Skip to content

Guide

Biometric attendance ban in Türkiye: what changed and what to do

Updated:

Since 2 June 2026, fingerprint and face-recognition attendance tracking is unlawful in Türkiye. Employee consent does not change that. Your existing hardware, however, may not need replacing.

The Turkish Personal Data Protection Board issued principle decision 2026/921, dated 29 April 2026, finding the processing of biometric data for attendance tracking unlawful. It was published in the Official Gazette on 2 June 2026 and is in force. The scope is broad: fingerprint, palm vein, facial recognition, iris and retina. It binds private employers and public bodies alike.

This page covers the practical consequences and the technical migration plan. It is not legal advice — privacy notices, employee communications and destruction records need your lawyer. We are the side that moves the system.

The common practice used to be: obtain explicit consent from the employee, then install the biometric system. The Board closed that route. The reasoning is proportionality: legislation obliges employers to record working time, but does not require biometric identification. When less intrusive methods exist — cards, PINs, location-verified mobile check-in — choosing the most intrusive one is not proportionate.

Whether consent in an employment relationship is ever “freely given” was already contested: does an employee worried about their job really have the freedom to refuse? The Board settled that argument — having obtained consent does not change the outcome.

What this means in practice: “we collected consent, so we are fine” is no longer a defence. If your system reads fingerprints, the thickness of your consent file is irrelevant.

Do you have to throw the hardware away?

Probably not. Most attendance terminals on the market are multi-mode: the same device reads fingerprints, cards and PINs. What is required is disabling biometric verification and switching the device to card or PIN mode. That is usually a software setting, not a hardware change.

Only devices that are biometric-only, with no card reader, need replacing. There, two options: swap for a card-capable terminal, or remove terminals altogether and move to location-verified mobile check-in. The second is cheaper for most companies, because per-device cost and device-failure risk disappear.

One caution: switching to card mode is not sufficient on its own. Old biometric templates held in device memory — and on any local server — must also be destroyed. It is one of the first things an inspection will ask about.

Migration plan, in order

The order matters. Destroy templates before disabling verification and the data is still exposed; disable verification before the replacement works and you lose attendance records that feed payroll.

Which methods remain lawful?

The ban targets biometric data only. The following can still be used — each with its own obligations (notice, data minimisation, retention limits).

Which methods remain lawful?
MethodStatusSuitsWatch out for
Card / badgeLawfulSingle-entrance factories, officesCards get lent out; you need a lost-card process
PIN / passwordLawfulSmall teams, low costShareable; weak verification on its own
Mobile + location checkLawful (if proportionate)Field teams, sites, multi-locationLocation is personal data too; capture only at check-in and check-out, never all-day tracking
Web interfaceLawfulDesk-based staffWithout a location check, people can clock in for each other
Fingerprint / face / irisProhibitedKVKK 2026/921 · consent does not change it

A warning about mobile plus location: lawful does not mean unlimited. Location is personal data and proportionality applies here too. The correct design captures location only at check-in and check-out, uses it for a distance check, and does not retain raw coordinates for long. A setup that tracks staff all day escapes biometrics only to create a different violation.

What are the penalties?

Turkish administrative fines apply to breaches of data security obligations and the amounts are revalued annually. Check the authority’s published figures for the current amount — we do not print a number here, because fixing a figure that changes within the year would mislead.

The larger cost is rarely the fine. An investigation triggered by one employee complaint puts every data-processing activity in the organisation on the table. An inspection that began with a single fingerprint reader can turn into an open-ended compliance programme.

Companies operating in several countries

This decision is specific to Türkiye. Under the GDPR, processing biometric data remains possible with a valid legal basis and an impact assessment. So a setup that is fine in your German plant may be unlawful in your Turkish one.

For multi-country deployments, forcing one uniform system is the wrong architecture; keeping the check-in method configurable per country is the right one. Our workforce management system supports that split: one panel, different check-in methods per location.

Frequently asked

What exactly does the decision say?

Principle decision 2026/921 of the Turkish Personal Data Protection Board, dated 29 April 2026, finds the processing of biometric data — fingerprint, facial recognition, iris, retina — for attendance tracking unlawful. It was published in the Official Gazette on 2 June 2026. The reasoning is proportionality: no statute requires biometric identification and less intrusive alternatives exist. Both private employers and public bodies are covered.

Our employees consented. Is it still prohibited?

Yes, still prohibited. This is the decisive part of the decision: explicit consent does not make the processing lawful. The reasoning is that consent in an employment relationship is questionably free, and that less intrusive alternatives exist. Your consent forms provide no protection here.

Do we have to scrap our fingerprint readers?

Usually not. Most attendance terminals also support card and PIN modes; disabling biometric verification and switching to card mode is a software setting on most models. Only biometric-only devices need replacing, or a move to mobile check-in. But switching mode is not enough on its own — old biometric templates in device and server memory must be destroyed, and the destruction recorded.

Must we delete our historical records?

The biometric templates, yes. Clock-in and clock-out times are not biometric data and can be retained under payroll and labour law obligations. The distinction: “this person’s fingerprint template” must go; “this person clocked in at 08:03” can stay. Check your backups too — a template sitting in an old backup still counts as data you hold.

Is location-verified mobile check-in lawful?

Yes, if proportionate. Location is personal data as well. The correct design captures location only at check-in and check-out, uses it for a distance check, and does not retain raw coordinates for long. A setup collecting location all day escapes biometrics only to create a different violation. Employees also need to know what is recorded and when.

Do you handle the migration?

We handle the technical side: device inventory, switching terminals to card or PIN mode, setting up the new check-in method, migrating the data and destroying biometric templates. The legal documents — privacy notice, employee communication, the legal form of the destruction record — are your lawyer’s work, and be wary of offers that blur that line. Our own workforce management system processes no biometric data; you are not obliged to use it, but it is a fitting option.

Let us plan the migration

Tell us what devices and locations you run. We will say clearly whether your terminals can switch to card mode and which method fits you.