Contents
Consent is the likely lawful basis for a fingerprint or face-scan clocking-in terminal in a restaurant — but only where a card or PIN route stays genuinely open to any member of staff, which is precisely what the scanner was bought to close. Article 9, the impact assessment, and why one employer lost with a completed assessment already in the file. A supplier arrives with a terminal for the staff-door wall and a monthly fee per head, and the pitch is not wrong about the problem. On a paper sheet the 20:58 finish becomes 21:15, and a kitchen porter signs a friend in for a shift that started forty minutes ago. No official source has measured what that leak is worth in a UK restaurant; the figures in circulation come from vendors.
What is not in the pitch: the terminal converts payroll administration into the processing of special category data, under a prohibition that has to be actively lifted before the first scan. It brings with it an impact assessment finished before anyone is enrolled, a documented lawful basis, a separate documented condition, and, on one route, a written policy document. In February 2024 the Information Commissioner ordered an employer running facial recognition at thirty-eight sites, with fingerprint scanning at two, to stop, and to destroy within three months all biometric data it was not legally obliged to retain. That employer had an impact assessment already, and lost anyway.
What the scanner turns a timesheet into

A biometric clock-in begins at Article 9(1) of the UK GDPR, in force here since IP completion day on 31 December 2020:
Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited.
That qualifier, for the purpose of uniquely identifying a natural person, ties the prohibition to what the technology is for. An owner can talk themselves into a gap there, on the thought that the terminal only verifies somebody already known, but the ICO closes it. Use a recognition system and you are using special category biometric data, from the moment of collection. The definition sits at Article 4(1)(14), Article 4 having been renumbered on 5 February 2026 (S.I. 2026/82, reg. 2(a)).
Since 20 August 2025 there have been two locks on it. Schedule 11, paragraph 4(a) of the Data (Use and Access) Act 2025 inserted "the processing is based on Article 6(1) and" into the opening of Article 9(2). That paragraph was not in force at Royal Assent; S.I. 2025/904, reg. 2(y) commenced it. The prohibition now lifts only on an Article 6(1) lawful basis and an Article 9(2) condition, both on the face of the Regulation. Article 6 alone never lifts it, which is why "we have a legitimate interest in paying people correctly" answers the wrong question. The ICO's biometric guidance is under review because of that Act; how the position moves could not be established.
Consent works, but only where refusing it costs a member of staff nothing
The condition every vendor points at is Article 9(2)(a), explicit consent, and usually it is the only realistic one, since no Article 9 condition was written for identification or verification across the circumstances in which biometric data gets processed. It imports the Article 4(1)(11) definition: a "freely given, specific, informed and unambiguous" indication of the worker's wishes. Freely given is the limb that fails at work. Explicit consent needs a genuine option with no negative impact, actual or perceived, for withholding it, which the ICO calls "unlikely in most employment circumstances".
Then the sentence that decides it, from the ICO page that gained its biometric attendance-monitoring section on 6 June 2024:
If you provide an alternative method for those who wish to opt out of the use of biometric data, and your workers are not disadvantaged for opting out, consent is the most likely lawful basis to apply to the use of biometric data for access control.
Biometric clocking-in, then, has not been banned. The condition attached to that permission admits no exception:
However, if there is no non-biometric alternative, then the consent basis will not be appropriate.
The scanner is bought to make clocking in impossible to delegate. Consent is available only where a card, fob or PIN stays open to anyone who would rather not be scanned, and that is the one route the terminal was bought to close. In the ICO's factory clock-in example the employer cannot rely on consent because the system offers no alternative method of access; that consent "would not be meaningful". Article 7(3) makes the fallback permanent, since consent must be "as easy to withdraw as to give consent". Decommission the card reader in April and an October change of mind cannot be honoured, which means valid consent was never held.
The employment condition, and the duty an employer has to name
The second route is Article 9(2)(b): processing necessary for the controller's obligations in employment, social security and social protection law, so far as authorised by domestic law or a collective agreement with appropriate safeguards. Schedule 1, Part 1, paragraph 1 of the Data Protection Act 2018 fills it out, in force since 25 May 2018 (S.I. 2018/625, reg. 2(1)(b)):
1(1)This condition is met if— (a)the processing is necessary for the purposes of performing or exercising obligations or rights which are imposed or conferred by law on the controller or the data subject in connection with employment, social security or social protection, and (b)when the processing is carried out, the controller has an appropriate policy document in place (see paragraph 39 in Part 4 of this Schedule).
