Original Turkey Compass decision chart showing routine biometric attendance as non-compliant, critical access as conditional and cards or PINs as alternatives
Original Turkey Compass editorial graphic based on the KVKK clarification of 27 August 2026

Türkiye's Personal Data Protection Authority has answered a practical question left after its April principle decision on biometric attendance. An employer cannot turn a fingerprint, palm or similar identifier into ordinary data merely by storing a mathematical template rather than the raw image. For routine clock-in and clock-out tracking, the authority says even valid employee consent does not cure the proportionality problem. The clarification is relevant to Turkish employers and to foreign employees working under the same data-protection framework; it is not a blanket ban on every security-related biometric system.

A coded template is still biometric data

KVKK says information produced through a specific technical method and capable of uniquely identifying or authenticating a person remains biometric data. Converting a fingerprint or palm scan into a mathematical code before database storage does not change that classification. The security of the storage method matters, but it does not remove the legal safeguards for special-category personal data.

Why employee consent is not enough for attendance

Employers must record working time, but KVKK notes that Turkish law does not expressly require them to use biometric identification for that task. The authority's 2026/921 principle decision found routine biometric attendance unsupported by the processing grounds in Article 6 of Law No. 6698 and disproportionate under Article 4, even where consent could otherwise be considered valid.

Lower-impact systems remain the practical route

The original principle decision identifies encrypted cards, PIN systems, RFID or NFC identity cards, traditional signatures, paper attendance sheets and supervised manual entry as less intrusive alternatives. A business reviewing its system should document purpose, necessity and alternatives rather than assuming a signed consent form settles the issue.

Critical-security access is a different question

The 27 August clarification separates ordinary timekeeping from biometric identity checks used for security, authorisation or access to genuinely critical areas. Such processing is not automatically lawful. It must be limited to the necessary areas and people, alternative methods must be inadequate, and the interference must be proportionate to a concrete security need.

What employees and international employers should check

Employees should first establish whether the system records attendance, controls access, or does both. Employers operating in Türkiye should map the exact purpose, data flow, retention and deletion rules, access permissions and any alternative entry method. Cross-border group policies or technology contracts do not replace a Türkiye-specific assessment under Law No. 6698.

Turkey Compass assessment

Confirmed: coded fingerprint and palm templates remain biometric data, and consent does not make routine biometric timekeeping proportionate. Too broad: saying all workplace biometrics are now prohibited. Security uses outside attendance fall outside the specific principle decision and must be assessed case by case. This report is general information, not an individual legal opinion.

Turkish Personal Data Protection Authority (KVKK) — workplace biometrics clarification, 27 August 2026

Open the primary source →