What the decision says
With principle decision 2026/921 dated 29 April 2026, the Turkish data protection board banned the processing of biometric data for access and working-time tracking. The ban does not depend on the method: fingerprint, vein pattern, palm geometry and face recognition all fall inside it.
The decision is not advice; processing that falls inside its scope is unlawful. The institution itself answers for it, because the school is the data controller — not the company that installed the turnstile.
Why explicit consent does not help
Explicit consent cannot make a prohibited processing activity lawful. On top of that, consent between a school and its students or parents is not freely given: when passing the gate is compulsory, the price of saying “no” is being unable to enter the school.
Encryption and hashing are not a defence either. A hash maps the same finger to the same value every time; it is a record that recognises a person, and it does not stop being biometric data.
What a school with a fingerprint turnstile should do
- Move identification to a card, a tag or an identifier the institution issues itself; the turnstile, the panel and the reader can stay where they are.
- Destroy the biometric templates and record the destruction; deactivating a record is not destroying it.
- Update your privacy notice and any consent records you hold.
- Set the retention and destruction period for access records yourself, as the institution.
The signal at the gate is enough without biometrics
A turnstile that reads a card or a tag answers two questions: who passed and when. The live presence list, occupancy, the pre-filled attendance draft, parent notifications and the emergency roster are all built from those two facts; none of them needs a fingerprint.
TurniGate does not process biometric data in any version, and does not offer it as a setting either.