Skip to content

Ελληνικά

Is fingerprint or face clock-in legal in Cyprus?

The short answer

Why a fingerprint is not just another HR field

Treat a fingerprint template or a face scan like an ordinary staff record and you have already gone wrong. The GDPR defines biometric data as information from specific technical processing of a person’s physical, physiological or behavioural characteristics that allows or confirms their unique identification: fingerprints and facial images are the textbook examples. [2] The moment that data is used to single someone out, it becomes a special category, and processing it is prohibited in principle unless one of the narrow conditions in Article 9(2) applies. [3] In Cyprus this sits inside Law 125(I)/2018, the national law that gives effect to and complements the GDPR. [4] So a fingerprint clock-in does not merely collect a time. It processes a special category of personal data, and the law starts from a flat no.

One nuance decides what actually counts as biometric processing, and it trips people up constantly. The trigger is the technical processing for unique identification, not the mere presence of an image. The GDPR says so directly: a photograph is not automatically special-category data; it is biometric data only when processed through specific technical means allowing the unique identification or authentication of a person. [5] Picture it in your car park. A camera over the card reader (the very safeguard the Commissioner offers as a less-intrusive alternative below) records footage; on its own it does not extract a facial template to identify anyone, so it is ordinary video, not biometric processing. Feed that same footage into a facial-recognition system that matches faces to name each employee, and you have crossed the line into biometric data used for unique identification, with Article 9 and its prohibition-in-principle now in play. [3] [5] What draws the line is what the technology does, not whether a face happens to appear in the frame.

What counts as biometric data under Cyprus law?

Under the GDPR, which applies in Cyprus, biometric data is personal data resulting from specific technical processing of a person’s physical, physiological or behavioural characteristics that allows or confirms their unique identification: fingerprints and facial images being the textbook examples, and, when used to identify someone uniquely, a special category of data. [2] [3] The trigger is that technical processing for unique identification, not the mere presence of an image: a photograph is biometric only when processed through specific technical means to identify a person. [5]

The one question the regulator asks

The Commissioner is not waging war on technology. The reasoning is a proportionality test, and it turns on a single question: could you have logged attendance a less intrusive way? Almost always, yes. The Opinion’s own examples are a card swipe, unannounced spot-checks of the card system, a supervisor on the floor, or a camera positioned over the card reader; and a PIN or QR code is the same idea in modern form. Because any of those already does the job, a biometric system is more than the purpose needs, and it fails the necessity and proportionality principles. [1] The upshot: for routine attendance, biometric clock-in is not permitted in Cyprus. Be clear about what that is not. It is not a claim that biometrics are unlawful everywhere, and it is not a rule you can engineer around by buying a cleverer device. The test is the less-intrusive-method question, and for a timesheet, a less intrusive method always exists. That same lens is not reserved for biometrics; it is exactly how the Commissioner weighs workplace monitoring generally, from cameras to location tracking, which is why the analysis here reads across so cleanly to other tools.

A hospital tried it: and lost in court

This is not just a regulator’s opinion you might hope to argue around. It has been to court and survived. A private hospital rolled out a fingerprint system to control its employees’ working hours, then challenged the Commissioner’s decision that the practice was unlawful. The Administrative Court of Cyprus dismissed the recourse and sided with the Commissioner: collecting and processing employees’ fingerprints for the sole purpose of controlling their working hours breaches the principle of proportionality and is a disproportionate interference in employees’ human dignity and private life, and the employees’ consent does not cure that unlawfulness once a breach of proportionality is established. [6] Weigh that as a business owner. A court, not merely the regulator, called fingerprint clock-in for attendance a disproportionate breach and threw out consent as a fix: the very consent argument vendors still lean on.

One caveat keeps this citation honest and sets how much weight the judgment carries today. The court decided the case under the data-protection law then in force, Law 138(I)/2001, which has since been repealed and replaced by Law 125(I)/2018 as the instrument giving effect to the GDPR in Cyprus. [6] [4] So read the ruling as judicial confirmation of the proportionality position (an authoritative affirmation that the disproportionality analysis and the rejection of employment consent hold up), not as a statement of the current statute. The governing law now is the GDPR and Law 125(I)/2018; the case shows a Cyprus court applying the same proportionality principle those instruments carry forward, and landing in exactly the same place.

Why the signed consent form will not save you

The most common mistake is to think a signed consent form makes biometric clock-in lawful. It does not. The Commissioner’s view is that employee consent does not cure the problem, because consent in the employment context is not freely given. [1] The reason is the plain imbalance of power between an employer and someone who needs the job. So when a vendor or template leans on “the employee agreed,” read it as a red flag, not a green light. And note which way the argument runs at EU level, examined next: even where explicit consent is the condition an employer would rely on, that requirement makes the deployment harder to justify, not easier. It is a demanding bar, not a rubber stamp.

This is Europe’s stance, not a local quirk

Cyprus is not an outlier here. It is applying a settled European approach to biometrics, and once you see the frame you can predict the Commissioner’s conclusion in almost any new case. The European Data Protection Board (the body that keeps GDPR interpretation consistent across the EU) has spelled out how biometric processing must be judged. In its Guidelines 3/2019, the EDPB holds that biometric data, and facial recognition in particular, carries heightened risks for people’s rights, so any use of such technologies must respect lawfulness, necessity, proportionality and data minimisation; before deploying them, a controller should assess the impact on fundamental rights and ask whether a less intrusive means would achieve the same purpose. [7] That is the same necessity-and-least-intrusive-means test the Cyprus DPC applied: the Commissioner was moving with the European consensus, not inventing a local rule.

The EDPB is just as blunt about the lawful basis, and this is where employer plans come apart. Biometric data processed to uniquely identify a person falls under Article 9, and where a private organisation deploys it for its own purposes, the EDPB’s position is that in most cases it will require the explicit consent of all the data subjects. [7] [3] Now set that beside the Cyprus consent point and the trap snaps shut. The special-category gate usually demands explicit consent, yet in the employment relationship that consent is the single hardest thing to obtain validly, because the power imbalance means it is not freely given. [1] You are caught between two requirements pulling opposite ways: the only realistic Article 9 condition for many private-sector biometric deployments is explicit consent, while employment is the one setting where consent is least likely to be valid. That squeeze is a big part of why routine biometric attendance so rarely survives scrutiny, and it bites just as hard on any special-category attendance data, a point developed in our GDPR guide to attendance data.

Where biometrics ARE allowed: and where they are not

Whether biometrics are lawful depends on the environment, and on one distinction people love to blur: guarding a door versus recording the hours. The DPC accepts that, by exception and strictly for premises security, biometrics can be justified to control entry to genuinely high-security locations; what it will not accept is biometrics as the hours-and-attendance mechanism. [1] Read the two rows below by asking one thing: what is this device actually doing?

Row 1: Routine environments (office, retail, hospitality, most sites). Purpose: recording attendance. Compliant method: card or fob, QR code, or PIN. Biometrics: not permitted for attendance. A card swipe, spot-checks, supervisor confirmation, or a camera over the reader already get the job done, so biometrics are disproportionate here. [1]

Row 2: Genuinely high-security physical access. The DPC’s own examples are ports, airports and military installations; comparable controlled spaces include a data centre, a restricted pharmaceutical area, or a cash or vault room. [1] Purpose: controlling who may enter a sensitive space. Biometric access control: can be lawful, but only with a completed DPIA and a valid Article 9(2) condition. [8] [3] Important caveat: even where a biometric door is justified, take the attendance record itself from a non-biometric method. Someone being buzzed through a secure door is an access event, not a timesheet. Keeping the two apart is what keeps the design defensible.

MethodRoutine attendanceWhere it fits
Card or fob, QR code, or PINCompliant [1]Everyday clock-in across an office, shop floor or hospitality site [1]
Fingerprint or facial recognitionNot permitted [1]Genuine high-security physical access only, with a completed DPIA and a valid Article 9(2) condition; never the timesheet [8] [3] [1]

The door genuinely needs it? Two steps before go-live

Where an environment truly justifies biometric access control, two legal steps are non-negotiable before you switch it on. First, because this is high-risk processing of a special category, carry out a data protection impact assessment beforehand; the GDPR requires a DPIA prior to processing that is likely to result in a high risk to people’s rights and freedoms. [8] Second, pin down a specific Article 9(2) condition that lifts the general prohibition on processing biometric data used for unique identification: a lawful basis for the special category, written down, not assumed. [3] The DPIA is where you record the security necessity, the less-intrusive alternatives you weighed and why they fell short for that space, and the safeguards you have put in place (template-only storage, strict access, retention limits). Do all of this for the door if the door needs it, and keep the timesheet on a non-biometric method. [1] The mechanics of the assessment, and the special-category duties that come with it, are set out in our guide to GDPR and attendance data, the companion to this article on the data-protection side.

The compliant path your terminals already support

The design that keeps the DPC happy is a multi-method one, built on the compliant methods ordinary attendance terminals already support. Use card, QR, or PIN for the attendance record everywhere: that is the proportionate way to log hours across an office, a shop floor, or a hospitality site. Reserve biometrics for the narrow case where the environment lawfully justifies access control, and even then let the biometric guard the door while a non-biometric method captures the timesheet. That mirrors exactly what the Commissioner asks for: less intrusive means for attendance, biometrics confined to genuine security needs. [1] It is also simply easier to live with: a lost card is a five-minute fix, whereas a fingerprint template is a liability you have to justify, secure, and one day delete.

Quick answers to the questions owners ask

Can we use a fingerprint scanner if every employee signs a consent form?

No. The DPC’s position is that consent in the workplace is not freely given (the power imbalance between employer and worker), so it cannot make disproportionate biometric attendance lawful; a Cyprus court affirmed exactly this, holding that consent does not cure the breach once disproportionality is established. [1] [6]

We are a small office: does this still apply?

Yes. The proportionality test does not care about headcount; a card, QR, or PIN already records attendance, so a biometric system is disproportionate whatever your size. [1]

Isn’t a camera over the clock-in point automatically biometric data?

Not by itself. A photograph or video becomes biometric data only when processed through specific technical means to identify a person uniquely; plain footage from a camera over the reader is ordinary video, whereas running it through facial recognition to match employees would cross into special-category biometric data. [5] [3]

We run a data centre with a biometric door: is that a problem?

Not necessarily. Biometric access control can be lawful for a genuinely high-security space, provided you complete a DPIA and rely on a valid Article 9(2) condition, but take the attendance record from a non-biometric method. [8] [3] [1]

Is a face or fingerprint really “sensitive” data?

When it is used to identify a person uniquely, yes: it is a special category under the GDPR, prohibited in principle unless an Article 9(2) condition applies, and it fits the Article 4(14) definition of biometric data. [3] [2]

This article is general guidance on Cyprus law and the DPC’s published position, not legal advice for your specific situation. Every legal statement above is footnoted to a primary source; check each one against the original in our sources and references.

References

  1. Γνώμη 2/2018 για ΚΚΒΠ και βιομετρικά στο χώρο εργασίας (Opinion 2/2018 on CCTV and biometrics in the workplace) . Office of the Commissioner for Personal Data Protection (Cyprus), 2018-10-19 (CY)
  2. Regulation (EU) 2016/679 (GDPR), Article 4(14) — Definition of biometric data . European Union (Official Journal L 119), 2016-04-27 (EU)
  3. Regulation (EU) 2016/679 (GDPR), Article 9 — Processing of special categories of personal data . European Union (Official Journal L 119), 2016-04-27 (EU)
  4. Ο περί της Προστασίας των Φυσικών Προσώπων Έναντι της Επεξεργασίας των Δεδομένων Προσωπικού Χαρακτήρα και της Ελεύθερης Κυκλοφορίας των Δεδομένων αυτών Νόμος του 2018 (125(I)/2018) . Republic of Cyprus (via CyLaw), 2018-07-31 (CY)
  5. Regulation (EU) 2016/679 (GDPR), Recital 51 . European Union (Official Journal L 119), 2016-04-27 (EU)
  6. ΑΠΟΛΛΩΝΕΙΟ ΙΔΙΩΤΙΚΟ ΝΟΣΟΚΟΜΕΙΟ ΔΗΜΟΣΙΑ ΕΤΑΙΡΕΙΑ ΛΤΔ ν. Επιτρόπου Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, Υπόθεση Αρ. 1930/2012 (ECLI:CY:DD:2017:189) . Administrative Court of Cyprus (via CyLaw), 2017-05-19 (CY)
  7. Guidelines 3/2019 on processing of personal data through video devices, Version 2.0 . European Data Protection Board, 2020-01-29 (EU)
  8. Regulation (EU) 2016/679 (GDPR), Article 35 — Data protection impact assessment . European Union (Official Journal L 119), 2016-04-27 (EU)