Attendance System Without Biometrics | GDPR - Fresh QR

An Attendance System Without Biometrics

If you have been researching face-recognition or fingerprint time clocks, you have probably run into GDPR's most protected data category. Fresh QR is an attendance system without biometrics: employees scan a paper QR code posted at the workplace with their own phone, and GPS confirms they are actually standing there. Same protection against buddy punching — using ordinary personal data, with none of the Article 9 paperwork.

✓ No facial or fingerprint data · ✓ EU company, GDPR-native · ✓ 30-day free trial, no credit card

512
companies
active in past 30 days
166 596
clock-ins
last 30 days
4 084
vacations
last 30 days
5 / 5 (31 reviews)

Yes — attendance can be tracked reliably without biometric data. A posted QR code scanned with the employee's own phone, combined with GPS verification and an optional workplace photo, confirms who clocked in and where. That uses ordinary personal data under GDPR Article 6, avoiding the Article 9 special-category burden that fingerprint and facial systems carry.

Why Biometric Clock-In Is a Legal Burden, Not a Feature

Face and fingerprint terminals solve buddy punching by collecting the most heavily regulated data GDPR knows. Three reasons that trade is worse than it looks.

Biometric data is Article 9 special-category data

Under GDPR Article 9, biometric data used to identify a person is prohibited from processing by default. To run a fingerprint or facial clock-in, an employer must establish one of the narrow Article 9(2) exceptions — and for something as routine as attendance, where less intrusive methods clearly exist, that is hard to do. Add the data-protection impact assessment (DPIA) typically required, elevated security duties, and the fact that a leaked fingerprint can never be changed like a password.

Employee consent doesn't save you

The obvious workaround — "our staff agreed to it" — is the one regulators reject most consistently. The EDPB's position is that consent is generally invalid in the employment context because of the power imbalance between employer and employee: someone whose clock-in determines their pay cannot refuse freely. Italy's Garante and Spain's AEPD have both dismissed consent as a legal basis for biometric attendance in their decisions.

Regulators are actively fining employers

This is not a theoretical risk buried in guidance documents. National data protection authorities have issued real fines against real employers — including small companies and a school — specifically for biometric attendance systems. The reasoning repeats across cases: attendance can be verified with ordinary means, so collecting body data for it fails the proportionality test.

What EU Regulators Have Actually Decided

To be precise: GDPR does not make biometric attendance uniformly illegal across the EU. But in the cases that have been decided, authorities keep reaching the same conclusion — the employer could not justify it. A few documented examples:

Face or Fingerprint Clock-In vs. a Posted QR Code

Both approaches answer the same question — was this person really at work? — but they answer it with very different data. Here is the side-by-side comparison for a GDPR-compliant attendance tracking decision.

Face / fingerprint clock-in Posted QR + GPS (Fresh QR)
Data category under GDPR Article 9 special-category biometric data — processing prohibited unless a narrow exception applies Ordinary personal data under Article 6: name, timestamp, clock-in location
Legal basis difficulty Hard to establish — consent is generally invalid at work, and proportionality fails when gentler methods exist Standard employment-record footing: legitimate interest or performance of the employment contract
DPIA burden Typically mandatory — systematic special-category processing of employees Usually a light exercise folded into your existing employee-data documentation
Employee acceptance Frequent pushback — staff must hand over face or fingerprint templates just to get paid A two-second scan on their own phone; no body data ever leaves them
Shift change at the door One terminal, one face or finger at a time — a queue at 6:00 a.m. The whole crew scans the same poster in parallel, each from their own phone
Hardware at the site A dedicated terminal to buy, mount, power, maintain and eventually replace A sheet of paper. If it gets torn or rained on, print another one — free

Honest Part: "No Biometrics" Does Not Mean "No Data"

Fresh QR still processes personal data, and you should know exactly what. At the moment of each clock-in or clock-out we record the employee's name, the timestamp, and the GPS position of that single scan — not continuous location tracking during the shift. An optional workplace photo can be added as a second verification step, but only if your company enables it as policy and employees are informed; it is opt-in at the company level, never silent. All of this is ordinary personal data under Article 6, purpose-limited to verifying attendance — and it still deserves proper handling: tell your employees what is collected and why, keep it in your records of processing, and set a sensible retention period. GDPR-friendly is not the same as GDPR-exempt, and we would rather say so on the landing page than in the fine print.

