Biometric data, such as fingerprints, facial images or voice patterns, is a special category of personal data under the GDPR when it is processed to identify a person uniquely. In the Netherlands such processing is in principle prohibited; the main exception is where it is necessary for authentication or security purposes, and for employees that test is rarely met by a time clock or an office door.
The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) applies these rules strictly and has fined employers and technology companies for using biometrics without a valid basis. Below we explain what counts as biometric data, which legal grounds are available, when you need a data protection impact assessment, which safeguards are expected and what to do if something goes wrong.
What is biometric data under the GDPR?
Biometric data is personal data resulting from specific technical processing of a person’s physical, physiological or behavioural characteristics, which allows or confirms that person’s unique identification. The purpose and the technique decide, not the type of image or recording.
This definition is in Article 4(14) of the General Data Protection Regulation (GDPR). A photograph of an employee on an ID badge is personal data, but not automatically biometric data. The moment the same photograph is converted into a facial template and used by a recognition system to grant access to a building, it becomes biometric data. That shift changes the legal framework completely.
Examples of biometric identifiers are fingerprints, facial geometry, iris and retina patterns, voice patterns and behavioural traits such as typing rhythm or the way someone walks. What they have in common is that they are used to recognise one specific individual.
Why does the GDPR treat biometric data differently?
Under Article 9 GDPR, biometric data processed for the purpose of uniquely identifying a person belongs to the special categories of personal data. The same category includes data on racial or ethnic origin, political opinions, religious beliefs, health and sex life.
The reason is that the consequences of misuse are serious and often irreversible. A password can be changed; a fingerprint or an iris cannot. If a database of biometric templates is compromised, the people concerned face a lasting risk of identity fraud. The table below shows common applications.
| Biometric identifier | Example application | Special category? |
|---|---|---|
| Fingerprints | Unlocking a company phone, time registration | Yes, when used for unique identification. |
| Facial recognition | Access control, identity verification in an app | Yes, when used for unique identification. |
| Iris or retina scan | Access to high-security facilities | Yes, when used for unique identification. |
| Voice patterns | Authenticating a caller to a secure service | Yes, when used for unique identification. |
| Keystroke dynamics | Behavioural verification for fraud detection | Yes, when used for unique identification. |
| Gait analysis | Identifying individuals by the way they walk | Yes, when used for unique identification. |
The common thread is the purpose of unique identification. Where that purpose is present, the prohibition in Article 9 applies and you need one of the specific exceptions.
How strict is the Dutch approach?
The AP interprets these rules strictly. Its starting point is that biometric identification is prohibited, and that the exceptions are narrow.
The Dutch GDPR Implementation Act (Uitvoeringswet Algemene verordening gegevensbescherming, UAVG) adds a national exception. Under Article 29 UAVG, biometric data may be processed for unique identification if this is necessary for authentication or security purposes. “Necessary” is the key word. It means that the purpose cannot reasonably be achieved with less intrusive means, such as a badge, a code or a key. The AP has made clear in its guidance that facial recognition in publicly accessible places, such as shops, is in principle not allowed.
Which legal basis do you need?
You need two: a lawful basis under Article 6 GDPR for the processing as such, and an exception under Article 9(2) GDPR or Article 29 UAVG to lift the prohibition on special categories. Without both, the processing is unlawful.
Article 6 GDPR lists six lawful bases: consent, performance of a contract, a legal obligation, vital interests, a task in the public interest and legitimate interests. That is the first hurdle, and it applies to all personal data.
Because biometric data is a special category, you must then satisfy one of the conditions of Article 9(2) GDPR, or the Dutch exception in Article 29 UAVG. These are the only routes through which the prohibition can be lifted. Before you start, also determine who is the controller and who acts as processor, for instance the supplier of the scanning system. Our article on the roles of controller and processor under the GDPR explains the difference and the processing agreement you need.
When is explicit consent valid?
Explicit consent is a higher standard than ordinary consent. It must be given by a clear, affirmative statement and must be specific, informed, unambiguous and freely given.
- Specific: a general reference to “security purposes” is not enough; you must state precisely why you need the biometric data.
- Informed: people must know which data you collect, what you do with it, who has access and how long you keep it.
- Freely given: the person must be able to refuse without negative consequences, and must be able to withdraw consent at any time.
