 on 29 April 2026. It was published in the Official Gazette on 2 June 2026.

The decision addresses biometric data used for employee attendance and working-time monitoring. It identifies several core problems:

  • Turkish employment rules require employers to track and document working time, but they do not expressly require this to be done with biometrics.
  • The Article 6 processing conditions other than explicit consent do not provide a basis for biometric timekeeping in the circumstances addressed by the decision.
  • Consent in an employment relationship may not be freely given because of the structural imbalance between employer and employee.
  • Even genuinely valid consent cannot repair a processing activity that fails Article 4’s proportionality requirement.
  • Less intrusive options are available, including PIN-based systems, encrypted cards, RFID or NFC cards, signed attendance sheets and supervised manual entry.

The Board therefore concluded that biometric attendance processing is carried out without an applicable Article 6 condition and fails proportionality even if valid explicit consent exists. It also treated compliance with these conclusions as part of the controller’s obligation under Article 12 to prevent unlawful processing and warned that non-compliance may lead to action under Article 18.

This is not merely guidance suggesting a preferred practice. It is a principle decision adopted in response to an infringement the Board considered widespread.

For a private-sector controller, potential consequences include an administrative fine under Article 18 for failure to meet Article 12 obligations and a case-specific order to stop or remedy the unlawful processing. Failure to comply with a served Board order may create an additional Article 18 issue. For public institutions and public professional organizations, Article 18 instead provides for disciplinary action against the responsible officials following the Board’s notification. Article 17 also connects failure to delete or anonymize data in breach of Article 7 with Article 138 of the Turkish Criminal Code. Administrative-fine amounts are adjusted annually, so organizations should check the amounts applicable when an enforcement decision is made rather than relying on an older published figure.

What the KVKK Authority clarified on 27 August 2026

After the decision was published, organizations from different sectors asked whether particular technologies and security environments should be treated differently. The Authority’s 27 August announcement clarified four points.

First, fingerprint and palm-derived identifiers are biometric data when technical processing makes them suitable for uniquely identifying or authenticating a person.

Second, converting the biometric sample into a mathematical code or template does not remove its biometric character. A system does not fall outside Article 6 simply because it says it stores “only a hash,” “only coordinates” or “only an irreversible template” rather than a raw fingerprint image.

Third, Decision No. 2026/921 is directed at biometric processing for attendance or timekeeping. Biometric processing for a different purpose is not automatically governed by the same conclusion; its legality must be assessed according to its actual purpose, the nature of the work and the facts of the case.

Fourth, the Authority recognized that some facilities or activities create security risks serious enough for biometric authentication to form part of a multilayered access-control system. Even there, processing must be limited to necessary critical areas and people, less intrusive alternatives must be inadequate, and the biometric measure must be proportionate to the concrete security need.

That is a narrow route for case-specific justification—not a general “security” label that rescues an ordinary attendance system.

Fingerprints, palm scans and facial recognition

The legal classification follows function, not the supplier’s terminology.

A fingerprint, palm or vein pattern that is technically processed to verify or uniquely identify an employee is biometric data and therefore special-category personal data under Article 6. Storing a derived template instead of the original image may reduce some security risks, but it does not change the classification.

Facial recognition should be approached in the same way when a system technically processes facial features to uniquely identify or authenticate a person. The April decision expressly lists facial recognition, iris scanning and retina scanning among biometric identification systems, and the August clarification applies the same functional logic.

An ordinary photograph or CCTV image is not automatically biometric data merely because it shows a face. It enters the biometric category when it is subjected to specific technical processing for unique identification or authentication. CCTV still involves personal-data processing and needs its own lawful-purpose, transparency, proportionality, retention and security assessment.

Why working-time recordkeeping is not enough

Article 9 of the Working Time Regulation under the Labour Law requires an employer to document employees’ working time using appropriate means. The rule does not prescribe biometric identification.

This distinction matters. A legal duty to keep a record can support processing that is necessary to create and retain an appropriate working-time record. It does not automatically authorize the most intrusive technology available for producing that record.

The 2024 amendments to Article 6 added a condition for special-category processing that is necessary to fulfil legal obligations in employment, occupational health and safety, social security, social services and social assistance. Decision No. 2026/921 nevertheless concludes that the listed non-consent conditions in Article 6—including this employment-related condition—do not apply to biometric timekeeping. The existence of workable non-biometric methods also defeats a claim that biometrics are necessary.

