Food company fined EUR 5,000 for unlawful processing of employees’ biometric data

29.09.2026

On 25 September 2026, the Romanian DPA concluded an investigation into a company operating in the food sector. According to the DPA, the controller had processed employees’ biometric data without a legal basis under the GDPR and had infringed the principle of data minimisation. As a result, the Romanian DPA issued an administrative fine amounting to RON equivalent of EUR 5,000.

The investigation followed a complaint from an individual about the company’s use of a fingerprint-based system to control employees’ access to its premises and record their working time. Further to the investigation, the DPA found that the company had not relied on an adequate legal basis for the processing of employees’ biometric data and had infringed the principle of data minimisation, as the envisaged purposes could have been achieved through less intrusive means.

In addition to the fine, the DPA ordered the company to replace the biometric-based access control and timekeeping system with an alternative solution allowing the same purposes to be achieved without processing employees’ biometric data.

The DPA also emphasised that controllers using biometric technologies must be able to demonstrate that an applicable condition for processing is met and that the use of such technologies is necessary and proportionate to the purposes pursued. In this regard, DPA further highlighted the importance of assessing whether the same purposes could be achieved through alternative, less intrusive means, in order to limit the impact on individuals’ privacy and other fundamental rights and freedoms.

The press release is available here (Romanian only).

Statistics