← Blog

Is Biometric Time Attendance Legal in Turkey After the KVKK Decision?

Is Biometric Time Attendance Legal in Turkey After the KVKK Decision?

Is biometric time attendance legal in Turkey? In many Turkish workplaces the routine has not changed for years: the employee presses a finger on the fingerprint reader at the door, the record lands in the HR system, and payroll is built from it at month end. After the Turkish data protection authority's (KVKK) Principle Decision No. 2026/921, dated 29.04.2026, was published in the Official Gazette on 2 June 2026, that first link changed: processing biometric data solely for time and attendance tracking does not satisfy the conditions of Law No. 6698.

This is not a restatement of the law. Taking the reader off the door is the easy part. The real work is who produces and verifies the attendance record from now on, how it reaches payroll, in what order existing biometric templates are erased, and how that erasure is evidenced.

What did the KVKK actually decide?

A note on terms: a Principle Decision is a binding decision of the KVKK's Board published in the Official Gazette — not a new statute, not an amendment to the law.

The decision finds that processing biometric data solely for attendance tracking does not satisfy the law's conditions. Two strands carry it: the structural power imbalance between employer and employee means explicit consent alone is not a sufficient basis; and Article 4 of Law No. 6698 requires proportionality, so the route reaching the purpose with less data must be preferred. Readers who know the GDPR will recognise Article 9 and Recital 51 here.

Diagram of an attendance flow moving from a fingerprint reader at the door to a card record feeding payroll

The boundary matters: the decision targets one purpose, not biometric processing in Turkey as such. In its second public announcement, dated 27 August 2026, the KVKK stated that biometric processing outside attendance tracking is not assessed under the Principle Decision — its lawfulness must be assessed by the controllers themselves, considering the purpose, the nature of the business and the case at hand. So if the reader at the door exists for attendance, that route closes; if not, the decision and its reasoning stay with you.

One clarification about face recognition. The biometric-data definition quoted in the KVKK's public announcement is built around fingerprint, vein pattern and palm. But the KVKK also repeats that data rendered suitable for uniquely identifying or verifying a natural person by a particular technical method qualifies as biometric data. The right reading is scope, not a list of names: a facial image processed that way falls under the same regime.

Why your older consent file may no longer answer the question

Article 6, governing special categories of personal data, was rewritten by Law No. 7499: published in the Official Gazette on 12 March 2024, with the provisions concerning Law No. 6698 in force from 1 June 2024. Decision 2026/921 is read against that newer text, so a file assembled before 2024 on the premise that "we obtained explicit consent, so we are done" no longer settles the question. Our data privacy compliance guide for SMEs covers the baseline obligations; this article rebuilds one process end to end.

We are deliberately not putting a number on enforcement. The announcement of 2 June 2026 states that where non-compliance with the stated points is established, action will be taken against the relevant controllers pursuant to Article 18 of the law. No separate transition or grace calendar appears in the announcements.

Is there an opening for high-security sites?

In areas such as national security and critical infrastructure, the 27 August 2026 announcement notes, biometric verification stops serving attendance alone and becomes an inseparable part of multi-layered security: identity verification, authorisation, access control to critical areas. That runs through Article 28/1-(ç): processing aimed at national defence, national security, public safety, public order or economic security may, under conditions, fall outside the law's scope. The announcement stresses that the exception is not unlimited — it must be proportionate to a concrete security need, and alternative methods must be insufficient.

To be plain: this opening is not available to an ordinary office, warehouse or plant arguing that "we have secure areas too." The legal characterisation belongs to your counsel; we only relay the wording here.

What happens at the door on Monday morning?

The alternatives the KVKK lists are:

  • encrypted card or PIN-based systems
  • wet-signature paper timesheets (in Turkish practice, puantaj)
  • RFID/NFC staff identity cards
  • supervised manual entry

Those are technology options. The real decision is which record payroll relies on, and who approves it.

The duty to record working time has not gone away. Article 67 of Labour Law No. 4857 governs the recording of working hours, and for overtime, Article 41 with the overtime regulation requires the employee's written consent at the start of each year plus a document showing overtime hours, both kept in the personnel file. The burden of proof stays with the employer, so no gap can be left in the chain. Confirm retention periods for timesheets and payroll documents with your accountant (in Turkey, a mali müşavir) and your HR adviser.