Employers should therefore separate the obligation from the method:

  • Obligation: maintain adequate working-time and, where relevant, overtime records.
  • Method: use a proportionate non-biometric tool capable of producing reliable records.

A card or PIN system may still need anti-abuse controls, but the possibility that employees could share a card or code does not by itself make biometric collection necessary. The controller should first test less intrusive combinations such as personalized credentials, manager verification, anomaly review and disciplinary controls.

Why explicit consent does not solve proportionality

Explicit consent is not a waiver of the KVKK principles.

In employment, the employee may reasonably fear that refusal will affect access to the workplace, scheduling, pay, performance evaluation or job security. If refusal or withdrawal creates a disadvantage, consent is unlikely to represent a real choice. A theoretically available paper form is not enough if it is slower, stigmatizing or impractical in daily use.

There is a second and independent problem. Article 4 applies regardless of the processing condition. If a biometric identifier is excessive when compared with the simple aim of recording arrival and departure, consent cannot make that use proportionate.

This means an employer cannot cure an attendance system merely by:

  • issuing a new consent form;
  • adding a consent checkbox to onboarding;
  • describing the system as voluntary while keeping biometrics as the default; or
  • obtaining renewed consent from existing staff.

For timekeeping, the operational answer is to change the method.

Critical-area access control: a narrow route, not a blanket exemption

The August clarification distinguishes biometric timekeeping from security-driven identity authentication, authorization and access control in genuinely critical environments. Examples could include a narrowly defined room, system, laboratory or infrastructure area where unauthorized access would create serious and demonstrable consequences.

The announcement does not provide a list of automatically qualifying industries or sites. It also does not say that every factory, data centre, hospital, financial institution or regulated business may use biometrics throughout its premises.

A defensible assessment should answer all of the following:

  1. What is the concrete threat? Describe the harm the control is intended to prevent, not merely the general importance of security.
  2. Why is strong identity binding necessary? Explain why a badge, PIN, mobile credential, security guard or two-factor combination cannot adequately manage the risk.
  3. Where is biometric access required? Limit it to the specific critical zone rather than the building, campus or workforce as a whole.
  4. Who needs to be enrolled? Include only roles that actually require access.
  5. Which Article 6 condition applies? A security purpose and a proportionality case do not create a legal basis by themselves.
  6. How will the system be secured and deleted? Define template storage, access, logs, retention, incident handling and verified deletion before deployment.

Private organizations should be especially cautious about Article 28(1)(ç). That full exemption concerns preventive, protective and intelligence activities carried out by public institutions and organizations that have been given duties and powers by law for specified national, public-order and economic-security purposes. A private site does not enter that exemption merely because it is commercially important or security-sensitive.

For a private critical facility, the safer reading is that the controller must identify an Article 6 processing condition and satisfy the remaining KVKK duties. If a sector-specific law is relied on, it should be checked for an express biometric-processing rule or a sufficiently clear legislative route; a general obligation to maintain security may not be enough.

Access control and HR timekeeping must be separated

A security system and an attendance system can observe the same physical event, but their purposes are different.

Security access control asks: Is this person authorized to enter this protected area now?

HR timekeeping asks: When did this employee start or finish work, and what should be reflected in attendance, payroll or overtime records?

If biometric access events are routinely exported to HR, converted into shifts or absences, or used to calculate pay, the system has a timekeeping purpose even if the supplier calls it an access-control product. A “dual-purpose” label does not preserve the security justification for the HR use.

The 27 August announcement does not expressly decide how every incidental access log should be treated. A cautious operational interpretation is to keep security event logs limited to security, investigations and access governance, with restricted recipients and a purpose-specific retention period. Do not feed them into payroll or attendance workflows. Use a separate non-biometric process to document working time.

Where an exceptional security incident makes a particular access event relevant to a legal claim or investigation, that later use should be assessed narrowly and documented. It should not become a routine back door for daily attendance monitoring.

What existing-system operators should do now

Neither the 29 April decision nor the 27 August clarification creates a general grace period or a future compliance date. The Authority has not published a transition timetable for existing biometric attendance systems.

