orderConcluded
ANSPDCP (Romanian DPA) — ARRISE LIVE SRL
March 12, 2026 · Romania
ANSPDCP issued a warning to ARRISE LIVE over its plan to deploy a facial-recognition system for employee access control, finding the biometric processing would breach GDPR lawfulness, necessity and proportionality and recommending less-intrusive access methods.
Key takeaway — how to prevent this
Biometric data (faces, iris, fingerprints) needs an explicit lawful basis or consent. Scraping or capturing it without one is unlawful across the EU/UK and many US states (e.g. Illinois BIPA) — and draws the largest fines.
Inclusion does not imply wrongdoing or liability. Status reflects the latest information we have — always check the official source for current status.