Information Note on the Personal Data Protection Authority’s Public Announcement Regarding Requests for Opinions on the Principle Decision on the Processing of Biometric Data for Attendance Monitoring
Document Type: Public Announcement
Announcement Date: 27 August 2026
Summary of the Announcement
Following the publication of the Personal Data Protection Board’s (the ‘Board’) Principle Decision No 2026/921 dated 29 April 2026 on the Processing of Biometric Data for Attendance Monitoring (the ‘Principle Decision’) in the Official Gazette on 2 June 2026, data controllers operating in various sectors submitted several requests for opinions to the Personal Data Protection Authority (the ‘Authority’). In response, the Authority issued a Public Announcement (the ‘Announcement’) to clarify certain matters concerning the scope and implementation of the Principle Decision.
The Announcement fully maintains the fundamental approach adopted in the Principle Decision. It reiterates that biometric-data processing activities carried out solely for attendance monitoring purposes do not rely on any of the processing conditions under Article 6 of the Personal Data Protection Law No 6698 (the ‘Law’ or ‘PDPL’) and would not satisfy the proportionality criterion under Article 4 of the Law, even if valid explicit consent has been obtained. Nevertheless, the Announcement is of importance as it clarifies three points that have been subject to debate in practice:
- Converting data obtained through palm or fingerprint scanning into a mathematical code (template/hash) and storing them as such does not remove their status as biometric data;
- In certain facilities and fields of activity carrying high security risks, biometric identification systems cease to be merely attendance-monitoring tools and become part of identity authentication, authorisation and access-control processes for critical areas; and these circumstances diverge from the general assessment in the Principle Decision;
- Processing of biometric data activities for purposes other than attendance monitoring will not be evaluated within the scope of the Principle Decision; their lawfulness will be assessed directly by the data controllers themselves by reference to the purpose, the nature of the work and the circumstances of the particular case; the Board will separately examine each notification and complaint submitted to the Authority on its own facts.
Therefore, under the Announcement, the decisive criterion is whether the processing of biometric data goes beyond ‘attendance monitoring’ and is used to protect security and critical infrastructure.
Key Points of the Announcement
Scope of the Biometric Data Concept and the ‘Mathematical Code’ Argument
The Authority stated that some requests for opinions argued that data obtained through methods such as palm scanning or fingerprint capture should not be treated as biometric data. In practice, this argument is made particularly in relation to personnel attendance control systems (known by the Turkish abbreviation PDKS) solutions that store only a template or hash value rather than the raw image.
The Authority rejected this view. It expressly stated that converting data into a mathematical code and storing them in a database does not remove their biometric nature. The Authority also recalled that the special categories of personal data listed in Article 6 of the Law are exhaustive and cannot be expanded by analogy; biometric data are expressly included among those categories.
This clarification means that the argument often advanced by PDKS suppliers – that an encrypted numerical value is stored – no longer carries legal weight before the Authority. The irreversibility of the template or the fact that no raw image is stored does not take the data outside the regime under Article 6 of the Law.
Confirmation of the Absence of a Legal Basis and of the Principle Decision
The Authority reiterated that, although employers are required to monitor and document working time, there is no express statutory provision requiring that obligation to be fulfilled through biometric identification systems. It confirmed that using biometric-data processing for attendance monitoring may therefore be unlawful.
Facilities and Fields of Activity Carrying High Security Risks
The most significant aspect of the Announcement in terms of implementation is the acknowledgement that certain facilities and fields of activity differ from the general assessment due to the security risk they carry and the potential consequences that a breach could cause. According to the Authority, in these settings, biometric identification systems cease to be merely a tool serving attendance monitoring and become an integral part of multi-layered security processes, such as identity authentication, authorisation and access control for critical areas. In such circumstances, the purpose of the processing is not to monitor personnel working hours but to protect security and critical infrastructure directly.
