MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Biometric authentication in the workplace is not easily enforceable in the Netherlands. A fingerprint, iris scan, or facial recognition constitutes special personal data, for which there is, in principle, a processing prohibition under the GDPR. Employee consent often offers no solution, as it is rarely considered “free” due to the hierarchical relationship. In practice, mandatory use is only permitted if it is demonstrably necessary for security or authentication and there is no less intrusive alternative. For most SME employers, this means: first look at PIN codes, access cards, or tokens before deploying biometrics.
Can an employer require biometric authentication? Short answer
In most cases, no. An employer may only require biometrics if they can concretely demonstrate that it is necessary for authentication or security purposes and that less restrictive means (PIN code, access card, token) are insufficient. If this substantiation is not possible – and this rarely happens in SMEs – then mandatory biometrics is in violation of the GDPR. Requesting consent is usually not a valid alternative, as consent is generally not considered freely given in an employment relationship.
What exactly is biometric authentication?
Authentication proves that a person is indeed the person requesting access. Many companies use multifactor authentication (MFA): in addition to a password, a second element is added to confirm the identity. Examples include an SMS code, a token generator, or a biometric characteristic.
Biometric authentication uses unique physical characteristics to recognize an individual. The best-known examples are fingerprints, iris scans , and facial recognition. Because many smartphones and laptops already have such a feature built in, it is logical for employers to deploy biometrics in the workplace as well, for example, to secure a point-of-sale system or a server room. Legally speaking, however, doing so immediately places you on the strictest part of privacy legislation.
Biometric data is special personal data
The GDPR classifies biometric data, insofar as it is processed for the purpose of uniquely identifying a person, as special personal data. The GDPR uses a broad definition in this regard: it concerns the “result of specific technical processing of physical, physiological or behavioural characteristics” of a person, on the basis of which that person can be uniquely identified.
The Dutch Data Protection Authority cites fingerprints, iris scans, and facial recognition as clear examples. In addition, characteristics such as voice, heart rate, or certain behavioral patterns may also fall under the definition, provided they are technically processed to uniquely identify an individual. There is still relatively little published case law in this area, meaning the exact boundaries are still becoming clearer. Special categories of personal data are subject to a stricter protection regime than “ordinary” personal data such as a name or email address.
The legal framework in brief
For those who want to quickly understand where the boundaries lie, it revolves around three layers:
- Processing prohibition: in principle, you may not process special personal data.
- Consent as an exception: express, freely given consent can be a ground, but usually does not work in an employment relationship (see below).
- Necessity for authentication or security: the Dutch Implementing Act (UAVG) permits processing if it is genuinely necessary for authentication or security purposes. This is often the only realistic route for employers, and the bar is set high.
Why asking for permission is usually not enough
In principle, a processing prohibition. The legislator aims to prevent identity fraud and abuse. However, there are exceptions to this prohibition. A well-known exception is the explicit consent of the data subject.
However, it is precisely in the employer-employee relationship that this route is difficult. The GDPR requires that consent be given freely, specifically, informed, and unambiguously . According to the regulator, a truly free choice is generally not possible as soon as a hierarchical relationship exists, and in the case of an employment contract, this is by definition the case. An employee may feel pressured to say “yes” out of fear of consequences for his or her job. As a result, consent-based biometrics in the workplace often do not hold up.
As an employer, do not count on a signature on a consent form being sufficient. In an employment relationship, such consent is taken very seriously and is often not considered freely given.
Allowed: only if biometrics are necessary
There is a second route. The Dutch Implementing Act for the GDPR (the UAVG) contains an exception for situations where the processing of biometric data is necessary for authentication or security purposes. This word “necessary” should not be treated lightly. The explanatory notes to the Act cite the security of a nuclear power plant as an example – thus truly situations involving a compelling interest. Access to, for example, an ordinary workshop or shop generally does not meet that threshold.
The practical test amounts to a balancing of interests:
- Proportionality: is the infringement on privacy proportionate to the security interest?
- Subsidiarity: is there no less intrusive alternative that achieves the same goal, such as a PIN code, access card, or token generator?
- Justification: can you demonstrate with documents and an assessment why you are specifically choosing biometrics?
If you cannot demonstrate that a less invasive measure is insufficient, the necessity is quickly lacking and biometrics are not permitted.
The Manfield case: fingerprints on the cash register
A striking example is a ruling by the Amsterdam District Court on August 12, 2019, concerning shoe retailer Manfield. Manfield had equipped its point-of-sale systems with a fingerprint scanner and required employees to provide their fingerprints. According to the company, this was necessary to prevent fraud and protect sensitive data in the point-of-sale system.
The judge did not agree with this. Manfield had insufficiently substantiated why a fingerprint system specifically was necessary, while less intrusive alternatives existed, such as numerical codes and access cards, possibly in combination. According to the court, Manfield's business interest did not entail the necessity for security or authentication purposes required by law. The lesson: a general appeal to “security” or “fraud prevention” is not enough. You must be able to concretely demonstrate the necessity, preferably supported by a DPIA and demonstrable research into alternatives.
