Back to all lessons
Awareness Lessons
6 months ago

Spanish University Fined €160K for Unlawful Biometric Data Processing in Online Exams

Universidad Europea de Valencia violated GDPR by implementing facial recognition for online exam monitoring without proper legal basis or impact assessment. The university requested consent just one day before exams, creating coercion that invalidated the consent under GDPR Article 9 requirements for biometric data processing. The authority determined that less intrusive alternatives existed but weren't considered, and no Data Protection Impact Assessment was conducted before processing sensitive biometric data. This case demonstrates that time pressure and lack of genuine alternatives can invalidate consent for sensitive data processing, even in educational contexts.

Tactical Insight

Immediate actions

  • Conduct Data Protection Impact Assessments before implementing any biometric or sensitive data processing systems
  • Review all current biometric data processing activities to ensure valid legal basis exists
  • Provide genuine alternatives to biometric monitoring that don't disadvantage users

Long-term improvements

  • Establish privacy-by-design principles requiring consideration of less intrusive alternatives before deploying surveillance technologies
  • Implement consent management processes that allow sufficient time for informed decision-making without coercion
  • Create data protection governance framework requiring legal review before processing special categories of personal data

Compliance measures

  • Train staff on GDPR requirements for biometric data processing and valid consent collection
  • Establish regular audits of data processing activities to ensure ongoing compliance with privacy regulations