FB pixel

CNIL sets rules for biometric employee time and attendance systems in France

 

France’s Commission nationale de l’informatique et des libertés (CNIL) has published regulations for companies using employee’s biometrics, requiring the use of the technology to be justified to the CNIL, “rigorous” security measures to protect biometric data, and a GDPR data protection impact assessment to be conducted.

The French Data Protection Act has required businesses to obtain approval from the CNIL for deploying biometrics to track employees, and the regulator issued a fine of €10,000 last September to a company that had failed to do so.

The CNIL launched public consultation on the draft of the regulations around the same time, amid a legal shift that includes GDPR but also legislative changes to French computer law made in recognition of the popularity and utility of biometric access control.

The regulation allows morphological biometrics, such as fingerprints, vein patterns, or iris scans, but not biological modalities, such as blood or DNA matching, or behavioral biometrics, following the definitions included in GDPR. Justifying the deployment of biometrics to CNIL will require identifying a specific context that requires a high degree of security, and demonstrating the inadequacy of “less intrusive means” to do so. Employee consent is not required.

This latter point marks a major departure from Illinois’ BIPA, which has generated hundreds of law suits on the basis of alleged violations of informed consent process rules.

The regulations apply to private and public sector employers alike, according to an FAQ accompanying the announcement, while third parties designing and installing biometric systems will be considered subcontractors under GDPR. This means the employer organization is considered the system’s controller and is responsible for ensuring the subcontractor meets the regulatory requirements.

Liisa Thomas of Sheppard Mullin Richter & Hampton LLP advises in a blog post to Lexology that business using biometrics should anticipate the possibility of other countries following France’s lead.

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

AI deepfakes push biometric industry toward measurable assurance

The rise of AI-generated deepfakes and injection attacks is reshaping how organizations evaluate biometric security systems, pushing the industry toward…

 

Security, ruggedness key for reliable biometric physical access control tools

A recent webinar from Biometric Update and Goode Intelligence opens up the hood on the 2026 Biometric Physical Access Control…

 

Trident pivots to multi‑vertical holding company focused on sovereign digital infrastructure

Trident Digital Tech Holdings Ltd. is overhauling its corporate structure to strengthen focus on its offerings for national digital economies….

 

South Africa Home Affairs seeks $828M budget for digital ID, biometric visa projects

South Africa’s Department of Home Affairs has tabled a budget of 13.8 billion Rand (about US$828 million) in parliament for…

 

NIST biometric age estimation update show demographic, accuracy gains

Demographic disparities and mean error rates are falling among the newest age estimation and verification algorithms submitted to the U.S.’…

 

Identity verification becomes core compliance infrastructure across regulated sectors

Identity verification is increasingly becoming embedded operational infrastructure across regulated industries as tighter AML, KYC and fraud-prevention requirements push organizations…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events