[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f70VSCtMxcAAoTt-_BnvmM_l3lvE3pb6d86jiMRhu_lc":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"330b558c-f290-441f-ab1d-5a41e2ddccf0","ANSPDCP (Romania) - TIP TOP FOOD INDUSTRY SRL","anspdcp-romania-tip-top-food-industry-srl-f57427","← Older revision Revision as of 08:23, 29 September 2026 Line 90: Line 90: === Facts === === Facts === TIP TOP FOOD INDUSTRY SRL (controller) used a time-and-attendance and access-control system on its employees at its premise. This system was using personal data in the form of the employees’ fingerprints. TIP TOP FOOD INDUSTRY SRL (controller) used a time-and-attendance and access-control system on its employees at its premise. This system was using personal data in the form of the employees’ fingerprints. An individual lodged a complaint with the DPA. An individual lodged a complaint with the DPA. === Holding === === Holding === The DPA held that the system used by the controller violated the principles of data minimisation ([[Article 5 GDPR|Article 5(1)(c) GDPR]]) and lawfulness because the controller could not rely on a legal basis for processing biometric data pursuant to [[Article 9 GDPR|Article 9 GDPR]]. The DPA held that the system used by the controller violated the principles of data minimisation ([[Article 5 GDPR|Article 5(1)(c) GDPR]]) and lawfulness because the controller could not rely on a legal basis for processing biometric data pursuant to [[Article 9 GDPR]]. According to the DPA, the controller could have used less intrusive means for the objectives of access control and time tracking and therefore violated [[Article 5 GDPR|Article 5(1)(c) GDPR]]. The DPA stressed that when processing biometric data, the controller must pay specific attention to the principles of lawfulness, necessity, data minimisation and proportionality. This is because of the significant risks arising from the processing of biometric data in case of unauthorized access and the possibility to link biometric data to the identity of the data subject. According to the DPA, the controller could have used less intrusive means for the objectives of access control and time tracking and therefore violated [[Article 5 GDPR|Article 5(1)(c) GDPR]]. The DPA stressed that when processing biometric data, the controller must pay specific attention to the principles of lawfulness, necessity, data minimisation and proportionality. This is because of the significant risks arising from the processing of biometric data in case of unauthorized access and the possibility to link biometric data to the identity of the data subject. The DPA fined the controller Romanian RON 26,236 (€5,000). Additionally, the DPA ordered the controller to replace the access control and time-keeping system with an alternative system that is less intrusive and does not rely on the processing of biometric data, and thus complies with the principle of data minimisation. The DPA fined the controller Romanian RON 26,236 (€5,000). Additionally, the DPA ordered the controller to replace the access control and time-keeping system with an alternative system that is less intrusive and does not rely on the processing of biometric data, and thus complies with the principle of data minimisation.","The Romanian Data Protection Authority (ANSPDCP) fined TIP TOP FOOD INDUSTRY SRL €5,000 for violating GDPR principles. The company used employee fingerprints for time-and-attendance and access control without a proper legal basis, infringing on data minimization and lawfulness. The DPA ordered the company to replace the system with a less intrusive alternative.","Romania's DPA fines TIP TOP FOOD INDUSTRY SRL €5,000 for unlawful biometric data processing.","Help ANSPDCP (Romania) - TIP TOP FOOD INDUSTRY SRL: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 08:23, 29 September 2026 view sourceLh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators75 edits Tag: Decisions [1.0] Latest revision as of 08:23, 29 September 2026 view source Lh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators75 editsmTag: Visual edit Line 90: Line 90: === Facts ====== Facts === TIP TOP FOOD INDUSTRY SRL (controller) used a time-and-attendance and access-control system on its employees at its premise. This system was using personal data in the form of the employees’ fingerprints. TIP TOP FOOD INDUSTRY SRL (controller) used a time-and-attendance and access-control system on its employees at its premise. This system was using personal data in the form of the employees’ fingerprints. An individual lodged a complaint with the DPA.An individual lodged a complaint with the DPA. === Holding ====== Holding === The DPA held that the system used by the controller violated the principles of data minimisation ([[Article 5 GDPR|Article 5(1)(c) GDPR]]) and lawfulness because the controller could not rely on a legal basis for processing biometric data pursuant to [[Article 9 GDPR|Article 9 GDPR]]. The DPA held that the system used by the controller violated the principles of data minimisation ([[Article 5 GDPR|Article 5(1)(c) GDPR]]) and lawfulness because the controller could not rely on a legal basis for processing biometric data pursuant to [[Article 9 GDPR]]. According to the DPA, the controller could have used less intrusive means for the objectives of access control and time tracking and therefore violated [[Article 5 GDPR|Article 5(1)(c) GDPR]]. The DPA stressed that when processing biometric data, the controller must pay specific attention to the principles of lawfulness, necessity, data minimisation and proportionality. This is because of the significant risks arising from the processing of biometric data in case of unauthorized access and the possibility to link biometric data to the identity of the data subject.According to the DPA, the controller could have used less intrusive means for the objectives of access control and time tracking and therefore violated [[Article 5 GDPR|Article 5(1)(c) GDPR]]. The DPA stressed that when processing