investigationOngoing
UOOU (Czech DPA) — Employer (fingerprint biometric attendance system)
December 31, 2024 · Czech Republic
A completed UOOU inspection found an employer breached the GDPR data-minimisation principle by processing hashes of employees' fingerprints in an electronic attendance system, where the biometric data were not necessary for attendance record-keeping.
Key takeaway — how to prevent this
Biometric data (faces, iris, fingerprints) needs an explicit lawful basis or consent. Scraping or capturing it without one is unlawful across the EU/UK and many US states (e.g. Illinois BIPA) — and draws the largest fines.
Inclusion does not imply wrongdoing or liability. Status reflects the latest information we have — always check the official source for current status.