"name": "ISO 27001 Readiness & Documentation", "url": "https://kooch.co/en/iso-27001-readiness-documentation" }, { "@type": "Service", "name": "Ongoing Compliance Management", "url": "https://kooch.co/en/ongoing-compliance-management" }, { "@type": "Service", "name": "Data Controller Representative in Türkiye", "url": "https://kooch.co/en/data-controller-representative-turkiye" } ] }

Türkiye’s Personal Data Protection Authority has drawn a clearer line between two uses of employee biometrics: using a fingerprint, palm scan or similar identifier to record working time, and using biometrics to control access to genuinely critical areas.
The practical conclusion is direct. Employers should not use biometric identification systems for ordinary attendance or timekeeping. The Personal Data Protection Board considers this use to lack an applicable processing condition under Article 6 of Law No. 6698 and to be disproportionate even where an employer believes it has obtained valid explicit consent.
Security-related access control is different, but it is not automatically lawful. A controller must still identify an applicable Article 6 condition, show that less intrusive measures are inadequate, restrict the system to the necessary people and locations, and apply the additional safeguards required for special-category personal data.
The Board adopted Principle Decision No. 2026/921 on 29 April 2026. It was published in the Official Gazette on 2 June 2026.
The decision addresses biometric data used for employee attendance and working-time monitoring. It identifies several core problems:
The Board therefore concluded that biometric attendance processing is carried out without an applicable Article 6 condition and fails proportionality even if valid explicit consent exists. It also treated compliance with these conclusions as part of the controller’s obligation under Article 12 to prevent unlawful processing and warned that non-compliance may lead to action under Article 18.
This is not merely guidance suggesting a preferred practice. It is a principle decision adopted in response to an infringement the Board considered widespread.
For a private-sector controller, potential consequences include an administrative fine under Article 18 for failure to meet Article 12 obligations and a case-specific order to stop or remedy the unlawful processing. Failure to comply with a served Board order may create an additional Article 18 issue. For public institutions and public professional organizations, Article 18 instead provides for disciplinary action against the responsible officials following the Board’s notification. Article 17 also connects failure to delete or anonymize data in breach of Article 7 with Article 138 of the Turkish Criminal Code. Administrative-fine amounts are adjusted annually, so organizations should check the amounts applicable when an enforcement decision is made rather than relying on an older published figure.
After the decision was published, organizations from different sectors asked whether particular technologies and security environments should be treated differently. The Authority’s 27 August announcement clarified four points.
First, fingerprint and palm-derived identifiers are biometric data when technical processing makes them suitable for uniquely identifying or authenticating a person.
Second, converting the biometric sample into a mathematical code or template does not remove its biometric character. A system does not fall outside Article 6 simply because it says it stores “only a hash,” “only coordinates” or “only an irreversible template” rather than a raw fingerprint image.
Third, Decision No. 2026/921 is directed at biometric processing for attendance or timekeeping. Biometric processing for a different purpose is not automatically governed by the same conclusion; its legality must be assessed according to its actual purpose, the nature of the work and the facts of the case.
Fourth, the Authority recognized that some facilities or activities create security risks serious enough for biometric authentication to form part of a multilayered access-control system. Even there, processing must be limited to necessary critical areas and people, less intrusive alternatives must be inadequate, and the biometric measure must be proportionate to the concrete security need.
That is a narrow route for case-specific justification—not a general “security” label that rescues an ordinary attendance system.
The legal classification follows function, not the supplier’s terminology.
A fingerprint, palm or vein pattern that is technically processed to verify or uniquely identify an employee is biometric data and therefore special-category personal data under Article 6. Storing a derived template instead of the original image may reduce some security risks, but it does not change the classification.
Facial recognition should be approached in the same way when a system technically processes facial features to uniquely identify or authenticate a person. The April decision expressly lists facial recognition, iris scanning and retina scanning among biometric identification systems, and the August clarification applies the same functional logic.
An ordinary photograph or CCTV image is not automatically biometric data merely because it shows a face. It enters the biometric category when it is subjected to specific technical processing for unique identification or authentication. CCTV still involves personal-data processing and needs its own lawful-purpose, transparency, proportionality, retention and security assessment.
