Fingerprint time tracking is back on the agenda of boards and HR departments across Spain. The reason: a June 2026 judgment of the Spanish National Court. That ruling annulled the AEPD guidance on biometric attendance control. However, many headlines read it as a green light. It is not. Here we explain what was struck down, what remains intact and what your company must prove before installing a fingerprint reader.
In this article we will discuss...
What the National Court actually annulled
Judgment 367/2026, of 30 June 2026, annulled the guidance the AEPD published on 23 November 2023. It was handed down by Section 1 of the Administrative Chamber (ordinary proceedings 84/2024, reporting judge Helmuth Moya Meyer). The claimant was the Spanish Association of Security Companies.
That said, the reason is purely procedural. The Court concluded that the document was not advisory guidance at all, but in substance a circular: it laid down binding criteria. Therefore it should have followed the procedure in article 55 of the Spanish Data Protection Act and article 6 of Royal Decree 389/2021. As the judgment itself puts it, what matters is not the label on the document, but its content.
Two nuances deserve emphasis. First, the National Court does not rule on the merits: it does not dispute that biometric data are special category data, nor does it correct the substantive criteria. Second, the judgment is not final, since an appeal to the Supreme Court is still available. At the time of writing, the AEPD has not yet approved a replacement instrument. The document does, however, already appear on its website marked “under review”.
Why fingerprint time tracking still has no green light
This is exactly where most readers go wrong. We already analysed biometric processing in the workplace and the framework has not moved. In other words, the instrument fell, not the rule. And the rule has not changed by a single comma.
Fingerprints are still special category data
Article 9(1) GDPR prohibits processing biometric data for the purpose of uniquely identifying a person. Moreover, the European Data Protection Board confirmed this in its Guidelines 05/2022 (version 2.0, paragraph 12). Both identification (1:N) and simple authentication (1:1) fall within those special categories of data. Therefore every fingerprint time tracking project needs an exception under article 9(2). And, on top of that, a legal basis under article 6(1).
Spain has no enabling law for ordinary companies
The article 9(2)(b) exception is narrower than most people assume. It requires the processing to be necessary for specific rights or obligations in employment law. It also requires authorisation either by a statute or by a collective agreement that provides for it expressly and with appropriate safeguards. That agreement, in turn, is subject to full judicial review of necessity (CJEU, Case C-65/23, 19 December 2024).
However, articles 20.3 and 34.9 of the Spanish Workers’ Statute contain no such authorisation. They lack the specificity that constitutional case law demands (Constitutional Court judgments 292/2000 and 76/2019). Two regional authorities reached the same conclusion. The Catalan Data Protection Authority said so (Opinion 2/2022) and the Andalusian Transparency and Data Protection Council repeated it (Opinion 1/2023). In short, the average private company has no first layer of legitimacy today.
In fact, the legislator confirms the point. The Draft Act on the Protection and Resilience of Critical Entities, in parliamentary process since March 2026, creates an express biometric authorisation. But only for critical entities, and only with a mandatory impact assessment.
Employee consent is rarely freely given
EDPB Guidelines 05/2020 (paragraphs 21 and 22) are clear: in employment there is an imbalance that makes free consent unlikely. It is available only in exceptional circumstances, where refusing carries no adverse consequence and a genuinely equivalent alternative exists. Consequently, an “authorisation” form signed by the workforce solves nothing. Indeed, it may instead evidence that the company knew the requirement and worked around it.
The Litera Meat case: the exception that proves the rule
Clients often ask us about “the meat factory judgment”. One correction is due: it is not a judgment, but an archiving decision by the AEPD (file EXP202408491). The Agency found no evidence of an infringement on the information available. It therefore closed the file without opening sanction proceedings, “without prejudice to possible subsequent action”.
One detail is usually left out: the decision does not identify which article 9(2) exception lifts the prohibition. It merely assesses the necessity the company documented, and that came down to three things almost nobody documents:
- Genuine necessity: strict food safety standards and protective equipment covering the worker completely, which makes visual identification difficult.
- Proportionate scope: fingerprints only in the production area (some 1,508 workers) and cards in offices, maintenance, laundry and the laboratory (182 workers).
- Prior analysis of alternatives: earlier incidents with identity cards, an impersonation risk assessment and a reasoned explanation of why less intrusive means were not equivalent.
That decision does not legitimise fingerprint time tracking in general. On the contrary, it sets a very high bar. So what if your justification comes down to convenience or the cost of replacing readers? Then the precedent works against you. It shows the alternative exists and was dropped on financial grounds.
What the courts and the AEPD are doing
While the academic debate runs on, decisions keep landing on the same side.
- Aena: EUR 10,043,002 (PS/00431/2024, November 2025) for 1:N facial recognition with a central database and no valid impact assessment. The AEPD also ordered the processing to be suspended.
- CTC Externalización: EUR 365,000 (2024) for fingerprint time tracking. The fine breaks down into inadequate information (art. 13, 200,000), insufficient security measures (art. 32, 65,000) and no impact assessment (art. 35, 100,000).
- High Court of Justice of Galicia 144/2026, 15 January (Social Chamber, ECLI:ES:TSJGAL:2026:613): EUR 7,501 in non-material damages. The employer ran facial recognition attendance for almost two years without consent or demonstrated necessity. The works council had proposed cards instead.
The practical reading is uncomfortable but useful: risk no longer arrives only through the regulator. Any employee can bring a claim of their own before the labour courts. And win damages even if the AEPD never opens a file.
Access control and attendance control: a distinction that will not save you
Another common argument is that the reader “does not clock anyone in, it just opens the door”. The purpose changes, and with it the article 6(1) basis. But the article 9 layer does not move: the data remain special category and the exception is still required.
There is an added risk, too. If the system logs the date and time of every entry, it creates a de facto attendance trail. A labour inspection or a court may classify that as disguised working time monitoring, with its own lack of legitimacy.
1:1 versus 1:N: less risk does not mean lawful
The AEPD has accepted one technical nuance in its recent practice. “Local” 1:1 verification is less intrusive than 1:N identification against a central database. So yes, that improves proportionality and makes the impact assessment easier. However, it does not create a legal basis.
In the one case where the Agency did validate 1:1 biometrics, lawfulness came from sector-specific public security legislation. That was prior consultation REGAGE25e00024730156, of 18 July 2025, concerning Guardia Civil facilities. It relied on Organic Law 7/2021 and Organic Law 2/1986. Not on the Workers’ Statute.
Checklist before installing or keeping biometrics
Consequently, if you intend to defend a biometric system, build this file before switching it on:
- The article 9(2) exception identified in writing, not just the article 6(1) basis.
- A prior data protection impact assessment (DPIA), with the threefold test of suitability, necessity and strict proportionality.
- Documentary proof of necessity: real incidents, metrics, risks specific to the area.
- An analysis of alternatives considered and rejected, with the technical reason for each rejection.
- Scope limited to critical areas, with a non-biometric credential everywhere else.
- A genuinely equivalent non-biometric alternative, at no cost or detriment, for anyone who declines.
- Minimum architecture: an irreversible, encrypted template, no original image, ideally under the person’s own control (card or phone) and no cloud copies.
- An article 28 contract with the vendor and control over remote maintenance access.
- Article 13 information and an opinion from the data protection officer.
What to do if the system is already running
A missing prior impact assessment cannot be fixed by carrying one out later, although it does show subsequent diligence. That is why we recommend an orderly sequence.
First, freeze new biometric enrolments and hand an alternative credential to every new joiner. Then have management approve a written migration plan with a budget and a timetable. Next, document an honest DPIA supporting the decision. Finally, delete the templates under certificate when the process closes, and reflect the change in your record of processing activities.
Such a plan, documented and under way, is also your best defence if someone complains during the transition. The AEPD itself has viewed migration favourably. In the Litera Meat case, in fact, an earlier complaint was dismissed because the company showed it was moving to cards.
Conclusion
Annulling the guidance removes an instrument, not a criterion. Fingerprint time tracking remains special category processing. It requires an enabling law or genuinely free consent, demonstrated necessity and a prior impact assessment. Until the AEPD publishes its new institutional response, prudence means documenting more, not relaxing controls.
At Auratech Legal we assess whether your biometric system is defensible as part of a data protection audit and we prepare the DPIA. Where it is not defensible, we design the migration plan. Request a review of your access and attendance system.
Frequently asked questions
Is fingerprint time tracking legal after the June 2026 judgment? Not automatically. The judgment annulled the AEPD guidance on procedural grounds. Article 9 GDPR, by contrast, still prohibits the processing unless an exception applies.
Does having employees sign an authorisation help? In an employment relationship, consent is treated as vitiated by the imbalance between the parties. It would be valid only if a genuinely equivalent alternative exists and refusing carries no consequence.
Can I use fingerprints only to open the door, not to clock in? That changes the purpose, but it does not change the nature of the data. It remains special category and it still needs an article 9(2) exception.
Is 1:1 verification enough to comply? It reduces risk and improves proportionality. However, it does not on its own create the legal basis the GDPR requires.
What if we have used fingerprints for years with no impact assessment? In that case the infringement counts as continuing for as long as the processing lasts (article 30.2 of Act 40/2015). The sooner you document the plan and migrate, the sooner the limitation period starts to run.
