CTC EXTERNALIZACIÓN, S.L

€365,000

Insufficient fulfilment of information obligations

Date de décision

12 février 2024

Autorité

Spanish Data Protection Authority (aepd)

ES

Secteur

Employment

Pays

ES

Droit

GDPR

Statut

FINAL

Description

The Spanish DPA has imposed a fine of EUR 365,000 on CTC EXTERNALIZACIÓN, S.L.. An employee had filed a complaint with the DPA due to the fact that the controller had requested fingerprints of employees in order to implement a new time and attendance system. However, it was not communicated that the fingerprints would also be stored in the staff portal. For this reason, the DPA found that the controller had violated its duty to inform. The DPA also found that the controller was unable to demonstrate sufficient security measures for the processing of fingerprints. Finally, the DPA found that the controller had failed to carry out a required data protection impact assessment.

Citations légales

Art. 13Art. 32Art. 35

Questions et violations

Insufficient fulfilment of information obligations

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.