Open menu
01September2026

The KVKK's Public Announcement on the Processing of Biometric Data for Attendance Tracking Purposes: The Scope of the Principle Decision and the Limits of Application

Türkiye's National Artificial Intelligence Action Plan 2026–2030: A New Era for the Private Sector

Principle Decision No. 2026/921 of the Personal Data Protection Board ("Board") dated April 29, 2026 on the Processing of Biometric Data for Attendance Tracking Purposes ("Principle Decision") was published in the Official Gazette dated June 2, 2026. Following the publication of the Principle Decision, various requests for opinion were submitted to the Personal Data Protection Authority ("Authority") by data controllers operating in different sectors, and these requests gave rise to the need to clarify certain matters.

By way of the public announcement published on August 27, 2026, the Authority resolved these uncertainties and clarified the scope of application of the Principle Decision.

In our previously published article titled "KVKK Principle Decision: Processing of Biometric Data for Attendance Tracking Purposes" we addressed the scope of the Principle Decision, the regime to which biometric data is subject as a special category of personal data, the assessment that explicit consent does not constitute a sufficient legal basis on its own due to the imbalance of power in the employer and employee relationship, and the court decisions referred to by the Board. In this article, we assess the matters clarified by the announcement and their practical consequences for data controllers.

A Reminder of the Starting Point of the Principle Decision

The use of biometric identification systems has become increasingly widespread for the purposes of carrying out employee attendance tracking digitally and enhancing workplace security, and the Authority has established that this practice is among the unlawful practices most frequently raised in the reports and complaints submitted to it.

Special categories of personal data are exhaustively regulated under Article 6 of the Personal Data Protection Law No. 6698 ("Law"), and biometric data falls within this scope. It is not possible to extend the categories of special categories of personal data listed in the Law by analogy.

Although employers are under an obligation to track and document working hours pursuant to Article 9 of the Regulation on Working Times Relating to the Labor Law, titled "Documentation of Working Time," there is no explicit statutory provision requiring this obligation to be fulfilled through the use of biometric identification systems. For this reason, the Principle Decision concluded that biometric data processing activities carried out solely for attendance tracking purposes do not rely on any of the processing conditions set out in Article 6 of the Law, and that even where valid explicit consent exists, such processing would not satisfy the proportionality criterion regulated under Article 4 of the Law.

Conversion into a Mathematical Code Does Not Remove the Nature of Biometric Data

In the requests for opinion submitted to the Authority, it was argued that data obtained through methods such as palm scanning or fingerprint collection should not be regarded as biometric data.

The Authority did not accept this approach. Although the legislation does not contain a comprehensive definition of biometric data, Article 3 of the Civil Registration Services Law No. 5490 defines biometric data as person-specific data obtained from fingerprints, vein patterns and the palm of the hand for the purposes of identification and authentication through electronic systems.

The announcement further refers to Recital 51 of the European Union General Data Protection Regulation, stating that data rendered capable of uniquely identifying or authenticating a natural person through the use of a specific technical method constitutes biometric data. Accordingly, converting such data into a mathematical code and storing it in a database does not remove its nature as biometric data.

This finding directly addresses a defense frequently encountered in practice. The fact that the system stores only a template or hash value rather than the raw fingerprint image does not result in the processing activity being assessed outside the regime applicable to special categories of personal data.

The Scope of the Principle Decision Is Limited to Attendance Tracking Purposes

The second matter clarified by the announcement concerns the scope of the Principle Decision. The Principle Decision addresses biometric data processing activities carried out for employee attendance tracking purposes.

Biometric data processing activities falling outside attendance tracking will not be assessed within the scope of the Principle Decision. The lawfulness of such activities is to be assessed by the data controllers themselves, taking into account the purpose of the processing, the nature of the business and the characteristics of the specific case. As regards reports or complaints submitted to the Authority on this matter, the Board will carry out a separate assessment for each specific case.

This clarification rules out the interpretation that the Principle Decision prohibits biometric data processing altogether. However, falling outside the scope does not amount to a presumption of lawfulness. On the contrary, the burden of assessment remains with the data controller, and it is important that this assessment be documented in accordance with the principle of accountability.

Assessment for Facilities with a High Security Risk

The Authority stated that certain facilities and fields of activity are distinguished from the general assessment on account of the security risk they carry and the consequences that potential breaches may give rise to.

In such areas, biometric identification systems cease to be a tool serving attendance tracking alone and become an inseparable part of multi-layered security processes such as authentication, authorization and control of access to critical areas. Accordingly, in such areas the purpose of processing biometric data is not the monitoring of personnel working hours but, in most cases, directly ensuring security and the security of critical infrastructure.

Nevertheless, this distinction does not grant unlimited discretion. Biometric data processing activities carried out in such areas must also be limited to the necessary critical areas and persons, alternative methods must be insufficient, and the processing activity must be proportionate to the concrete security need.

The point requiring attention in practice is the use of biometric data collected for the purpose of controlling access to critical areas also for attendance tracking purposes. Such use may bring the processing activity back within the scope of the Principle Decision. For this reason, it is important that the system operated for security purposes and the attendance and timekeeping processes be separated in terms of data flow.

The Exception Under Article 28 of the Law

The announcement recalls that, pursuant to subparagraph (ç) of the first paragraph of Article 28 of the Law, data processing activities carried out for the protection of national defense, national security, public safety, public order or economic security may, under certain conditions, fall outside the scope of the Law.

While this exception provides significant flexibility for large-scale public security institutions, it does not render the use of biometric data unlimited. An assessment must be carried out for each specific case, taking into account the gravity of the security risk, the insufficiency of alternative methods and the purpose of the processing activity.

In the Authority's words, the decisive matter for compliance with the Principle Decision relates to whether the processing of biometric data goes beyond the purpose of attendance tracking and is used for ensuring public security.

Actions to Be Taken by Data Controllers

Following the announcement, it is important for companies to review the following matters:

  • Determining whether biometric data is processed within the existing attendance tracking system. Methods such as fingerprints, palm reading and facial recognition fall within the scope of biometric data even where they are stored as templates or mathematical codes.
  • Preparing a transition plan for carrying out attendance tracking through alternative methods such as encrypted card or PIN based systems, RFID and NFC identity cards, paper-based attendance sheets or manual entry under the supervision of a supervisor.
  • Separating other processes in which biometric data is processed on the basis of purpose, and verifying whether data processed for the purpose of controlling access to critical areas is transferred to timekeeping or payroll processes.
  • Documenting in writing, where reliance is placed on a security purpose, the assessment as to why alternative methods are insufficient and why the processing activity is proportionate to the concrete security need.
  • Terminating attendance tracking practices carried out on the basis of explicit consent and destroying the biometric data previously obtained within this scope in accordance with the Personal Data Retention and Destruction Policy.
  • Updating privacy notices, explicit consent declarations, the personal data processing inventory and VERBIS records.
  • Reviewing the agreements concluded with biometric system suppliers in terms of data processor status, retention periods and destruction obligations.

As previously emphasized by the Board, these matters fall within the administrative and technical measures to be taken by data controllers pursuant to the first paragraph of Article 12 of the Law. Where it is established that these matters have not been complied with, action will be taken against the relevant data controllers pursuant to the provisions of Article 18 of the Law.

Conclusion

The public announcement does not alter the obligations set out in the Principle Decision; it clarifies its scope and the limits of its application. Following the announcement, the position may be summarized as follows: processing biometric data for attendance tracking purposes is unlawful even where explicit consent has been obtained. Purposes other than attendance tracking fall outside the scope of the Principle Decision, yet the assessment of proportionality and necessity in those cases rests directly with the data controller.

Companies should therefore ask the following fundamental control question: what is the actual purpose of our system processing biometric data, can that purpose be met through a less intrusive method providing the same level of security, and has this assessment been documented?

If there is no clear answer to this question based on a written assessment, the existing practice should be reconsidered within the scope of the Principle Decision and the announcement.

You can access the relevant announcement here. (In Turkish)

Author Ezgi Anasız, Category Personal Data Protection Law

  • Notification!

    The content in this article is for general information purposes only and belongs to CottGroup® member companies. This content does not constitute legal, financial, or technical advice and cannot be quoted without proper attribution.

    CottGroup® member companies do not guarantee that the information in the article is accurate, up-to-date, or complete and are not liable for any damages that may arise from errors, omissions, or misunderstandings that the information may contain.

    The information presented here is intended to provide a general overview. Each specific case may require different assessments, and this information may not be applicable to every situation. Therefore, before taking any action based on the information provided in the article, it is strongly recommended that you consult a competent professional in the relevant fields such as legal, financial, technical, and other areas of expertise. If you are a CottGroup® client, do not forget to contact your client representative regarding your specific situation. If you are not our client, please seek advice from an appropriate expert.

    To reach CottGroup® member companies, click here.

About The Author

/tr/mevzuat/item/mesai-takibi-biyometrik-veri-islenmesine-iliskin-kvkk-duyurusu-ilke-karari-kapsami-uygulama-sinirlari

Other Legislation

Lets start
Get a quote for your service requirements.

Would you like to know more
about our services?