The CNIL publishes a standard regulation on access control to premises and working hours monitoring

The National Commission on Informatics and Liberty (CNIL) has detailed the rules applicable to access control devices for premises and monitoring of working hours.

The employer may implement individual control tools to secure access to buildings and restricted areas, as well as to manage attendance times. However, these devices must be proportionate to the intended purpose. The use of biometrics or the systematic taking of photographs for simple working hours control is considered excessive and contrary to the data minimization principle. Moreover, information collected for security purposes, such as badge reader logs, cannot be used to monitor employees' working hours, pursuant to the purpose limitation principle set out in Article 5, paragraph 1, point b of the GDPR. These systems must also not be used to monitor internal movements or to hinder the freedom of staff representatives.

Access to data must be strictly limited to authorized services, such as human resources or security. Retention periods are set at 3 months for access logs and can extend up to 5 years in intermediate archiving for working time monitoring data. Employees and staff representative bodies must be informed of the implementation of these devices. Any processing must be recorded in the processing activities register and, in case of high risk, notably with biometrics, a data protection impact assessment is mandatory. The use of biometrics must remain subsidiary, justified by security imperatives that non-biometric means cannot satisfy.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire