Operational notes Regulation

Fingerprint, Face, Iris: The Proof Your Reader’s Vendor Never Handed Over

8 min read

An anonymous biometric reader on a rough concrete wall in an empty corridor, in black and white
The device decides whether the door opens. What happens afterwards to the model of your face is, as a rule, something nobody tells you.

A manufacturing company replaces its old magnetic badge with a fingerprint reader at the entrance to the quality department. The vendor delivers the terminal, a manual, and one reassuring line: the data stays on the device, everything is GDPR-compliant. Nobody asks where each employee’s fingerprint model ends up, who can extract it, or how long it stays there. A simple question that, in many Italian companies today, nobody could answer: what law authorises the biometric reading of a worker for clocking in and out?

The double filter no vendor hands over

A fingerprint, a face, an iris never depend on a single rule. Article 9(1) GDPR prohibits processing “biometric data for the purpose of uniquely identifying a natural person” — defined by Article 4(14) as “personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data”. The prohibition lifts only for one of the derogations in paragraph 2: for employment, point (b) allows it where “necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law”, and only where there are “appropriate safeguards for the fundamental rights and the interests of the data subject”.

That is not enough. Paragraph 4 of the same Article 9 lets member states maintain “further conditions, including limitations”. Italy did so with Article 2-septies of the Privacy Code (Legislative Decree 196/2003, in force since 19 September 2018), headed Safeguard measures for the processing of genetic, biometric and health data: processing is lawful only where one of the conditions under paragraph 2 of that article applies, and in accordance with the safeguard measures set by the Garante. Cumulative, not alternative, conditions — and those measures the Garante must adopt at least every two years, after a public consultation of at least sixty days. We found none adopted for biometrics, and we do not conclude that none exist: the case below turns on the other filter, the one missing outright in Tropea.

The case that proves it: Tropea, March 2025

On 27 March 2025 the Garante fined an Italian school — the “P. Galluppi” Istituto in Tropea — for tracking staff attendance with a fingerprint reader (decision no. 167/2025, doc-web 10138981). The system worked like almost all of them do, the decision explains: fingerprints were digitised, processed and compressed through an irreversible mathematical algorithm — not to be confused with encryption or cryptography — until a mathematical model, a template, was obtained, linked to the employee’s code. No image saved, no identity data on the reader: the argument vendors use to reassure. The Garante rejects it: that information can still be traced back to a code that directly identifies each employee, and allows or confirms their unique identification, and remains biometric data under Article 4(1) and (14) GDPR. The template saves nobody.

What matters most comes next. The Garante writes that in the absence of specific provisions governing the processing of biometric data for attendance purposes, and of the related safeguards, that processing cannot be lawfully carried out, there being no legal basis. Nor is this a public-sector problem alone: in the same decision the Garante recalls having found, in numerous cases, the unlawfulness of the processing of employees’ biometric data for attendance-tracking purposes carried out by public and private bodies alike. Not even the written consent of all the support staff bar the two who had complained — thirty-four people in all, the decision says — is enough: consent does not, as a rule, constitute a valid basis for lawfulness when processing personal data in an employment setting. Nor does offering an alternative help: staff who opted out could still clock in through traditional means that did not involve the processing of biometric data — a mitigating factor in the fine, not a condition for lawfulness. The €4,000 fine stayed low because the school had already suspended the system and deleted the data: the same conduct was, by law, liable for up to €20 million (Article 83(5) GDPR).

The paradox of Article 4 of the Workers’ Statute

Article 4 of Law 300/1970 (in force since 8 October 2016) requires, for instruments from which the possibility of remote monitoring of workers’ activity also follows, a union agreement or Labour Inspectorate authorisation — the same constraint that governs the logs of company AI assistants. Paragraph 2, though, excludes instruments recording access and attendance: a biometric reader used only for clocking in needs no union agreement on its own.

The paragraph 1 exemption does nothing, though, to the biometric-data regime: separate rules, separate interests. A company can have every box ticked on the union front and still lack a legal basis on the biometric one, exactly as happened in Tropea. The processing also falls, under item 11 of the list the Garante published on 11 October 2018 (measure no. 467, Official Gazette no. 269/2018), among those for which Article 35 GDPR requires an impact assessment: systematic processing of biometric data, taking into account in particular the volume of data, and the duration or persistence of the processing activity.

Where every piece of proof sits today

No single document holds the whole answer: it is split across different places, rarely read together.

  • The vendor contract: whether it names the legal basis, who processes the template — controller or processor under Article 28 — where it sits, and who can access it.
  • The terminal’s configuration: template or image, where the match happens, how long the data survives a fault or a swap.
  • The attendance system: whether it links the template to a name, who can query it, whether it reports per employee beyond plain clocking.
  • The record of processing activities: whether biometric processing appears as a distinct entry, with its own purpose, legal basis and retention period.
  • The impact assessment: whether one exists, whether it was updated after installation, whether it considers the alternative.
  • The staff notice: whether it discloses the alternative to those who opt out, before activation and not after a complaint.

The limit, and what belongs in a procurement spec

We have not read any draft measure on safeguards for biometrics, and the search — general search engines, not the internal one on garanteprivacy.it — found none adopted: we do not conclude that none exist. We have not checked whether collective agreements authorise biometrics, under Article 9(2)(b), for purposes other than clocking in — access control, system authentication.

For a procurement spec: a written statement on the nature of the stored data — template or image — and its irreversibility; storage location and who is authorised to extract it, with an Article 28 clause if the vendor accesses it remotely; retention periods and verifiable automatic deletion; a non-biometric alternative always available and described in the manual. Three checks suffice at acceptance: extract a single template and watch who does it and with what credentials; check that the record of processing cites Article 2-septies; read the staff notice and verify the non-biometric alternative appears in writing, not just spoken.

How we solve this

The Tropea case leaves a question that has nothing to do with the vendor’s good faith: in front of an inspector, can you show where the template sits, who extracted it, and under what legal basis? That is the first axis on which we build dedicated, closed AI: separating biometric data from the attendance system, tracing every privileged access to the template — the same principle that governs the credentials of whoever administers a company AI system — and updating the impact assessment with every change, not writing it once and filing it away. The second axis makes the first sustainable: an on-premises environment, without deep integration into the client’s network, or our dedicated cloud, with a dedicated VPN and a data centre in Italy that we secure directly — the data behind a face or a fingerprint never passes through a third party’s server.

Could you say today, for the biometric reader already installed at your company, which law authorises its use and where your employees’ templates are stored? Half an hour with one of our experts is enough for the first map.

Sources