pepteam

Guide

KVKK and time tracking

Attendance tracking processes personal data: clock-in/out times, often location, and in some systems biometric data. That is why which data is collected, and how, matters under Türkiye's Personal Data Protection Law No. 6698 (KVKK). This guide outlines the essentials; it is not a binding legal opinion.

This page is informational and does not constitute legal advice. For your own situation, consult a legal advisor or data-protection specialist.

Why is biometric data sensitive?

Biometric data such as fingerprints and face recognition is listed as "special-category personal data" under Article 6 of KVKK. Processing data in this category is subject to stricter conditions and heavier obligations than ordinary personal data. Using biometrics for a routine purpose like attendance places that heavy framework on the employer.

This does not mean biometrics can never be used; it can, but the conditions are demanding. The point is that if the same result is achievable without biometrics, the data-minimisation principle favours that path.

Three principles at the core

Purpose limitation

Data is collected only for a defined purpose. The purpose of attendance tracking is to record working time; collecting data beyond that purpose should be avoided.

Data minimisation

No more than necessary is collected. If biometrics are not required to record clock-ins, not collecting them is what this principle asks for.

Transparency and notice

The employee should know which of their data is processed and for what purpose. The notice obligation applies regardless of how the data is collected.

Location tracking or verification?

Location data can be used in two very different ways. All-day continuous tracking follows an employee's movements and is heavy on privacy. A match check only at the moment of clock-in against a defined site is an instantaneous verification: location is read at that moment, and what is kept is the "matched/not matched" result, not a continuous trail. The difference matters under KVKK too.

How Pepteam fits this framework

Pepteam collects no biometric data: clock-ins work via QR code and location verification, with no fingerprints or face recognition. Location is checked only at the moment of record, for a match against the defined site; there is no all-day tracking. Employees join with an eight-character invite code — a corporate email is not even required — so the data collected stays limited to what the job needs. This is an approach aligned with the data-minimisation principle above.

See the Security & KVKK page

Official sources

Related guides

KVKK & time-tracking FAQ

Is biometric data (fingerprint/face) required for attendance?
No. Clock-ins can be recorded with non-biometric methods such as QR codes and location verification. Biometrics are special-category data under KVKK and their use is subject to heavier conditions.
Is using location against KVKK?
It depends on how location is used. All-day continuous tracking and a match check only at the moment of record are very different; the latter is closer to data minimisation. For a definitive assessment, consult your legal advisor.
Is the employee's explicit consent always required?
That is a legal assessment that varies with the type of data and the processing basis; it cannot be answered with a blanket yes/no. Consult a data-protection specialist for your own setup.
Must I prepare a privacy notice?
The notice obligation applies to data controllers processing personal data; for its scope and form, obtaining legal support is advisable.
Does using Pepteam exempt me from KVKK obligations?
No. Pepteam is a tool that collects no biometrics and works with minimal data, but KVKK obligations belong to the employer as data controller. The tool can ease compliance; it does not assume legal responsibility.

This page is informational and does not constitute legal advice. For your own situation, consult a legal advisor or data-protection specialist.