Skip to content

Ελληνικά

GDPR and attendance data: what Cyprus employers must do

The short answer

Is a clock-in record personal data?

Yes, and it is worth being precise about why, because the answer shapes everything downstream. A record that a named person clocked in at a given time is information relating to an identified individual, which is the core of personal data, and its processing in Cyprus is governed by the GDPR as given effect and complemented by Law 125(I)/2018. [1] Most attendance data is ordinary personal data: a name, a date, a pair of timestamps. The line that matters is with biometric attendance. The GDPR defines biometric data as data resulting from specific technical processing of a person's physical, physiological or behavioural characteristics that allows or confirms their unique identification: fingerprints and facial images being the textbook examples. [3] Where such data is used to identify someone uniquely, it is a special category whose processing is prohibited in principle unless an Article 9(2) condition applies. [2] So a card swipe or PIN log is ordinary personal data; a fingerprint clock-in is special-category data. The duties that follow differ accordingly, and conflating the two is the most common source of trouble.

One nuance catches employers out: the photograph. A face captured on a clock-in photo is not automatically special-category data. The GDPR treats photographs as ordinary personal data, and covers them by the biometric definition only when they are processed through specific technical means that allow the unique identification or authentication of a person. [5] A snapshot filed against a timestamp is ordinary personal data; the same image fed to a facial-recognition template that matches the face to an identity crosses into the special category. What draws the line is what the technology does with the image, not the fact that a face appears in it: which is exactly where the biometric analysis in our companion guide to biometric attendance takes over.

Picking a lawful basis (and why consent is the trap)

Every processing of attendance data needs a lawful basis, and the choice matters more than it first looks. The instinct is to reach for employee consent, but in the workplace that is the weak foundation. The imbalance of power between employer and worker makes consent hard to treat as freely given [6], and a consent the worker can withdraw at will is a fragile footing for a record you are operationally required to keep. This is not just a local reading. At EU level the Article 29 Working Party (the body that preceded the European Data Protection Board) concluded that employees are almost never in a position to freely give, refuse or revoke consent, given the dependency inherent in the relationship, so consent can be a valid basis only in the exceptional case where no consequence at all attaches to accepting or refusing. [7] For ordinary attendance data, most employers lean instead on a basis tied to the employment relationship and the legitimate running of the business: documented, not assumed. Whatever you pick sits within the Cyprus framework of the GDPR as complemented by Law 125(I)/2018, so the reasoning should be written down and defensible to the Commissioner. [1] Biometric attendance is where reaching for consent fails twice over. Because biometric-for-identification is special-category data, an ordinary lawful basis is not enough: you additionally need a specific Article 9(2) condition to lift the general prohibition, and that condition must genuinely apply, not simply be asserted. [2] And in Cyprus the Commissioner has held, in the biometric-attendance context, that employee consent does not lift the unlawfulness, because consent in the employment context is not freely given. [6] In short: choose a basis on purpose, treat consent in the workplace with suspicion, and for biometrics know that a second, special-category gate stands in the way.

The workplace angle: Article 88

Attendance data is workplace data, and the GDPR treats the workplace as a setting that may earn its own rules. Article 88(1) lets Member States, by law or by collective agreement, lay down more specific rules to protect employees' personal data in the employment context: expressly including processing for recruitment, for performance of the employment contract, and for the management, planning and organisation of work, which is the very bucket attendance and rostering fall into. [8] That matters for two reasons. First, the framework you operate under in Cyprus is the GDPR as given effect and complemented by Law 125(I)/2018, read in a workplace-specific light rather than as generic data-protection law. [1] Second, and more useful, Article 88(2) tells you what any such employment rules must contain: suitable and specific measures safeguarding the worker's human dignity, legitimate interests and fundamental rights, with particular regard to the transparency of processing, the transfer of data within a group of undertakings, and, named outright, monitoring systems at the workplace. [8] Read that list as a checklist for your own attendance processing: be transparent about what you record and why, take care when attendance data flows to a parent or affiliate, and treat any attendance mechanism that shades into monitoring as the sensitive case the Regulation plainly considers it. That transparency-and-monitoring thread is the same one running through our guide to workplace monitoring and proportionality. It is no accident the drafters singled those out.

What is a DPIA, and when do you need one?

Under the GDPR, which applies in Cyprus, a data protection impact assessment (DPIA) is an assessment the controller must carry out before processing begins, whenever a type of processing (in particular one using new technologies) is likely to result in a high risk to people's rights and freedoms. [4] For an ordinary card or PIN attendance log the high-risk trigger is not usually met; a biometric attendance system, being high-risk special-category processing, is the case that needs one. [4] [2]

When you owe a DPIA before go-live

A data protection impact assessment is required before you start processing that is likely to result in a high risk to people's rights and freedoms, particularly where new technologies are involved. [4] For everyday attendance (a card, fob, QR code or PIN producing a name and two timestamps), the high-risk trigger is not usually met, though minimisation and retention discipline still apply. Biometrics change the picture decisively. Using a fingerprint or facial scan to identify employees is exactly the kind of high-risk processing of a special category the DPIA obligation is aimed at, so where biometric attendance is on the table the DPIA comes first: before go-live, not retrofitted after an inspector asks for it. [4] [2] The European Data Protection Board frames the substance the assessment must grapple with: biometric processing, and facial recognition in particular, carries heightened risks, so any recourse to it must respect lawfulness, necessity, proportionality and data minimisation, and the controller should first assess the impact on fundamental rights and weigh less intrusive means before adopting it. [9] The Board adds a sharp point for the private sector: where biometric data is processed to identify a person uniquely, it falls under Article 9 and, when a private organisation deploys it for its own purposes, will in most cases require the explicit consent of every data subject. Explicit consent is exactly what the employment relationship makes hard to get freely. [9] [2] One Cyprus-specific warning: for routine attendance the Commissioner has already answered the question the DPIA asks: biometric clock-in is disproportionate because less intrusive methods achieve the same purpose, so expect the assessment to point you away from biometrics for the timesheet, not through them. [6] The DPIA is where you set out the purpose, weigh the less-intrusive alternatives and why they fell short, and record the safeguards: restricted access, template-only storage, a defined retention period. Treat it as the discipline that decides whether the processing should happen at all, not a form you file once you have already decided.

Keep less, keep it shorter

Two GDPR principles do quiet, continuous work on attendance data: collect only what the purpose needs, and keep it only as long as that purpose lasts. Minimisation means the record stops at the hours actually worked: a timestamp is enough to run payroll and evidence attendance; a running location trail, a photo on every punch, or a biometric template collected "to be safe" is more than the purpose requires. Retention means deciding, up front, how long each category of attendance data is kept, then deleting or anonymising it when that period ends, rather than letting years of timestamps pile up by default. Because this all sits within the GDPR as complemented by Cyprus Law 125(I)/2018, the retention schedule and the minimisation choices should be written down and defensible to the Commissioner, not left implicit. [1] The instinct that keeps you on the right side of both: prefer the least data that answers "was this person at work, and for how long?", and where biometrics are involved, remember that minimisation cuts hard against holding a special category of data the Commissioner has already found disproportionate for routine attendance. [2] [6]

Quick answers to the questions owners ask

Is a simple clock-in record really covered by GDPR?

Yes: a named person's attendance times are personal data, processed in Cyprus under the GDPR as given effect and complemented by Law 125(I)/2018. [1]

Can we just rely on employees consenting?

Be careful. In employment, consent is a weak basis because of the power imbalance [6], and the Article 29 Working Party concluded at EU level that employees can almost never give consent freely, so it holds only where accepting or refusing carries no consequence at all. [7] For biometric attendance an ordinary basis is not even enough: you also need an Article 9(2) condition to lift the special-category prohibition. [2]

Are there special rules for employee data?

Member States may set them: Article 88 lets national law or collective agreements provide more specific employment-data rules, and requires safeguards for dignity and fundamental rights with particular regard to transparency and workplace monitoring systems. [8]

Is a photo of an employee special-category data?

Not by itself. A photograph is ordinary personal data, and becomes biometric data only when processed by specific technical means to identify a person uniquely, such as facial recognition. [5]

Do we need a DPIA for a normal card or PIN system?

Usually not; the DPIA trigger is high-risk processing, particularly involving new technologies. But a biometric attendance system is high-risk special-category processing and should have a DPIA completed beforehand. [4] [2]

What makes biometric attendance data "special"?

When a fingerprint or facial image is used to identify a person uniquely it meets the Article 4(14) definition of biometric data and becomes a special category, prohibited in principle unless Article 9(2) applies. [3] [2]

How long can we keep attendance records?

Only as long as the purpose needs; set a retention period in advance, delete or anonymise afterwards, and keep the schedule defensible under Law 125(I)/2018. [1]

This article is general guidance on GDPR and Cyprus Law 125(I)/2018, not legal advice for your specific situation. Every legal statement above is footnoted to a primary source you can read in full on our sources and references page.

References

  1. Ο περί της Προστασίας των Φυσικών Προσώπων Έναντι της Επεξεργασίας των Δεδομένων Προσωπικού Χαρακτήρα και της Ελεύθερης Κυκλοφορίας των Δεδομένων αυτών Νόμος του 2018 (125(I)/2018) . Republic of Cyprus (via CyLaw), 2018-07-31 (CY)
  2. Regulation (EU) 2016/679 (GDPR), Article 9 — Processing of special categories of personal data . European Union (Official Journal L 119), 2016-04-27 (EU)
  3. Regulation (EU) 2016/679 (GDPR), Article 4(14) — Definition of biometric data . European Union (Official Journal L 119), 2016-04-27 (EU)
  4. Regulation (EU) 2016/679 (GDPR), Article 35 — Data protection impact assessment . European Union (Official Journal L 119), 2016-04-27 (EU)
  5. Regulation (EU) 2016/679 (GDPR), Recital 51 . European Union (Official Journal L 119), 2016-04-27 (EU)
  6. Γνώμη 2/2018 για ΚΚΒΠ και βιομετρικά στο χώρο εργασίας (Opinion 2/2018 on CCTV and biometrics in the workplace) . Office of the Commissioner for Personal Data Protection (Cyprus), 2018-10-19 (CY)
  7. Opinion 2/2017 on data processing at work (WP249) . Article 29 Data Protection Working Party, 2017-06-08 (EU)
  8. Regulation (EU) 2016/679 (GDPR), Article 88 — Processing in the context of employment . European Union (Official Journal L 119), 2016-04-27 (EU)
  9. Guidelines 3/2019 on processing of personal data through video devices, Version 2.0 . European Data Protection Board, 2020-01-29 (EU)