That does not mean every employer has received an individual 30-day order. The maximum 30-day period in Article 15(5) applies when the Board identifies an infringement in a specific examination, orders the controller to remedy it and serves that decision. For the wider market, the absence of a special transition period means there is no stated safe harbour for continuing biometric timekeeping until a later date.

Organizations should act promptly:

  1. Stop new biometric enrolment for attendance.
  2. Prevent the system from using biometric matches to generate attendance, payroll, lateness or overtime outputs.
  3. Deploy a workable non-biometric timekeeping method.
  4. Map every copy of biometric templates and related enrolment data across terminals, local servers, cloud dashboards, mobile applications, test environments, backups, vendors and subprocessors.
  5. Determine whether any remaining biometric use has a distinct and defensible security purpose and Article 6 condition.
  6. Delete or destroy templates and related biometric enrolment data for which all processing conditions have disappeared, and preserve evidence of the operation.

Under the deletion regulation, a controller with a retention and disposal policy performs ex officio deletion, destruction or anonymization in the first periodic disposal cycle after the duty arises; the cycle cannot exceed six months. A controller that is not required to maintain such a policy must act within three months. These are outer procedural periods, not permission to continue using the data. In an earlier employee-fingerprint decision, the Board ordered the controller to end the system and destroy previously processed fingerprint data promptly, with documentary proof.

Historical attendance records require a separate decision from biometric templates. Employment rules may require an employer to retain working-time, overtime, wage or employment-file records. That does not normally require retention of the biometric template used to create them. Before deletion, the organization should identify which ordinary employment records must lawfully remain, migrate necessary records to an appropriate non-biometric format where justified, and avoid treating employment recordkeeping as a reason to preserve the biometric identifier itself.

If the legality of a historical record or its use in litigation is material, obtain case-specific Turkish employment and data-protection advice before altering evidential records. A later need to defend a claim does not automatically cure an unlawful method of collection.

Vendor and processor responsibilities

The employer will normally be the controller where it chooses the purpose and essential means of employee attendance or access processing. A biometric-system provider, cloud host, support company or facilities contractor may act as a processor when it handles the data only on documented instructions. Roles can change if a provider determines its own purposes or essential means.

Outsourcing does not transfer accountability. Under Article 12, a controller is jointly responsible with a person processing data on its behalf for the measures required to protect the data.

The remediation plan should therefore cover:

  • contract instructions that prohibit attendance use where the system is retained only for security;
  • a complete inventory of storage locations, administrative portals and subprocessors;
  • role-based support access and auditable access records;
  • deletion from terminals, servers, cloud tenants, caches and scheduled backup expiry;
  • written deletion confirmation and evidence sufficient for the controller to verify completion;
  • incident-notification and cooperation duties;
  • return or deletion at contract end; and
  • Article 9 compliance if the vendor or support team causes a transfer abroad.

A vendor’s statement that a template is “non-reversible” or “not personal data” should not be accepted without legal and technical review.

Article 12 and special-category security measures

Security measures cannot make an unnecessary processing activity lawful. They become relevant only after the controller has established a valid purpose, processing condition, necessity and proportionality.

Where a justified biometric security use remains, Article 12 and Board Decision No. 2018/10 require a heightened control environment. The measures include:

  • a separate, sustainable policy and procedure for special-category data;
  • regular training and confidentiality obligations for personnel involved in processing;
  • clearly defined access permissions, periodic entitlement reviews and immediate removal of access following a role change or departure;
  • cryptographic protection of electronic data, with keys kept securely and separately;
  • secure logging of all activity involving the data;
  • continuous security updates, regular testing and recorded test results;
  • application-level authorization and regular security testing;
  • at least two-factor authentication for remote access;
  • physical protection of relevant environments; and
  • protected transfer methods appropriate to the medium.

For biometric deployments, practical implementation should also address template isolation, endpoint tamper resistance, enrollment fraud, false acceptance and rejection handling, compromise response, deletion verification, supplier access and the fact that a biometric characteristic cannot be reissued like a password.

Remediation checklist

From decision to verified change

Assign each action to a named owner and retain evidence. A policy update alone does not show that biometric processing has stopped.

Contain

Stop new attendance enrolment

Disable new fingerprint, palm or facial enrollment and prevent biometric events from creating payroll or attendance outputs.