Article 9 of the Working Time Regulation under the Labour Law requires an employer to document employees’ working time using appropriate means. The rule does not prescribe biometric identification.
This distinction matters. A legal duty to keep a record can support processing that is necessary to create and retain an appropriate working-time record. It does not automatically authorize the most intrusive technology available for producing that record.
The 2024 amendments to Article 6 added a condition for special-category processing that is necessary to fulfil legal obligations in employment, occupational health and safety, social security, social services and social assistance. Decision No. 2026/921 nevertheless concludes that the listed non-consent conditions in Article 6—including this employment-related condition—do not apply to biometric timekeeping. The existence of workable non-biometric methods also defeats a claim that biometrics are necessary.
Employers should therefore separate the obligation from the method:
A card or PIN system may still need anti-abuse controls, but the possibility that employees could share a card or code does not by itself make biometric collection necessary. The controller should first test less intrusive combinations such as personalized credentials, manager verification, anomaly review and disciplinary controls.
Explicit consent is not a waiver of the KVKK principles.
In employment, the employee may reasonably fear that refusal will affect access to the workplace, scheduling, pay, performance evaluation or job security. If refusal or withdrawal creates a disadvantage, consent is unlikely to represent a real choice. A theoretically available paper form is not enough if it is slower, stigmatizing or impractical in daily use.
There is a second and independent problem. Article 4 applies regardless of the processing condition. If a biometric identifier is excessive when compared with the simple aim of recording arrival and departure, consent cannot make that use proportionate.
This means an employer cannot cure an attendance system merely by:
For timekeeping, the operational answer is to change the method.
The August clarification distinguishes biometric timekeeping from security-driven identity authentication, authorization and access control in genuinely critical environments. Examples could include a narrowly defined room, system, laboratory or infrastructure area where unauthorized access would create serious and demonstrable consequences.
The announcement does not provide a list of automatically qualifying industries or sites. It also does not say that every factory, data centre, hospital, financial institution or regulated business may use biometrics throughout its premises.
A defensible assessment should answer all of the following:
Private organizations should be especially cautious about Article 28(1)(ç). That full exemption concerns preventive, protective and intelligence activities carried out by public institutions and organizations that have been given duties and powers by law for specified national, public-order and economic-security purposes. A private site does not enter that exemption merely because it is commercially important or security-sensitive.
For a private critical facility, the safer reading is that the controller must identify an Article 6 processing condition and satisfy the remaining KVKK duties. If a sector-specific law is relied on, it should be checked for an express biometric-processing rule or a sufficiently clear legislative route; a general obligation to maintain security may not be enough.
A security system and an attendance system can observe the same physical event, but their purposes are different.
Security access control asks: Is this person authorized to enter this protected area now?
HR timekeeping asks: When did this employee start or finish work, and what should be reflected in attendance, payroll or overtime records?
If biometric access events are routinely exported to HR, converted into shifts or absences, or used to calculate pay, the system has a timekeeping purpose even if the supplier calls it an access-control product. A “dual-purpose” label does not preserve the security justification for the HR use.
The 27 August announcement does not expressly decide how every incidental access log should be treated. A cautious operational interpretation is to keep security event logs limited to security, investigations and access governance, with restricted recipients and a purpose-specific retention period. Do not feed them into payroll or attendance workflows. Use a separate non-biometric process to document working time.
Where an exceptional security incident makes a particular access event relevant to a legal claim or investigation, that later use should be assessed narrowly and documented. It should not become a routine back door for daily attendance monitoring.

Neither the 29 April decision nor the 27 August clarification creates a general grace period or a future compliance date. The Authority has not published a transition timetable for existing biometric attendance systems.
That does not mean every employer has received an individual 30-day order. The maximum 30-day period in Article 15(5) applies when the Board identifies an infringement in a specific examination, orders the controller to remedy it and serves that decision. For the wider market, the absence of a special transition period means there is no stated safe harbour for continuing biometric timekeeping until a later date.
Organizations should act promptly:
Under the deletion regulation, a controller with a retention and disposal policy performs ex officio deletion, destruction or anonymization in the first periodic disposal cycle after the duty arises; the cycle cannot exceed six months. A controller that is not required to maintain such a policy must act within three months. These are outer procedural periods, not permission to continue using the data. In an earlier employee-fingerprint decision, the Board ordered the controller to end the system and destroy previously processed fingerprint data promptly, with documentary proof.
