Law note · France
CNIL Standard Regulation on Workplace Biometric Access Control (Deliberation No. 2019-001)
CNIL's binding standard regulation for workplace biometric access control (English: Standard Regulation on the Implementation of Biometric Access-Control Devices) replaces the prior authorization regime with an accountability model: the controller must justify necessity and proportionality, run a data protection impact assessment before deployment, and document why a less intrusive alternative was rejected.
A companion CNIL page states the standard regulation's definition of biometrics names fingerprints, iris, facial recognition, gait, and voice as covered modalities, though CNIL's own worked operational guidance emphasizes the physical modalities and carries no voice-specific worked example.
CNIL guidance states that employee consent alone is not a valid legal basis for a workplace biometric system, since workplace hierarchy undermines the General Data Protection Regulation (GDPR)'s freely-given requirement; the employer must rely on a legal obligation or legitimate-interest basis instead, or offer a genuinely equivalent non-biometric alternative where consent is used.
What it asks of an app
- Run a data protection impact assessment and document why a less intrusive alternative was rejected before deploying a biometric access-control system for employees or building access in France.
- Do not rely on employee consent alone as the legal basis for a workplace biometric system; use a legal-obligation or legitimate-interest basis, or pair consent with a genuinely equivalent non-biometric alternative.
When LexLint raises it
Declared activities: processes_biometrics, processes_voice
Primary source: CNIL, Deliberation n. 2019-001 du 10 janvier 2019 (PDF, direct fetch)
CNIL, "Le controle d'acces biometrique sur les lieux de travail" and "Question-reponses sur le reglement type biometrie" (direct fetch)