Evidence: Change ticket, configuration export and dated screenshots.

Inventory

Map systems and copies

Identify devices, servers, cloud portals, mobile tools, test environments, backups, vendors and subprocessors holding biometric data.

Evidence: Data-flow map, asset list and processor register.

Separate

Split security from timekeeping

Block routine transfer of biometric access events to HR and implement a distinct non-biometric method for working-time records.

Evidence: Interface map, disabled integration and new operating procedure.

Justify

Review any remaining security use

Record the Article 6 condition, concrete threat, rejected alternatives, critical zones, enrolled roles, retention and review date.

Evidence: Necessity and proportionality assessment approved by accountable owners.

Replace

Deploy a less intrusive method

Use cards, PINs, mobile credentials, signed records or supervised entry, with proportionate anti-abuse controls.

Evidence: Test results, employee instructions and go-live record.

Delete

Destroy unnecessary templates

Delete templates and enrollment data from active systems and manage backup expiry. Keep necessary ordinary employment records separately.

Evidence: Destruction log, device report and vendor confirmation.

Secure

Apply special-category safeguards

Implement encryption, separate key control, least privilege, access logging, testing, two-factor remote access and staff confidentiality controls.

Evidence: Access review, test report, training record and control configuration.

Update

Align governance records

Update the inventory, notices, retention schedule, vendor instructions, policies, incident plan and VERBİS information where applicable.

Evidence: Approved revisions, communication record and final validation sign-off.

Practical remediation checklist

Use the following sequence to turn the decision into an auditable change programme.

The supplied checklist component covers ownership, immediate containment, purpose mapping, alternatives, deletion, vendor action, documentation and validation. It is designed to be used by HR, privacy, legal, information security and facilities teams together.

Frequently asked questions

Are fingerprint templates still biometric data if the original image cannot be reconstructed?

Yes. The Authority expressly states that converting fingerprint- or palm-derived information into a mathematical code and storing that code does not remove its biometric character when it is used for unique identification or authentication.

Does the decision apply to facial-recognition attendance systems?

Yes, where facial features are technically processed to uniquely identify or authenticate employees for attendance. The April decision expressly includes facial recognition among the biometric identification methods it discusses. Ordinary CCTV imagery is not automatically biometric data, although it remains personal data.

Can employees consent to biometric attendance if a card option also exists?

The decision’s broader conclusion is that biometric timekeeping fails proportionality even where valid explicit consent exists. Offering a card alternative may improve the freedom-of-choice analysis, but it does not repair the proportionality problem for the biometric attendance purpose.

Can a critical facility use biometrics for access control?

Potentially, but not because “critical facility” is a self-declared exemption. The controller must establish a valid Article 6 condition, demonstrate a concrete security need, show that alternatives are inadequate, restrict processing to necessary areas and people, and implement heightened safeguards. The legality remains case-specific.

Can security access logs be used to calculate working time?

The clarification does not expressly decide every incidental-log scenario. Routine export of biometric access events into HR, payroll or attendance systems is high risk because it gives the biometric system a timekeeping purpose. Separate the systems and use a non-biometric timekeeping method.

Did the Authority give existing systems a transition period?

No general grace period or migration deadline appears in the decision or the 27 August clarification. Existing operators should not wait for a future date before reviewing and stopping non-compliant attendance processing.

Conclusion

The 2026 position is now difficult to avoid: biometric timekeeping is not justified merely because it is accurate, difficult to manipulate or supported by an employee consent form.

Organizations need to separate working-time documentation from high-security access control. Ordinary attendance should move to less intrusive methods. Any remaining biometric access system should be narrowed to a concrete security need, supported by an Article 6 condition, kept out of routine HR timekeeping and protected as special-category personal data.

The strongest remediation is operational, not cosmetic: change the workflow, remove unnecessary templates, separate purposes, control vendors and preserve evidence of each decision.

Kooch Cybersecurity & Compliance can support a targeted review of employee-data flows, biometric and access-control systems, vendor arrangements, retention rules and technical safeguards through a KVKK/GDPR Gap Analysis. Where the conclusion depends on sector-specific law, public-security powers or employment litigation, the review should be coordinated with qualified Turkish legal counsel.

Sources / References

Masoud Salmani