[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$faKiSrmc63-aciXK1NCwynCz1dtQE2fp-0iShhlec2Vw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"0b0836d9-4ed6-42df-b93b-9aaeb918c475","spanish-university-fined-160k-for-unlawful-biometric-data-processing-in-online-exams","f5e684d6-28c0-4f8b-8082-c831556dfb07","Spanish University Fined €160K for Unlawful Biometric Data Processing in Online Exams","Universidad Europea de Valencia violated GDPR by implementing facial recognition for online exam monitoring without proper legal basis or impact assessment. The university requested consent just one day before exams, creating coercion that invalidated the consent under GDPR Article 9 requirements for biometric data processing. The authority determined that less intrusive alternatives existed but weren't considered, and no Data Protection Impact Assessment was conducted before processing sensitive biometric data. This case demonstrates that time pressure and lack of genuine alternatives can invalidate consent for sensitive data processing, even in educational contexts.","**Immediate actions:**\n- Conduct Data Protection Impact Assessments before implementing any biometric or sensitive data processing systems\n- Review all current biometric data processing activities to ensure valid legal basis exists\n- Provide genuine alternatives to biometric monitoring that don't disadvantage users\n\n**Long-term improvements:**\n- Establish privacy-by-design principles requiring consideration of less intrusive alternatives before deploying surveillance technologies\n- Implement consent management processes that allow sufficient time for informed decision-making without coercion\n- Create data protection governance framework requiring legal review before processing special categories of personal data\n\n**Compliance measures:**\n- Train staff on GDPR requirements for biometric data processing and valid consent collection\n- Establish regular audits of data processing activities to ensure ongoing compliance with privacy regulations",[12,13,14,15,16,17],"GDPR Article 9","GDPR Article 35","GDPR Article 7","NIST Privacy Framework PR.AC-1","ISO 27001 A.18.1.4","CIS Control 3","published","2026-04-10T16:09:54.561929+00:00","2026-04-10T16:09:54.184+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_EXP202405320&diff=51255&oldid=0","aepd-spain-exp202405320-4e8c54","AEPD (Spain) - EXP202405320",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":33,"name":34,"slug":35,"description":36,"color":37},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]