Spain Spain

CTC EXTERNALIZACIÓN, S.L

365,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2024-02-12.

Rank · Sector
#9
of 213 in Employment
Rank · Spain
#45
of 1,075
Rank · All fines
#280
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2024-02-12
Controller / Processor
CTC EXTERNALIZACIÓN, S.L
Sector
Employment
Quoted Articles
Art. 13 GDPR, Art. 32 GDPR, Art. 35 GDPR
Type of violation
Insufficient fulfilment of information obligations

Summary

The Spanish DPA has imposed a fine of EUR 365,000 on CTC EXTERNALIZACIÓN, S.L.. An employee had filed a complaint with the DPA due to the fact that the controller had requested fingerprints of employees in order to implement a new time and attendance system. However, it was not communicated that the fingerprints would also be stored in the staff portal. For this reason, the DPA found that the controller had violated its duty to inform. The DPA also found that the controller was unable to demonstrate sufficient security measures for the processing of fingerprints. Finally, the DPA found that the controller had failed to carry out a required data protection impact assessment.

Open original source Links to the regulator's original publication or another source.

Related fines