ASOCIACION DE CONSUMIDORES Y USUARIOS EN ACCION - FACUA – €3,150,000 Fine (Spain, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Spanish DPA fined Mercadona for using facial recognition technology to deny entry to people with criminal records without proper consent. This matters because it emphasizes the importance of respecting privacy rights and obtaining consent before using surveillance technologies.
What happened
Mercadona used a facial recognition system to prevent entry to individuals with entry bans.
Who was affected
Individuals who were denied entry to Mercadona stores due to their criminal records were affected.
What the authority found
The DPA found that Mercadona did not have a valid legal basis for processing personal data through facial recognition.
Why this matters
This ruling sets a precedent for how companies must handle biometric data and reinforces the necessity of obtaining consent for surveillance practices. Businesses should evaluate their use of such technologies to avoid similar issues.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
Entities Involved
The Spanish DPA (AEPD) launched an investigation on Mercadona, a supermarket chain, after having notice, via the media, that it was using a video surveillance system using facial recognition to prevent access to their premises of people convicted for robbery or other crimes related with Mercadona and with entry bans in force. Afterwards, also two complaints were lodged in this regard by a consumers association and an association for computer enabled crimes and problems. Mercadona started to use this system on 1/06/2020 until 6/05/2021, after the AEPD issued an interim measure ordering the controller to stop the processing. Additionally, the process was brought to court in the meantime, what resulted in an order to stop the processing by a Spanish court in AP Barcelona - Auto 72/2021. The system used a facial recognition process that compares a "dubious biometric sample", obtained from one or more images of a person, against a database of biometric samples already associated with the identity of a person, which have been previously registered through one or more images of that person. To this end, the "dubious biometric samples" are transformed into patterns though algorithmic calculations that are evaluated based on previously established matching thresholds. The data processing included the capture, matching, storage and destruction - in case of negative identification (after 0.3 seconds of its collection) - of the captured biometric image of any person entering the supermarket. Mercadona, the controller, informed that they were relying on a public interest, from Article 6(1)(e) GDPR, for the processing, as it purpose was to ensure the safety of the people and goods, as well as of their premises. The particular national law alleged was the [https://www.boe.es/buscar/act.php?id=BOE-A-2014-3649 Private Security Act]. As regards to biometric data, the controller acknowledged that they were processing special categories of data from Article 9 GDPR, and that they were
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for ASOCIACION DE CONSUMIDORES Y USUARIOS EN ACCION - FACUA in ES
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
23 July 2021
Authority
Agencia Española de Protección de Datos
Fine Amount
€3,150,000
GDPRhub ID
gdprhub-3677About this data
Cite as: Cookie Fines. ASOCIACION DE CONSUMIDORES Y USUARIOS EN ACCION - FACUA - Spain (2021). Retrieved from cookiefines.eu
Last updated: