Italy Italy

Azienda sanitaria provinciale di Enna

30,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2021-01-14.

Rank · Sector
#50
of 213 in Employment
Rank · Italy
#162
of 543
Rank · All fines
#882
of 3,042

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2021-01-14
Controller / Processor
Azienda sanitaria provinciale di Enna
Sector
Employment
Quoted Articles
Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 9 GDPR
Type of violation
Insufficient legal basis for data processing

Summary

The Italian DPA (Garante) imposed a fine of EUR 30,000 on Azienda sanitaria provinciale di Enna. The controller processed biometric data of employees for the purpose of registering their attendance. Garante found that such processing was not proportionate and therefore constituted an unjustified infringement of the rights of the data subjects. Subsequently, Garante determined that the processing of biometric data had taken place without a legal basis.

Open original source Links to the regulator's original publication or another source.

Related fines