In an employment relationship, the last condition is the problem. An employee who refuses may fear consequences, and the AP therefore takes the view that employee consent is rarely freely given. An employer that relies on consent must be able to show that a real alternative existed and was offered in practice, not only on paper.
For customers, consent can work, provided participation is truly voluntary. A customer who chooses to pay with facial recognition, with an equivalent alternative available at the same counter, is in a different position from an employee who must use a fingerprint scanner to start work.
What other exceptions are there?
The other exceptions are narrow. The table below compares the most relevant ones.
| Exception | Key requirement | Example | Common pitfall |
|---|---|---|---|
| Explicit consent (Art. 9(2)(a) GDPR) | Specific, informed, unambiguous and freely given. | A customer voluntarily enrolling in a facial recognition payment system, with an easy alternative. | Relying on employee consent despite the imbalance of power. |
| Authentication or security (Art. 29 UAVG) | Biometrics must be necessary; less intrusive means must be insufficient. | Access to a laboratory with hazardous substances or a high-security data centre. | Using biometrics for convenience, such as time registration, where a badge would do. |
| Employment and social security law (Art. 9(2)(b) GDPR) | Necessary to meet obligations under employment or social security law, based on a specific legal provision. | Rare in practice; requires a statutory basis for the processing. | Assuming that the employment relationship itself is enough. |
| Vital interests (Art. 9(2)(c) GDPR) | Necessary to protect someone who is physically or legally unable to consent. | Identifying an unconscious patient in an emergency. | Applying it to routine situations. |
| Substantial public interest (Art. 9(2)(g) GDPR) | Based on EU or Dutch law and proportionate to the aim. | Processing by public authorities under a specific statutory mandate. | A private company invoking public interest without a legal basis. |
Choosing the right basis requires a documented analysis of your specific situation. Choosing the most convenient ground without that analysis is a quick route to non-compliance.
Can you use fingerprints or face scans for employees?
Only if biometrics is truly necessary for authentication or security, and a less intrusive means would not do. For time registration, a till or an ordinary office door, that is usually not the case.
The test under Article 29 UAVG is whether the purpose could reasonably be achieved by less intrusive means. A scanner that controls access to a till, a time-registration system or an office door normally fails that test, because a badge, a code or a key achieves the same result without biometric data. Where biometric access is accepted, the security interest is substantial and specific: a facility handling hazardous materials, a secure laboratory, a data centre or a vault.
Consent rarely rescues such a system, for the reasons explained above. And there is a second, separate requirement. Where a works council (ondernemingsraad) exists, a system that registers or monitors employees’ attendance, behaviour or performance, or that processes their personal data, requires its consent under Article 27(1)(k) and (l) of the Works Councils Act (Wet op de ondernemingsraden, WOR). Complying with the GDPR does not remove that requirement, and a system introduced without consent can be challenged.
Can you use biometrics for customers?
Sometimes, but the same strict rules apply. With customers, explicit consent can be a valid ground, provided using biometrics is truly optional and an equivalent alternative is available.
Common examples are unlocking a banking app with a fingerprint, identity verification with a selfie when opening an account online, and access to a gym or event with facial recognition. Where the biometric check takes place entirely on the customer’s own phone, using the phone’s built-in technology, the company usually does not receive the biometric data itself. That significantly reduces the risk and the obligations for the company.
Where the company does process the data itself, for instance by comparing a selfie with a passport photo on its own servers, it needs a valid ground. Consent requires that the customer can choose another route, such as verification by a bank transfer or a visit to a branch, without a disadvantage. For banks and other financial institutions, customer due diligence obligations under anti-money laundering legislation play a role, but they do not in themselves require biometric processing.
What about cameras with facial recognition?
Facial recognition cameras in shops, stadiums or other publicly accessible places are in principle not allowed for private parties. People walking past cannot give explicit consent, and there is rarely a necessity that meets the Article 29 UAVG test.
The AP has warned retailers that using facial recognition to identify shoplifters or recognise customers is not allowed. Ordinary camera surveillance, without biometric identification, is subject to different, less strict rules, but still requires a legitimate interest, clear notices and limited retention periods. Adding facial recognition software to an existing camera system changes the assessment completely.
When do you need a data protection impact assessment?
Almost always. Processing biometric data to identify people is high-risk processing, and the AP has placed it on its list of processing operations that require a data protection impact assessment (DPIA) under Article 35 GDPR.
