GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Dutch DPA

Country
Netherlands
Fine
725,000 EUR
Date
2020-04-30
Sector
Business Sector
Articles
Art. 9(1) GDPR

Processing of fingerprints (biometric data) by obliging employees to have their fingerprints scanned when they log in and out for work.

The processing of biometric personal data deserves specific protection because of this unique identification. By virtue of Article 9 GDPR, the processing of biometric data is therefore prohibited, unless one of the exhaustive listed exceptions to Article 9(2) of the GDPR arise. In this case the controller couldn't demonstrate that its employees have given (explicit) permission for the processing of their fingerprints. Thereby several employees stated that fingerprint scanning was mandatory and that permission is not requested for this, not even in the context of signing the employment contract or by receipt of the employee handbook. Some employees where not informed at all. Whether identification by means of biometrics is necessary and proportionate for authentication or security purposes does not hold in this case, because there were other less far-reaching ways to make sure that the employees made their workhours.

Additional information

<link https://www.autoriteitpersoonsgegevens.nl/sites/default/files/atoms/files/onderzoek_vingerafdrukken_personeel.pdf>https://www.autoriteitpersoonsgegevens.nl/sites/default/files/atoms/files/onderzoek_vingerafdrukken_personeel.pdf</link>