Auratech Legal Solutions

Fingerprint time tracking in 2026: annulling the AEPD guidance did not make it legal

Fingerprint time tracking reader at a company entrance

Fingerprint time tracking is back on the agenda of boards and HR departments across Spain. The reason: a June 2026 judgment of the Spanish National Court. That ruling annulled the AEPD guidance on biometric attendance control. However, many headlines read it as a green light. It is not. Here we explain what was struck down, what remains intact and what your company must prove before installing a fingerprint reader.

What the National Court actually annulled

Judgment 367/2026, of 30 June 2026, annulled the guidance the AEPD published on 23 November 2023. It was handed down by Section 1 of the Administrative Chamber (ordinary proceedings 84/2024, reporting judge Helmuth Moya Meyer). The claimant was the Spanish Association of Security Companies.

That said, the reason is purely procedural. The Court concluded that the document was not advisory guidance at all, but in substance a circular: it laid down binding criteria. Therefore it should have followed the procedure in article 55 of the Spanish Data Protection Act and article 6 of Royal Decree 389/2021. As the judgment itself puts it, what matters is not the label on the document, but its content.

Two nuances deserve emphasis. First, the National Court does not rule on the merits: it does not dispute that biometric data are special category data, nor does it correct the substantive criteria. Second, the judgment is not final, since an appeal to the Supreme Court is still available. At the time of writing, the AEPD has not yet approved a replacement instrument. The document does, however, already appear on its website marked “under review”.

Why fingerprint time tracking still has no green light

This is exactly where most readers go wrong. We already analysed biometric processing in the workplace and the framework has not moved. In other words, the instrument fell, not the rule. And the rule has not changed by a single comma.

Fingerprints are still special category data

Article 9(1) GDPR prohibits processing biometric data for the purpose of uniquely identifying a person. Moreover, the European Data Protection Board confirmed this in its Guidelines 05/2022 (version 2.0, paragraph 12). Both identification (1:N) and simple authentication (1:1) fall within those special categories of data. Therefore every fingerprint time tracking project needs an exception under article 9(2). And, on top of that, a legal basis under article 6(1).

Spain has no enabling law for ordinary companies

The article 9(2)(b) exception is narrower than most people assume. It requires the processing to be necessary for specific rights or obligations in employment law. It also requires authorisation either by a statute or by a collective agreement that provides for it expressly and with appropriate safeguards. That agreement, in turn, is subject to full judicial review of necessity (CJEU, Case C-65/23, 19 December 2024).

However, articles 20.3 and 34.9 of the Spanish Workers’ Statute contain no such authorisation. They lack the specificity that constitutional case law demands (Constitutional Court judgments 292/2000 and 76/2019). Two regional authorities reached the same conclusion. The Catalan Data Protection Authority said so (Opinion 2/2022) and the Andalusian Transparency and Data Protection Council repeated it (Opinion 1/2023). In short, the average private company has no first layer of legitimacy today.

In fact, the legislator confirms the point. The Draft Act on the Protection and Resilience of Critical Entities, in parliamentary process since March 2026, creates an express biometric authorisation. But only for critical entities, and only with a mandatory impact assessment.

Employee consent is rarely freely given

EDPB Guidelines 05/2020 (paragraphs 21 and 22) are clear: in employment there is an imbalance that makes free consent unlikely. It is available only in exceptional circumstances, where refusing carries no adverse consequence and a genuinely equivalent alternative exists. Consequently, an “authorisation” form signed by the workforce solves nothing. Indeed, it may instead evidence that the company knew the requirement and worked around it.

The Litera Meat case: the exception that proves the rule

Clients often ask us about “the meat factory judgment”. One correction is due: it is not a judgment, but an archiving decision by the AEPD (file EXP202408491). The Agency found no evidence of an infringement on the information available. It therefore closed the file without opening sanction proceedings, “without prejudice to possible subsequent action”.

