ASOCIACION DE CONSUMIDORES Y USUARIOS EN ACCION - FACUA – €3,150,000 Fine (Spain, 2021)

€3,150,000Agencia Española de Protección de Datos23 July 2021Spain
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Spanish DPA fined Mercadona for using facial recognition technology to deny entry to people with criminal records without proper consent. This matters because it emphasizes the importance of respecting privacy rights and obtaining consent before using surveillance technologies.

What happened

Mercadona used a facial recognition system to prevent entry to individuals with entry bans.

Who was affected

Individuals who were denied entry to Mercadona stores due to their criminal records were affected.

What the authority found

The DPA found that Mercadona did not have a valid legal basis for processing personal data through facial recognition.

Why this matters

This ruling sets a precedent for how companies must handle biometric data and reinforces the necessity of obtaining consent for surveillance practices. Businesses should evaluate their use of such technologies to avoid similar issues.

GDPR Articles Cited

AI-verified

Art. 6(GDPR)
Art. 9(GDPR)
Art. 12(GDPR)
Art. 13(GDPR)
Art. 35(GDPR)
Art. 5(1)(c) GDPR
Art. 25(1) GDPR
Art. 57(1) GDPR
Art. 83(4)(a) GDPR
Art. 83(5)(a) GDPR
Art. 83(5)(b) GDPR
View original scraped data
Art. 5(1)(c) GDPR
Art. 6(GDPR)
Art. 9(GDPR)
Art. 12(GDPR)
Art. 13(GDPR)
Art. 25(1) GDPR
Art. 35(GDPR)
Art. 57(1) GDPR
Art. 83(4)(a) GDPR
Art. 83(5)(a) GDPR
Art. 83(5)(b) GDPR

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

LOPDGDD

Entities Involved

ASOCIACION DE CONSUMIDORES Y USUARIOS EN ACCION - FACUA
Mercadona, S.A.
Source verified 2 April 2026
articles corrected
national law identified
scope corrected
Full Legal Summary
Detailed

The Spanish DPA (AEPD) launched an investigation on Mercadona, a supermarket chain, after having notice, via the media, that it was using a video surveillance system using facial recognition to prevent access to their premises of people convicted for robbery or other crimes related with Mercadona and with entry bans in force. Afterwards, also two complaints were lodged in this regard by a consumers association and an association for computer enabled crimes and problems. Mercadona started to use this system on 1/06/2020 until 6/05/2021, after the AEPD issued an interim measure ordering the controller to stop the processing. Additionally, the process was brought to court in the meantime, what resulted in an order to stop the processing by a Spanish court in AP Barcelona - Auto 72/2021. The system used a facial recognition process that compares a "dubious biometric sample", obtained from one or more images of a person, against a database of biometric samples already associated with the identity of a person, which have been previously registered through one or more images of that person. To this end, the "dubious biometric samples" are transformed into patterns though algorithmic calculations that are evaluated based on previously established matching thresholds. The data processing included the capture, matching, storage and destruction - in case of negative identification (after 0.3 seconds of its collection) - of the captured biometric image of any person entering the supermarket. Mercadona, the controller, informed that they were relying on a public interest, from Article 6(1)(e) GDPR, for the processing, as it purpose was to ensure the safety of the people and goods, as well as of their premises. The particular national law alleged was the [https://www.boe.es/buscar/act.php?id=BOE-A-2014-3649 Private Security Act]. As regards to biometric data, the controller acknowledged that they were processing special categories of data from Article 9 GDPR, and that they were

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for ASOCIACION DE CONSUMIDORES Y USUARIOS EN ACCION - FACUA in ES

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

23 July 2021

Authority

Agencia Española de Protección de Datos

Fine Amount

€3,150,000

GDPRhub ID

gdprhub-3677

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. ASOCIACION DE CONSUMIDORES Y USUARIOS EN ACCION - FACUA - Spain (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: