CARTONAJES BAÑERES, S.A

€220,000

Insufficient technical and organisational measures to ensure information security

Decision Date

November 22, 2024

Authority

Spanish Data Protection Authority (aepd)

ES

Sector

Employment

Country

ES

Law

GDPR

Status

FINAL

Description

The Spanish DPA has fined CARTONAJES BAÑERES, S.A. EUR 220,000. During its investigation, the DPA found that the controller had failed to grant a former employee access to their personal data. The DPA also found that the controller had failed to carry out a data protection impact assessment regarding the operation of a biometric facial recognition system installed to track working hours.

Legal Citations

Art. 15Art. 35

Issues & Violations

Insufficient technical and organisational measures to ensure information security

Stay Updated on Privacy Enforcement

We respect your privacy. One email per month, no spam, unsubscribe anytime.