Face recognition

Face recognition and data protection: what institutions should know

One of the first questions a school, tutoring centre or workplace asks before installing a face recognition check-in system is about data protection. It is a fair question: data derived from a face image is among the most sensitive types of data under the law. This article summarises the basic points to know before an installation in Türkiye.

Note: This article is for general information and is not legal advice. We recommend consulting a lawyer for an assessment specific to your institution.

Biometric data is special category personal data

Turkey's Personal Data Protection Law No. 6698 (KVKK) lists biometric data as "special category personal data". Processing this type of data is subject to stricter conditions than ordinary personal data. One of the conditions set out in the law must be met, in most cases the explicit consent of the person concerned. Where students are involved, this consent is usually obtained from the parent.

People must be informed

The person whose data will be processed must be told clearly which data will be processed, for what purpose, for how long, and what their rights are. A short, clear information notice for parents gets the installation off to the right start.

Offering an alternative is good practice

For consent to be genuinely free, it is good practice to offer students or staff who do not want to use face recognition another option, such as manual attendance. We also recommend reviewing the Personal Data Protection Authority's guidance on biometric data.

Where is the data kept, and by whom?

On the technical side, this is the most important question. In the BE Soft Face Recognition System:

  • Each institution runs in a separate, isolated installation; no institution can see another's records.
  • Face recognition runs inside the installation itself; images are not sent to a third-party face recognition service.
  • Panel access depends on permissions; attendance, SMS and system settings are unlocked with separate roles.
  • Traffic is encrypted with HTTPS and data is backed up regularly.

The institution itself is the data controller for student, staff and parent data in the system. BE Soft processes this data on the institution's behalf and on its instructions.

Do not collect more than you need

Collect only the information needed for attendance and parent notifications, and delete the records of students who leave after a period you define. This fits the law's principle of proportionality and lowers the risk if something goes wrong.

A short checklist

  • Have parents received an information notice?
  • Has explicit consent been obtained and stored?
  • Is there an alternative for those who do not want face recognition?
  • Is it clear who can access the panel, and with which permissions?
  • Has it been decided when the data of students who leave will be deleted?

We can also help with the information notice and the process during installation. Feel free to write to us with any questions.

← All articles
Try it at your institution for a week.Let us set it up and see it with your own students.
Request a demo

Get in
touch.

A face recognition demo, an app or a website. Tell us what you need and we will tell you how we would build it, how long it takes and what it costs, the same day.

Tell us about your project

Your details are not stored on our site; you send the message yourself on WhatsApp.