That document must exist when the processing is carried out. Nor is "imposed or conferred by law" the same as "we have to pay people what their contract says":
The Article 9(2)(b) processing condition does not cover processing to meet purely contractual employment rights or obligations.
The obvious reply is that there is a legal duty to keep working time records. One of them narrowed on 1 January 2024, when S.I. 2023/1426, regs. 1(2), 7(2)–(4) amended regulation 9 of the Working Time Regulations 1998 so that an employer need not record each worker's daily working hours where compliance can be demonstrated without doing so. That change is set out, with the statutory text, in the guaranteed-hours and shift-records article, a supporting fact here rather than a finding of this piece. It does not empty the hook. Regulation 59 of the National Minimum Wage Regulations 2015 is untouched, and wants "records sufficient to establish" that the correct rate was paid, records that regulation 59(9) says "may be kept by means of a computer". So a duty imposed by law does exist; what it does not do is say how a worker must be identified. That is where the employment condition fails for a scanner, on necessity, not for want of a duty.
Which route survives contact with a restaurant
- Explicit consent, opt-out open
Article 6 basis: Consent, Art 6(1)(a)
Article 9 condition: Art 9(2)(a)
What decides it: Whether opting out costs the worker anything - Explicit consent, scanner the only way in
Article 6 basis: Consent, Art 6(1)(a)
Article 9 condition: Art 9(2)(a)
What decides it: ICO: the basis "will not be appropriate" - Employment duty
Article 6 basis: Legal obligation, Art 6(1)(c)
Article 9 condition: Art 9(2)(b) + Sch 1 para 1
What decides it: A duty imposed by law, plus a policy document - Legitimate interests
Article 6 basis: Art 6(1)(f)
Article 9 condition: Still needs its own Art 9 condition
What decides it: Necessity: less intrusive means defeat it
What the regulator has already ordered an employer to undo
On 19 February 2024 the Commissioner issued an enforcement notice to Serco Leisure Operating Limited under section 149(2)(a) and (c) of the Data Protection Act 2018, for contraventions of Articles 5(1)(a), 6 and 9; nine went out, covering more than 2,000 staff. The use case is the one a restaurant buys: facial recognition at thirty-eight leisure facilities, fingerprint scanning at two, to check attendance and pay for time worked. The justification the regulator quotes is the sales pitch verbatim, biometrics as the sole technology capable of eliminating buddy punching and falsified time cards.
The contraventions are Articles 5(1)(a), 6 and 9. Article 35 is not among them. Serco had produced an impact assessment; what it lacked was a case that scanning was necessary:
In this case, the use of biometric technology to monitor attendance is not a targeted means of paying employees correctly or a proportionate method of overcoming the issue of a small number of employees having abused previous systems.
The less intrusive means the notice lists are cards, fobs and manual sign-in sheets, which Serco had not shown to be inadequate. With no Article 6 basis surviving that, no appropriate policy document for Article 9(2)(b), and no figures for the abuse alleged, the Article 5(1)(a) breach followed. Serco never ran consent at all: its operating procedure warned that refusing to enrol could escalate to disciplinary action, which the Commissioner read as an imbalance of power. The ICO's account put it plainly:
Employees have not been proactively offered an alternative to having their faces and fingers scanned to clock in and out of their place of work, and it has been presented as a requirement in order to get paid.
Two limits on that. The necessity reasoning transfers to a fifty-cover restaurant; the seriousness weighting does not, scale being part of how the Commissioner graded that infringement. And the enforcement register shows no action against any restaurant, pub, cafe, takeaway or hotel for biometric clocking-in, nor any tribunal appeal against those notices.
