Biometric data such as fingerprints, facial features or voice is sensitive personal data under Chile's Law 21.719. To use it for attendance or access control, your company will need to comply with article 16 ter: disclose the biometric system used, the specific purpose, the period of use and how to exercise data subject rights, and justify necessity and proportionality.
The essentials in 30 seconds
- Article 16 ter: biometric data is sensitive personal data and requires disclosing four specific things (system, purpose, period and how to exercise rights).
- Law 21.719 will take effect on December 1, 2026 in Chile; until then there is room to get the time and attendance clock and facial access in order.
- Access, rectification, deletion, objection and portability requests are answered within 30 calendar days, extendable once (article 11).
- Article 35: minor infringements, written warning or a fine of up to 5,000 UTM; serious ones, up to 10,000 UTM; very serious ones, up to 20,000 UTM. The article 39 register is public for five years.
In Chile, the fingerprint time and attendance clock is probably the most widespread processing of sensitive personal data and, at the same time, the least documented. Almost every mid-sized company has one at the entrance; very few have a document explaining what system it is, what it is used for, for how long and how an employee can ask for their data to be deleted. When Law 21.719 takes effect on December 1, 2026, that gap will stop being an administrative detail and become an identifiable breach. If you want the full picture, start with our guide to the data protection law in Chile.
Chilean law did something unusual: on top of including biometric data among sensitive personal data, it gave it a rule of its own, article 16 ter, with four concrete information duties. These are not abstract principles, they are four things you have to tell the data subject. Many companies do not meet them today, not out of bad faith, but because the time clock was bought as an operations matter and never went through a privacy review.
This guide is written for HR, IT, security and operations. It reviews the legal definition, why the standard is higher, the four duties under article 16 ter, the real problem with consent in an employment relationship, what to do with biometric templates and how all of this differs from ordinary video surveillance.
What is biometric data under Law 21.719?
Under article 16 ter of Law 21.719, biometric data is data obtained through specific technical processing, relating to the physical, physiological or behavioral characteristics of a person, that allows or confirms their unique identification. The rule itself gives examples: the fingerprint, the iris, hand or facial features and the voice.
There are two elements in that definition worth reading slowly. The first is “specific technical processing”: on a reasonable reading of the rule, having an image or a recording is not enough, because what turns that material into biometric data is processing it to extract patterns. The second is “unique identification”: the system has to serve to identify or confirm who that particular person is, not simply to describe them.
That is why, in practice, the time and attendance clock that turns an employee's fingerprint into a mathematical template and the facial reader at the door that matches a face against a database of enrolled people both fall under article 16 ter. So do the voice verification systems some companies use in help desks or internal call centers.
- Fingerprint: the mass-scale case in Chile (time and attendance clocks and access to warehouses or restricted areas).
- Facial features: turnstiles and doors with facial recognition in offices, plants and corporate buildings.
- Iris: less common, used in high-security facilities.
- Hand features: hand geometry readers, still present in industry and mining.
- Voice: identity verification over the phone or in internal support systems.
Why are fingerprints and faces sensitive data, and what higher standard does that imply?
They are, because Law 21.719 includes them in the catalogue of sensitive personal data it regulates in article 16 and the articles that follow, alongside health and the human biological profile, beliefs or convictions, political or union membership, sexual life and sexual orientation and, distinctively in Chile, socioeconomic status. On top of that, the law devotes a rule of its own to biometric data in article 16 ter, and the practical consequence is that the processing regime tightens on several fronts at once.
Article 16 ter provides that biometric data may only be processed where the first paragraph of article 16 is complied with and, in addition, provided that the data controller gives the data subject the specific information set out in its subparagraphs a) to d). In other words, an additional requirement is added that does not exist for ordinary personal data. The law allows processing without consent only in the cases in the second paragraph of article 16 bis, which are narrow situations and were not designed for office time and attendance control.
The higher standard also shows up in security breaches. Article 14 sexies requires the data controller to report to the Agency, by the fastest possible means and without undue delay, any breach causing destruction, leakage, loss or alteration of the data, or unauthorized access to it, where there is a reasonable risk to the rights and freedoms of data subjects. When the breach affects sensitive personal data such as biometric data, it must also be communicated to each data subject in clear and plain language and, if that is not possible, through a notice in a mass media outlet with national reach. The same article requires those communications to be recorded. One frequent misconception is worth clearing up: Chilean law does not set a 72-hour deadline; that deadline belongs to the European regulation.
There is also an argument that is not legal but carries weight: a leaked password can be changed; a leaked fingerprint cannot. That irreversibility helps explain why the Chilean legislator raised the bar.
- An extra specific information requirement (article 16 ter, subparagraphs a) to d)) that does not apply to ordinary data.
- Stricter legal bases for processing: without consent only in the cases in the second paragraph of article 16 bis.
- Breaches with reasonable risk: report to the Agency and, because this is sensitive personal data, communication to the affected data subjects (article 14 sexies).
- Real enforcement risk: under article 35, a written warning or a fine of up to 5,000 UTM for minor infringements, up to 10,000 UTM for serious ones and up to 20,000 UTM for very serious ones.
What information does article 16 ter require before switching on the time and attendance clock?
Article 16 ter requires four specific disclosures: a) identification of the biometric system used; b) the specific purpose for which the data collected by the system will be used; c) the period during which the biometric data will be used; and d) the way in which the data subject can exercise their rights. All four, not three.
This is where most companies are caught short. The usual approach is a generic paragraph in the contract stating that “the company may use attendance control systems”. That does not identify the system, does not define a specific purpose, does not set a period and does not explain how to exercise rights. It is, essentially, zero out of four.
The good news is that meeting these four duties is cheap and fast compared with almost any other obligation under Law 21.719. It is solved with an addendum to the employment contract, a visible sign next to the device and a published internal policy, all carrying the same text. What does not work is burying it in the fine print: article 14 ter, on the duty of information and transparency, and the transparency and information principle in article 3 point to information that is understandable, not merely available.
A reasonable operating rule: deliver the information before the person puts their finger or face on the device for the first time, not afterwards. And update it if you change provider, technology or purpose.
- The information notice must cover all four subparagraphs of article 16 ter, without leaving out the period of use, which is the one most often forgotten.
- The same content must appear in the contract addendum, on the sign at the device and in the internal policy.
- The information is delivered before the first enrollment and updated whenever the system or the purpose changes.
| Subparagraph of article 16 ter | What the law requires | How to comply in practice | Sample wording |
|---|---|---|---|
| a) Identification of the biometric system used | State which technology is used, which feature it captures and what it generates from it | Contract addendum, sign next to the device and internal policy, with the same text in all three places | “Attendance control uses a brand X, model Y fingerprint reader, which converts your fingerprint into an encrypted mathematical template and does not store the image of your finger.” |
| b) Specific purpose of the data collected | A concrete, bounded purpose, not an open-ended list of possible uses | Write the purpose in a single sentence and expressly state the excluded uses | “Your fingerprint is used solely to record the start and end of your working day. It is not used to assess performance or productivity, or for any other purpose.” |
| c) Period during which the data will be used | A defined term or end rule, not indefinite processing | A term clause in the addendum, plus a deletion rule built into the offboarding procedure | “Your biometric template will be used for as long as your employment relationship lasts and will be deleted when the contract ends, within the period set in our internal retention policy.” |
| d) The way in which the data subject can exercise their rights | Explain how to exercise access, rectification, deletion, objection and portability, as well as blocking | A single identified channel, a designated internal owner and a documented response procedure | “You can exercise your rights of access, rectification, deletion, objection and portability by writing to privacy@yourcompany.cl. We will respond within 30 calendar days of the date your request is submitted, a period that may be extended once.” |
Is the employee's consent enough to use fingerprints?
Consent is the general rule for processing under article 12 of Law 21.719, but in the Chilean employment context it is a fragile basis. Whoever signs is in a relationship of subordination and dependence, and can hardly refuse without cost. If your only defense before the Agency is “everyone signed”, you are resting an entire biometric system on the weakest link.
The practical recommendation is not to rely on the signature alone, but to document a serious necessity and proportionality analysis. Article 3 of the law enshrines, among others, the principles of lawfulness and fairness, purpose and proportionality, and article 14 quater imposes a duty, not a recommendation, of protection by design and by default: applying appropriate technical and organizational measures before and during the processing, and ensuring that only the specific data that is strictly necessary is processed, taking into account the amount of data collected, the extent of the processing, the retention period and its accessibility.