biometric data, the controller must pay specific attention to the principles of lawfulness, necessity, data minimisation and proportionality. This is because of the significant risks arising from the processing of biometric data in case of unauthorized access and the possibility to link biometric data to the identity of the data subject. The DPA fined the controller Romanian RON 26,236 (€5,000). Additionally, the DPA ordered the controller to replace the access control and time-keeping system with an alternative system that is less intrusive and does not rely on the processing of biometric data, and thus complies with the principle of data minimisation. The DPA fined the controller Romanian RON 26,236 (€5,000). Additionally, the DPA ordered the controller to replace the access control and time-keeping system with an alternative system that is less intrusive and does not rely on the processing of biometric data, and thus complies with the principle of data minimisation. Latest revision as of 08:23, 29 September 2026 ANSPDCP - TIP TOP FOOD INDUSTRY SRL Authority: ANSPDCP (Romania) Jurisdiction: Romania Relevant Law: Article 5(1)(c) GDPR Article 9 GDPR Type: Complaint Outcome: n\u002Fa Started: Decided: Published: Fine: 26236.0 RON Parties: n\u002Fa National Case Number\u002FName: TIP TOP FOOD INDUSTRY SRL European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Romanian Original Source: Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (in RO) Initial Contributor: lh The DPA fined a company €5,000 (RON 26,236) for using a system to monitor its employees’ attendance and access to its premises that relies on the processing of personal data in the form of fingerprints. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts TIP TOP FOOD INDUSTRY SRL (controller) used a time-and-attendance and access-control system on its employees at its premise. This system was using personal data in the form of the employees’ fingerprints. An individual lodged a complaint with the DPA. Holding The DPA held that the system used by the controller violated the principles of data minimisation (Article 5(1)(c) GDPR) and lawfulness because the controller could not rely on a legal basis for processing biometric data pursuant to Article 9 GDPR. According to the DPA, the controller could have used less intrusive means for the objectives of access control and time tracking and therefore violated Article 5(1)(c) GDPR. The DPA stressed that when processing biometric data, the controller must pay specific attention to the principles of lawfulness, necessity, data minimisation and proportionality. This is because of the significant risks arising from the processing of biometric data in case of unauthorized access and the possibility to link biometric data to the identity of the data subject. The DPA fined the controller Romanian RON 26,236 (€5,000). Additionally, the DPA ordered the controller to replace the access control and time-keeping system with an alternative system that is less intrusive and does not rely on the processing of biometric data, and thus complies with the principle of data minimisation. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Romanian original. Please refer to the Romanian original for more details. September 25, 2026 Fine for Violation of the GDPR The National Supervisory Authority for Personal Data Processing has concluded an investigation into TIP TOP FOOD INDUSTRY SRL and found a violation of the provisions of Article 5(1)(c) (1)(c) in conjunction with Article 9 of Regulation (EU) 2016\u002F679. As such, TIP TOP FOOD INDUSTRY SRL was assessed an administrative fine of 26,236 lei (equivalent to 5,000 euros). The investigation was conducted following a complaint submitted by an individual alleging the use of a time-and-attendance and access control system based on the processing of employees’ fingerprints at the premises owned by the controller. The investigation found that the operator processed the biometric data of its own employees for the purposes of access control and work time tracking without a legal basis, in violation of the legal requirements established by the provisions of Article 9 of Regulation (EU) 2016\u002F679, in conjunction with a violation of the principle of data minimization, as provided for in Article 5(1)(c) of the same European regulation. At the same time, it was noted that the purposes pursued by the controller could have been achieved through the use of alternative means that were less intrusive to the employees’ privacy. In order to remedy the situation identified and ensure that the processing operations comply with the provisions of Regulation (EU) 2016\u002F679, the Authority also ordered a corrective measure, requiring the controller to ensure compliance with the principle of data minimization, by replacing the access control and time-keeping system based on the processing of employees’ biometric data with an alternative solution that achieves the same objectives without processing biometric data. We emphasize that, when using biometric data, special attention must be paid to compliance with the principles of lawfulness, necessity, proportionality, and data minimization. At the same time, any compromise or unauthorized access to biometric data can pose significant risks to the rights and freedoms of indi","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=ANSPDCP_(Romania)_-_TIP_TOP_FOOD_INDUSTRY_SRL&diff=53205&oldid=53204","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fc\u002Fc2\u002FLogoRO.jpg","2026-09-29T08:23:59+00:00","2026-09-29T10:00:17.645822+00:00",7,[18,21],{"name":19,"type":20},"ANSPDCP","vendor",{"name":22,"type":23},"time-and-attendance and access-control system","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40,45],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":41},{"id":42,"icon":26,"name":43,"slug":44},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":46},{"id":47,"icon":26,"name":48,"slug":49},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]