Follow us :
General

Construction Site IT: From Biometric Time Clocks to Subcontractors

Open laptop and a hard hat resting on a stack of bricks at a construction site — Xen Bilişim General

Türkiye’s Personal Data Protection Board sent a clear message to employers using fingerprint or facial recognition for time tracking: Decision No. 2026/921 calls the practice unlawful. The ruling applies broadly, but it lands hardest on construction firms, where biometric turnstiles are one of the most common ways to track who’s on-site. And biometrics is only the visible problem — data between the site and the office already moves through half a dozen channels, gets stored differently in each, and rarely syncs at all.

Why fingerprint time clocks are suddenly a liability

The Board’s decision, dated 29 April 2026, rests on three points. Labor law requires tracking working hours, but nothing says that has to happen biometrically. Given the power imbalance in an employment relationship, whether consent to biometric scanning is genuinely free is questionable — explicit consent alone isn’t enough of a legal basis. And on proportionality: when less invasive alternatives exist (encrypted cards, PIN codes, RFID/NFC badges, even a supervised paper sign-in sheet), a fingerprint or face scan is disproportionate.

The decision sets no formal compliance deadline, but the warning is explicit: if the practice is found unlawful, Article 18 penalties apply. For a firm operating at construction-site scale, that’s not a rounding error:

Violation type2026 minimum2026 maximum
Transparency obligation violation85,437 TL1,709,200 TL
Data security measures (Art. 12)256,357 TL17,092,242 TL

You don’t have to rip out the turnstile tomorrow. But if you can’t document where the fingerprint data lives, why you’re collecting it, and what safeguards protect it, that table is what’s waiting at the next audit.

Where data actually falls apart between the site and the office

Time tracking aside, the real gap shows up in daily operations. Progress reports get photographed and sent over WhatsApp. Material requests sit in a spreadsheet that gets emailed around. Safety incident forms get signed on paper and scanned weeks later. When connectivity is weak or nonexistent, crews still get the work done — but the record splits into two versions: whatever’s on paper or on someone’s phone at the site, and whatever made it into the office system. When the two disagree, nobody’s quite sure which one is right.

Device loss is its own line item. A tablet or phone goes missing or gets stolen on-site — and if it’s carrying unencrypted project files, or worse, personnel ID data, that alone can trigger a breach notification. Without mobile device management that lets you wipe a lost device remotely, the exposure multiplies with every additional site you run.

Managing subcontractor access

On a project running three or four subcontractors at once, each one touches the shared system somehow. The usual failure isn’t the access itself — it’s that nobody closes it once the job is done.

MethodAdvantageRisk
Shared Wi-Fi passwordFast to set up, no technical skill neededNot isolated; if the password never changes, access outlives the project
Temporary VPN accountClosed with one click when work ends, and loggedSomeone has to own setup and follow-through
Read-only cloud portalCentral oversight, visible activity logThe subcontractor’s own device security is outside your control

The practical fix isn’t a new system — it’s keeping the subcontractor list and the access list on the same document. Revoking access should be a line item in the contract close-out, not a separate task someone has to remember on their own.

The blind spot in equipment tracking

Even firms running GPS or RFID equipment tracking tend to have a one-way data flow: the site reports status, but it can take days to reach the central ERP. If a crane or generator has already left but the system still shows it “on-site,” that creates problems for insurance and project cost accounting alike. At smaller firms, this tracking often lives in a single spreadsheet — one person’s laptop, no backup, no updates while that person is on leave.

The same pattern shows up with personnel ID and license data. IDs, driver’s licenses, and safety certifications collected for site access tend to sit in a paper file or shared folder indefinitely; once a project wraps, most firms couldn’t say who deleted what. That’s personal data under KVKK too — with no defined retention period, an audit question follows fast: why does this still exist once its purpose has ended?

Frequently asked questions

Do we need to shut down our biometric turnstiles immediately? Not necessarily, but you need a defensible reason for keeping them — document why you didn’t adopt an alternative and what safeguards are in place. That’s what the Board looks for during an inspection.

Is a paper sign-in sheet fully compliant on its own? It avoids the proportionality problem, but retention period and access control are a separate question — it still needs to sit in a locked location with limited access.

Can we cut off a subcontractor’s VPN access before the project ends? Yes, and it’s often the better approach. Suspending access between milestones and reopening it only when needed beats leaving it open the whole time.

These gaps between the site and the office don’t close in one pass — fixing them tends to run from time tracking, to the access list, to device management, in that order. If you’d like a second set of eyes on your current setup, get in touch.

Share this post
Türkçe oku

Related Posts