Biometric Attendance and GDPR — Frequently Asked Questions

Is fingerprint or face recognition attendance illegal in the EU?

Not uniformly, and anyone telling you otherwise is oversimplifying. GDPR Article 9 prohibits processing biometric identification data unless a specific exception applies — and the burden of establishing one sits with the employer. In the attendance cases decided so far, authorities in Italy and Spain concluded no valid exception existed. The EU AI Act adds further obligations for facial data at work. Legal in theory, very hard to justify in practice.

Can't employees simply consent to a face recognition time clock?

Usually not in a way that survives scrutiny. Valid GDPR consent must be freely given, and the EDPB's long-standing position is that the employer-employee power imbalance generally prevents that: refusing must carry zero detriment, which is nearly impossible when clocking in is a condition of getting paid. Both the Italian Garante and the Spanish AEPD have rejected consent as a basis for biometric attendance.

Is GPS verification of clock-ins GDPR-compliant?

Yes, when done with purpose limitation — and this matters, because location is still personal data under Article 6. Fresh QR captures GPS only at the moment of a scan, to confirm the clock-in happened at the workplace, not to follow employees through their day. You still need to inform staff, document the processing, and set a retention period. Point-in-time verification tied to a legitimate purpose is a well-established, defensible setup.

How does Fresh QR prevent buddy punching without biometrics?

By layering ordinary signals instead of collecting body data. The QR code is physically posted at the workplace, each scan comes from the employee's own phone and personal app account, and GPS confirms the phone was actually on site. Your company can optionally require a workplace photo at clock-in as extra proof. A colleague at home cannot fake that combination, and anomalies show up immediately in the live dashboard.

We already have a biometric terminal. What should we do with it?

Don't rip it off the wall in a panic — but do put it on your DPO's desk this quarter. Check whether you can actually document a valid Article 9 exception and a DPIA; if you cannot, plan a migration. Remember that decommissioning is also processing: stored biometric templates must be properly deleted. Many teams run a QR system in parallel during the switch — Fresh QR's 30-day free trial exists for exactly that kind of side-by-side test.

Do we need a DPIA to use Fresh QR?

Often not, but check rather than assume. Fresh QR uses no special-category data, which removes the main DPIA trigger — however, some national DPA blacklists mention systematic processing of employee location, so review your local list. Because the data involved is short and simple (name, scan timestamps, point-in-time GPS, optional photo), a precautionary DPIA is typically a brief exercise, and we recommend it as cheap insurance.

Weighing your options more broadly? See how QR clock-in performs as a modern time clock alternative, what is genuinely free in a free QR code attendance system, and the full breakdown of our single-tier pricing. The main page shows how QR code attendance tracking works end to end.

Stop Buddy Punching Without Touching Article 9

You do not need your employees' faces or fingerprints to know they showed up — a posted QR code, GPS verification and an optional photo do the job with ordinary personal data. Fresh QR is built by an EU company, billed in EUR, with one flat tier: €1.95 per active employee per month, and anyone working under 40 hours a month is free. Unlimited sites, offline mode, NFC, live dashboard, Excel exports. Test everything free for 30 days — no credit card, no biometric terminal, no Article 9 file on your DPO's desk.

This page is general information, not legal advice. Regulatory positions and cited decisions are summarised as of July 2026 and may evolve; enforcement practice differs between EU member states. Before deploying or decommissioning any attendance system, consult your data protection officer or legal counsel.