Mercadona S.A. – €2,520,000 Fine (Spain, 2021)

€2,520,000Agencia Española de Protección de Datos26 July 2021Spain
reduced
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Mercadona was fined over 2 million euros for using facial recognition in their stores without proper consent and safeguards. The system tracked everyone entering the stores, including employees and minors, violating privacy rules. This case highlights the importance of having clear privacy measures when using advanced technology like facial recognition.

What happened

Mercadona used facial recognition systems in its stores to track individuals without proper consent or safeguards.

Who was affected

Everyone entering Mercadona stores, including minors and employees, was affected by the facial recognition system.

What the authority found

The Spanish DPA found Mercadona violated GDPR by lacking proper legal basis and safeguards for using facial recognition technology.

Why this matters

This case underscores the need for businesses to ensure compliance with privacy laws when implementing surveillance technologies. Companies should conduct thorough privacy impact assessments and inform individuals about data collection practices.

GDPR Articles Cited

AI-verified

Art. 6 GDPR
Art. 9 GDPR
Art. 12 GDPR
Art. 13 GDPR
Art. 35 GDPR
Art. 5(1)(c) GDPR
Art. 25(1) GDPR
View original scraped data
Art. 5(1)(c) GDPR
Art. 6 GDPR
Art. 9 GDPR
Art. 12 GDPR
Art. 13 GDPR
Art. 25(1) GDPR
Art. 35 GDPR

Original data from scraper before AI verification against source document.

Source verified 5 March 2026
amount discrepancy
Full Legal Summary
Detailed

The Spanish DPA (AEPD) has fined Mercadona S.A. EUR 2,520,000. The controller had installed facial recognition systems in Mercadona stores for the purpose of tracking individuals with criminal convictions or restraining orders. The system captured everyone who entered the stores, including minors and MERCADONA employees. During its investigation, the DPA found numerous privacy violations. For instance, the system violated the principle of data minimization, the principle of necessity and proportionality since the controller could process multiple biometric data - beyond the purpose of the system. In addition, the DPA concluded that Mercadona's privacy impact assessment was deficient as it did not take into account the specific and unique risks to Mercadona's employees posed by data processing through facial recognition systems. Furthermore, MERCADONA had violated its duty to inform according by not properly providing data subjects with information about the processing of their personal data. The original fine of EUR 3,150,000 consisted of EUR 500,000 due to a violation of Art. 5(1)(c), EUR 2,000,000 due to a violation of Art. 6 and Art. 9 of the GDPR, EUR 100,000 due to a violation of Art. 12 and Art. 13 of the GDPR, EUR 500,000 due to a violation of Art. 25(1) of the GDPR, and EUR 50,000 due to a violation of Art. 35 of the GDPR. The original fine was reduced to EUR 2,250,000 due to voluntary payment.

Details

Fine Date

26 July 2021

Authority

Agencia Española de Protección de Datos

Fine Amount

€2,520,000

Enforcement Tracker ID

ETid-777

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Mercadona S.A. - Spain (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: