For an EU biometric access-control project, start with the data flow, the legal basis and the evidence available for the exact model. This guide helps distributors, integrators and facility managers define that review.

Under GDPR (General Data Protection Regulation, EU 2016/679), biometric data used to uniquely identify a person — including fingerprints, face geometry templates, and iris scans — is Special Category personal data under Article 9. A deployment must establish both an Article 6 lawful basis and an applicable Article 9(2) condition, then assess the safeguards and local rules that apply to the project.

Project boundary: This page explains product and procurement checks. The controller remains responsible for the legal assessment, including applicable national rules. Confirm the proposed deployment with the responsible DPO or qualified local counsel.

1. When Access Data Becomes Biometric Data

Article 4(14) defines biometric data as: "personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person."

In practice, this means:

  • Face recognition templates stored on-device or in cloud — biometric data ✓
  • Fingerprint templates (mathematical hash) — biometric data ✓
  • CCTV footage used for identification — biometric data (if processed for recognition) ✓
  • RFID/NFC cards linked to a person — personal data (not biometric) — lower regulation tier
  • PIN codes — not personal data if not linked to identity in logs

2. Two Legal Tests Apply

Biometric access control requires two separate assessments: an Article 6 lawful basis for personal-data processing and an applicable Article 9(2) condition for Special Category data. The applicable route depends on the purpose, controller, data subjects and national law.

Explicit Consent (Art. 9(2)(a))

The data subject actively opts in. Consent must be freely given, specific, informed, and unambiguous. For workplace access control, consent is generally not acceptable — the employee power imbalance means consent cannot be truly freely given. Most EU DPAs confirm this view.

Substantial Public Interest (Art. 9(2)(g))

Applicable for government and critical infrastructure deployments where national law authorizes biometric processing. Requires proportionality assessment.

Commercial and Workplace Deployments

Contractual necessity or legitimate interests may be relevant to an Article 6 assessment in some circumstances, but they do not on their own permit biometric processing under Article 9. In workplace settings, consent is often unsuitable because it may not be freely given. Confirm the proposed processing with the controller's DPO and qualified local counsel before deployment.

Risk-reduction measure: Provide a non-biometric access option, such as RFID or PIN, where appropriate. It can reduce exclusion and help the controller assess necessity and proportionality, but it does not replace the legal assessment.

3. Specify Data Handling Before Purchase

  • Data minimization: Collect and retain only the biometric and access-event data needed for the documented purpose. Confirm whether a selected device stores templates, images or both.
  • Storage design: On-device storage may reduce exposure compared with a central cloud database, but the actual data flow and device configuration must be verified for the selected model.
  • Retention period: Define, document and periodically review a retention period that is necessary and proportionate for the security purpose. Delete or disable biometric data and access rights when they are no longer needed.
  • International transfers: A transfer outside the EU/EEA needs an applicable Chapter V transfer mechanism and appropriate safeguards. Confirm cloud location, subprocessors and transfer documentation before deployment.

4. Decide Whether a DPIA Is Required

A Data Protection Impact Assessment (DPIA) is required under GDPR Article 35 where processing is likely to result in a high risk to individuals' rights and freedoms. Biometric access-control deployments can meet that threshold; assess the selected design, scale, safeguards and applicable national guidance before deployment. A DPIA, where required, must:

  • Describe the processing operation and its purposes
  • Assess the necessity and proportionality
  • Identify and assess risks to individuals
  • Identify measures to address those risks

Consult the organization's Data Protection Officer (DPO) — where one is appointed — before deployment. Some EU member states require DPA consultation for high-risk biometric processing.

5. What to Request From the Supplier

Request this evidence for the selected model and cloud configuration:

  • Documented data flow for the selected model, including whether biometric templates, images or access logs leave the device
  • Verified deletion process for individual biometric records and access rights
  • Non-biometric access option where the controller's assessment requires it
  • Documented access-log fields and retention configuration
  • Cloud-region, subprocessor and international-transfer documentation where a cloud service is used
  • OSDP Secure Channel support, enabled configuration and key-management process where encrypted reader-to-controller communication is required
  • Firmware support and security-update policy for the selected model
  • Relevant security documentation or independent testing evidence for the cloud platform

6. Specify OSDP Secure Channel Where Needed

The Open Supervised Device Protocol v2 (SIA OSDP v2) supports secure reader-to-controller communication when Secure Channel is available and enabled on both devices. Legacy Wiegand interfaces generally do not provide encryption or mutual authentication. With Secure Channel correctly commissioned, OSDP can provide:

  • AES-128 encryption of the reader-to-panel channel
  • Mutual authentication between supported reader and controller devices
  • Supervision and device-status reporting where supported by the selected equipment
  • Bidirectional communication — panel can push commands to the reader

For new installations in Europe, evaluate OSDP v2 where the project needs encrypted reader communication and supervision. Wiegand may remain a retrofit option where replacing existing cable infrastructure is not feasible; confirm the selected reader, controller and acceptance requirements.

FAQ

Frequently Asked Questions: GDPR and Access Control in Europe

GDPR can apply to both. RFID cards linked to an identifiable person are personal data and require a lawful basis and the usual GDPR safeguards. Biometric data used to uniquely identify a person is Special Category data under Article 9. Its use requires both an Article 6 lawful basis and an applicable Article 9(2) condition, plus an assessment of whether a DPIA is required.

There is no EU-wide simple yes-or-no answer. Consent in employment settings is often unsuitable because of the power imbalance. Before using fingerprints, the controller should assess an Article 6 lawful basis, an Article 9(2) condition, applicable national employment law and whether a DPIA is required. A non-biometric access option should be considered as part of that assessment.

GDPR does not set a fixed retention period. The controller should document a period that is necessary and proportionate for its stated purpose, then review it against local guidance and the actual security need. Biometric templates and access rights should be deleted or disabled when they are no longer needed.

On-device storage can reduce data exposure, but it does not establish GDPR compliance by itself. The controller still needs an Article 6 lawful basis, an Article 9(2) condition where biometrics are used for unique identification, appropriate security controls and an assessment of whether a DPIA is required. Confirm the selected model's data flows, deletion process and cloud configuration before deployment.

A DPIA is required where processing is likely to result in a high risk to individuals' rights and freedoms under Article 35. Biometric access-control deployments can meet that threshold, but the assessment depends on the processing design, scale, safeguards and applicable national guidance. Employee headcount is not a DPIA threshold.

For the selected hardware, request the applicable CE and RoHS documentation, plus technical evidence for data flows, deletion capability and cloud configuration. For cloud-connected systems, assess the provider's security documentation and testing. OSDP provides encrypted, authenticated reader-to-controller communication only when both devices support Secure Channel and it is correctly enabled and commissioned.

Face recognition in residential buildings can affect residents, visitors and service personnel, so the controller should assess necessity, proportionality, the lawful basis, the Article 9(2) condition and local requirements before deployment. A non-biometric option, limited data collection and documented deletion controls may reduce risk, but do not replace that assessment.

Review a European Project

Share the selected model, cloud route, reader-controller topology and destination. We will identify the available product documentation for project review.

Request Model Documentation Review Europe Market Page