The Price of a Face
When a public hospital in Madeira introduced facial recognition to monitor staff attendance, it reignited a fundamental question in European data protection law: can biometric processing be justified when simpler alternatives exist? This article examines the legal framework governing biometric attendance systems under the GDPR, Portuguese law, and the EU AI Act, and argues that the principle of necessity (not technological capability) must remain the decisive test.

Biometric Attendance Control and the Limits of Necessity under Portuguese Law
Context
In June 2026, the Health Service of the Autonomous Region of Madeira (“SESARAM”) announced a mandatory attendance monitoring system combining facial recognition with staff ID cards, starting from July.
The measure was challenged by a regional political party, which filed complaints before the Portuguese Ombudsman and the Portuguese National Data Protection Supervisory Authority (“CNPD”), and, in August 2026, by a doctors' union, which argued before the CNPD that less intrusive alternatives had not been considered. SESARAM has stated that the system relies on biometric templates rather than stored facial images, and that its Data Protection Officer issued a favourable, albeit conditional, opinion.
Critics also invoked the cyberattack SESARAM suffered in August 2023, although SESARAM has maintained that no clinical information was lost. The argument nonetheless makes a legal point: where special categories of personal data are involved, the security of processing (Article 32 of the GDPR) is part of the proportionality assessment.
Why it matters beyond Madeira
Facial recognition promises efficiency: cards may be forgotten or lent, passwords misplaced and signatures forged, but a face remains permanently attached to its owner.
That is also what makes it legally problematic. Biometric characteristics are intrinsically connected to a person’s physical identity and, once compromised, cannot be replaced like a password. Biometric infrastructures also tend to outgrow their original purpose, which is why the GDPR places particular emphasis on purpose limitation and data minimisation.
The legal framework
Biometric data are a special category of personal data when processed to uniquely identify a natural person (Articles 4(14) and 9(1) of the GDPR). In the employment context, the processing of employees’ biometric data is considered lawful only for the purposes of monitoring attendance and controlling access to the employer’s premises (Article 28(6) of Law 58/2019, read with Articles 9(2)(b) and 88 of the GDPR). Consent is not a realistic alternative, as it will rarely be freely given in an employment relationship (Recital 43 of the GDPR).
The same provision requires that only templates are used and that the collection process does not allow the data to be reversed, which controllers should be able to demonstrate, typically through a declaration from the system manufacturer.
A prior Data Protection Impact Assessment is also mandatory: the CNPD’s list of processing operations subject to a DPIA (Regulation 1/2018) expressly covers biometric data used to identify vulnerable data subjects, such as employees.
Labour law adds a further layer. Article 18 of the Portuguese Labour Code, which also applies to public-sector employees, allows biometric processing only where necessary, adequate and proportionate, requires the data to be destroyed when the employee is transferred or the contract ends, and provides for a prior, non-binding opinion of the workers’ committee.
Under the EU AI Act, a 1:1 card-plus-face verification falls outside the high-risk category, but inferring employees' emotions has been prohibited since February 2025 (Article 5(1)(f)): some extensions of an attendance system would meet an outright ban.
Is the face necessary when there is already a card?
Data minimisation (Article 5(1)(c) of the GDPR) requires controllers to show not merely that processing is useful, but that it is necessary. Where less intrusive identification measures remain available and operationally effective, the collection of biometric data becomes considerably more difficult to justify.
The strongest argument for adding facial recognition to an ID card is fraud prevention, since cards can be lent. That argument must be backed by evidence that the problem exists and that alternatives such as PIN codes or supervision are insufficient. Design also matters: in its Opinion 11/2024, the EDPB favoured solutions in which the biometric template remains under the individual's control, such as on the employee's own card, rather than in a central database.
Lessons learned
Conclusion
European data protection law does not ask whether biometric processing is possible, but whether it is necessary. As the SESARAM case shows, compliance depends less on how effectively an organisation can recognise a face than on how convincingly it can explain why a card was not enough.
Article provided by INPLP member: Ricardo Henriques (Abreu Advogados, Portugal)
