Fingerprint readers became the default in Kenyan offices for a simple reason: staff cannot lose a fingerprint, and they cannot lend one to a colleague.
Both of those advantages are real. But biometrics also carry a legal obligation that most organisations installing them do not know about, and there are environments where a fingerprint reader is straightforwardly the wrong technology.
This guide compares the three credential types in practical terms — how they behave in the real world, what they cost over time, and what the law requires — so you can specify the right one for each door rather than applying one technology everywhere.
The three options
Card and fob credentials. The user presents a card or fob to a reader. Modern systems use encrypted smart cards; older ones use low-frequency proximity cards, which are cheap and trivially cloneable with equipment available online. If you are specifying cards today, specify encrypted smart cards.
Biometrics. The reader measures a physical characteristic — most commonly fingerprint, increasingly facial recognition. The system stores a mathematical template derived from the characteristic rather than an image of it, and compares against that template.
Mobile credentials. The user's phone acts as the credential over Bluetooth or NFC. Credentials are issued and revoked remotely, which changes the administrative economics considerably.
Head-to-head comparison
| Card/fob | Biometric | Mobile | |
|---|---|---|---|
| Can be shared or lent | Yes — the main weakness | No | Rarely in practice |
| Can be lost | Frequently | No | Occasionally |
| Speed at the door | Fastest | Slower (varies) | Fast |
| Works with gloves / wet or worn hands | Yes | Fingerprint: often not | Yes |
| Hardware cost per door | Lower | Higher | Moderate |
| Ongoing credential cost | Card replacement, continuous | None | Usually licensing |
| Admin effort | Physical issue and collection | Enrolment session per person | Remote issue and revoke |
| Visitor and contractor handling | Easy | Awkward | Easy |
| Revocation on exit | Only if the card is returned | Immediate and certain | Immediate and remote |
| Data protection burden | Standard personal data | Sensitive personal data — higher bar | Standard personal data |
| Suits dusty or industrial sites | Yes | Fingerprint: poorly | Yes |
| Hygiene | Contactless | Contact readers are touched | Contactless |
The biometric obligation most organisations miss
This is the section worth reading carefully.
Under Kenya's Data Protection Act 2019, biometric data is classified as sensitive personal data. That is a distinct and higher category than ordinary personal data such as a name or a staff number.
Practically, that means:
A higher bar for justification. You need a lawful basis, and for sensitive personal data the requirements are stricter. Convenience alone is a weak justification. If a card system would meet the same security need, that weakens the case for collecting biometrics at all.
Consent from staff is more complicated than it looks. Consent must be freely given. In an employment relationship, where the employee has limited practical ability to refuse, consent is a fragile basis — and in some contexts regulators treat it as not genuinely free at all. If biometrics are the only way into the building, "consent" is not really consent. Consider whether an alternative credential is offered to those who object.
A DPIA is very likely required. Large-scale processing of biometric data is precisely the kind of high-risk processing that triggers a Data Protection Impact Assessment. Do it before procurement, not after installation.
Template security is a legal obligation, not a feature. A compromised password can be changed. A compromised fingerprint cannot. Specify systems that store irreversible mathematical templates rather than images, encrypt templates at rest and in transit, and — where the architecture allows — keep templates on the device rather than centralised on a server reachable from the office network.
Deletion on exit must actually happen. When someone leaves, their biometric template must be deleted in line with your retention policy. Many systems accumulate templates of former staff indefinitely because nobody owns the offboarding step. That is unlawful retention of sensitive personal data.
And registration applies. If you are processing biometric data, you are a data controller with the associated registration and accountability duties — the same framework we set out for surveillance in CCTV and Kenya's Data Protection Act.
None of this makes biometrics unusable. Plenty of Kenyan organisations run them lawfully. It does mean biometrics carry a governance cost that cards do not, and that cost belongs in the comparison.
Where each technology actually fits
Rather than standardising on one, specify per door against the risk and the environment.
Choose biometrics for: server rooms and data centres, cash handling areas, pharmacy and controlled drug stores, evidence and records rooms, high-security laboratories — a small number of high-consequence doors where credential sharing is the specific threat you are defending against, and the population is small enough to govern properly.
Choose cards or fobs for: general staff access, multi-tenant office buildings, sites with high headcount turnover, industrial and construction environments where hands are dirty or gloved, and any facility with significant contractor and visitor traffic. Use encrypted smart cards, not legacy proximity cards.
Choose mobile credentials for: distributed and multi-site organisations, environments with frequent onboarding and offboarding, contractor-heavy operations where remote issue and revocation saves real administrative time, and modern office fit-outs where users expect it.
Combine them where the risk justifies it. Multi-factor at a small number of critical doors — a card plus a PIN, or a card plus a fingerprint — gives you strong assurance exactly where it is needed without imposing the cost and governance burden everywhere.
Six specification points that matter more than the credential
The credential type is the visible decision. These determine whether the system works.
1. Fail-safe or fail-secure, and the fire interface. What happens to each door when power fails or the fire alarm activates? Doors on escape routes must release on fire alarm — this is a life-safety requirement, not a preference, and it is where access control intersects with your fire strategy. Get it wrong and you have locked people inside a burning building. This must be documented in the cause-and-effect matrix covered in our fire alarm compliance guide.
2. Anti-passback and tailgating. The most common real-world bypass is not a cloned card. It is one person holding the door for another. Anti-passback rules, interlocks, turnstiles at high-risk entrances, and — most effectively — integration with CCTV so that every access event has associated video.
3. Offline behaviour. If the controller loses its connection to the server, does the door still work, and does it still log? A system that fails open is a security problem; one that fails closed is an operational problem. Both are decisions to make deliberately.
4. Integration. Access control that shares a platform with surveillance and intrusion detection gives you a single audit trail — the badge event and the video of it, together. Standalone systems make you reconstruct incidents from separate sources with mismatched clocks, which is exactly the point we make in why integrated security beats standalone surveillance.
5. Audit logging and reporting. Who went where, when, and can you produce it. This matters for investigations, for regulatory obligations and, increasingly, for tenant and client assurance.
6. Standards, not just hardware. Open protocols over proprietary lock-in wherever possible. Proprietary systems from a single supplier become expensive at expansion and painful when that supplier's local presence changes.
The offboarding test
A simple diagnostic for any access control system, whichever credential it uses:
When an employee leaves on Friday, is their access revoked before Monday — reliably, every time, without depending on anyone remembering?
Card systems fail this constantly, because revocation depends on someone collecting the card or an administrator deactivating it. Uncollected cards accumulate for years.
Biometric and mobile systems handle it better, because revocation is administrative rather than physical. But the biometric template must also be deleted, not merely deactivated — otherwise you are holding sensitive personal data with no lawful basis.
If your HR offboarding checklist does not include an access control step with a named owner, the technology choice is secondary. That gap is the vulnerability.
Specify per door, not per building
Most facilities do not need one access control technology. They need biometrics on a handful of critical doors, encrypted cards or mobile credentials across general access, a properly designed fire interface, and integration with surveillance so every access event has video attached.
Fiacin Solutions designs and installs integrated access control for commercial, institutional and government facilities across Kenya — specified door by door against risk, environment and the compliance obligations that come with each credential type.
Request a site survey, or explore our access control systems.
0 Comments
No comments yet — be the first to share your thoughts.
Leave a comment
Your email will not be published. Comments are reviewed before appearing.