Skip to content
News · GDPRhub EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

ANSPDCP (Romania) - TIP TOP FOOD INDUSTRY SRL

The DPA fined a company €5,000 (RON 26,236) for using a system to monitor its employees’ attendance and access to its premises that relies on the processing of personal data in the form of fingerprints.

How it connects

C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 Supervisory Authorities Supervision Consent
C-65/23 MK v K GmbH In a preliminary ruling requested by the German Federal Labour Court (Bundesarbeitsgericht), the Court of Justice of the European Union interpreted Article 88 of the GDPR… CJEU ·Eighth Chamber Dec 19, 2024 Personal Data Types of Special Categories of Personal Data Liability
Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB 2020 Personal Data Privacy by Design & Default Processing
Guidelines 2/2018 derogations of Article 49 under Regulation 2016/679 Guidelines on derogations of Article 49 Guidelines ·EDPB May 25, 2018 Lawful Basis Privacy Shield Legitimate Interest

Full text

Machine translation of the decision, via GDPRhub — not the official text.

The DPA fined a company €5,000 (RON 26,236) for using a system to monitor its employees’ attendance and access to its premises that relies on the processing of personal data in the form of fingerprints. English Summary. Facts. TIP TOP FOOD INDUSTRY SRL (controller) used a time-and-attendance and access-control system on its employees at its premise. This system was using personal data in the form of the employees’ fingerprints. An individual lodged a complaint with the DPA. Holding. The DPA held that the system used by the controller violated the principles of data minimisation (Article 5(1)(c) GDPR) and lawfulness because the controller could not rely on a legal basis for processing biometric data pursuant to Article 9 GDPR. According to the DPA, the controller could have used less intrusive means for the objectives of access control and time tracking and therefore violated Article 5(1)(c) GDPR. The DPA stressed that when processing biometric data, the controller must pay specific att