Romanian Food Company Fined for Unlawful Biometric Employee Tracking

Tip Top Food Industry SRL, the operator behind Romania’s Tip Top pastry chain, has been ordered to pay €5,000 in fines following a data protection enforcement action by the country’s privacy regulator.

The National Authority for the Supervision of Personal Data Processing (ANSPDCP) determined that the food company unlawfully processed biometric fingerprint data of its workforce for attendance tracking and building access control purposes. The investigation found systematic violations of the General Data Protection Regulation, specifically breaching articles 5 and 9 concerning data minimization principles and the processing of special category personal data.

Unlawful Biometric Processing

Biometric data, including fingerprints, represents one of the most sensitive categories of personal information under GDPR. Processing such data requires explicit legal grounds and heightened safeguards. In this case, Tip Top Food Industry lacked the necessary legal basis to collect and store employee fingerprint records.

The ANSPDCP’s statement on the matter highlighted the core violation: “In the investigation it was found that the operator processed biometric data of its own employees for access control and time‑keeping purposes without a legal basis, violating GDPR provisions on data minimisation and special category data.”

The fine, equivalent to approximately 26,236 lei in Romanian currency, represents a proportionate penalty for the infraction. Beyond the monetary sanction, the regulatory authority has mandated that Tip Top Food Industry discontinue its current biometric system entirely.

Mandatory System Replacement

As part of the enforcement decision, the company must implement an alternative time-keeping and access control solution that does not rely on intrusive biometric collection. This requirement reflects GDPR’s principle of data minimization, which obligates organizations to limit personal data processing to what is necessary for legitimate purposes.

The ruling demonstrates Romania’s data protection authority maintaining vigilant oversight of employer practices. Employee privacy rights represent a particular concern for regulators across Europe, as power imbalances between employers and workers can create pressure for consent that may not be genuinely voluntary.

Broader European Compliance Landscape

The case underscores ongoing challenges within the European startup and business ecosystem regarding GDPR compliance, particularly regarding emerging technologies and employee monitoring practices. Similar enforcement actions have been pursued by data protection authorities across the EU, with regulators in countries including Austria, Germany, and France scrutinizing biometric systems in workplace settings.

For businesses operating across the EU, the decision serves as a reminder that technological convenience cannot override fundamental privacy protections. Organizations implementing employee monitoring systems must conduct thorough legal assessments and ensure adequate legal grounds exist before deploying biometric technologies. As regulatory enforcement accelerates across member states, compliance investments increasingly represent essential operational requirements rather than optional considerations for companies processing personal data at scale.

Leave a Comment