Data Privacy & Compliance

Türkiye's KVKK draws a line on fingerprint and face-scan clocking

Türkiye's Personal Data Protection Board (KVKK) decision 2026/921 sets legal limits on fingerprint and facial-recognition time tracking at work. What it means for manufacturing SMEs, and how to move to a compliant setup — sourced and practical.

Updated: 23 September 2026 The figures and legal references on this page are based on official/primary sources.

Türkiye's KVKK draws a line on fingerprint and face-scan clocking

In a growing number of manufacturing plants, clocking in is no longer a card swipe. A fingerprint scanner or a face-recognition camera at the gate logs the moment a worker starts a shift, feeds it straight into the time-and-attendance system (PDKS in Turkish HR terminology), and from there into payroll. It’s fast, hard to game, and fits neatly into a digitalization story.

Türkiye’s Personal Data Protection Board (KVKK) drew a clear boundary around this practice with decision 2026/921, dated 29 April 2026 and published on 2 June 2026. The Board doesn’t ban biometric time tracking outright, but it flags most current setups as likely non-compliant. For a manufacturing SME, that reads less as “rip out the scanners” and more as “review your attendance system before someone else does.”

What the decision actually says

PointBoard’s finding
Legal basisNo explicit provision in law authorizes biometric attendance tracking specifically — the gap itself creates legal risk
ConsentGiven the power imbalance in an employment relationship, a signed consent form alone doesn’t establish valid legal grounds
ProportionalityLess intrusive alternatives (PIN codes, encrypted cards, RFID) exist, which makes biometric use disproportionate
OutcomeNon-compliant setups can trigger administrative proceedings under Article 18 of Türkiye’s data protection law

The decision doesn’t order employers to drop biometrics entirely. But as written, it signals that a typical PDKS install — consent form on file, no real alternative offered — doesn’t meet the bar the Board has set.

Enforcement risk, before any fine is issued

Like most Board decisions, this one doesn’t come with a fixed penalty table; the general framework sits in Article 18 of the law. Fines for data-security violations are adjusted annually, so quoting a specific figure here would be misleading — check KVKK’s current schedule before budgeting for worst-case exposure.

The more immediate risk sits earlier in the process: in an inspection or a complaint, the employer has to justify why biometrics were chosen over an available alternative. If that alternative was never evaluated, the defense is thin. Most compliance advisors recommend acting before an inspection forces the issue, not after.

Valid consent under KVKK requires a free, unpressured choice. The Board questions whether a standard form handed to a new hire on day one really meets that bar — turning it down can carry a real fear of not being hired or being treated differently afterward. That tension is exactly what makes the “consent” defense weak in practice.

The practical takeaway: a signed form in a file isn’t sufficient documentation on its own. You need to show the consent was offered alongside a genuine alternative, that it’s revocable, and that no pressure was involved — and that burden of proof sits with the employer.

Proportionality: is there really an alternative

The Board’s second pillar is proportionality — if the same goal (logging attendance) can be met with a less invasive method, biometric data becomes disproportionate. The alternatives named in the decision:

  • Encrypted card or PIN-based access and logging systems
  • RFID/NFC identity cards
  • Manual entry under supervisor oversight
  • Traditional signature-based or paper attendance sheets

None of this calls for new technology. Card- and PIN-based readers are already the dominant category in the PDKS market; what changes is which one becomes the default choice.

PDKS is one endpoint in a chain that runs to payroll

In a manufacturing SME, attendance logging rarely stands alone. A record from a turnstile or card reader typically flows into HR, from there into payroll, and sometimes into production planning — shift fill rates, overtime tracking. If non-compliant data collection happens at one point in that chain, the exposure doesn’t stay contained to the device; it reaches payroll calculations, audit files, and the company’s own data-controller filings.

That’s why swapping out a PDKS setup is really a digitalization decision: redefining where data is collected, how, and on what legal basis. A properly configured card- or PIN-based system carries less “special category data” exposure than a biometric device, and integrates with ERP or payroll just as directly — this is a standard systems-integration project, not a months-long undertaking.

In a multi-shift plant, that integration also touches productivity reporting. If shift fill rates, overtime patterns, and absence trends are derived from PDKS data, data quality — accurate timestamps, deduplicated records — feeds straight into production planning. Moving from biometrics to card/PIN without breaking that reporting chain, meaning the new reader writes to the same ERP fields in the same format, deserves its own line in the project plan.

Migrating off biometrics: step by step

A move from biometric clocking to a card- or PIN-based setup typically follows this order:

  1. Inventory what you have — which locations, how many devices, what data (fingerprint templates, facial vectors) is being collected.
  2. Review the legal basis — check whether your current privacy notice and consent form meet the Board’s standard: free choice, a real alternative on offer.
  3. Pick the replacement hardware — RFID or PIN-based readers usually integrate directly with existing turnstile infrastructure.
  4. Destroy the historical biometric data — delete fingerprint or facial templates you no longer need, following KVKK’s retention-and-destruction rules, and keep a destruction record.
  5. Communicate the change — notify staff of the new method and update the privacy notice accordingly.

Most of these steps can be closed out within a week; the part that takes longer is inventorying existing devices and properly documenting the destruction of historical data.

How İkiz Eksen approaches this

İkiz Eksen starts by measuring what’s actually happening on the ground: which system collects what data, on what legal basis. From there, on the digital transition side, it connects PDKS/HR/payroll into your ERP and turns that into usable value; on the data-security side, it makes destruction policies and privacy notices part of a sustainable process rather than a one-off fix. Systems built on Microsoft Azure draw on the integration experience Qera has built across 550+ customers and 15+ sectors; projects run end-to-end, nationwide.

This kind of review rarely stays confined to attendance tracking alone. The same plant often runs access control, visitor logging, or shift-planning software with similar data-collection habits. A short inventory pass can cover all of them in one go — cheaper and less risky than revisiting each system separately, one compliance complaint at a time.

If you’d like a second look at your PDKS setup, browse our solution areas or get in touch directly — we can review your current setup together.

Frequently Asked Questions

Does KVKK decision 2026/921 ban biometric time tracking outright?

No. The Board doesn’t impose a direct ban — it finds the current legal basis insufficient and flags most existing setups as potentially disproportionate, expecting employers to evaluate alternatives.

Do we have to remove existing fingerprint scanners immediately?

The decision doesn’t set a fixed deadline for employers. But if your current setup’s legal basis is weak, starting the migration as soon as practical reduces inspection risk.

Is there a difference between facial recognition and fingerprint scanning?

Both count as biometric data and fall under the same framework in this decision. Facial-recognition systems may additionally involve processing camera footage, so your privacy notice needs to cover that too.

Is switching to an alternative system expensive?

Card- or PIN-based readers usually connect directly to existing turnstile and access-control infrastructure, so total cost depends on company size and current hardware. A firm figure requires reviewing your existing setup first.

How should we destroy historical biometric data?

Under KVKK’s data retention and destruction rules, you choose one of deletion, destruction, or anonymization, and document the action with a destruction record. If you’re unsure, consult a KVKK advisor or your legal counsel.

Share on LinkedIn

Related posts

This content is informational; confirm official regulation and incentive terms from primary sources (the relevant authority / Official Gazette).

Looking for where to start your digital or green transformation?

Starting with İkiz Eksen is simple: we first measure where you stand and build your roadmap together. You begin with a single step, not a large programme.