Biometrics or a lighter alternative? A brief comparison
Before opting for biometrics, it is wise to compare the common authentication methods. The rule of thumb: the less special personal data you process, the lower your legal risk.
- PIN code or password: no sensitive personal data, easy to reset, low privacy risk. Often sufficient.
- Access card or badge: personal data but no biometrics; to be blocked upon loss or termination of employment.
- Hardware token or authenticator app (MFA): strong security without physical identification; widely applicable.
- Biometrics (fingerprint, iris, face): special category of personal data, processing prohibition as a starting point, irreversible in the event of a breach. Only where demonstrable necessity.
In the vast majority of SME situations, the first three options achieve the same security goal. This is precisely what makes it so difficult for employers to justify the necessity of biometrics.
Risks associated with the improper use of biometrics
If you implement biometric authentication without a solid basis, you run multiple risks simultaneously as an employer:
- Enforcement by the Dutch Data Protection Authority: the supervisory authority can take action against processing that is in violation of the GDPR.
- Compensation: employees whose data has been processed unlawfully can claim compensation.
- Employment law tensions: an employee who refuses may not simply be punished for doing so, which can lead to conflicts or legal proceedings.
- Reputational damage: privacy incidents involving staff are sensitive and can damage trust within the company.
Moreover, biometric data is irreversible: unlike a password, you cannot reset a leaked fingerprint. This makes due diligence beforehand all the more important.
Step-by-step plan for SME employers
Are you considering biometric authentication or another far-reaching security measure? Then proceed in a structured manner:
- Determine the goal. What specific security or authentication problem do you want to solve?
- Explore alternatives. Are a strong password policy, MFA via a token, or an access card sufficient? If so, biometrics are probably not necessary.
- Conduct a balancing of interests. Weigh the security interest against the privacy of your employees and document this in writing.
- Conduct a DPIA. As a rule, a Data Protection Impact Assessment (DPIA) is recommended when processing special categories of personal data.
- Inform and involve staff. Be transparent and involve the Works Council where applicable.
- Record agreements. Incorporate it into your internal privacy policy and document the retention period and security of the data.
Frequently Asked Questions
Am I allowed to require my employees to use a fingerprint?
Only if you can demonstrate that this is necessary for security or authentication and that no less intrusive alternative exists. In most standard business situations, such substantiation is not possible, and mandatory biometrics are therefore not permitted.
Is employee consent sufficient?
Usually not. Due to the power imbalance between employer and employee, consent is often not considered “free.” Therefore, you cannot simply rely on consent to introduce biometrics.
Do fingerprint unlocking of a private phone and facial recognition also fall under this?
The question concerns who processes the data and for what purpose. If an employee unlocks their own device, you, as the employer, usually do not process that biometric data. However, if you impose a biometric system for access to company resources, you are the data controller and the strict rules apply.
What is a less invasive alternative to biometrics?
Consider a personal PIN code, an access card, a hardware token, or MFA via an app. Such means often achieve the same security goal without requiring you to process special personal data.
Do I need to conduct a DPIA for biometrics in the workplace?
As a rule, yes. The large-scale processing of special categories of personal data, such as biometrics, is generally considered high-risk processing. A Data Protection Impact Assessment (DPIA) helps you demonstrably weigh the necessity, proportionality, and alternatives—exactly what a judge or the supervisory authority expects of you.
Am I allowed to dismiss or punish an employee who refuses to provide their fingerprints?
Be very cautious with that. If the mandatory biometrics themselves are not legally tenable, the employee is acting lawfully by refusing, and a sanction or dismissal on that ground is risky. It could lead to an employment dispute. Therefore, first assess whether the measure is permitted at all before considering the consequences for the employee.
What happens if I break the rules?
The Dutch Data Protection Authority can enforce regulations, and affected employees can claim compensation. In addition, you risk employment disputes and reputational damage. Careful consideration beforehand prevents many problems.
Handling staff personal data with care
As an employer, you constantly come into contact with your employees' personal data, especially regarding digital systems, new working methods such as bring your own device , and security applications. A well-thought-out privacy policy prevents fines, claims, and hassle in the workplace. If you want to properly manage biometrics or another measure, define in advance what you process, why, and for how long – for example, in an internal privacy statement for employees. Because this affects the position of your staff, it is wise to align this with your broader employment law agreements.
Need help with privacy in the workplace?
Are you unsure whether your security measure passes legal scrutiny, or do you want to bring your privacy policy into order? Our legal experts are happy to think along with you, in a practical manner and without unnecessary jargon.
- More about our work in privacy and data protection
- Questions about personnel and the workplace? View our employment law
Schedule a no-obligation intake and discuss your situation with one of our legal experts.