Gambling operator
GDPR enforcement action by Croatian Data Protection Authority (azop) on 2026.
Case details
- Authority
- Croatian Data Protection Authority (azop)
- Date
- 2026
- Controller / Processor
- Gambling operator
- Sector
- Industry and Commerce
- Quoted Articles
- Art. 5 (1) a), c) GDPR, Art. 6 (1) GDPR, Art. 7 GDPR, Art. 9 (1) GDPR, Art. 12 (1) GDPR, Art. 13 GDPR
- Type of violation
- Insufficient legal basis for data processing
Summary
The Croatian DPA has imposed a fine of EUR 2,590,000 on a gambling operator. During an ex officio investigation into the controller's operations, the authority found that, while the controller offered to verify data subjects' eligibility to gamble by checking ID cards, they also offered to verify them via RFID chip or fingerprint. In order to make fingerprint verification possible, the controller scanned four of the data subjects' fingerprints, despite stating that only two were scanned. The consent form, which stated that two fingerprints were to be processed, was signed by 34,933 data subjects. The controller stated that the extra fingerprints were being stored in case of skin damage. However, the authority found that this purpose was not necessary for identification, as other forms of ID could be used. Furthermore, the consent form given to data subjects mixed several different processing activities and purposes for identification and biometric data; therefore, the consent given was neither specific nor free. The stated purposes were also contradictory.