Attendance, biometrics and the law in Cyprus
One principle runs through all of it
An inspector at your door, a fine on the table, a regulator that has already said no to the option many employers reach for first: that is the terrain this guide maps, and one idea keeps you on the right side of it: proportionality. Cyprus and EU data-protection law rarely ask “is this technology allowed?” and almost always ask “is this the least intrusive way to achieve the purpose?”. The Cyprus Commissioner for Personal Data Protection put it plainly for the workplace: a measure that goes further than necessary (a biometric system to record ordinary attendance, say) fails the necessity and proportionality principles even where the employer means well and the staff have signed a form. [1] That single test is the thread tying the five topics below together. Once you can put it to any attendance or monitoring decision (is there a less intrusive method that does the same job?), the specific rules stop reading as a list to memorise and start reading as one consistent idea in different settings.
The five questions this guide answers
Attendance touches five distinct areas of law, and keeping them apart is half the battle. First, biometrics: whether fingerprint or face clock-in is lawful for everyday attendance, and the narrow high-security case where it can still be justified. Second, working-time records: what Cyprus actually makes you log today, and where EU law is heading. Third, ERGANI and employment terms: the duty to register each employee's essential terms (the agreed hours schedule included) in the Cyprus ERGANI information system under Law 25(I)/2023. Fourth, GDPR and attendance data: every timesheet is personal data [2], so you need a lawful basis, data minimisation and a retention limit, and biometric attendance data is a special category that raises the bar [3]. Fifth, monitoring: how the same proportionality test governs cameras, location tracking and access logs, not just clock-in. Each has its own article below. The pillar keeps the map high-level and points you to the right one; the detail, the exceptions and the worked examples live in the articles.
Where to start
Choosing or reviewing an attendance system? Start with the biometric article: it is where most compliance mistakes begin, and its proportionality reasoning sets up everything else. If your question is about hours and records rather than the clock-in method, go straight to the working-time article. If you already collect attendance data and want to know your obligations as a controller, read the GDPR article next. And if your worry is wider surveillance (cameras, GPS, or logging), the monitoring article generalises the same principle. The references page at the end lists every primary source behind the guide (the Cyprus Commissioner’s Opinion, the relevant GDPR articles, Cyprus Law 125(I)/2018, the working-time law, the CJEU’s CCOO ruling and the European Commission report), each linked, dated and tagged by jurisdiction, so you can check any statement against its source. One note on scope: this is general guidance on Cyprus and EU law, accurate and current as of the review date above, not legal advice for your specific situation.
References
- Γνώμη 2/2018 για ΚΚΒΠ και βιομετρικά στο χώρο εργασίας (Opinion 2/2018 on CCTV and biometrics in the workplace) . Office of the Commissioner for Personal Data Protection (Cyprus), 2018-10-19 (CY)
- Ο περί της Προστασίας των Φυσικών Προσώπων Έναντι της Επεξεργασίας των Δεδομένων Προσωπικού Χαρακτήρα και της Ελεύθερης Κυκλοφορίας των Δεδομένων αυτών Νόμος του 2018 (125(I)/2018) . Republic of Cyprus (via CyLaw), 2018-07-31 (CY)
- Regulation (EU) 2016/679 (GDPR), Article 9 — Processing of special categories of personal data . European Union (Official Journal L 119), 2016-04-27 (EU)