{"id":16554,"date":"2023-12-01T14:45:30","date_gmt":"2023-12-01T14:45:30","guid":{"rendered":"https:\/\/businessadapter.es\/biometrics-for-workday-and-safety-registration\/"},"modified":"2024-12-11T10:44:38","modified_gmt":"2024-12-11T10:44:38","slug":"biometrics-for-workday-and-safety-registration","status":"publish","type":"post","link":"https:\/\/businessadapter.es\/en\/biometrics-for-workday-and-safety-registration\/","title":{"rendered":"Biometrics for workday and safety registration"},"content":{"rendered":"\n<h1><span style=\"color: #800000;\"><strong>Biometrics for workday and safety registration<\/strong><\/span><\/h1>\n<p style=\"text-align: justify;\">The use of  <strong>Biometrics for workday and access control<\/strong>is on everyone&#8217;s lips due to the publication, last November 23rd, of the &#8220;.<a href=\"https:\/\/www.aepd.es\/documento\/guia-control-presencia-biometrico-nov-2023.pdf\" target=\"_blank\" rel=\"noopener\">Guidance on the use of biometric data for time and attendance and access control<\/a>&#8220;elaborated by the  <a href=\"https:\/\/www.aepd.es\/informes-y-resoluciones\/resoluciones\" target=\"_blank\" rel=\"noopener\">AEPD<\/a>The new criteria for the use of this type of personal data, which are commonly used for the registration of working hours and the security control of access to facilities, are set out and thus comply with the requirements established in the data protection regulations (<a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/proteccion-datos-valencia\">GDPR 679\/2016<\/a>).<\/p>\n<h2><span style=\"color: #800000;\"><strong>Biometrics: high risk data<\/strong><\/span><\/h2>\n<p style=\"text-align: justify;\">Recall that Article 4(14) of the <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">GDPR<\/a> identifies biometric data as personal data obtained from specific technical processing, relating to the physical, physiological or behavioral characteristics of a natural person that allow or confirm the unique identification of that person, such as facial images or dactyloscopic data.<\/p>\n<p style=\"text-align: justify;\">Through biometric data (e.g. fingerprint or facial recognition) we can uniquely and unequivocally identify a person, hence the high risk that its processing entails for fundamental rights and freedoms.<a href=\"https:\/\/businessadapter.es\/en\/\"><img decoding=\"async\" class=\" wp-image-10529 alignright\" src=\"https:\/\/businessadapter.es\/wp-content\/uploads\/2022\/10\/finger-2081169_1280-300x169.jpg\" alt=\"\" width=\"614\" height=\"346\" srcset=\"https:\/\/businessadapter.es\/wp-content\/uploads\/2022\/10\/finger-2081169_1280-300x169.jpg 300w, https:\/\/businessadapter.es\/wp-content\/uploads\/2022\/10\/finger-2081169_1280-1024x576.jpg 1024w, https:\/\/businessadapter.es\/wp-content\/uploads\/2022\/10\/finger-2081169_1280-768x432.jpg 768w, https:\/\/businessadapter.es\/wp-content\/uploads\/2022\/10\/finger-2081169_1280-900x506.jpg 900w, https:\/\/businessadapter.es\/wp-content\/uploads\/2022\/10\/finger-2081169_1280-scaled.jpg 1200w\" sizes=\"(max-width: 614px) 100vw, 614px\" \/><\/a> the fundamental rights and freedoms of individuals.<\/p>\n<p>Also, biometric data are considered <a href=\"https:\/\/businessadapter.es\/datos-especiales-es-proteccion-de-dato\/\">special category<\/a> according to Article 9 of the <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">GDPR<\/a>, their processing considered high risk and prohibited except in the cases set out in Article 9.2 a) and b) of the <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">GDPR<\/a>, ie:  <\/p>\n<p>  1. La persona trabajadora de su consentimiento expl\u00edcito para el tratamiento de sus datos biom\u00e9tricos. <\/p>\n<p>  2. Cuando el tratamiento de datos biom\u00e9tricos es necesario para el cumplimiento de una obligaci\u00f3n legal. <\/p>\n<p style=\"text-align: justify;\">With this it could be understood that if the company requests authorization to the worker to treat his biometric data and also informs him that such treatment is necessary to comply with an obligation of the company, (the mandatory record of working hours), we would be complying with the provisions of the aforementioned articles 9.2 a) and b), <strong>but the conclusion of the AEPD exposed in the new <a href=\"https:\/\/www.aepd.es\/documento\/guia-control-presencia-biometrico-nov-2023.pdf\" target=\"_blank\" rel=\"noopener\">Guide to biometrics<\/a>, determines that this is NOT so and that this is not enough.<\/strong> We explain why:  <\/p>\n<h3><strong>The employee&#8217;s signature alone is insufficient:<\/strong><\/h3>\n<p style=\"text-align: justify;\">Consent alone will not be sufficient, because the AEPD considers that there is a situation of disadvantage of the worker against the employer, where if the processing of biometric data is not accepted, the worker may compromise his employment situation.<\/p>\n<h3><strong>Comply with the obligation to keep the workday record:<\/strong><\/h3>\n<p style=\"text-align: justify;\">The AEPD understands that the company&#8217;s obligation to comply with article 34.9 of the Workers&#8217; Statute, which requires it to keep a record of each worker&#8217;s working day, does not necessarily imply that this must be done using biometric data, since there is no regulation in the Spanish legal system with the rank of law that explicitly provides for the processing of biometric data for this purpose, and also determines that this record can be made by other less intrusive means.<\/p>\n<p style=\"text-align: justify;\">Here there is a change of interpretation by the AEPD, in relation to what was stated in the Guide &#8220;<a href=\"https:\/\/www.aepd.es\/prensa-y-comunicacion\/notas-de-prensa\/aepd-publica-guia-pd-y-relaciones-laborales\" target=\"_blank\" rel=\"noopener\">Data Protection in Labor Relations<\/a>&#8221; of May 2021, where the lawfulness was based on compliance with articles 20.3 and 34.9 of the Workers&#8217; Statute.