That analysis forces an uncomfortable question: can the objective be achieved with something less intrusive? For clocking in and out there are badges, PIN codes, apps with validation on the employee's device or supervisor-based records. If one of those alternatives reasonably meets the same goal, defending the fingerprint becomes harder. Bear in mind that if you evaluate an app with location tracking you move into article 16 sexies: geolocation is processed under the same legal bases as articles 12 and 13, and with clear, sufficient and timely information about the type of data, the purpose and duration of the processing and whether it will be communicated or transferred to a third party in order to provide a value-added service.
When processing is large-scale, affects the entire workforce and involves sensitive personal data, it is prudent to also consider an impact assessment, a mechanism the law provides for in article 15 ter. Even if you decide to go ahead with the biometric system, having that analysis in writing is what turns an operational decision into a defensible one.
- 1. Define the real objective (working-time control, perimeter security, traceability of critical access): do not mix purposes.
- 2. List at least two less intrusive alternatives and assess each one against verifiable criteria.
- 3. Explain in writing why those alternatives are not sufficient in your specific context.
- 4. Narrow the scope: apply biometrics only to the areas or roles where it is indispensable, not to the whole company by default.
- 5. Document the decision, the date, who made it and on what basis, and consider an impact assessment (article 15 ter) when the processing is large-scale.
How are biometric templates protected, retained and deleted?
With three technical decisions and one operational one. Article 14 quinquies establishes the duty to adopt security measures, and article 14 quater requires that, by default, only strictly necessary data is processed, expressly taking into account the retention period and accessibility. It is also worth knowing that article 14 septies allows the minimum information and security standards to be differentiated according to the type of data, the activity and the size of the entity under Law 20.416, standards the Agency will set through a general instruction.
First, do not store images when the template is enough. Most modern readers generate a mathematical vector from the feature and do not need to keep the photograph of the finger or the face; if your device does store them, that is the first setting to review. Second, encrypt the database and restrict who can query it: in many companies the time clock software has a single administrator password shared between IT and the front desk. Third, decide where the data lives. If the provider hosts it in its cloud, it acts as a third-party processor and the relationship must be governed in accordance with article 15 bis, with instructions and responsibilities in writing.
The operational part is deletion. The period you disclosed under subparagraph c) of article 16 ter has to be honored in practice: when someone leaves the company, their template must be deleted from the device and from every backup, not merely flagged as inactive. That step is worth adding to the HR offboarding checklist, alongside returning the laptop and the badge.
Also, be ready to respond to requests. Article 11 requires acknowledging receipt and issuing a decision no later than thirty calendar days, calendar and not business days, from the date the request is submitted, extendable once by up to thirty further calendar days. The response is sent in writing to the address or email provided, and you must store records proving it was sent, the date and the full content. If you refuse, the decision must be reasoned and must inform the data subject that they have 30 business days to complain to the Agency under article 41. For a temporary blocking request the deadline is shorter: two business days, and until you decide you cannot process that data.
- Store encrypted templates rather than images whenever the device allows it.
- Limit access to the biometric database to identified people, with individual accounts.
- Govern in writing the provider that hosts or administers the data (article 15 bis).
- Delete the template when the employment relationship ends, backups included.
- Have a breach procedure covering the report to the Agency and the communication to the affected data subjects (article 14 sexies).
Is it the same as video surveillance? Compliance checklist
It is not the same. A camera recording a corridor processes personal data, but not necessarily biometric data: as long as it only captures and stores images, there is no specific technical processing intended to allow or confirm the unique identification of a person, which is what article 16 ter of Law 21.719 describes. The recording is still subject to the principles of article 3, to the information and security duties and to the rights of the data subject, but not to the reinforced information requirement of article 16 ter.
The line is crossed the moment you add facial recognition analytics on top of that same video: at that point the system starts extracting facial patterns to identify people and becomes biometric processing, with everything that entails. It is a configuration change that is often switched on as a provider “improvement” and that nobody in the company reviews from a legal standpoint. If you have cameras, ask explicitly whether facial recognition is or will be enabled.
On timing: Law 21.719 will take effect on December 1, 2026 and, during the first twelve months, where a penalty would apply, the Agency may issue a written warning to companies classified as smaller enterprises under article two of Law 20.416. That rule in the sixth transitional article deserves a careful read: it is a power, not automatic immunity; it reaches only those companies; the warning is still subject to the registration duty of article 39, whose entries are public for five years; and it does not exempt anyone from substantive compliance. It is not a grace year. For those who want to go further, the law also provides for a voluntary infringement prevention model (article 49), which the Agency certifies and supervises (article 51).
