Privacy

Biometric authentication in the workplace: legally enforceable?

Biometric authentication in the workplace is not easily enforceable in the Netherlands. A fingerprint, iris scan, or facial recognition constitutes special personal data, for which there is, in principle, a processing prohibition under the GDPR. Employee consent offers...

Published on September 5, 2019 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote

Biometric authentication in the workplace is not easily enforceable in the Netherlands. A fingerprint, iris scan, or facial recognition constitutes special personal data, for which there is, in principle, a processing prohibition under the GDPR. Employee consent often offers no solution, as it is rarely considered “free” due to the hierarchical relationship. In practice, mandatory use is only permitted if it is demonstrably necessary for security or authentication and there is no less intrusive alternative. For most SME employers, this means: first look at PIN codes, access cards, or tokens before deploying biometrics.

Can an employer require biometric authentication? Short answer

In most cases, no. An employer may only require biometrics if they can concretely demonstrate that it is necessary for authentication or security purposes and that less restrictive means (PIN code, access card, token) are insufficient. If this substantiation is not possible – and this rarely happens in SMEs – then mandatory biometrics is in violation of the GDPR. Requesting consent is usually not a valid alternative, as consent is generally not considered freely given in an employment relationship.

What exactly is biometric authentication?

Authentication proves that a person is indeed the person requesting access. Many companies use multifactor authentication (MFA): in addition to a password, a second element is added to confirm the identity. Examples include an SMS code, a token generator, or a biometric characteristic.

Biometric authentication uses unique physical characteristics to recognize an individual. The best-known examples are fingerprints, iris scans , and facial recognition. Because many smartphones and laptops already have such a feature built in, it is logical for employers to deploy biometrics in the workplace as well, for example, to secure a point-of-sale system or a server room. Legally speaking, however, doing so immediately places you on the strictest part of privacy legislation.

Biometric data is special personal data

The GDPR classifies biometric data, insofar as it is processed for the purpose of uniquely identifying a person, as special personal data. The GDPR uses a broad definition in this regard: it concerns the “result of specific technical processing of physical, physiological or behavioural characteristics” of a person, on the basis of which that person can be uniquely identified.

The Dutch Data Protection Authority cites fingerprints, iris scans, and facial recognition as clear examples. In addition, characteristics such as voice, heart rate, or certain behavioral patterns may also fall under the definition, provided they are technically processed to uniquely identify an individual. There is still relatively little published case law in this area, meaning the exact boundaries are still becoming clearer. Special categories of personal data are subject to a stricter protection regime than “ordinary” personal data such as a name or email address.

The legal framework in brief

For those who want to quickly understand where the boundaries lie, it revolves around three layers:

  • Processing prohibition: in principle, you may not process special personal data.
  • Consent as an exception: express, freely given consent can be a ground, but usually does not work in an employment relationship (see below).
  • Necessity for authentication or security: the Dutch Implementing Act (UAVG) permits processing if it is genuinely necessary for authentication or security purposes. This is often the only realistic route for employers, and the bar is set high.

Why asking for permission is usually not enough

In principle, a processing prohibition. The legislator aims to prevent identity fraud and abuse. However, there are exceptions to this prohibition. A well-known exception is the explicit consent of the data subject.

However, it is precisely in the employer-employee relationship that this route is difficult. The GDPR requires that consent be given freely, specifically, informed, and unambiguously . According to the regulator, a truly free choice is generally not possible as soon as a hierarchical relationship exists, and in the case of an employment contract, this is by definition the case. An employee may feel pressured to say “yes” out of fear of consequences for his or her job. As a result, consent-based biometrics in the workplace often do not hold up.

As an employer, do not count on a signature on a consent form being sufficient. In an employment relationship, such consent is taken very seriously and is often not considered freely given.

Allowed: only if biometrics are necessary

There is a second route. The Dutch Implementing Act for the GDPR (the UAVG) contains an exception for situations where the processing of biometric data is necessary for authentication or security purposes. This word “necessary” should not be treated lightly. The explanatory notes to the Act cite the security of a nuclear power plant as an example – thus truly situations involving a compelling interest. Access to, for example, an ordinary workshop or shop generally does not meet that threshold.

The practical test amounts to a balancing of interests:

  • Proportionality: is the infringement on privacy proportionate to the security interest?
  • Subsidiarity: is there no less intrusive alternative that achieves the same goal, such as a PIN code, access card, or token generator?
  • Justification: can you demonstrate with documents and an assessment why you are specifically choosing biometrics?

If you cannot demonstrate that a less invasive measure is insufficient, the necessity is quickly lacking and biometrics are not permitted.

The Manfield case: fingerprints on the cash register

A striking example is a ruling by the Amsterdam District Court on August 12, 2019, concerning shoe retailer Manfield. Manfield had equipped its point-of-sale systems with a fingerprint scanner and required employees to provide their fingerprints. According to the company, this was necessary to prevent fraud and protect sensitive data in the point-of-sale system.

The judge did not agree with this. Manfield had insufficiently substantiated why a fingerprint system specifically was necessary, while less intrusive alternatives existed, such as numerical codes and access cards, possibly in combination. According to the court, Manfield's business interest did not entail the necessity for security or authentication purposes required by law. The lesson: a general appeal to “security” or “fraud prevention” is not enough. You must be able to concretely demonstrate the necessity, preferably supported by a DPIA and demonstrable research into alternatives.

