fineConcluded€50,000
Garante per la protezione dei dati personali (Garante Privacy) — eCampus
January 29, 2026 · Italy · Education
The Garante fined eCampus €50,000 for GDPR violations related to its use of a facial recognition system to verify student attendance during online lessons. The authority found issues with invalid consent, lack of a proper legal basis for processing biometric data, and breaches of data protection principles.
Key takeaway — how to prevent this
Biometric data (faces, iris, fingerprints) needs an explicit lawful basis or consent. Scraping or capturing it without one is unlawful across the EU/UK and many US states (e.g. Illinois BIPA) — and draws the largest fines.
Inclusion does not imply wrongdoing or liability. Status reflects the latest information we have — always check the official source for current status.