Sportitalia

€20,000

Non-compliance with general data processing principles

Date de décision

10 novembre 2022

Autorité

Italian Data Protection Authority (Garante)

IT

Secteur

Employment

Pays

IT

Droit

GDPR

Statut

FINAL

Description

The Italian DPA (Garante) imposed a fine of EUR 20,000 on Sportitalia. The controller processed biometric data (fingerprints) of employees for the purpose of registering their attendance. Garante found that such extensive processing was not proportionate and therefore constituted an unjustified infringement of the rights of the data subjects. Furthermore, Garante determined that the processing of biometric data had taken place without sufficiently informing the data subjects about the processing.

Citations légales

Art. 5 (1)Art. 9Art. 13Art. 30 (1)

Questions et violations

Non-compliance with general data processing principles

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.