Biometric access control in the EU is heavily regulated. Here is what distributors, integrators, and facility managers need to specify — and what to demand from hardware suppliers.
Under GDPR (General Data Protection Regulation, EU 2016/679), biometric data — including fingerprints, face geometry templates, and iris scans — is classified as "Special Category" personal data under Article 9. Processing this data for access control requires explicit legal basis, typically explicit consent or a legitimate interest assessment (LIA), and imposes significantly stricter obligations than standard personal data.
1. What Counts as Biometric Data Under GDPR?
Article 4(14) defines biometric data as: "personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person."
In practice, this means:
- Face recognition templates stored on-device or in cloud — biometric data ✓
- Fingerprint templates (mathematical hash) — biometric data ✓
- CCTV footage used for identification — biometric data (if processed for recognition) ✓
- RFID/NFC cards linked to a person — personal data (not biometric) — lower regulation tier
- PIN codes — not personal data if not linked to identity in logs
2. Legal Basis for Biometric Access Control
The most common legal bases used in European access control deployments:
Explicit Consent (Art. 9(2)(a))
The data subject actively opts in. Consent must be freely given, specific, informed, and unambiguous. For workplace access control, consent is generally not acceptable — the employee power imbalance means consent cannot be truly freely given. Most EU DPAs confirm this view.
Substantial Public Interest (Art. 9(2)(g))
Applicable for government and critical infrastructure deployments where national law authorizes biometric processing. Requires proportionality assessment.
Contractual Necessity + Legitimate Interest
Used for commercial deployments (offices, co-working). Requires a Legitimate Interest Assessment (LIA), Data Protection Impact Assessment (DPIA), and must offer a non-biometric alternative access method (RFID card, PIN).
3. Data Minimization and Storage Rules
- Template-only storage: Never store raw biometric images (photos, fingerprint scans). Store only the mathematical template — a one-way hash that cannot reconstruct the original biometric.
- On-device preferred: Store biometric templates only on the lock hardware or access reader, not in a central cloud database. This limits breach exposure.
- Retention period: Delete biometric data immediately upon termination of the access relationship (employee departure, contract end). Access log entries (time, door, credential type — not biometric template) can be retained for security purposes, typically 90 days to 1 year depending on national guidance.
- Data residency: Biometric data must not be transferred outside the EU/EEA without adequate safeguards (Standard Contractual Clauses or adequacy decision). This directly impacts cloud-based lock management systems hosted in China or the USA.
4. DPIA Requirement
A Data Protection Impact Assessment (DPIA) is mandatory before deploying biometric access control under GDPR Article 35. The DPIA must:
- Describe the processing operation and its purposes
- Assess the necessity and proportionality
- Identify and assess risks to individuals
- Identify measures to address those risks
Consult the organization's Data Protection Officer (DPO) — where one is appointed — before deployment. Some EU member states require DPA consultation for high-risk biometric processing.
5. Hardware and Software Requirements Checklist
When specifying access control hardware for European deployments, require the supplier to confirm:
- Biometric templates stored on-device only (not transmitted to cloud by default)
- Template deletion API — programmatic deletion of individual biometric records on demand
- Non-biometric fallback access method (RFID, PIN, mobile app)
- Audit log does not record biometric template data — only access event metadata
- Data residency configuration — cloud backend must support EU-region-only data storage
- OSDP v2 (Open Supervised Device Protocol) — encrypted, authenticated reader-to-controller communication
- Firmware update policy with security patch SLA
- Penetration test report or ISO 27001 certification for cloud platform
6. OSDP v2 for Secure Reader Communication
The Open Supervised Device Protocol v2 (SIA OSDP v2) is the current industry standard for secure communication between access control readers and access control panels. Unlike the legacy Wiegand protocol (which transmits credential data in clear text with no authentication), OSDP v2 provides:
- AES-128 encryption of the reader-to-panel channel
- Mutual authentication — prevents rogue reader attacks
- Supervised line — tamper detection for cable disconnection
- Bidirectional communication — panel can push commands to the reader
For new installations in Europe, specify OSDP v2 as mandatory. Wiegand is acceptable only for retrofit scenarios where replacing the cable infrastructure is not feasible.
Frequently Asked Questions: GDPR and Access Control in Europe
GDPR applies to both, but at different regulatory tiers. RFID cards linked to a named individual are personal data under Article 4(1) and subject to standard GDPR obligations. Biometric data — fingerprints, face geometry templates — is Special Category data under Article 9, requiring explicit legal basis, DPIA, and stricter storage controls. RFID-only deployments carry significantly lower compliance burden than biometric systems.
Generally no, not on the basis of consent alone. Most EU Data Protection Authorities — including the EDPB — have confirmed that employee consent is not freely given due to the power imbalance in the employment relationship. Employers must establish legal basis under Article 9(2)(b) (employment law obligation) or 9(2)(g) (substantial public interest), and must offer a non-biometric alternative access method such as an RFID card or PIN.
GDPR does not set a fixed minimum. The data minimization principle (Article 5(1)(e)) requires retention only as long as necessary for the stated purpose. For access control audit logs — recording time, door, and credential type but not biometric templates — 90 days is common for general office use; up to 12 months for security-critical facilities. Biometric templates themselves must be deleted immediately upon termination of the access relationship.
On-device storage is strongly preferred and significantly reduces compliance risk by limiting breach exposure to a single physical device. However, it is not automatically sufficient. You must still establish valid legal basis, complete a DPIA, ensure template deletion capability via API, and confirm the device firmware does not transmit biometric data to a cloud backend without explicit configuration. Verify data residency settings before deployment.
A DPIA is mandatory under Article 35 for any deployment involving biometric data processing, large-scale monitoring, or systematic profiling. For a single-door fingerprint reader in a small office with fewer than 10 users, some DPAs apply proportionality — but the safer position is to complete a lightweight DPIA for any biometric deployment. RFID-only systems with fewer than 250 employees typically do not require a full DPIA unless combined with other high-risk processing.
For hardware sold into the EU market, require: CE marking (mandatory for electromagnetic compliance under RED Directive 2014/53/EU), RoHS compliance (Directive 2011/65/EU), and GDPR-specific technical documentation confirming on-device biometric storage, template deletion API, and absence of default cloud transmission. For cloud-connected systems, ISO 27001 certification or a third-party penetration test report for the cloud platform is strongly recommended. OSDP v2 support confirms encrypted reader-to-controller communication.
Face recognition in residential buildings is treated as biometric data processing affecting non-consenting third parties — delivery personnel, visitors, emergency services — who have not provided consent. Several EU DPAs have issued enforcement actions against residential face recognition deployments. The compliant approach is to use face recognition only as an optional resident credential for door release, with RFID or PIN as default, and to ensure the system does not retain face images or templates of non-enrolled visitors beyond the immediate access event.
Sourcing for the European Market?
Our access control hardware supports on-device biometric storage, OSDP v2, EU data residency, and ships with CE certification. Request a compliance-focused product brief.
