HDPA (Greece) - 42/2024
| HDPA - 42/2024 | |
|---|---|
| Authority: | HDPA (Greece) |
| Jurisdiction: | Greece |
| Relevant Law: | Article 5(1)(a) GDPR Article 35 GDPR Article 38 GDPR Article 7 Law 4624/2019 |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | 22.04.2020 |
| Decided: | 23.12.2019 |
| Published: | 24.11.2018 |
| Fine: | 56,000 EUR |
| Parties: | n/a |
| National Case Number/Name: | 42/2024 |
| European Case Law Identifier: | n/a |
| Appeal: | n/a |
| Original Language(s): | Greek |
| Original Source: | HDPA's website (in EL) |
| Initial Contributor: | Iliana Papantoni |
The HPDA found that a Nautical Club unlawfully processed biometric data via an access control system and failed to conduct a DPIA, imposed €56,000 in fines, and ordered suspension of processing until a DPIA is completed.
English Summary
Facts
A companion of a member asked the HDPA how to object to biometric processing at a private nautical club, which triggered the HDPA’s investigation. On 6 April 2022, members were told access would henceforth be possible only via a new facial-recognition system, and the existing RFID card system would be disabled. The club asserted multiple Article 6 bases and Article 9 exceptions, circulated vendor assurances about encryption and non-reconstructability, and claimed the system did not process “sensitive” data, while also communicating that refusal could jeopardise membership. After objections, the club amended its internal rules to state that, upon withdrawal of consent, members could use a card, yet communications simultaneously suggested the card system had been discontinued and refusal could affect membership. The HDPA convened a hearing to assess alleged infringements including the lack of a DPIA and concerns over DPO independence. The biometric system processed special category data through facial recognition for roughly 3,500 data subjects (members and companions), indicating large-scale processing with heightened risk.
Holding
The HDPA confirmed that facial-recognition data are biometric data under Article 4 (14) and thus special category data under Article 9(1), requiring strict compliance with the principles of lawfulness, necessity, proportionality, and data minimisation. The controller failed to demonstrate necessity and proportionality, as less intrusive access-control methods were reasonably available, so the processing violated Article 5(1)(a) and the assessment of Article 6 and Article 9 bases was unnecessary once unlawfulness was established. The HDPA emphasised that consent cannot cure non-compliance with other controller obligations, and does not validate processing that breaches core principles. Given the large-scale special category processing using innovative technology and the potential high risk, a DPIA was required but not properly conducted. The HDPA ordered the controller to carry out a DPIA and to suspend biometric processing until completion, and imposed administrative fines totalling €56,000: €28,000 for unlawfulness under Article 5(1)(a), €14,000 for failing to conduct a DPIA (Article 35), and €14,000 for violating DPO independence (Article 38(3)).
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Greek original. Please refer to the Greek original for more details.
Athens, 18-11-2024
No. Prot.: 3211
DECISION 42/2024
The Personal Data Protection Authority met following
the invitation of its President in a meeting on Tuesday 28-07-2023 at 10:00 a.m. and
in a second meeting on Tuesday 19-12-2023 at 10:00 a.m., in order to examine
the case referred to in the history of this case. The President of the
Authority, Konstantinos Menudakos, the regular members Spyridon Vlachopoulos, Konstantinos
Lambrinoudakis, Charalambos Anthopoulos, Aikaterini Iliadou, Grigorios Tsolias and
Christos Kalloniatis, as rapporteur, were present. Present, without the right to vote, were Ioannis
Lykotrafitis, specialist scientist-informatics, Stefania Plota, specialist scientist
-lawyer, as assistants to the rapporteur and Irini Papageorgopoulou, employee of the
administrative affairs department, as secretary.
The Authority took into account the following:
With his request under no. prot. C/EIS/6282/20-04-2022, A addressed the Personal Data Protection Authority (hereinafter referred to as the “Authority”), asking how he can object as an escort of a member of the Vouliagmeni Nautical Club
(hereinafter referred to as “NOB” or “Group”) to the processing of his biometric data, about which he was informed by NOB by e-mail. According to this
information, the controlled entry-exit system will no longer be carried out by
showing, at the entrance to a guard, the member’s escort card but by
processing his biometric characteristics, without providing further
information and justification for the said measure.
1 The above question, interpreted either as a request for information to exercise a right of the subject, or as a question of the lawfulness of processing, falls outside the competences of the Authority. However, due to the importance of the issue, the Authority considered that it should be dealt with ex officio and, with its document No. C/ΕΣΕ/1226/20-05-2022
taking into account the renewed Operating Regulations of the group,
which, as posted on its website (last checked 19-05-
2022), state, in provision 2.1, the following: “Biometric characteristics are used for the entry of Members (main and protected) into the N.O.B. After their registration in the biometric features system, the plastic cards are cancelled. On the first visit of the member and his family to the Club, a short visit to the N.O.B. Secretariat is required to register the member in the system.”, called on N.O.B. to provide clarifications on the processing of biometric data for the control of its members’ access to the Club, including, among others, the legal basis and other characteristics of the intended processing, as well as whether an impact assessment study has been carried out on the effects of the processing on the protection of personal data. N.O.B. with the document no. C/ΕΙΣ/7663/02-06-2022, responded to the Authority
that “…until recently, only the entry system using an individual
magnetic card for each member, which also carried the photograph of the face
of each member, was used. Today, an entry system using an individual card for
each member, which also carries the photograph of the face, and is identified by the
display of a police ID or other public identification document. Finally,
an identification system is also used in parallel, which is based on
the geometry of the face, which is unique for each person. The
coordinates of each person are therefore processed by a very sophisticated algorithm, which
creates for each person a code like the one that an RFID card would have”. Specifically
for the technical specifications of this new system, the NOB states that “the
biometric authentic devices of ZKTeco, which concern access control (Access
Control) and time attendance (Time Attendance), are in accordance with personal
data, meaning that the biometric data of their users belong to them, because they are
1
2See Decision 52/2018 of the Data Protection Authority
https://nov.gr/wp-content/uploads/2021/06/Κανονισμός-Λειτυργίας-final-2022.pdf
2appropriately secured and stored with encryption methods within the
devices….With ZKTecoTimeAttendanceorAccessControl systems, images are never
stored. Photographs are taken and distinct
characteristics known as data elements are collected from the image. A studied algorithm is used to convert the data into a biometric template in the form of a digital code. ZKTeco Biometric Algorithms and Templates: As an additional security measure, the biometric template is then encrypted and the authentication process is carried out on ZK's palm and face recognition machines, which takes place inside the devices without an external factor. The necessary data is compared with the data on the terminal and the comparison result is exported. The comparison result is stored locally and sent to the client via the SSL/TSL encryption algorithm. The encryption algorithm for the data sent is random. The result is a system that provides the highest level of protection for biometric data, ensuring compliance with the GDPR personal data. Biometric templates can only be
recognized by the ZKTeco algorithm and cannot be converted into biometric images other than
this algorithm. ZKTeco Biometric templates cannot
be recognized by other biometric algorithms.” As for the legal basis of
processing, N.O.B. states that: “In this case, the lawfulness of the
processing pursuant to Article 6, paragraph 1 of the GDPR and the exceptions of Article 9, paragraph 2 of the GDPR both apply, if
it is considered that the data in question are sensitive personal data”, noting that first of all
the legal basis for the intended processing is based on Article 6, paragraph 1 of the GDPR and specifically
in paragraphs a, b, c, d, f and further that the exception to their processing
based on Article 9, in paragraphs a, b, c and d is permissible. Finally, the N.O.B. states that its members and
athletes, upon registration, have provided their explicit consent for
the processing of their personal data, which is freely revocable, i.e.
each member is entitled, at any time, to enter the Club with the alternative method of entry (identification with an individual card) that is still in force and that
"it is a primary duty and right, a vital interest, a statutory and legal
obligation of the Club to ensure a safe and healthy environment for our members
and athletes within our facilities. This is achieved primarily by
excluding third parties, who, for example, have stolen the entrance card, have
3 forged it, have borrowed it from an active member, etc. The absolutely Correct identification of those entering the Club is our primary responsibility and obligation, given that both through our statutes, the sports law and the Civil Code, we have a corresponding obligation and it is our duty to provide those entitled to enter with the safest and healthiest environment. And this taking into account that most hours of the day the majority of those entering consist of minors, for whose health and integrity their parents have entrusted the Club and the absolutely controlled environment of its facilities. The control of entry to the Club's facilities is the first and last line of defense against would-be thieves, pickpockets, demonstrators, rapists, pedophiles, kidnappers, etc., in order to avoid and prevent related criminal behavior. Also, in this way, the overcrowding that had previously occurred during the control of those entering with the individual entry card, which posed risks to public health, e.g. outbreaks of covid19 transmission, is being addressed. Finally, we must inform you that the above new entry system was chosen after the request of most members, who on the one hand felt a strong insecurity for third parties illegally entering the Group, and on the other hand were subject to the daily hassle of identification, especially when they forgot their entry card.
Subsequently, the Authority, with the document no. Γ/ΕΣΕ/1441/10-06-2022, called on the N.O.B. to provide additional clarifications regarding, among others, the
documentation of the application of the exception of Article 9(2)(a) of the GDPR, the technical
characteristics of the system in question, the relevant technical and organizational
security measures that have been put in place, any recipients of the personal
data that are being processed, the time of the decision to
install the system in question and the installation and start of operation of the
system, and the issue of whether an impact assessment study of
the effects of the processing on the protection of personal data has been carried out.
ON.O.B. with document no. Γ/ΕΙΣ/8383/29-06-2022 replied informing the Authority that, as regards the legal basis of the processing, multiple paragraphs of Article 6, paragraph 1 and Article 9, paragraph 2 of the GDPR apply, although it considers that “the system in question does not concern sensitive personal data” and clarifies that “our athletes enter through a special entrance only with the magnetic card procedure, i.e. the system in question does not apply to them. The only exception is when the athlete is also a child of a member’s family, in which case the athlete has also provided his or her data in question. Both our old and new members have been informed - are being informed (about the said login system and their right of withdrawal) and ultimately provide their explicit consent during the process of obtaining their required images (note: not photographs but a representation of distinct geometric elements of each person). Specifically, each member (old and new) must enter the special space of the Group in order to obtain the necessary data for their integration into the said system. During this process, the operation of the said login system as well as the alternative way of entering the Group is analyzed by our competent employee. After this, the member grants his explicit consent and is immediately informed of the possibility of revoking it. The
N.O.B. also states that the current sports law requires the maintenance of a register of members
with specific personal data and that any withdrawal of consent for
the legally required personal data may lead to the deletion of the
member and that the members, in addition to the above information, are informed of the
alternative method of entry by the members of the Board of Directors, the employees of the Group, as well as
the security guards at the entrances. In support of this, the Group states that all
the aforementioned procedures are also described in the current regulations of the Group, and
submits the relevant information forms to the Authority. Regarding the technical specifications
of the system, the Group adds that “During the process of registering a new user
(enrollment phase) the system collects the coordinates of the geometry of the person.
It does NOT photograph and does NOT store photos of the face. Then these
coordinates are processed by a very sophisticated algorithm which
creates a code for each user. The user is connected with this code and
therefore all the information recorded in the system's database is
the same as that which would be recorded by an RFID card identification system,
since the algorithm itself cannot create information that
represents a person. That is, at no time does the system photograph
and/or videotape faces, whether someone is in front of the identification device
or is near it. The above data is kept for as long as the member of the Group is
active. The said data is stored on a server in the offices of the Group's
5secretariat, in a secured area, within the private, fenced and
guarded area of the Group. The following
security systems are also active: IDS/IPS & Firewall. The detection of external online threats and
attacks is covered by …with the following services activated until 11/2/2023:
a)…b)…c)…d)…e)…,….The recipient and controller is the legal representative
of the Group and its president, Mr. B”. Regarding the decision to install the
controversial system, the Group states that it was taken unanimously by the Board of Directors. during the
meeting of 9 June 2021 and submits to the Authority the relevant minutes, from which
it emerges that the project in question was assigned to the company “NousPratlT”, while its operation is scheduled to start around mid-May 2022.
Finally, the NOB clarifies that no impact assessment study has been carried out for the system in question, this because, as
it was informed by the partner company, the processing in question does not pose a high
risk to the rights and freedoms of its members, given that it is not
a systematic and extensive assessment of personal aspects relating to natural persons
or large-scale processing or systematic monitoring of a publicly
accessible space on a large scale.
Moreover, while the ex officio inspection procedure of the case had been initiated in accordance with
the above, the Authority was submitted to the complaint under no. C/ΕΙΣ/8072/18-06-
2022 by A, whose … is a member of N.O.B., and he is her companion
, against N.O.B., in which the complainant states that on 06-04-2022 the members
of the Group were informed by email that access to the Group will now be
possible only by using the new access mechanism using biometric
face characteristics and the previously in operation entry card system (RFID)
will no longer function. The complainant notes that until the introduction of the new
system, “entry to the Club was possible either through entry cards for members
and their companions (1 companion for each member, […]), or by identification at the
entrance of the visitors’ identity details and their entry through a process that
presupposes the simultaneous personal presence of the member, who would have
reported at the entrance gate the name of the visitor he was expecting. That is, there was
identification of the visitor’s identity that had been declared with the person who
appeared by showing his Police Identity Card. Following
identification, the visitor was issued with an RFID card, which operated on
the corresponding card readers at the entry/exit turnstiles and was returned by the
visitor to the entry checkpoint upon exit. It is noted that the personalized member and companion ID cards have printed on them both the details of the member (name and surname), as well as the member number, the card number, and also include a photograph of the holder, so that quick identification by the NOB security staff is possible. In addition, when the card is read by the entrance card reader, both the photograph of the holder that is in the Group's file and the other details of the card are automatically displayed on an adjacent screen in the security office. Therefore, the validity is ensured and the forgery of the card is prevented, while allowing quick (either by showing it by the holder, or electronically) confirmation of the holder's identity when used for entry/exit to NOB. Following the email of 06-04-2022 from
N.O.B., the complainant and his … sent on 16-04-2022 electronically to the Group
a statement of objection to the processing of their personal data, regarding the
use/processing of any biometric data. On 28-04-2022, N.O.B.
