The Romanian authority sanctions TIP TOP FOOD INDUSTRY SRL for non-compliance with the GDPR regarding the use of biometric data
The Romanian data protection authority sanctioned a company for using a fingerprint timekeeping system for its employees, deeming this processing of biometric data unlawful and excessive in relation to the pursued purposes.
Facts and context
The Romanian data protection authority (ANSPDCP) has today published a sanction decision against TIP TOP FOOD INDUSTRY SRL (including the imposition of a €5,000 fine) for breaches related to the processing of biometric data of its employees.
The case originated from a complaint by a natural person denouncing the use of a timekeeping and access control system based on the processing of employees' fingerprint data.
Grounds for the decision
- Unlawful processing of biometric data and non-compliance with data minimisation (Article 9 of the GDPR and Article 5(1)(c) of the GDPR): The authority found that the company processed employees' biometric data to control access and record working time. It ruled that this processing was not based on any of the lawful bases provided for in Article 9 of the GDPR for special categories of data. Furthermore, the authority considered that the data minimisation principle was violated, as the purposes of access control and timekeeping could be achieved by alternative means less intrusive to employees' privacy.
Decision of the authority
Consequently, the authority imposed a fine of €5,000 (equivalent to 26,236 lei) on TIP TOP FOOD INDUSTRY SRL.
Moreover, the authority ordered the company to replace its biometric data-based access control and timekeeping system with an alternative solution, to ensure compliance with the data minimisation principle.
Lessons learned
This decision reminds that:
- The use of biometric data for monitoring employees' working time and access must be justified by a specific legal basis under Article 9 of the GDPR and cannot be the default solution.
- In accordance with the minimisation principle, a data controller must systematically assess whether less privacy-intrusive means can achieve the intended objectives before considering the processing of biometric data.
- The sensitive nature of biometric data and the significant risks in case of compromise require particularly rigorous justification of their necessity and proportionality.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire