Sportitalia

€20,000

Non-compliance with general data processing principles

Lēmuma datums

2022. gada 10. novembris

Iestāde

Italian Data Protection Authority (Garante)

IT

Nozare

Employment

Valsts

IT

Likums

GDPR

Statuss

FINAL

Apraksts

The Italian DPA (Garante) imposed a fine of EUR 20,000 on Sportitalia. The controller processed biometric data (fingerprints) of employees for the purpose of registering their attendance. Garante found that such extensive processing was not proportionate and therefore constituted an unjustified infringement of the rights of the data subjects. Furthermore, Garante determined that the processing of biometric data had taken place without sufficiently informing the data subjects about the processing.

Juridiskās atsauces

Art. 5 (1)Art. 9Art. 13Art. 30 (1)

Jautājumi un pārkāpumi

Non-compliance with general data processing principles

Atjauniniet informāciju par konfidencialitātes ieviešanu

Mēs respektējam jūsu konfidencialitāti. Viens e-pasts mēnesī, bez surogātpasta, jebkurā laikā varat atteikties no abonēšanas.