fineConcludedTRY 225,000
KVKK (Turkish Data Protection Authority) — Gym / sports-facility operator (redacted)
February 27, 2020 · Turkey
KVKK fined a gym operator TRY 225,000 for processing members' biometric data (palm/fingerprint) for entry-exit control in violation of proportionality, and ordered it to cease processing and destroy the biometric data.
Key takeaway — how to prevent this
Biometric data (faces, iris, fingerprints) needs an explicit lawful basis or consent. Scraping or capturing it without one is unlawful across the EU/UK and many US states (e.g. Illinois BIPA) — and draws the largest fines.
Inclusion does not imply wrongdoing or liability. Status reflects the latest information we have — always check the official source for current status.