Finish with this checklist. If you can tick all ten items with documentary evidence, your biometric system is in a reasonable position under the law.
- 1. Inventory: which biometric devices exist, where they are, what brand they are and who administers them.
- 2. Written definition of the specific purpose of each system, with no ancillary uses.
- 3. Documented necessity and proportionality analysis, with less intrusive alternatives assessed.
- 4. Impact assessment (article 15 ter) when the processing is large-scale or high-risk.
- 5. An information notice covering the four subparagraphs of article 16 ter, delivered before the first enrollment.
- 6. Contract addendum, sign next to the device and internal policy with the same content.
- 7. Verified configuration: encrypted template instead of image, individual access accounts, query logging.
- 8. Contract with the provider that hosts or administers the data, in accordance with article 15 bis.
- 9. Deletion rule when the employment relationship ends, built into the offboarding checklist.
- 10. A channel and procedure to answer rights requests within 30 calendar days, with records of dispatch and content.
Will your time and attendance clock comply with article 16 ter?
At AlayIAtrust we review biometric attendance and access systems in Chilean companies: device inventory, necessity and proportionality analysis, information notices compliant with article 16 ter and a deletion procedure. Let's talk before December 1, 2026.
Schedule an assessmentFrequently asked questions
Can I keep using the fingerprint time and attendance clock after December 1, 2026?
Yes. Law 21.719 will not ban biometrics in Chile: it will require compliance with article 16 ter, disclosing the system used, the specific purpose, the period of use and how to exercise rights. It is also advisable to justify in writing that the processing is necessary and proportionate compared with less intrusive alternatives.
Do I need each employee's written consent to take their fingerprint?
Consent is the general rule under article 12, but in an employment relationship it is a fragile basis because of the subordination involved. The practical recommendation in Chile is not to rely on the signature alone and to back it up with a documented necessity and proportionality analysis, plus full compliance with article 16 ter.
Where should I deliver the information required by article 16 ter?
In the places where the person will actually see it before enrolling: an addendum to the employment contract, a visible sign next to the device and a published internal policy. The content must be identical in all three formats and cover the four subparagraphs of article 16 ter, in understandable language.
Is facial recognition at the door the same as a security camera?
No. A camera that only records images processes personal data, but not biometric data. When the system processes the face to uniquely identify or confirm a person, article 16 ter of Law 21.719 applies, along with its reinforced information requirement, which is specific to sensitive personal data.
What happens if an employee refuses to register their fingerprint?
Law 21.719 does not resolve that employment dispute on its own, but it does make it more likely if your only basis is consent. The prudent approach in Chile is to have an alternative clocking method available, such as a badge or a supervisor-based record, and to document it in the internal policy.
How long can I retain biometric templates?
For the period you disclosed under subparagraph c) of article 16 ter, and that period has to be real. Article 14 quater requires that by default only strictly necessary data is processed, taking the retention period into account. The reasonable practice is to delete the template when the employment relationship ends, backups included.
How long do I have to respond if someone asks to delete their biometric data?
Article 11 of Law 21.719 requires acknowledging receipt and issuing a decision within thirty calendar days from the date the request is submitted, extendable once by up to thirty further calendar days. These are calendar days, not business days, and you must keep records of the dispatch, its date and the full content.
Do I need an impact assessment for biometric time and attendance control?
Law 21.719 provides for the impact assessment in article 15 ter and, in processing that affects the entire workforce and involves sensitive personal data, carrying one out is highly advisable. Even if you decide to keep the system, having that analysis in writing turns an operational decision into one you can defend before the Agency.
What if the time clock provider stores the data in its cloud?
That provider acts as a third-party processor and the relationship must be governed in accordance with article 15 bis of Law 21.719, with instructions and responsibilities in writing. Your company remains responsible before data subjects, including the breach communication under article 14 sexies if there is a leak.
What is the real risk for a small company that does not comply?
Under article 35, minor infringements are penalized with a written warning or a fine of up to 5,000 UTM, serious ones with up to 10,000 UTM and very serious ones with up to 20,000 UTM. During the first twelve months the Agency may issue a written warning to smaller enterprises under Law 20.416: it is a power, the warning is recorded and it does not exempt anyone from compliance.
Official sources
This article is for information purposes only and does not constitute legal advice for a specific case.