Biometrics or a lighter alternative? A brief comparison

Before opting for biometrics, it is wise to compare the common authentication methods. The rule of thumb: the less special personal data you process, the lower your legal risk.

  • PIN code or password: no sensitive personal data, easy to reset, low privacy risk. Often sufficient.
  • Access card or badge: personal data but no biometrics; to be blocked upon loss or termination of employment.
  • Hardware token or authenticator app (MFA): strong security without physical identification; widely applicable.
  • Biometrics (fingerprint, iris, face): special category of personal data, processing prohibition as a starting point, irreversible in the event of a breach. Only where demonstrable necessity.

In the vast majority of SME situations, the first three options achieve the same security goal. This is precisely what makes it so difficult for employers to justify the necessity of biometrics.

Risks associated with the improper use of biometrics

If you implement biometric authentication without a solid basis, you run multiple risks simultaneously as an employer:

  • Enforcement by the Dutch Data Protection Authority: the supervisory authority can take action against processing that is in violation of the GDPR.
  • Compensation: employees whose data has been processed unlawfully can claim compensation.
  • Employment law tensions: an employee who refuses may not simply be punished for doing so, which can lead to conflicts or legal proceedings.
  • Reputational damage: privacy incidents involving staff are sensitive and can damage trust within the company.

Moreover, biometric data is irreversible: unlike a password, you cannot reset a leaked fingerprint. This makes due diligence beforehand all the more important.

Step-by-step plan for SME employers

Are you considering biometric authentication or another far-reaching security measure? Then proceed in a structured manner:

  1. Determine the goal. What specific security or authentication problem do you want to solve?
  2. Explore alternatives. Are a strong password policy, MFA via a token, or an access card sufficient? If so, biometrics are probably not necessary.
  3. Conduct a balancing of interests. Weigh the security interest against the privacy of your employees and document this in writing.
  4. Conduct a DPIA. As a rule, a Data Protection Impact Assessment (DPIA) is recommended when processing special categories of personal data.
  5. Inform and involve staff. Be transparent and involve the Works Council where applicable.
  6. Record agreements. Incorporate it into your internal privacy policy and document the retention period and security of the data.

Frequently Asked Questions

Am I allowed to require my employees to use a fingerprint?

Only if you can demonstrate that this is necessary for security or authentication and that no less intrusive alternative exists. In most standard business situations, such substantiation is not possible, and mandatory biometrics are therefore not permitted.

Is employee consent sufficient?

Usually not. Due to the power imbalance between employer and employee, consent is often not considered “free.” Therefore, you cannot simply rely on consent to introduce biometrics.

Do fingerprint unlocking of a private phone and facial recognition also fall under this?

The question concerns who processes the data and for what purpose. If an employee unlocks their own device, you, as the employer, usually do not process that biometric data. However, if you impose a biometric system for access to company resources, you are the data controller and the strict rules apply.

What is a less invasive alternative to biometrics?

Consider a personal PIN code, an access card, a hardware token, or MFA via an app. Such means often achieve the same security goal without requiring you to process special personal data.

Do I need to conduct a DPIA for biometrics in the workplace?

As a rule, yes. The large-scale processing of special categories of personal data, such as biometrics, is generally considered high-risk processing. A Data Protection Impact Assessment (DPIA) helps you demonstrably weigh the necessity, proportionality, and alternatives—exactly what a judge or the supervisory authority expects of you.

Am I allowed to dismiss or punish an employee who refuses to provide their fingerprints?

Be very cautious with that. If the mandatory biometrics themselves are not legally tenable, the employee is acting lawfully by refusing, and a sanction or dismissal on that ground is risky. It could lead to an employment dispute. Therefore, first assess whether the measure is permitted at all before considering the consequences for the employee.

What happens if I break the rules?

The Dutch Data Protection Authority can enforce regulations, and affected employees can claim compensation. In addition, you risk employment disputes and reputational damage. Careful consideration beforehand prevents many problems.

Handling staff personal data with care

As an employer, you constantly come into contact with your employees' personal data, especially regarding digital systems, new working methods such as bring your own device , and security applications. A well-thought-out privacy policy prevents fines, claims, and hassle in the workplace. If you want to properly manage biometrics or another measure, define in advance what you process, why, and for how long – for example, in an internal privacy statement for employees. Because this affects the position of your staff, it is wise to align this with your broader employment law agreements.

Need help with privacy in the workplace?

Are you unsure whether your security measure passes legal scrutiny, or do you want to bring your privacy policy into order? Our legal experts are happy to think along with you, in a practical manner and without unnecessary jargon.

Schedule a no-obligation intake and discuss your situation with one of our legal experts.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

July 24, 2026

Having a non-compete clause drafted: costs and process

Having a non-compete clause drafted by a lawyer: what does it cost, how does the process work, and when to choose a custom draft over a template.

July 24, 2026

Checking contracts: step-by-step plan for SME entrepreneurs

Checking or reviewing a contract before signing: step-by-step plan, red flags, checklist, and when you need a lawyer.

July 24, 2026

Having general terms and conditions drafted for contractors: costs and process

Having general terms and conditions for contractors drafted by a lawyer: what does it cost, how does the process work, and when do you choose custom work over...

July 23, 2026

Having general terms and conditions drafted: costs and process

Having general terms and conditions drafted by a lawyer: what does it cost, how does the process work, and when to choose a custom-made version over a template.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation