[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBYXRDgbOlvJ_F0kRdRUaFxSHg3uaYoDhFBixa5lZ1Go":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"b4dbb56a-5e58-4702-b902-30deb6f6fc73","ANSPDCP (Romania) - TIP TOP FOOD INDUSTRY SRL","anspdcp-romania-tip-top-food-industry-srl-308f45","← Older revision Revision as of 14:58, 29 September 2026 Line 84: Line 84: }} }} The DPA fined a company €5,000 (RON 26,236) for using a system to monitor its employees’ attendance and access to its premises that relies on the processing of personal data in the form of fingerprints. The DPA fined an employer RON 26,236 (€5,000) for using a system to monitor its employees’ attendance and access to its premises that relies on the processing of personal data in the form of fingerprints. == English Summary == == English Summary ==","Romania's National Supervisory Authority for Personal Data Processing (ANSPDCP) fined TIP TOP FOOD INDUSTRY SRL €5,000 (RON 26,236) for violating GDPR. The company used employee fingerprints for attendance and access control, which the DPA deemed unlawful due to a lack of legal basis and violation of data minimization principles. The company was also ordered to replace the system with a less intrusive alternative.","Romania's DPA fines TIP TOP FOOD INDUSTRY SRL €5,000 for unlawful fingerprint data processing.","Help ANSPDCP (Romania) - TIP TOP FOOD INDUSTRY SRL: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 14:08, 29 September 2026 view sourceMba (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators988 editsm Tag: Visual edit← Older edit Latest revision as of 14:58, 29 September 2026 view source Lh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators78 editsmTag: Visual edit Line 84: Line 84: }}}} The DPA fined a company €5,000 (RON 26,236) for using a system to monitor its employees’ attendance and access to its premises that relies on the processing of personal data in the form of fingerprints. The DPA fined an employer RON 26,236 (€5,000) for using a system to monitor its employees’ attendance and access to its premises that relies on the processing of personal data in the form of fingerprints. == English Summary ==== English Summary == Latest revision as of 14:58, 29 September 2026 ANSPDCP - TIP TOP FOOD INDUSTRY SRL Authority: ANSPDCP (Romania) Jurisdiction: Romania Relevant Law: Article 5(1)(c) GDPR Article 9 GDPR Type: Complaint Outcome: n\u002Fa Started: Decided: Published: Fine: 26236.0 RON Parties: n\u002Fa National Case Number\u002FName: TIP TOP FOOD INDUSTRY SRL European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Romanian Original Source: Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (in RO) Initial Contributor: lh The DPA fined an employer RON 26,236 (€5,000) for using a system to monitor its employees’ attendance and access to its premises that relies on the processing of personal data in the form of fingerprints. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts TIP TOP FOOD INDUSTRY SRL (controller) used a time-and-attendance and access-control system on its employees at its premise. This system was using personal data in the form of the employees’ fingerprints. An individual lodged a complaint with the DPA. Holding The DPA held that the system used by the controller violated the principles of data minimisation (Article 5(1)(c) GDPR) and lawfulness because the controller could not rely on a legal basis for processing biometric data pursuant to Article 9 GDPR. According to the DPA, the controller could have used less intrusive means for the objectives of access control and time tracking and therefore violated Article 5(1)(c) GDPR. The DPA stressed that when processing biometric data, the controller must pay specific attention to the principles of lawfulness, necessity, data minimisation and proportionality. This is because of the significant risks arising from the processing of biometric data in case of unauthorized access and the possibility to link biometric data to the identity of the data subject. The DPA fined the controller RON 26,236 (€5,000). Additionally, the DPA ordered the controller to replace the access control and time-keeping system with an alternative system that is less intrusive and does not rely on the processing of biometric data, and thus complies with the principle of data minimisation. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Romanian original. Please refer to the Romanian original for more details. September 25, 2026 Fine for Violation of the GDPR The National Supervisory Authority for Personal Data Processing has concluded an investigation into TIP TOP FOOD INDUSTRY SRL and found a violation of the provisions of Article 5(1)(c) (1)(c) in conjunction with Article 9 of Regulation (EU) 2016\u002F679. As such, TIP TOP FOOD INDUSTRY SRL was assessed an administrative fine of 26,236 lei (equivalent to 5,000 euros). The investigation was conducted following a complaint submitted by an individual alleging the use of a time-and-attendance and access control system based on the processing of employees’ fingerprints at the premises owned by the controller. The investigation found that the operator processed the biometric data of its own employees for the purposes of access control and work time tracking without a legal basis, in violation of the legal requirements established by the provisions of Article 9 of Regulation (EU) 2016\u002F679, in conjunction with a violation of the principle of data minimization, as provided for in Article 5(1)(c) of the same European regulation. At the same time, it was noted that the purposes pursued by the controller could have been achieved through the use of alternative means that were less intrusive to the employees’ privacy. In order to remedy the situation identified and ensure that the processing operations comply with the provisions of Regulation (EU) 2016\u002F679, the Authority also ordered a corrective measure, requiring the controller to ensure compliance with the principle of data minimization, by replacing the access control and time-keeping system based on the processing of employees’ biometric data with an alternative solution that achieves the same objectives without processing biometric data. We emphasize that, when using biometric data, special attention must be paid to compliance with the principles of lawfulness, necessity, proportionality, and data minimization. At the same time, any compromise or unauthorized access to biometric data can pose significant risks to the rights and freedoms of individuals, given the specific nature of such data and the possibility of directly linking it to a person’s identity. Therefore, the use of biometric data must be carried out with particular caution, and data controllers must be able to demonstrate the existence of an applicable legal basis, as well as the fact that the processing is necessary and proportionate to the purposes pursued. In this context, the Authority reminds controllers of their obligation to carefully assess the necessity of using biometric technologies and to opt for solutions that involve alternative, less intrusive means, so as to ensure that risks to privacy and other fundamental rights and freedoms of individuals are minimized. Legal and Communications Department A.N.S.P.D.C.P. Retrieved from \"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=ANSPDCP_(Romania)_-_TIP_TOP_FOOD_INDUSTRY_SRL&oldid=53221\" Categories: ANSPDCP (Romania)RomaniaArticle 5(1)(c) GDPRArticle 9 GDPRRomanian This page was last edited on 29 September 2026, at 14:58. Content is available under Creative Commons Attribution-NonCommercial-ShareAlike unless otherwise noted. Privacy policy About GDPRhub Disclaimers","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=ANSPDCP_(Romania)_-_TIP_TOP_FOOD_INDUSTRY_SRL&diff=53221&oldid=53218","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fc\u002Fc2\u002FLogoRO.jpg","2026-09-29T14:58:25+00:00","2026-09-29T16:00:40.447705+00:00",7,[18,21],{"name":19,"type":20},"ANSPDCP","vendor",{"name":22,"type":23},"TIP TOP FOOD INDUSTRY SRL","product","d95477d7-eb04-4fad-a2dc-be1428040ce7",{"id":24,"icon":26,"name":27,"slug":28},null,"Privacy Fines","privacy-fines",[30,35,40,45],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":41},{"id":42,"icon":26,"name":43,"slug":44},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":46},{"id":24,"icon":26,"name":27,"slug":28},[]]