The Authority did not list these areas exhaustively; however, it stipulated three cumulative conditions for biometric-data processing within them:
- Limiting the processing only to necessary critical areas and persons
- The proportionality of the processing activity to the concrete security need
- The inadequacy of alternative methods (card/PIN, RFID/NFC, supervised entry, etc)
Limits of the Exemption under Article 28(1)(ç) of the Law
The Authority recalled that, pursuant to Article 28(1)(ç) of the Law, data-processing activities aimed at maintaining national defence, national security, public security, public order or economic security may fall outside the scope of the Law under certain circumstances. However, although this exemption provides a significant margin of flexibility for large-scale public security authorities, it does not permit unrestricted use of biometric data. Each case must be assessed by considering the severity of the security risk, the inadequacy of alternative methods and the purpose of the processing. Accordingly, even the exemption under Article 28(1)(ç) does not automatically exempt public bodies that use biometric data for attendance monitoring.
Separation of Attendance Monitoring and Other Purposes
In the conclusion section of the Announcement, the Authority clearly separated the two categories. Regarding biometric data processing activities carried out for the purpose of employee attendance monitoring, data controllers must act in accordance with the Principle Decision. Biometric-data processing for purposes other than attendance monitoring will not be assessed under the Principle Decision; data controllers themselves must assess its lawfulness in light of the purpose of processing, the nature of the work and the circumstances of the concrete case. Notices and complaints submitted to the Authority will be examined separately by the Board on a case-by-case basis.
Potential Effects of the Announcement
Focus of the Compliance Assessment
Data controllers must functionally separate their existing biometric systems; they need to document whether the system provides data for timekeeping, payroll or overtime calculations, and whether those data can be obtained independently from security-oriented access control. Any structure in which the output of the biometric data is an attendance record will remain within the scope of the Principle Decision, regardless of how it is described.
Assessment Obligation for High-Security Facilities
Data controllers operating in critical infrastructures such as port facilities, shipyards, energy and petrochemical facilities, data centres, defence industry production areas, airport security zones and similar critical infrastructures must base their assessments on documentary evidence if they wish to rely on the distinction set out in the Announcement. This assessment is expected to include. At a minimum, this assessment is expected to define the critical areas and the personnel who require access to them; give specific reasons why alternative methods are inadequate for each area; explain the proportionality of the processing to the specific security need; and show that the attendance-monitoring function has been physically and logically separated from the biometric system.
Compliance Status of Template/Hash-Based Systems
The Authority’s rejection of the mathematical-code argument creates a direct risk of non-compliance for data controllers that rely on suppliers’ representations that PDKS solutions storing only templates are exempt from the Principle Decision. The templates stored in these systems also constitute special-category personal data. Where they are processed for attendance monitoring, the consequences set out in the Principle Decision apply equally. The obligations concerning erasure, destruction or anonymisation, as well as the adequate measures set out in the Board’s Decision No 2018/10, remain fully applicable.
Conclusion and Assessment
The Announcement does not alter the categorical approach of the Principle Decision regarding the processing of biometric data for attendance monitoring purposes. It establishes that the use of biometric identification systems for the protection of security and critical infrastructure falls outside the scope of the Principle Decision where the processing is limited to critical areas and persons, alternative methods are inadequate and the processing is proportionate to a specific security need. Even in such cases, the lawfulness assessment and the related burden of proof rest with the data controller, and the Board will examine each concrete case separately.
You may access the full text of the Announcement referred to above via the link below.
Personal Data Protection Authority-Public Announcement
Should you require further information on this matter, please feel free to contact us at any time using the contact details below.
| Selçuk S. Esenyel Founding and Managing Partner Tel: +90 212 397 19 91 Mob: +90 506 792 76 90 | Semih Sander semih.sander@esenyelpartners.com Partner Tel: +90 212 397 19 91 Mob: +90 532 590 92 32 |
| Hande Ertuğrul hande.uygun@esenyelpartners.com Counsel Tel: +90 212 397 19 91 Mob: +90 539 896 46 82 | |