Foodinho – €5,000,000 Fine (Italy, 2024)

€5,000,000Garante per la protezione dei dati personali13 November 2024Italy
final
ePrivacy
Fine

Foodinho was fined €5 million for using tracking and facial recognition technology on its delivery workers without proper consent. This is important because it raises concerns about privacy in the workplace, especially for gig workers. Companies should be transparent about how they use technology to monitor employees and ensure they have consent.

What happened

Foodinho used tracking and facial recognition technology on delivery workers without valid consent.

Who was affected

Delivery workers employed by Foodinho were affected.

What the authority found

The Italian DPA found that Foodinho violated GDPR by failing to obtain consent for tracking and biometric data processing.

Why this matters

This ruling highlights the need for transparency and consent in employee monitoring practices. Businesses should carefully evaluate their use of technology to ensure compliance with data protection laws.

GDPR Articles Cited

AI-verified

Art. 6(GDPR)
Art. 13(GDPR)
Art. 14(GDPR)
Art. 25(GDPR)
Art. 28(GDPR)
Art. 32(GDPR)
Art. 35(GDPR)
Art. 5(1)(a) GDPR
Art. 5(1)(c) GDPR
Art. 5(1)(d) GDPR
Art. 88(GDPR)
Art. 9(2)(b) GDPR
Art. 22(3) GDPR
View original scraped data
Art. 5(1)(c) GDPR
Art. 5(1)(d) GDPR
Art. 5(1)(a) GDPR
Art. 6(GDPR)
Art. 9(2)(b) GDPR
Art. 13(GDPR)
Art. 14(GDPR)
Art. 22(3) GDPR
Art. 25(GDPR)
Art. 28(GDPR)
Art. 32(GDPR)
Art. 35(GDPR)
Art. 88(GDPR)

Original data from scraper before AI verification against source document.

Source verified 2 April 2026
articles corrected
national law identified
scope corrected
Full Legal Summary
Detailed

In this case the controller is Foodinho a food delivery company managing the service “Glovo” in Italy. This company is owned by Glovoapp23 SA, a Spanish holding. The DPA started its investigation following the death of one of its employees while he was delivering food. The controller uses an online platform provided by Glovo ES (appointed as processor) to manage its employees and the deliveries. This platform allows to see a map of every place in the World where Glovo operates and the live location of each employee. The controller, by clicking on a “rider”, can view their location, the time slots in which they are available, the deliveries they performed and the track they followed. The investigation showed that this geolocation function was active, in some cases, even outside working hours and when the app was not active. Moreover, the controller implemented a facial recognition function for identity verification purposes, provided by a processor, Jumio Corporation. According to this procedure, the data subjects (employees) needed to upload an ID card and take a selfie of themselves. After that, the data subjects were asked to take a selfie in random occasions. If they refused to do so, their possibility of getting further delivery time slots was blocked. The controller argued that this processing was necessary to comply with Article 23 of the applicable collective agreement, stating that it’s forbidden for the employees to be replaced by a third party. Furthermore, the investigation showed that the controller’s software allowed to rate the data subjects. The controller argued that this rating function is not active for Italy. The DPA considered that the data processing is made by Foodinho, who fits the definition of controller as it decides the purposes and means of processing, as laid out in the privacy notice given to riders and in the contract with GlovoApp 23 SA. The case at hand does not concern a cross-border data processing activity as the data processi

Violations (1)

Third-Party Cookies Without Consent
critical

Third-party tracking cookies or scripts are loaded without obtaining prior user consent.

Art. 13, 14 GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Foodinho in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

13 November 2024

Authority

Garante per la protezione dei dati personali

Fine Amount

€5,000,000

GDPRhub ID

gdprhub-8604

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Foodinho - Italy (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: