[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqfXLMgvMo7TfOuIzVKVMOtDdnThDL9r26dk1hza1yeI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"2230f14c-b728-4251-9e2d-91bda89ce340","romanian-firm-fined-5000-for-unlawful-biometric-employee-tracking","26a44aa0-6995-4dc6-ab98-8ea15f587da0","Romanian Firm Fined €5,000 for Unlawful Biometric Employee Tracking","TIP TOP FOOD INDUSTRY SRL deployed a fingerprint-based attendance and access control system without a lawful basis under GDPR, violating the data minimization principle by collecting biometric data — a special category requiring strict justification — when less intrusive alternatives were available. Biometric data is inherently sensitive and irreversible; unlike passwords, a compromised fingerprint cannot be changed. The DPA's intervention highlights that organizations must conduct a proportionality assessment before processing special category data and must demonstrate necessity, not just convenience. This case underscores that operational efficiency goals do not override employees' fundamental rights to data protection.","**Immediate actions:**\n- Conduct a Data Protection Impact Assessment (DPIA) before deploying any biometric or special-category data processing system.\n- Replace biometric attendance systems with less intrusive alternatives (e.g., PIN cards, RFID badges) where no clear legal necessity exists.\n\n**Policy & Compliance measures:**\n- Establish an internal review process requiring DPO sign-off and documented lawful basis before any new personal data processing system is introduced.\n- Map all existing data processing activities involving special-category data and validate each against GDPR Article 9 lawful bases.\n- Train HR and operations teams on GDPR obligations specific to employee data, including biometrics and consent requirements.\n\n**Long-term improvements:**\n- Embed data minimization and privacy-by-design principles into procurement and system design workflows.\n- Schedule annual audits of all access control and workforce management systems to ensure ongoing compliance with data protection regulations.\n- Develop a vendor assessment checklist to evaluate the privacy implications of any third-party attendance or HR technology before adoption.",[12,13,14,15,16,17,18,19,20],"GDPR Article 5(1)(c) – Data Minimisation","GDPR Article 9 – Processing of Special Categories of Personal Data","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","GDPR Article 88 – Processing in the Context of Employment","NIST SP 800-122 – Guide to Protecting the Confidentiality of PII","NIST Privacy Framework PR.DS-P1 – Data minimization","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 – Privacy Information Management System","EDPB Guidelines 05\u002F2022 on the use of facial recognition technology in the area of law enforcement","published","2026-09-29T17:20:26.524435+00:00","2026-09-29T17:20:26.435+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=ANSPDCP_(Romania)_-_TIP_TOP_FOOD_INDUSTRY_SRL&diff=53218&oldid=53205","anspdcp-romania-tip-top-food-industry-srl-ed7d53","ANSPDCP (Romania) - TIP TOP FOOD INDUSTRY SRL",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":42,"name":43,"slug":44,"description":45,"color":46},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]