<\/p>\n<h2><span style=\"color: #800000;\"><strong>Requirements for using biometrics<\/strong><\/span><\/h2>\n<p>So we are facing a new situation and biometric data can only be processed if the following assumptions are met:<\/p>\n<h3><strong>Lawfulness of treatment:<\/strong><\/h3>\n<p style=\"text-align: justify;\">If the processing is not lawful, it is impossible to carry it out. In other words, it is necessary to lift the prohibition and this could be carried out by means of a truly free consent that allows the person to decide on the use of his biometric data or to opt for another alternative, after informing the worker clearly about the high risks involved in the processing of biometric data. <\/p>\n<p style=\"text-align: justify;\">Another possibility that would make the processing lawful would be for collective labor agreements to provide for the recording of working hours or access control through the use of biometric data.<\/p>\n<h3>Choice of biometric system<\/h3>\n<p style=\"text-align: justify;\">Once the essential step of legality has been overcome, it is necessary to choose a system that guarantees the rights and freedoms of the users of the biometric system and something that could help in this choice will be to ask the supplier or manufacturer to provide its own Impact Assessment of the system to be implemented by the responsible party and that this system certifies that the biometric reader system complies with at least the following:<\/p>\n<h5>Organizational measures<\/h5>\n<ul>\n<li style=\"text-align: justify;\">That such a system can revoke the identity link between the biometric template and the natural person.<\/li>\n<li style=\"text-align: justify;\">Delete biometric data when they are no longer related to the purpose for which they were collected.<\/li>\n<li style=\"text-align: justify;\">Minimization of biometric data, processing only what is necessary and without additional data.<\/li>\n<li style=\"text-align: justify;\">That the system is contemplated and authorized by the collective bargaining agreements and that it complies with the set of guarantees in relation to these treatments.<\/li>\n<\/ul>\n<h5>Technical measures<\/h5>\n<ul>\n<li style=\"text-align: justify;\">That it has guarantees that prevent the use of biometric templates for any purpose other than the registration of the working day as a control measure and access control as a security measure.<\/li>\n<li style=\"text-align: justify;\">Encrypt the biometric data information, guaranteeing its confidentiality, as well as its availability and integrity.<\/li>\n<li style=\"text-align: justify;\">Use technologies that prevent the interconnection of biometric databases.<\/li>\n<li style=\"text-align: justify;\">Periodic review of the systems, as well as their updates.<\/li>\n<li style=\"text-align: justify;\">If Artificial Intelligence is used in biometric systems, they must comply with industry standards, such as the future European Regulation on Artificial Intelligence.<\/li>\n<\/ul>\n<h3><strong>Conduct an Impact Assessment:<\/strong><\/h3>\n<p style=\"text-align: justify;\">Having overcome the above, the Controller must prepare an Impact Assessment<a href=\"https:\/\/businessadapter.es\/evaluacion-de-impacto-de-proteccion-de-datos-eipd-valencia\/\">(EIPD<\/a>) which must offer a favorable result after the analysis of the risks of the processing of biometric data, overcoming the necessity, suitability and proportionality of the system to be implemented.<\/p>\n<p style=\"text-align: justify;\">This means that the data controller must be able to justify and document that there is no other less intrusive measure for the desired purpose (recording of working hours), thus overcoming the requirement of necessity, and that the processing of biometric data is suitable for the intended purpose and that it is proportional, since it generates more benefits than disadvantages for the data subjects.<\/p>\n<h2><span style=\"color: #800000;\"><strong>Do I remove the biometric readers?<\/strong><\/span><\/h2>\n<p style=\"text-align: justify;\">As we have seen, implementing a workday registration or access control system through the use of biometric data implies assuming significant risks and legal implications, which must be overcome and with guarantees to avoid sanctions, which must be used to decide whether its use is worthwhile.<\/p>\n<p style=\"text-align: justify;\">If you need personalized advice contact your consultant or request advice by email: <a href=\"mailto:info@businessadapter.es,%20\">info@businessadapter.es, <\/a> you can also call <a href=\"http:\/\/tel.961318804\">96 131 88 04<\/a>, or leave your message in this form:<\/p>\n<p> <\/p>\n<p><strong>[su_button url=&#8221;https:\/\/businessadapter.es\/contacto&#8221; target=&#8221;blank&#8221; background=&#8221;#f6f903&#8243; color=&#8221;#181818&#8243; size=&#8221;7&#8243; center=&#8221;yes&#8221; icon_color=&#8221;#000000&#8243;]Contact us, we will be pleased to help you.[\/su_button]<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Biometrics for workday and safety registration The use of Biometrics for workday and access controlis on everyone&#8217;s lips due to [&hellip;]<\/p>\n","protected":false},"author":1373,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[75],"tags":[93],"class_list":["post-16554","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-biometrics"],"_links":{"self":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16554","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/users\/1373"}],"replies":[{"embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/comments?post=16554"}],"version-history":[{"count":1,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16554\/revisions"}],"predecessor-version":[{"id":16556,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16554\/revisions\/16556"}],"wp:attachment":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/media?parent=16554"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/categories?post=16554"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/tags?post=16554"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}