Historical attendance records require a separate decision from biometric templates. Employment rules may require an employer to retain working-time, overtime, wage or employment-file records. That does not normally require retention of the biometric template used to create them. Before deletion, the organization should identify which ordinary employment records must lawfully remain, migrate necessary records to an appropriate non-biometric format where justified, and avoid treating employment recordkeeping as a reason to preserve the biometric identifier itself.
If the legality of a historical record or its use in litigation is material, obtain case-specific Turkish employment and data-protection advice before altering evidential records. A later need to defend a claim does not automatically cure an unlawful method of collection.
The employer will normally be the controller where it chooses the purpose and essential means of employee attendance or access processing. A biometric-system provider, cloud host, support company or facilities contractor may act as a processor when it handles the data only on documented instructions. Roles can change if a provider determines its own purposes or essential means.
Outsourcing does not transfer accountability. Under Article 12, a controller is jointly responsible with a person processing data on its behalf for the measures required to protect the data.
The remediation plan should therefore cover:
A vendor’s statement that a template is “non-reversible” or “not personal data” should not be accepted without legal and technical review.
Security measures cannot make an unnecessary processing activity lawful. They become relevant only after the controller has established a valid purpose, processing condition, necessity and proportionality.
Where a justified biometric security use remains, Article 12 and Board Decision No. 2018/10 require a heightened control environment. The measures include:
For biometric deployments, practical implementation should also address template isolation, endpoint tamper resistance, enrollment fraud, false acceptance and rejection handling, compromise response, deletion verification, supplier access and the fact that a biometric characteristic cannot be reissued like a password.
Use the following sequence to turn the decision into an auditable change programme.
The supplied checklist component covers ownership, immediate containment, purpose mapping, alternatives, deletion, vendor action, documentation and validation. It is designed to be used by HR, privacy, legal, information security and facilities teams together.
Yes. The Authority expressly states that converting fingerprint- or palm-derived information into a mathematical code and storing that code does not remove its biometric character when it is used for unique identification or authentication.
Yes, where facial features are technically processed to uniquely identify or authenticate employees for attendance. The April decision expressly includes facial recognition among the biometric identification methods it discusses. Ordinary CCTV imagery is not automatically biometric data, although it remains personal data.
The decision’s broader conclusion is that biometric timekeeping fails proportionality even where valid explicit consent exists. Offering a card alternative may improve the freedom-of-choice analysis, but it does not repair the proportionality problem for the biometric attendance purpose.
Potentially, but not because “critical facility” is a self-declared exemption. The controller must establish a valid Article 6 condition, demonstrate a concrete security need, show that alternatives are inadequate, restrict processing to necessary areas and people, and implement heightened safeguards. The legality remains case-specific.
The clarification does not expressly decide every incidental-log scenario. Routine export of biometric access events into HR, payroll or attendance systems is high risk because it gives the biometric system a timekeeping purpose. Separate the systems and use a non-biometric timekeeping method.
No general grace period or migration deadline appears in the decision or the 27 August clarification. Existing operators should not wait for a future date before reviewing and stopping non-compliant attendance processing.
The 2026 position is now difficult to avoid: biometric timekeeping is not justified merely because it is accurate, difficult to manipulate or supported by an employee consent form.
Organizations need to separate working-time documentation from high-security access control. Ordinary attendance should move to less intrusive methods. Any remaining biometric access system should be narrowed to a concrete security need, supported by an Article 6 condition, kept out of routine HR timekeeping and protected as special-category personal data.
The strongest remediation is operational, not cosmetic: change the workflow, remove unnecessary templates, separate purposes, control vendors and preserve evidence of each decision.
Kooch Cybersecurity & Compliance can support a targeted review of employee-data flows, biometric and access-control systems, vendor arrangements, retention rules and technical safeguards through a KVKK/GDPR Gap Analysis. Where the conclusion depends on sector-specific law, public-security powers or employment litigation, the review should be coordinated with qualified Turkish legal counsel.