Illizeo — Header EN (preview mega-menus)
Clocking — Methods and legal framework

Biometrics, badge or QR code: what can you deploy?

The terminals recognise six methods. The choice is not primarily technical: three of them are biometric data, and their use in the workplace is regulated. Here is what you need to decide before ordering hardware.

The six methods

What each one does, what it requires, and where it fails.

Biometric data

Fingerprint

The reader compares a template computed from the finger. Fast, inexpensive, but useless with gloves and degraded on damaged or very dry hands.

Biometric data

Facial recognition

The module combines visible light and infrared, which makes it usable in variable lighting. It is also the most legally exposed method.

Biometric data

Palm recognition

Reads the vein network or palm lines, without contact. Tolerates dirty or wet hands, where fingerprint fails.

Non-biometric data

RFID badge

125 kHz proximity. The access-control standard: cheap, replaceable when lost, but easily lent from one employee to another.

Non-biometric data

NFC badge

Same principle as RFID, on a more recent frequency. Lets a phone act as a badge where the device fleet allows it.

Non-biometric data

QR code

The employee presents a code shown on their phone. Nothing to hand out, no sensitive data, but it depends on the employee’s phone.

What the legal framework says

In Switzerland as in the European Union, the dividing line runs not between technologies but between categories of data.

Three of the six methods are sensitive data

Fingerprint, face and palm are biometric data under the GDPR and Swiss data protection law. Badge, NFC and QR code are not. That is the dividing line that matters, before any technical consideration.

An impact assessment is expected

Deploying a biometric device in the workplace means documenting the necessity of the processing, the absence of a less intrusive alternative, and the security measures chosen. This assessment is prepared before the hardware is ordered, not after.

In France, timekeeping is not access control

The CNIL’s standard regulation on workplace biometrics covers devices controlling access to premises, applications and work tools. Time tracking is not its object: justifying biometrics for timekeeping alone is markedly harder.

Badge and QR remain the simple route

None of the three constraints above applies to RFID, NFC or QR code. In most of the rollouts we support, that combination meets the need without opening a legal file.

This page describes a general framework and does not replace legal advice. We help you frame the choice, not qualify your processing.

Six questions to settle it

In our experience, the decision comes down to these six points, in this order.

Are hands gloved or soiled?
In food processing, healthcare or workshops, fingerprint fails. Palm, badge and QR get through.
Is badge lending a real risk?
If clocking in for an absent colleague is a founded, documented concern, it is the strongest argument for biometrics. Otherwise it is not one.
What is your turnover rate?
On fast-moving teams, handing out and recovering badges costs more than it looks. QR code removes that line item.
Who owns the compliance file?
An impact assessment needs a named owner and time. If nobody can run it, the question is settled.
How many sites, under which jurisdiction?
A Swiss rollout and a French one do not have the same room. The same method can fit here and be a problem elsewhere.
Must you pick a single method?
No. All six coexist on the same terminal, and you can enable several on one site or one work profile.

What does not change

Whichever method you choose, Illizeo receives the same timestamps and produces the same result: the day rebuilt, eleven alerts, six counters and the payroll export.

Let us talk about your site before we talk hardware

The right terminal depends on your flows, your hygiene constraints and what you are allowed to collect. We look at all three together.