Cappello Giovanni & Figli s.r.l.

€120,000

Non-compliance with general data processing principles

Date de décision

6 juin 2024

Autorité

Italian Data Protection Authority (Garante)

IT

Secteur

Employment

Pays

IT

Droit

GDPR

Statut

FINAL

Description

The Italian DPA has imposed a fine of EUR 120,000 on Cappello Giovanni & Figli s.r.l.. The controller had used facial recognition technology to monitor the attendance of employees. During its investigation, the DPA found that such extensive recording of biometric data to monitor attendance was not permitted. The controller referred to the consent given by the employees as the legal basis for the data processing. However, the DPA concluded that the controller could not rely on consent, as voluntary consent is questionable in an employee-employer relationship. In addition, the DPA found that the recordings were stored for an excessively long time.

Citations légales

Art. 5 (1)Art. 6Art. 9 (2)Art. 13

Questions et violations

Non-compliance with general data processing principles

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.