A woman with digital code projections on her face, representing technology and future concepts.
| | | | |

Ban on Using Facial Recognition for Employee Attendance Tracking

The Case: Employee Attendance Tracking Through Facial Recognition

In recent decisions published in the newsletter of March 28, 2024, the Italian Data Protection Authority (Garante per la protezione dei dati personali) sanctioned several employers who, following complaints from employees, had implemented biometric data collection systems for employee attendance tracking at the workplace. Indeed, they specifically used facial recognition.

As a result, this practice was deemed an unlawful processing of data, lacking a valid legal basis, and contrary to the principles of lawfulness, necessity, and proportionality.

Legal Framework on Biometric Data

Biometric data are defined in Article 4, paragraph 14, of EU Reugulation 2016/679 (GDPR) as

personal data obtained through a specific technical processing related to the physical, physiological, or behavioral characteristics of a natural person which allow or confirm the unique identification of that person, such as facial images or fingerprint data.

EU Reugulation 2016/679 (GDPR) – Article 4, paragraph 14

Generally, the processing of such data is generally prohibited under Article 9, paragraph of the GDPR. However, this doesn’t apply under one of the conditions specified in paragraph 2 of the same article. Specifically, processing is allowed only when necessary to meet employment or social security obligations or rights and is authorized by law or a collective agreement. Moreover, appropriate safeguards must protect employees’ fundamental rights.

Furthermore, Article 2-septies of Italian Legislative Decree 196/2003 confirms that genetic, biometric, and health-related data may be processed under the conditions of Article 9, paragraph 2 of the GDPR and in accordance with the safeguards established by the Authority through biennial measures. However, such measures are still under approval.

Consequently, even the employee’s consent cannot be considered a valid legal basis for processing biometric data in the employment relationship.

The Authority’s Decision

Considering the absence of specific legislation, the Authority confirmed that:

  • The current legal framework does not permit the processing of biometric data for the purpose of monitoring attendance at the workplace.
  • Using biometric data to address disciplinary issues or disputes over overtime compensation is not compliant with the principles of data minimization and proportionality. This also applies to the use of other tools that can effectively ensure attendance monitoring at the workplace, such as badge systems.

Additional Violations and Sanctions

In this context, the Authority identified further violations committed by employers, as data controllers:

  • Failure to provide information. Not informing employees and collaborators about the essential characteristics of the data processing activities, as required by Article 13 of the GDPR.
  • Failure to designate a Data Processor. Not appointing the third-party company managing the facial recognition application as a Data Processor, as stipulated by Article 28 of the GDPR.
  • Failure to conduct a Data Protection Impact Assessment (DPIA). Not carrying out a DPIA, as mandated by Article 35 of the GDPR, to assess the risks associated with the processing of biometric data.
  • Omission of biometric data in the data processing register. The employer failed to list biometric data among the types of data processed in the register maintained by the data controller.
  • Insufficient technical and organizational measures. The employer did not implement adequate measures to ensure a level of security appropriate to the risk, guaranteeing the confidentiality of data on an ongoing basis.

IAs a result of these findings, injunction orders were issued against each of the companies involved. They required the payment of administrative fines ranging from €2,000 to €70,000. These injunctions were proportionate to the size of the companies, as well as to their conduct during the proceedings. Additionally, the measures were published on the Authority’s official website.