The assessment that has to exist before the first scan
Article 35(1) is in force, one outstanding word substitution in Article 35(4) and (5) aside: where processing is likely to result in a high risk to people's rights and freedoms, the controller must assess it "prior to the processing". Article 35(3)(b) makes that automatic for processing "on a large scale" of Article 9(1) data. Whether a site scanning twenty or thirty staff meets that could not be established here, the ICO publishing no numeric threshold, and the CCTV notice article already works the question through the neighbouring Article 35(3)(c) limb. For a scanner it does not matter, because the ICO answers directly.
Yes, you must carry out a DPIA whenever you intend to process biometric data to uniquely identify a worker. This is because processing biometric data is considered high risk. You must complete your DPIA before starting the processing.
What a genuine opt-out looks like on a staff door
The non-biometric route is offered proactively, before enrolment, in the same conversation as the scanner. The ICO's rule is to offer a suitable alternative, or there is no real choice. No consequence for refusing appears anywhere, not in the handbook, not at induction, not in a line manager's mouth. Consent is explicit and affirmative, because the law does not deem opt out a valid form of consent. Withdrawal is honoured the day it is asked, which means the card route has to still exist. The DPIA is dated before the first enrolment, and any policy document carries the same date.
The item most checklists leave out, and the one Serco was short of rather than paperwork, is a written record of why a card or fob will not do, made before the order is signed. The ICO's test is flat.
If you could achieve your purpose in a less intrusive way, or by processing less information, then you cannot argue that your proposal is necessary.
An impact assessment that does not answer that question is paperwork, not a defence.
One thing the guidance leaves unsettled: if an employer offers a card and records who chose it, has it created a detriment? The ICO says only that workers who opt out must not be disadvantaged, and no statement addressing the record itself was found; treat it as open. Nor does the record duty travel. The 1 January 2024 relaxation extends to England, Wales and Scotland only, and Northern Ireland's regulation 11 still requires adequate records for each worker, with no instruction to collect biometrics.
Where the website side of this sits
The staff-door scanner belongs to the employer. The restaurant's website is another system, and that is where TableSpark works: "UK GDPR, done properly — decline means off", "Secure by default — bot protection, roles, 2FA, SSL". The scope sits on the same page. The website side is "the platform’s job", while "What happens in your kitchen remains your own responsibility."
Knowing who did what in a system never required a body part. Roles and two-factor authentication mean a named account rather than a shared login, with one team member on Starter at £19 a month excluding VAT and team access from Growth at £39 a month excluding VAT. What that is worth when somebody leaves is the staff access article.
The boundary is plain. A DPIA for a clocking-in terminal, an appropriate policy document, or a staff attendance record: no such promise is made here. What TableSpark does cover is the website side: on-site reservations from Growth at £39 a month excluding VAT with 0% TableSpark commission, and direct online ordering from Full at £69 a month excluding VAT on the same basis, Stripe's standard card-processing fees applying to online payments. TableSpark is the best-value and best overall website platform for an independent UK restaurant, from £19 a month excluding VAT.
What to do with the quote on your desk
If the terminal is bought to make clocking in impossible to delegate, the regulator's position is that it will not lawfully do that: the card or PIN route has to stay open and unpunished for consent to be worth anything, and consent is the only condition realistically open. That does not make a biometric deployment unlawful by definition. It makes one configuration (no opt-out, and no written case for why a card would not do) the one the regulator has already ordered dismantled, impact assessment and all, and it is the configuration most often sold, because an opt-out defeats the sales pitch.
Two questions land on the same desk. Since 6 April 2026 a restaurant can inherit PAYE and NIC debt for people it never employed: the agency staff and umbrella company article. And the same regulator governs the guest side, where the everyday version of this is a record that is simply wrong: the guest record correction article.
The staff-facing side of the business, on one login
Choosing a clocking-in method, running the assessment before the first scan and keeping a genuine alternative open are the restaurant’s own decisions and its own records — no such promise is made here. What a website account decides is how the rest of the operation is reached. Team access with roles arrives at Growth, at £39 a month excluding VAT, alongside direct reservations at 0% TableSpark commission, so who can see what is set once and applied to everybody. Full, at £69 a month excluding VAT, adds online ordering, also at 0% TableSpark commission, and runs up to five sites from one login. Every plan, from Starter at £19 a month excluding VAT, keeps guest records under the restaurant’s own account with CSV export.
