If you have been researching face-recognition or fingerprint time clocks, you have probably run into GDPR's most protected data category. Fresh QR is an attendance system without biometrics: employees scan a paper QR code posted at the workplace with their own phone, and GPS confirms they are actually standing there. Same protection against buddy punching — using ordinary personal data, with none of the Article 9 paperwork.
✓ No facial or fingerprint data · ✓ EU company, GDPR-native · ✓ 30-day free trial, no credit card
(32 reviews)
Yes — attendance can be tracked reliably without biometric data. A posted QR code scanned with the employee's own phone, combined with GPS verification and an optional workplace photo, confirms who clocked in and where. That uses ordinary personal data under GDPR Article 6, avoiding the Article 9 special-category burden that fingerprint and facial systems carry.
Face and fingerprint terminals solve buddy punching by collecting the most heavily regulated data GDPR knows. Three reasons that trade is worse than it looks.
Under GDPR Article 9, biometric data used to identify a person is prohibited from processing by default. To run a fingerprint or facial clock-in, an employer must establish one of the narrow Article 9(2) exceptions — and for something as routine as attendance, where less intrusive methods clearly exist, that is hard to do. Add the data-protection impact assessment (DPIA) typically required, elevated security duties, and the fact that a leaked fingerprint can never be changed like a password.
The obvious workaround — "our staff agreed to it" — is the one regulators reject most consistently. The EDPB's position is that consent is generally invalid in the employment context because of the power imbalance between employer and employee: someone whose clock-in determines their pay cannot refuse freely. Italy's Garante and Spain's AEPD have both dismissed consent as a legal basis for biometric attendance in their decisions.
This is not a theoretical risk buried in guidance documents. National data protection authorities have issued real fines against real employers — including small companies and a school — specifically for biometric attendance systems. The reasoning repeats across cases: attendance can be verified with ordinary means, so collecting body data for it fails the proportionality test.
To be precise: GDPR does not make biometric attendance uniformly illegal across the EU. But in the cases that have been decided, authorities keep reaching the same conclusion — the employer could not justify it. A few documented examples:
Both approaches answer the same question — was this person really at work? — but they answer it with very different data. Here is the side-by-side comparison for a GDPR-compliant attendance tracking decision.
| Face / fingerprint clock-in | Posted QR + GPS (Fresh QR) | |
|---|---|---|
| Data category under GDPR | Article 9 special-category biometric data — processing prohibited unless a narrow exception applies | Ordinary personal data under Article 6: name, timestamp, clock-in location |
| Legal basis difficulty | Hard to establish — consent is generally invalid at work, and proportionality fails when gentler methods exist | Standard employment-record footing: legitimate interest or performance of the employment contract |
| DPIA burden | Typically mandatory — systematic special-category processing of employees | Usually a light exercise folded into your existing employee-data documentation |
| Employee acceptance | Frequent pushback — staff must hand over face or fingerprint templates just to get paid | A two-second scan on their own phone; no body data ever leaves them |
| Shift change at the door | One terminal, one face or finger at a time — a queue at 6:00 a.m. | The whole crew scans the same poster in parallel, each from their own phone |
| Hardware at the site | A dedicated terminal to buy, mount, power, maintain and eventually replace | A sheet of paper. If it gets torn or rained on, print another one — free |
Fresh QR still processes personal data, and you should know exactly what. At the moment of each clock-in or clock-out we record the employee's name, the timestamp, and the GPS position of that single scan — not continuous location tracking during the shift. An optional workplace photo can be added as a second verification step, but only if your company enables it as policy and employees are informed; it is opt-in at the company level, never silent. All of this is ordinary personal data under Article 6, purpose-limited to verifying attendance — and it still deserves proper handling: tell your employees what is collected and why, keep it in your records of processing, and set a sensible retention period. GDPR-friendly is not the same as GDPR-exempt, and we would rather say so on the landing page than in the fine print.
Weighing your options more broadly? See how QR clock-in performs as a modern time clock alternative, what is genuinely free in a free QR code attendance system, and the full breakdown of our single-tier pricing. The main page shows how QR code attendance tracking works end to end.
You do not need your employees' faces or fingerprints to know they showed up — a posted QR code, GPS verification and an optional photo do the job with ordinary personal data. Fresh QR is built by an EU company, billed in EUR, with one flat tier: €1.95 per active employee per month, and anyone working under 40 hours a month is free. Unlimited sites, offline mode, NFC, live dashboard, Excel exports. Test everything free for 30 days — no credit card, no biometric terminal, no Article 9 file on your DPO's desk.
This page is general information, not legal advice. Regulatory positions and cited decisions are summarised as of July 2026 and may evolve; enforcement practice differs between EU member states. Before deploying or decommissioning any attendance system, consult your data protection officer or legal counsel.