The Spanish authority fines VIPTHINK €2,400 for GDPR breaches related to biometric data collection and processing
Facts and context
The Spanish Data Protection Authority (AEPD) today published a sanction decision against VIPTHINK, S.L. (including a fine of €2,400) for breaches related to excessive data collection, unlawful processing of biometric data, and failure to inform data subjects.
The case originated from a complaint filed on 4 July 2023 by a person forced to use a mobile application for online registration, which required photographing both sides of their identity document as well as a photograph of their face.
Reasons for the decision
The authority first analyzed the qualification of VIPTHINK, S.L., which presented itself as a mere processor acting on behalf of accommodation establishments. The AEPD rejected this qualification based on the European Data Protection Board (EDPB) Guidelines 07/2020 on the concepts of controller and processor. It considered that VIPTHINK, S.L. decisively determined the means of processing by designing and imposing the functionalities of its application, notably the use of biometric verification. Furthermore, its privacy policy mentioned its own purposes, such as sending commercial information. Under Article 28(10) of the GDPR, a processor who determines the purposes and means of processing is considered a controller. The authority therefore concluded joint responsibility with the accommodation establishment.
On this basis, the authority found the following breaches:
- Data minimization obligation (Article 5(1)(c) of the GDPR): The authority found that the application required a photograph of both sides of the identity document and a photograph of the user's face. However, the applicable Spanish regulation (Royal Decree 933/2021) requires recording certain specific traveler data (name, surname, document number, etc.) but does not require collecting a full copy of the document or a facial image. Therefore, the collection of these data was deemed inadequate, irrelevant, and excessive regarding the purpose of legal compliance, thus violating the minimization principle.
- Prohibition on processing special categories of data (Article 9 of the GDPR): The verification process involved an automated comparison between the photo of the identity document and the user's facial photograph. The authority recalled that, according to the definition in Article 4(14) of the GDPR, biometric data are those that allow or confirm the unique identification of a person. It emphasized that processing such data, even for verification purposes (one-to-one comparison), constitutes processing of special categories of data, subject to the prohibition principle of Article 9(1). The company having demonstrated none of the derogations provided in Article 9(2), the processing was deemed unlawful.
- Information obligation (Article 13 of the GDPR): At the time of the facts, the application's privacy policy was incomplete. It mentioned purposes related to contract performance and legitimate interest but did not clearly and specifically inform about the purpose of compliance with the legal obligation to register travelers. Moreover, information regarding the processing of biometric data and its purpose was absent, thus depriving the user of complete and transparent information on the use of their personal data.
Authority's decision
Consequently, the authority imposed a fine of €2,400 on VIPTHINK, S.L., broken down as follows: €700 for violation of Article 5(1)(c), €1,200 for violation of Article 9, and €500 for violation of Article 13 of the GDPR.
Lessons learned
This decision reminds that:
- A technology solution provider who determines essential processing features, such as the use of biometrics, and defines its own purposes is qualified as a joint controller, notwithstanding the existence of a processing contract.
- The processing of biometric data for the purpose of verifying or authenticating a person (one-to-one comparison) constitutes processing of special categories of data within the meaning of Article 9 of the GDPR, subject to the prohibition principle and its strict interpretation exceptions.
- The existence of a legal obligation to collect data does not justify collecting information exceeding what the norm strictly requires; collecting a full copy of an identity document is thus deemed excessive if the law only requires certain information contained therein.
- Information provided to data subjects must transparently and specifically detail each purpose, including recourse to a precise legal obligation and the use of intrusive technologies such as facial recognition.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire