Law / France

CNIL Standard Regulation on Workplace Biometric Access Control (Deliberation No. 2019-001)

CNIL Deliberation n. 2019-001 du 10 janvier 2019 portant reglement type relatif a la mise en oeuvre de dispositifs de controle d'acces… biometrique

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 10 January 2019.

A biometric privacy rule binding public and private bodies.

As of 24 August 2026.

What it requires

  • Run a data protection impact assessment and document why a less intrusive alternative was rejected before deploying a biometric access-control system for employees or building access in France.
  • Do not rely on employee consent alone as the legal basis for a workplace biometric system; use a legal-obligation or legitimate-interest basis, or pair consent with a genuinely equivalent non-biometric alternative.

Who checks it

Audit expectation

periodic

Who audits it

Self

Where the report goes

Produced on request

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

CNIL's binding standard regulation for workplace biometric access control (English: Standard Regulation on the Implementation of Biometric Access-Control Devices) replaces the prior authorization regime with an accountability model: the controller must justify necessity and proportionality, run a data protection impact assessment before deployment, and document why a less intrusive alternative was rejected.

A companion CNIL page states the standard regulation's definition of biometrics names fingerprints, iris, facial recognition, gait, and voice as covered modalities, though CNIL's own worked operational guidance emphasizes the physical modalities and carries no voice-specific worked example.

CNIL guidance states that employee consent alone is not a valid legal basis for a workplace biometric system, since workplace hierarchy undermines the General Data Protection Regulation (GDPR)'s freely-given requirement; the employer must rely on a legal obligation or legitimate-interest basis instead, or offer a genuinely equivalent non-biometric alternative where consent is used.

When LexLint raises it

  • processes_biometrics
  • processes_voice

Read the law

CNIL, Deliberation n. 2019-001 du 10 janvier 2019 (PDF)
CNIL, "Le controle d'acces biometrique sur les lieux de travail" and "Question-reponses sur le reglement type biometrie"

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app