CNIL Standard Regulation on Workplace Biometric Access Control (Deliberation No. 2019-001)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 10 January 2019.
A biometric privacy rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Run a data protection impact assessment and document why a less intrusive alternative was rejected before deploying a biometric access-control system for employees or building access in France.
- Do not rely on employee consent alone as the legal basis for a workplace biometric system; use a legal-obligation or legitimate-interest basis, or pair consent with a genuinely equivalent non-biometric alternative.
Who checks it
Audit expectation
periodic
Who audits it
Self
Where the report goes
Produced on request
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
CNIL's binding standard regulation for workplace biometric access control (English: Standard Regulation on the Implementation of Biometric Access-Control Devices) replaces the prior authorization regime with an accountability model: the controller must justify necessity and proportionality, run a data protection impact assessment before deployment, and document why a less intrusive alternative was rejected.
A companion CNIL page states the standard regulation's definition of biometrics names fingerprints, iris, facial recognition, gait, and voice as covered modalities, though CNIL's own worked operational guidance emphasizes the physical modalities and carries no voice-specific worked example.
CNIL guidance states that employee consent alone is not a valid legal basis for a workplace biometric system, since workplace hierarchy undermines the General Data Protection Regulation (GDPR)'s freely-given requirement; the employer must rely on a legal obligation or legitimate-interest basis instead, or offer a genuinely equivalent non-biometric alternative where consent is used.
When LexLint raises it
processes_biometricsprocesses_voice
Read the law
CNIL, Deliberation n. 2019-001 du 10 janvier 2019 (PDF)
CNIL, "Le controle d'acces biometrique sur les lieux de travail" and "Question-reponses sur le reglement type biometrie"
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.