In practice: the raw card or PIN record is matched against the shift plan and produces a daily or weekly summary a manager approves; exceptions — a forgotten card, field work, leave — are captured as supervised manual entries, logging who entered them. To avoid clerical creep, hand the approval and summary steps to rule-based automation, as our piece on business process automation and RPA describes.

Deleting biometric templates, and proving it

The legal trigger also appears in the KVKK's Guidelines on Matters to Be Considered in the Processing of Biometric Data, dated 16.10.2021: when the necessity ceases, the data is destroyed without delay. Once that purpose falls away, there is nothing to wait for.

Saying "we deleted the templates" is not enough; the operation must be recorded. The Regulation on the Deletion, Destruction or Anonymisation of Personal Data settles three points:

  • Article 7(3): records of deletion, destruction and anonymisation are kept at least three years, other legal obligations aside.
  • Article 11(2): periodic destruction can in no case exceed six months.
  • Article 5(1): a retention and destruction policy is mandatory for controllers required to register with VERBİS, the authority's registry of data controllers.

The legislation prescribes no technical erasure procedure. What it requires is a completely defined scope: the device's local memory, the server database, exported files and backups. A scattered backup regime means a scattered scope — our guide to data security and backup helps assemble the inventory. If a breach occurs mid-transition, the obligation rests on Article 12(5) of Law No. 6698 and the Board's decision No. 2019/10 dated 24.01.2019; notification goes through ihlalbildirim.kvkk.gov.tr within 72 hours, as our data breach response plan sets out.

We moved to cards. Is the compliance work over?

No. An RFID/NFC or PIN system that maps a card number to an employee is still processing personal data, so privacy notices and the authorisation matrix continue to apply; and if you are a controller required to register with VERBİS, your retention and destruction policy has to cover this new process too. What changes is the regime: this data falls under the general processing conditions of Article 5 rather than the Article 6 regime for special categories. That is an inference from the structure of the legislation; the announcements contain no such sentence.

Writing the rule down is not confined to one process: the same logic applies to tools employees adopt on their own — our article on AI and personal data protection covers that side. To set the same rule company-wide rather than process by process, the inventory and policy outline in shadow AI and a workplace AI usage policy is a practical starting point.

In what order should the transition run?

Sequence matters, because switching the device off over a weekend and leaving attendance unrecorded creates a fresh payroll risk. First, document what every device at the door is for and where its data flows. Second, choose the alternative record method and wire it into payroll.

Third, run both systems in parallel briefly and reconcile them. Last, destroy the biometric templates within a defined scope and create the destruction record. All of this is a software and integration job — replacing the reader without building the line between the recording point, the approver and payroll only postpones the problem.

The official texts are published at kvkk.gov.tr; the Principle Decision and both announcements are worth reading there. For support on the system side while rebuilding your attendance workflow, see our services or get in touch.

This article is not legal or tax advice; for your own situation, consult your legal counsel or accountant.

Frequently Asked Questions

Is fingerprint-based time attendance legal in Turkey?
Principle Decision No. 2026/921 of Turkey's Personal Data Protection Board, dated 29.04.2026, was published in the Official Gazette on 2 June 2026 and found that processing biometric data solely for time and attendance tracking does not meet the conditions of Law No. 6698. The decision is tied to that purpose: biometric processing outside attendance tracking is not assessed under it, and the assessment stays with the data controller. The full texts are published at kvkk.gov.tr, and a lawyer should review your own situation.
If we collect explicit consent, can we keep the fingerprint reader?
The decision turns precisely on rejecting that approach. The Board does not treat explicit consent as a sufficient basis on its own, because of the structural power imbalance between employer and employee, and Article 4 of Law No. 6698 requires proportionality, meaning the route that achieves the purpose with less data must be preferred. Strengthening the consent text does not change that finding.
How long do we have to comply with the KVKK decision?
The public announcements of 2 June 2026 and 27 August 2026 do not set out a separate transition or grace calendar. The June announcement states that where non-compliance with the stated points is established, action will be taken against the relevant data controllers pursuant to Article 18 of the law. The current framework should be followed on kvkk.gov.tr.
Is deleting the fingerprint records enough, and how do we prove it?
Deletion is required, but it also has to be provable. Under the Regulation on the Deletion, Destruction or Anonymisation of Personal Data, Article 7(3) requires records of such operations to be kept for at least three years, other legal obligations aside, and Article 11(2) provides that the periodic destruction interval can in no case exceed six months. Define the scope so it covers the device's local memory, the server database, exported files and backups.

Need help with this topic?

Contact Us