Sportitalia – €20,000 Fine (Italy, 2022)

€20,000Garante per la protezione dei dati personali10 November 2022Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Sportitalia was fined EUR 20,000 by the Italian Data Protection Authority for using fingerprints to track employee attendance without proper justification. The authority found this practice unnecessary and that employees weren't properly informed. This case highlights the need for proportionality and transparency in using biometric data.

What happened

Sportitalia used employee fingerprints to track attendance without proper justification or informing employees.

Who was affected

Employees whose biometric data (fingerprints) were processed by Sportitalia.

What the authority found

The Italian DPA fined Sportitalia for unjustified and non-transparent processing of biometric data, violating GDPR.

Why this matters

This ruling stresses that companies must justify the use of sensitive data like fingerprints and ensure employees are fully informed. Businesses should evaluate the necessity of biometric data and ensure transparency to avoid similar fines.

GDPR Articles Cited

Art. 9 GDPR
Art. 13 GDPR
Art. 5(1)(a) GDPR
Art. 30(1)(c) GDPR
Full Legal Summary
Detailed

The Italian DPA (Garante) imposed a fine of EUR 20,000 on Sportitalia. The controller processed biometric data (fingerprints) of employees for the purpose of registering their attendance. Garante found that such extensive processing was not proportionate and therefore constituted an unjustified infringement of the rights of the data subjects. Furthermore, Garante determined that the processing of biometric data had taken place without sufficiently informing the data subjects about the processing.

Related Enforcement Actions (0)

No other enforcement actions found for Sportitalia in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

10 November 2022

Authority

Garante per la protezione dei dati personali

Fine Amount

€20,000

Enforcement Tracker ID

ETid-1542

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Sportitalia - Italy (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: