Back to all lessons
Awareness Lessons
2 weeks ago

Romanian Firm Fined €5,000 for Unlawful Biometric Time-Tracking Without Legal Basis

TIP TOP FOOD INDUSTRY SRL collected and processed employee fingerprints for attendance and access control without establishing a valid legal basis under GDPR, violating Articles 5 and 6. Biometric data is classified as 'special category' data under GDPR Article 9, requiring explicit consent or another qualifying legal ground — none of which the company demonstrated. The core failure was deploying an intrusive biometric system without first conducting a legal and proportionality review, ignoring the data minimization principle. This case illustrates that convenience-driven technology adoption can carry significant legal and financial consequences when privacy-by-design principles are ignored from the outset.

Tactical Insight

Immediate actions

  • Audit all existing systems that collect biometric or special category data and verify a documented lawful basis exists for each.
  • Replace or suspend any biometric processing system that lacks a compliant legal justification until proper grounds are established.

Policy & Governance improvements

  • Conduct a Data Protection Impact Assessment (DPIA) before deploying any system processing biometric, health, or other special category data.
  • Implement a privacy-by-design review process so that less intrusive alternatives (e.g., PIN cards, RFID badges) are evaluated before biometric solutions are selected.
  • Establish a formal data minimization policy requiring business justification for all personal data collected.

Training & Awareness measures

  • Train HR, IT, and procurement teams on GDPR special category data obligations before they evaluate or purchase new workforce management tools.
  • Assign a Data Protection Officer (DPO) or privacy lead with authority to approve or reject data collection systems prior to deployment.