Mercadona S.A. – €2,520,000 Fine (Spain, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Mercadona was fined over 2 million euros for using facial recognition in their stores without proper consent and safeguards. The system tracked everyone entering the stores, including employees and minors, violating privacy rules. This case highlights the importance of having clear privacy measures when using advanced technology like facial recognition.
What happened
Mercadona used facial recognition systems in its stores to track individuals without proper consent or safeguards.
Who was affected
Everyone entering Mercadona stores, including minors and employees, was affected by the facial recognition system.
What the authority found
The Spanish DPA found Mercadona violated GDPR by lacking proper legal basis and safeguards for using facial recognition technology.
Why this matters
This case underscores the need for businesses to ensure compliance with privacy laws when implementing surveillance technologies. Companies should conduct thorough privacy impact assessments and inform individuals about data collection practices.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The Spanish DPA (AEPD) has fined Mercadona S.A. EUR 2,520,000. The controller had installed facial recognition systems in Mercadona stores for the purpose of tracking individuals with criminal convictions or restraining orders. The system captured everyone who entered the stores, including minors and MERCADONA employees. During its investigation, the DPA found numerous privacy violations. For instance, the system violated the principle of data minimization, the principle of necessity and proportionality since the controller could process multiple biometric data - beyond the purpose of the system. In addition, the DPA concluded that Mercadona's privacy impact assessment was deficient as it did not take into account the specific and unique risks to Mercadona's employees posed by data processing through facial recognition systems. Furthermore, MERCADONA had violated its duty to inform according by not properly providing data subjects with information about the processing of their personal data. The original fine of EUR 3,150,000 consisted of EUR 500,000 due to a violation of Art. 5(1)(c), EUR 2,000,000 due to a violation of Art. 6 and Art. 9 of the GDPR, EUR 100,000 due to a violation of Art. 12 and Art. 13 of the GDPR, EUR 500,000 due to a violation of Art. 25(1) of the GDPR, and EUR 50,000 due to a violation of Art. 35 of the GDPR. The original fine was reduced to EUR 2,250,000 due to voluntary payment.
Related Enforcement Actions (1)
Other enforcement actions involving Mercadona S.A. in ES
Details
Fine Date
26 July 2021
Authority
Agencia Española de Protección de Datos
Fine Amount
€2,520,000
Enforcement Tracker ID
ETid-777
About this data
Cite as: Cookie Fines. Mercadona S.A. - Spain (2021). Retrieved from cookiefines.eu
Last updated: