
Biometric Access at Work in Monaco
Monaco's APDP published new guidance on fingerprint and facial access control at work. What is allowed, what is banned, and what paperwork you need.
A fingerprint reader on an office door is a common enough sight in Monaco. A file explaining why it is there is not. In March 2026 the APDP — Monaco's Autorité de Protection des Données Personnelles — published a guidance sheet on biometric access control to professional premises, and it is unusually specific about what is permitted, what is banned outright, and what documentation must exist before the first finger touches a sensor.
If your business uses fingerprints, facial recognition, hand geometry or voice to decide who gets through a door, this is the text your setup will be measured against. The short version: biometrics at the door can be lawful, biometrics on the time clock cannot, and almost everyone is missing the paperwork.
Two permitted purposes, and no others
Under Article 7 of Law No. 1.565 of 3 December 2024, an employer may only process biometric data where strictly necessary to control access to workplaces and to the devices and applications employees use in their duties. The APDP narrows that further, admitting such systems for exactly two security purposes: controlling access to premises the employer has specifically identified as requiring restricted circulation, and where relevant, gathering evidence in the event of an offence.
The guidance calls these two purposes exhaustive. Anything else — monitoring attendance, managing working hours, disciplinary oversight — is strictly prohibited. That single sentence invalidates much of the hardware sold as all-in-one "access and attendance" kit. The device may support both functions. You may use only one.
Time-tracking still works — just not with bodies
None of this means you cannot know when people arrive. The APDP's separate guidance on workplace monitoring treats badge systems as an ordinary, acceptable way to manage entry, exit, zone access and presence hours, with timestamps generally kept no longer than three months absent a documented sector-specific justification.
So the fix is not to abandon attendance tracking but to decouple it: badges or codes for the hours, biometrics — if justified at all — reserved for the two or three doors that genuinely need restricted circulation. If your attendance process is painful enough that biometrics looked like the easy answer, the better route is automation around a badge or app check-in, not a more intrusive sensor.
The necessity test most systems fail
Before any technical detail, the APDP asks a blunt question: is biometrics necessary and proportionate here? If a badge, PIN or smart card secures the premises adequately, or the premises are not particularly sensitive, biometrics may simply not be justifiable. A server room, a vault, a room holding client files in a private-wealth practice — arguable. The main entrance to a five-person office — much harder to defend.
Consent is a weaker escape route than it looks. The APDP applies it strictly in employment, since the subordination inherent in a work contract compromises free consent, and it only works where a non-biometric alternative is offered with no consequence for anyone who declines. Most employers will lean on legitimate interest instead, and will need the balancing exercise documented.
Where the template is stored decides everything
A biometric template is a mathematical, non-reversible representation of a characteristic, not a stored image of the fingerprint. The APDP permits two storage architectures and states a clear preference:
- Type 1 — individual support (preferred). The template lives only on a badge or smart card held by the employee; nothing is stored centrally, and the reader compares the finger against the template on the card.
- Type 2 — encrypted central database (exceptional). Templates sit encrypted on the employer's server behind two-factor authentication: a personal secret code plus the biometric, with no data retained on the reader.
Unless you can document genuinely exceptional circumstances — premises of extreme sensitivity — Type 1 must be used, and Type 2 is a last resort. This is a purchasing decision too: many mid-market access-control products are centralised by default, so the architecture question belongs in the tender, not the audit afterwards.
Retention follows the same logic. Templates and associated identity data are kept for the duration of the person's authorisation and deleted immediately on expiry — departures must trigger deletion, not deactivation.
The impact assessment is not optional
Under Ministerial Order No. 2025-361 of 14 July 2025, implementing Article 35 of Law No. 1.565, any biometric system is deemed likely to present a high risk to rights and freedoms — sensitive data, and employees as a structurally vulnerable group. A data protection impact assessment must therefore be carried out before deployment, documenting why biometrics was chosen over a less intrusive technology.
Systems already running when the law took effect are not exempt: Article 109 gives a three-year transitional window to complete that assessment as part of a risk reassessment. If you inherited a fingerprint reader from a previous fit-out and nobody ever wrote down why it exists, that is the gap to close.
Tell people first, in writing
Article 10 requires the system to be brought to the attention of everyone affected — employees, visitors, contractors — in writing and before biometric enrolment, not after. The notice covers the controller's identity, purposes and legal basis, data categories, retention, recipients, how to exercise data rights, and the right to complain to the APDP.
Then check your maintenance provider. The APDP is explicit that a contractor servicing the system carries the same security and confidentiality obligations you do, with access limited to what the contract strictly requires. If no written arrangement covers the installer who can remote into your reader, that is live exposure.
A realistic 90-day plan
Inventory every biometric touchpoint — doors, laptops, applications — and write down each purpose, confirming it falls inside the two permitted ones. Kill any attendance or disciplinary use immediately. Establish whether storage is Type 1 or Type 2, then justify or migrate. Draft the impact assessment, issue the written notice, tighten the vendor contract. Where the review points to new hardware, the Fonds Bleu can subsidise a substantial share of eligible digital projects.
A caveat: Monaco is not an EU member state, so the GDPR does not apply to a Monaco business by default. Law 1.565 follows comparable standards but is its own instrument, and the above reflects APDP guidance as published. Since administrative fines under this law reach into the millions, confirm anything material with the APDP or a qualified Monaco adviser before acting.
To map where personal data actually flows through your systems, our work on data protection compliance and broader digital strategy starts from exactly that inventory. Get in touch.
Related services