One detail is usually left out: the decision does not identify which article 9(2) exception lifts the prohibition. It merely assesses the necessity the company documented, and that came down to three things almost nobody documents:

  1. Genuine necessity: strict food safety standards and protective equipment covering the worker completely, which makes visual identification difficult.
  2. Proportionate scope: fingerprints only in the production area (some 1,508 workers) and cards in offices, maintenance, laundry and the laboratory (182 workers).
  3. Prior analysis of alternatives: earlier incidents with identity cards, an impersonation risk assessment and a reasoned explanation of why less intrusive means were not equivalent.

That decision does not legitimise fingerprint time tracking in general. On the contrary, it sets a very high bar. So what if your justification comes down to convenience or the cost of replacing readers? Then the precedent works against you. It shows the alternative exists and was dropped on financial grounds.

What the courts and the AEPD are doing

While the academic debate runs on, decisions keep landing on the same side.

The practical reading is uncomfortable but useful: risk no longer arrives only through the regulator. Any employee can bring a claim of their own before the labour courts. And win damages even if the AEPD never opens a file.

Access control and attendance control: a distinction that will not save you

Another common argument is that the reader “does not clock anyone in, it just opens the door”. The purpose changes, and with it the article 6(1) basis. But the article 9 layer does not move: the data remain special category and the exception is still required.

There is an added risk, too. If the system logs the date and time of every entry, it creates a de facto attendance trail. A labour inspection or a court may classify that as disguised working time monitoring, with its own lack of legitimacy.

1:1 versus 1:N: less risk does not mean lawful

The AEPD has accepted one technical nuance in its recent practice. “Local” 1:1 verification is less intrusive than 1:N identification against a central database. So yes, that improves proportionality and makes the impact assessment easier. However, it does not create a legal basis.

In the one case where the Agency did validate 1:1 biometrics, lawfulness came from sector-specific public security legislation. That was prior consultation REGAGE25e00024730156, of 18 July 2025, concerning Guardia Civil facilities. It relied on Organic Law 7/2021 and Organic Law 2/1986. Not on the Workers’ Statute.

Checklist before installing or keeping biometrics

Consequently, if you intend to defend a biometric system, build this file before switching it on:

What to do if the system is already running

A missing prior impact assessment cannot be fixed by carrying one out later, although it does show subsequent diligence. That is why we recommend an orderly sequence.

First, freeze new biometric enrolments and hand an alternative credential to every new joiner. Then have management approve a written migration plan with a budget and a timetable. Next, document an honest DPIA supporting the decision. Finally, delete the templates under certificate when the process closes, and reflect the change in your record of processing activities.

Such a plan, documented and under way, is also your best defence if someone complains during the transition. The AEPD itself has viewed migration favourably. In the Litera Meat case, in fact, an earlier complaint was dismissed because the company showed it was moving to cards.

Conclusion

Annulling the guidance removes an instrument, not a criterion. Fingerprint time tracking remains special category processing. It requires an enabling law or genuinely free consent, demonstrated necessity and a prior impact assessment. Until the AEPD publishes its new institutional response, prudence means documenting more, not relaxing controls.

At Auratech Legal we assess whether your biometric system is defensible as part of a data protection audit and we prepare the DPIA. Where it is not defensible, we design the migration plan. Request a review of your access and attendance system.

Frequently asked questions

Is fingerprint time tracking legal after the June 2026 judgment? Not automatically. The judgment annulled the AEPD guidance on procedural grounds. Article 9 GDPR, by contrast, still prohibits the processing unless an exception applies.

Does having employees sign an authorisation help? In an employment relationship, consent is treated as vitiated by the imbalance between the parties. It would be valid only if a genuinely equivalent alternative exists and refusing carries no consequence.

Can I use fingerprints only to open the door, not to clock in? That changes the purpose, but it does not change the nature of the data. It remains special category and it still needs an article 9(2) exception.

Is 1:1 verification enough to comply? It reduces risk and improves proportionality. However, it does not on its own create the legal basis the GDPR requires.

What if we have used fingerprints for years with no impact assessment? In that case the infringement counts as continuing for as long as the processing lasts (article 30.2 of Act 40/2015). The sooner you document the plan and migrate, the sooner the limitation period starts to run.

Exit mobile version