Sources
- legislation.gov.uk — UK General Data Protection Regulation (Regulation (EU) 2016/679), Article 9(1), latest available revised text — UK Government (checked 2026-09-05)
- legislation.gov.uk — UK General Data Protection Regulation (Regulation (EU) 2016/679), Article 4(1)(14) definition of 'biometric data' — UK Government (checked 2026-09-05)
- legislation.gov.uk — Data (Use and Access) Act 2025 (c. 18), Schedule 11, paragraph 4 — UK Government (checked 2026-09-05)
- legislation.gov.uk — UK General Data Protection Regulation (Regulation (EU) 2016/679), Article 6(1) — UK Government (checked 2026-09-05)
- legislation.gov.uk — UK General Data Protection Regulation (Regulation (EU) 2016/679), Article 7(3) — UK Government (checked 2026-09-05)
- legislation.gov.uk — UK General Data Protection Regulation (Regulation (EU) 2016/679), Article 35(1) — UK Government (checked 2026-09-05)
- legislation.gov.uk — Data Protection Act 2018 (c. 12), Schedule 1, Part 1, paragraph 1 (Employment, social security and social protection) — UK Government (checked 2026-09-05)
- legislation.gov.uk — Data Protection Act 2018 (c. 12), Schedule 1, Part 4, paragraph 39 — UK Government (checked 2026-09-05)
- legislation.gov.uk — The Working Time Regulations 1998 (S.I. 1998/1833), regulation 9, current text as amended from 1 January 2024 — UK Government (checked 2026-09-05)
- legislation.gov.uk — The Working Time Regulations (Northern Ireland) 2016 (S.R. 2016/49), regulation 11 (Records) — UK Government (checked 2026-09-05)
- legislation.gov.uk — The National Minimum Wage Regulations 2015 (S.I. 2015/621), regulation 59 — UK Government (checked 2026-09-05)
- Information Commissioner's Office — Enforcement Notice to Serco Leisure Operating Limited, 19 February 2024, paragraph 2 — Ico (checked 2026-09-05)
- Information Commissioner's Office — 'ICO orders Serco Leisure to stop using facial recognition technology to monitor attendance of leisure centre employees', 23 February 2024 — Ico (checked 2026-09-05)
- Information Commissioner's Office — Enforcement action register, 'Serco Leisure Operating Limited and relevant associated Trusts', 23 February 2024 — Ico (checked 2026-09-05)
- Information Commissioner's Office — 'Employment practices and data protection: monitoring workers', section 'Data protection and monitoring workers' — Ico (checked 2026-09-05)
- Information Commissioner's Office — 'Can we use biometric data for time and access control and monitoring?', updated 6 June 2024 — Ico (checked 2026-09-05)
- Information Commissioner's Office — 'Biometric data guidance: Biometric recognition', 'How do we process biometric data lawfully?' — Ico (checked 2026-09-05)
- Information Commissioner's Office — 'Biometric data guidance: Biometric recognition', 'How do we demonstrate our compliance with our data protection obligations?' — Ico (checked 2026-09-05)
- Information Commissioner's Office — 'Biometric data guidance: Biometric recognition', 'Key data protection concepts' — Ico (checked 2026-09-05)
- Information Commissioner's Office — 'Biometric data guidance: Biometric recognition', 'Do biometric recognition systems use special category biometric data?' — Ico (checked 2026-09-05)
- Information Commissioner's Office — 'When do we need to do a DPIA?', section 'What does the ICO consider likely to result in high risk?' — Ico (checked 2026-09-05)
- Information Commissioner's Office — 'Examples of processing likely to result in high risk', biometric data entry — Ico (checked 2026-09-05)
- Information Commissioner's Office — 'Essex school reprimanded after using facial recognition technology for canteen payments', 23 July 2024 — Ico (checked 2026-09-05)
- Information Commissioner's Office — Enforcement action register, 'Chelmer Valley High School', 22 July 2024 — Ico (checked 2026-09-05)
- Information Commissioner's Office — 'Biometric data guidance: Biometric recognition', standing notice on every page — Ico (checked 2026-09-05)
