Law note · Spain
GDPR Article 9 and AEPD Biometric Guidance, Special Categories
LOPDGDD Article 9 supplies no independent biometric definition; it operates entirely within General Data Protection Regulation (GDPR) Article 9's special-category frame.
The AEPD's November 2023 guide on biometric presence-control systems, read directly (and itself marked "en revision", under review, so treated as the AEPD's current stated position rather than a settled rule), concludes that current Spanish law contains no sufficiently specific statutory authorization for biometric employee time-and-attendance processing, applying the Tribunal Constitucional's STC 76/2019 reserva-de-ley standard.
The AEPD fined Mercadona EUR 2,520,000 (Resolucion PS/00120/2021) for a facial-recognition system matching shoppers against people with criminal convictions or restraining orders, holding the processing categorically prohibited under Article 9.1 with no Article 9.2 exception available.
What it asks of an app
- Do not deploy a biometric employee time-and-attendance system in Spain on the Estatuto de los Trabajadores alone; the AEPD's own guidance holds that statute does not itself authorize biometric means, and a genuine General Data Protection Regulation (GDPR) Article 9(2) basis is needed.
- Do not run a facial-recognition matching system against members of the public without a valid Article 9.2 exception; the AEPD categorically prohibited exactly that in its Mercadona enforcement and fined it EUR 2,520,000.
When LexLint raises it
Declared activities: processes_biometrics, processes_voice, high_risk_decisions
Primary source: AEPD, "Guia sobre tratamientos de control de presencia mediante sistemas biometricos" (Nov. 2023, direct read)
AEPD Resolucion PS/00120/2021 (direct read)