fineConcluded€5,000
ANSPDCP (Romanian DPA) — Entirely Shipping & Trading S.R.L.
September 15, 2020 · Romania
ANSPDCP fined Entirely Shipping & Trading ~EUR 5,000 for unlawfully processing employees' biometric data (fingerprints) for access control under Article 9 GDPR when less-intrusive means were available.
Key takeaway — how to prevent this
Biometric data (faces, iris, fingerprints) needs an explicit lawful basis or consent. Scraping or capturing it without one is unlawful across the EU/UK and many US states (e.g. Illinois BIPA) — and draws the largest fines.
Inclusion does not imply wrongdoing or liability. Status reflects the latest information we have — always check the official source for current status.