A single palm-vein reader sits at a manufacturing site’s main entrance. An employee presents a hand, the turnstile releases, and the same gesture writes that morning’s clock-in record into the HR system. Security treats the device as a control against unauthorised entry, HR as the source of the timesheet. One piece of hardware, two purposes, one data flow.
The Personal Data Protection Board’s public announcement (kamuoyu duyurusu), issued on the requests for opinion that followed Principle Decision (ilke kararı) No. 2026/921, addresses that arrangement. It neither softens the decision nor widens it, but marks where the decision ends: no general prohibition on biometric data, but a closed door for attendance and entry-exit tracking (mesai takibi).
That distinction is a design instruction rather than a point of legal subtlety. The employer’s task is to re-describe its installation in the announcement’s language. What does this reader verify, what output does it produce, where does that output flow, and what breaks if it stops flowing? Without written answers to those four questions, the purpose the device serves cannot be defended.
The announcement draws a boundary rather than retreating
Our detailed treatment of the Principle Decision set out the frame. Processing fingerprints, faces or palm patterns as special category personal data (özel nitelikli kişisel veri) for attendance purposes is unlawful, and employee agreement does not change that outcome. A principle decision taken under Article 15/6 of Law No. 6698 applies generally, with no secondary regulation to await. The subject here is not the decision but the grey area the later questions exposed.
Does the reader on a chemical store door fall inside it? Does a system that converts a fingerprint into a “template” fall outside it? Can a record produced by a system installed for security be fed into payroll? The answers share one premise: the assessment is made by purpose, not by device.
The consent argument is closed for attendance
The announcement’s first point is that using biometric data solely for attendance and entry-exit tracking breaches the proportionality principle, and that obtaining explicit consent (açık rıza) does not alter that assessment. The reasoning has two layers. Article 3 defines explicit consent as a declaration expressed with free will, and an agreement that carries a cost for refusing does not meet that definition.
The second layer is independent of consent’s quality, and it decides the question. Relying on Article 6/3-(a) does not remove the separate obligation under Article 4/2-(ç) to keep processing relevant, limited and proportionate to its purpose. A processing ground and the general principles are not substitutes for one another. Attendance is a narrow administrative purpose, and because cards, PINs and passwords serve it, capturing an irreversible identifier is not treated as necessary. Rewriting the consent form changes nothing, because the defect lies in the measure rather than the paperwork around it. Board practice on proportionality was already moving this way, and the courts have read it the same.
Why is “we store templates, not images” not a defence?
This is where the announcement bites hardest. Converting biometric data into a mathematical code or template, rather than storing it directly, does not strip it of its character as biometric data. The line in vendor brochures and tender files, “we keep only a template, not the raw image”, is a technical description rather than a legal basis. Filing that sentence as a defence files nothing.
A template identifies a person for as long as it distinguishes them from every other employee, and if it stopped doing so the system would not work. Such a conversion is pseudonymisation (takma adlaştırma), and pseudonymised data remains personal data. What takes data outside the Law is anonymisation, the person ceasing altogether to be identified or identifiable. An output that can be reversed, or that remains suitable for matching, does not clear that threshold.
Hashing and encryption do not change the picture. They are data security measures assessed under Article 12 and owed in any event, so they create no processing ground and do not stand in for a proportionality analysis. The question is not how the data is stored but whether it needs to be collected at all. Debating key lengths before answering that is the wrong table.
No prohibition, but a division by purpose
The third point confirms that the decision imposes no general ban. Use for other purposes, such as access to critical areas, identity verification or a high security requirement, may be possible on the facts of the specific case. That is not an exemption, and not an invitation. The assessment runs purpose by purpose, and each purpose must carry its own Article 6/3 ground and its own proportionality analysis.
In one company, one installation can survive while another falls. A data centre cabinet entered by a handful of named people and a main turnstile crossed by hundreds of staff attract different assessments, even where the technology is identical. Keeping the critical area narrowly defined, the authorised list short, and that limit documented makes up the body of the defence. “The whole factory is a critical area” does not pass this test.
What happens when one reader serves two purposes?
In the most common arrangement, a device procured for security quietly feeds its records into the attendance system, and that rationale does not legitimise the attendance record. A lawful verification step does not licence reuse of its output for a second purpose, and that purpose must build its own foundation, which for attendance is absent. The remedy lies less in replacing the device than in separating the data flow by purpose.
- Cut the output. A security verification should not reach timesheets, payroll or absence reports, and the integration should be switched off on the record.
- Run attendance separately. Entry and exit times belong in a card, PIN or comparable non-biometric system that alone feeds the timesheet.
- Narrow the scope. Biometric verification should stay live only at genuinely critical points, for the people who must enter them.
- Tie retention to purpose. Security access logs should run for the period that purpose requires, not the attendance reporting period.
- Split the permissions. Security should see the access logs and HR the attendance records, because one shared administrator screen dissolves the separation.
The hardest part of this separation is organisational: the unit that buys the device and the unit that uses the data are rarely the same, and nobody owns the whole flow. The record of processing activities (veri işleme envanteri) helps here, because writing the same reader as two entries, with two purposes and two legal grounds, forces the separation to exist on paper.
Who documents necessity, and how
The fourth point shows where the burden sits. It matters that alternative methods such as cards or passwords are inadequate, that biometric use is genuinely necessary, and that it is confined to the areas and people that require it. Each has to be shown through a document produced at the time of the decision, not afterwards. “We had thought about it” carries no weight in an inspection.
- Eliminate alternatives concretely. Why a card, a password or a PIN falls short here must be written against the facts of the site, because general security rhetoric will not fill the gap.
- Limit scope by definition. Which door, which job description, which shift: the narrower the boundary, the sturdier the defence.
- Write the assessment when you decide. The necessity analysis belongs before installation, fixed in a dated record.
- Align the registers. The processing inventory, the VERBİS notification and the privacy notice should describe the same purpose in the same words, because a discrepancy is what an inspection notices first.
Where the processing is high risk, a data protection impact assessment‘s logic makes the job easier: identify the risk, compare the alternatives, record whether the residual risk was accepted. Those are the necessity test’s own questions, and the exercise produces the document already owed.
Three things are worth doing today. List every biometric reader on site and write one purpose against each, because two purposes mean the flow has not been separated. Close every integration that feeds attendance and minute the destruction of stored templates, since changing the clock-in method while leaving templates in place means the processing continues. Then put the necessity assessment in writing for the installations meant to survive. Until all three are done, the risk of administrative sanction under Article 18 stays with the company.
This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.
Author
-
View all postsVircon Legal'de Avukat / Associate at Vircon Legal. Venture transactions · IP and licensing · Tech-sector regulatory
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro callMore from Vircon Insights
"A Friend Gave Us Your Number": Turkey's DPA Draws the Line on Referral Marketing
July 21, 2026Authentication, Email and Physical Access: The Security Standard in Five Decisions
August 15, 2026The Proportionality Test: CCTV, Audio, Biometrics, Cookies and Masking
August 21, 2026Ransomware and Unauthorised Access: Which Technical Measures Does the Board Expect?
August 14, 2026KVKK Is Already Regulating Your AI: Automated Decisions, Biometrics, Training Data
July 8, 2026Two Credit Bureau Decisions and the Full Index of the 47 Decision Summaries
August 23, 2026Related Practice Areas
Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →ICOs, Crypto & Blockchain
Crypto-asset regulation, token offerings, exchange and custody licensing.
View service →US Company Formations & Flip-Ups
Delaware C-Corp, flip-up structures, SAFE/convertible notes, 83(b).
View service →