GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

A gym owner company

Country
Turkey
Fine
Unknown
Date
2019-05-31
Sector
Technical Sector
Articles
Article 6 of GDPRArticle 4, 12 and 18 of the Turkish DPL

Insufficient technical and organisational measures to ensure information security + Insufficient legal basis for data processing

The KVKK analyses the possibility of biometric data processing conditions for gyms in its decision. Relavant GDPR regulations and Turkish DPL regulations are evaluated in the decision. KVKK forbids the processing of such data underlining the principle of proportionality even though data subjects provide their explicit consents. A fine was issued based on the lack of technical and organisational measures. KVKK finally orders all data controllers to either destroy or anonymyse the relevant biometric data in terms of controlling the entrance and exit information of users. Authority: Turkish Data Protection Authority (KVKK)