A DPIA is a structured privacy risk assessment. It forces you to describe what you plan to do, identify the risks for the people involved and decide how to manage those risks before you scan a single fingerprint or face. If the remaining risk is high and cannot be sufficiently reduced, you must consult the AP before you start (Article 36 GDPR).
The DPIA builds on the legal basis: you first establish a basis under Article 6 and an exception under Article 9 or Article 29 UAVG, and then assess whether the specific system is necessary and proportionate.
What does a DPIA contain?
Take a fingerprint scanner for access to a server room as an example. A DPIA covers four elements.
- A description of the processing. Which data do you collect: a template or a full image? How is it collected, where is it stored, how is it used and when is it deleted? Who has access? Is a supplier involved?
- Necessity and proportionality. Which specific problem are you solving, such as unauthorised access to the server room? Why are badges or codes not sufficient in this case? Is the data you collect the minimum needed?
- The risks for the people involved. What if the database of templates is stolen? Could the data later be used for other purposes, such as monitoring working hours (function creep)? What happens to employees whose fingerprints cannot be read? What if the system locks out an authorised person during an emergency?
- Measures to address the risks. Technical measures such as encryption and storage on a card or the device; organisational measures such as a policy, training and a breach response plan; and a non-biometric alternative so that no one is excluded.
A DPIA is not a one-off document. Review it when the scope, nature or context of the processing changes. It is your main evidence that you considered the deployment carefully. An analysis written after a complaint carries little weight; the same analysis carried out beforehand shows that the decision was well considered.
Which safeguards are expected?
Collect as little as possible, keep it no longer than necessary and protect it with strong technical and organisational measures. These principles follow from Articles 5 and 32 GDPR.
Start with data minimisation: collect only the biometric data needed for the specific, legitimate purpose. For access control, a template is usually enough; a high-resolution facial scan is not needed. Combine this with storage limitation: set a retention period and delete the data securely as soon as it is no longer needed, for instance when an employee leaves or no longer needs access.
Technical and organisational measures
Security must match the high risk. Key technical measures include:
- Encryption of biometric data, both at rest and in transit.
- Strict access controls, so that only authorised staff with a clear need can access the data.
- Decentralised storage: where possible, store templates on the device or on the user’s own card rather than in a central database. That makes a mass breach much less likely.
Technology alone is not enough. Organisational measures, such as a written policy on biometric data, staff training, periodic security audits and clear agreements with suppliers, are equally important. If a supplier processes the data on your behalf, you need a processing agreement under Article 28 GDPR.
A clear privacy notice
People have the right to know what you do with their biometric data (Articles 13 and 14 GDPR). The information must be concise, easy to find and written in plain language.
A privacy notice on biometric processing should explain who you are and how to contact you, why you process the data, the legal basis under Article 6 and the exception relied on, which data you collect (for instance a fingerprint template), how long you keep it, with whom you share it, including suppliers, and which rights people have, such as access, rectification, erasure and objection.
An example of clear wording: “We use a fingerprint template, a numerical representation of your fingerprint, to give you access to the server room. The template is stored only on your personal access card. We delete it from our systems when your access ends. You can ask to see or delete your data at any time.”
Does the AI Act also apply?
Yes, for certain biometric systems. The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) adds rules on top of the GDPR.
Since 2 February 2025, the AI Act prohibits a number of practices outright, including untargeted scraping of facial images from the internet or camera footage to build facial recognition databases, emotion recognition in the workplace and in education (except for medical or safety reasons) and biometric categorisation to infer sensitive characteristics such as race or sexual orientation. Other biometric systems, such as remote biometric identification, are classified as high-risk and are subject to strict requirements. Check both frameworks before introducing a system.
What are the consequences of non-compliance?
High fines, orders to stop processing and claims for damages. For unlawful processing of special categories, the GDPR allows fines of up to 20 million euros or 4% of worldwide annual turnover, whichever is higher.
These maximum amounts follow from Article 83(5) GDPR and apply, among other things, to processing without a valid basis or exception. Breaches of the obligations on security and breach notification (Articles 32 to 34 GDPR) can lead to fines of up to 10 million euros or 2% of worldwide turnover. Fines must be effective, proportionate and dissuasive. The AP determines the amount under its own fining policy.
What has the AP enforced?
The AP has fined both employers and technology companies for unlawful biometric processing. Two decisions stand out.
