Romanian Firm Fined €5,000 for Unlawful Biometric Time-Tracking Without Legal Basis
TIP TOP FOOD INDUSTRY SRL collected and processed employee fingerprints for attendance and access control without establishing a valid legal basis under GDPR, violating Articles 5 and 6. Biometric data is classified as 'special category' data under GDPR Article 9, requiring explicit consent or another qualifying legal ground — none of which the company demonstrated. The core failure was deploying an intrusive biometric system without first conducting a legal and proportionality review, ignoring the data minimization principle. This case illustrates that convenience-driven technology adoption can carry significant legal and financial consequences when privacy-by-design principles are ignored from the outset.
Tactical Insight
Immediate actions
- Audit all existing systems that collect biometric or special category data and verify a documented lawful basis exists for each.
- Replace or suspend any biometric processing system that lacks a compliant legal justification until proper grounds are established.
Policy & Governance improvements
- Conduct a Data Protection Impact Assessment (DPIA) before deploying any system processing biometric, health, or other special category data.
- Implement a privacy-by-design review process so that less intrusive alternatives (e.g., PIN cards, RFID badges) are evaluated before biometric solutions are selected.
- Establish a formal data minimization policy requiring business justification for all personal data collected.
Training & Awareness measures
- Train HR, IT, and procurement teams on GDPR special category data obligations before they evaluate or purchase new workforce management tools.
- Assign a Data Protection Officer (DPO) or privacy lead with authority to approve or reject data collection systems prior to deployment.