In 2020 the AP imposed a fine of 725,000 euros on a company that scanned employees’ fingerprints for attendance and time registration. The AP found that neither exception applied: the employees’ consent was not freely given, and convenience in registering hours is not a security purpose that makes biometric processing necessary. In September 2024 the AP fined the American company Clearview AI 30.5 million euros for building a database of facial images, including of Dutch people, without a legal basis.
Four questions run through the AP’s enforcement. What is the purpose, stated specifically rather than as “security” in general? Could it be achieved by less intrusive means? If consent is relied on, could people refuse without consequences? And was this assessed and documented before the system was introduced? Our article on the Dutch Data Protection Authority explains the AP’s powers in more detail.
Other consequences
A fine is not the only risk. The AP can order you to stop the processing, which can halt a system your operations depend on, and it can order you to delete unlawfully collected data. People whose data was processed unlawfully can claim compensation for material and non-material damage under Article 82 GDPR, and in the Netherlands such claims can also be brought collectively. The reputational damage of a public enforcement decision can be considerable.
What do you do if biometric data is leaked?
Contain the breach, assess the risk, notify the AP within 72 hours and, if the risk is high, inform the people affected without undue delay. Prepare this in a response plan before anything goes wrong.
Under Article 33 GDPR, you must report a personal data breach to the AP without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the people concerned. The notification describes the nature of the breach, the categories and approximate number of people and records affected, the likely consequences and the measures taken or proposed. If you cannot provide all information at once, you can supplement it later.
Step 1: contain the breach and assess the impact
Your first priority is to stop the breach. Isolate the affected systems, preserve logs and other evidence for the investigation, and establish exactly which data was affected: raw images or encrypted templates, and of whom.
Step 2: decide whether to inform the people affected
Under Article 34 GDPR, you must inform the people affected without undue delay if the breach is likely to result in a high risk to their rights and freedoms. With biometric data, that threshold will often be met, because the data cannot be changed. The exception is, for example, data that was strongly encrypted and whose key was not compromised. The message must be in plain language: what happened, which data was involved and what people can do to protect themselves.
Step 3: carry out and document the response
Record every step: the moment of discovery, the decisions taken, the communications and the technical measures. Under Article 33(5) GDPR you must document every breach, including those you did not have to report. Good documentation shows the AP that you acted carefully and can affect how it assesses the case.
How does it work in practice?
Most questions we see come from employers who want to replace badges with fingerprints or face scans, and from companies that want to use biometrics for customer verification. The outcome depends on necessity and on the alternatives available.
Take a logistics company that wants to use fingerprint scanners at the entrance of its warehouse. The DPIA shows that the aim is to prevent badge sharing, but that personal badges with a PIN code would largely solve that problem. The company opts for badges and PIN codes, and keeps biometric access only for a small vault room with high-value goods, where it offers a non-biometric alternative, stores templates on personal cards and has obtained the works council’s consent. That is the kind of reasoning the AP expects to see.
In summary
- Biometric data used for unique identification is a special category under Article 9 GDPR; processing is prohibited unless an exception applies.
- In the Netherlands, Article 29 UAVG allows it only where necessary for authentication or security; convenience is not enough.
- Employee consent is rarely valid; offer a real non-biometric alternative and obtain the works council’s consent where required.
- Carry out a DPIA beforehand, minimise the data, store templates locally and encrypt them.
- Report breaches to the AP within 72 hours; fines can reach 20 million euros or 4% of worldwide turnover.
Frequently asked questions
Can I require employees to use a biometric time clock?
In almost all cases, no. Time registration can be done with a badge or code, so biometrics is not necessary for authentication or security under Article 29 UAVG. Employee consent is rarely freely given. The AP fined a company 725,000 euros in 2020 for scanning employees’ fingerprints for attendance and time registration.
Is using facial recognition to unlock a company phone a GDPR risk?
It can be. If the facial template is stored only on the device and never sent to company servers, the risk is much lower, because the employer does not process the biometric data itself. Be transparent with employees about how it works and offer a PIN or password as an alternative.
How long can we store biometric data after an employee leaves?
No longer than necessary for the original purpose. For access control, delete the template when the employee leaves or no longer needs access. Set a clear retention period and, where possible, automate the deletion.
Law & More advises employers and technology companies on biometric systems, DPIAs, data breaches and proceedings before the AP. Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.
How Law & More can help you with this is explained on our IT lawyer page.