responded electronically only to the complainant's ... regarding the statement of objection, stating as the reason for abolishing the use of the contactless access card that it "posed risks to public health" due to overcrowding during the control of those entering with an access card and that "for reasons of completeness of this, we must inform you that any refusal to comply may constitute a reason for not maintaining your status as a member of the Group". The complainant states that
the Group never responded to him as a subject, while regarding the argument for
avoidance of crowding, he states that any "crowding" results only from the
simultaneous arrival, for example, of two large families, and does not last more than
a few seconds for each person to access through the turnstiles, and, because the
subject must take a position motionless facing the reader of the biometric
characteristics, the time is identical or perhaps a little additional in relation to
the use of an RFID card, and further argues that from the response of N.O.B. it follows
that no alternative way of access (entry/exit) to
the Group's premises is provided, other than the use of biometric characteristics and any
objection to the said processing may constitute a reason for the deletion of the member.
7Also, the complainant states that in the new Operating Regulation of the N.O.B., which came into force on 04-05-2022, there is no mention of the parallel use of access cards, nor has there been any information regarding the rights of the subjects and the exercise of these, while exclusively and only biometric characteristics are proposed as a method of entry/exit, and from the beginning to mid-May 2022, a letter from the N.O.B. was sent to the parents of children who are engaged in various activities of the Group to visit the Group Secretariat immediately to renew the access cards, as “from Monday, May 16, they will not operate, regardless of financial status, due to a change in the access system”, namely from 16-5-2022 and from now on the only way to enter/exit the Club by
members/accompanists/family members (children), who until then had personalized
entry cards with a photo, is through the use of biometric facial features.
Also, the complainant states that on 09-06-2022, through the Group's electronic newsletter, members were informed that they are now required to use the new system for entry, while visitors to the Group's members can, without any identification, such as by showing and recording their ID at the entrance and the required additional personal presence of the member, enter its premises at any time they wish, without the necessary simultaneous presence of the member, by simply using a combination of numbers (6+7 digits), which is quite easy to leak in any form, such as verbally, and/or its correct use based on the wishes of the subject/member cannot be checked, putting the other biometrically identified persons at an immediate security risk. characteristics
present. Finally, the complainant states that, as several members oppose the
use/processing of their biometric characteristics, the N.O.B.'s B.O.C.
temporarily accepted and gave directions to the security personnel to allow entry to
members who do not wish their biometric data to be processed to enter
side by side, with the mediation of the security personnel (door opening). Entry will be allowed upon presentation of the existing entrance card, which can be easily and
directly identified for its validity from the electronic files maintained by the N.O.B., a terminal (PC) of which is connected on-line to the
entrance gate. Specifically, as the complainant claims, during his visit to the N.O.B. on 13-06-2022, he was asked by security personnel in addition to the member's ID
and his police ID for identity verification, although there is
a printed photograph of the member on the entry ID. Another example
of the obstacle presented to those who do not wish to use biometrics, as
reported by the complainant, is that after 8 p.m. there is no staff at the entry/exit checkpoint, so if a member wants to enter at 6 p.m. and
wants to leave after 8 p.m., the only alternative is to call an
emergency telephone number and have one of the staff who is
"on call" come to open the door next door - at least 45 minutes with a 1-hour wait
to arrive - while the visitor enters or leaves by simply using a
number combination. The same applies to entering the N.O.B. premises after 8 p.m., since there is no security guard present and the previous
procedure must be followed, namely the emergency telephone number. With the no. prot. C/ΕΙΣ/10657/03-
10-2022 supplementary document, the complainant submits to the Authority the initial electronic message from 06-04-
2022 with the electronic newsletter of the N.O.B., in which the
Group informs its members, among other things, about the upcoming change in the incoming control system
.Specifically, this email states that:
“Now the controlled entry-exit system at N.O.B. has been modernized with new
technologies for security and the best experience for members. All that is needed
is 3 minutes of your time to obtain your biometric characteristics: go
to the N.O.B. Secretariat to complete your registration and then…
get rid of the card!”. Also, the complainant, with the same document, informs the Authority
that in an announcement that the Club had posted on its website on 09-03-2022
regarding the new controlled access system, it states, among other things, that: “The
Vouliagmeni Nautical Club is upgrading its systems with the aim of providing the best
possible experience for its Members, athletes and employees. The controlled access system at the N.O.B. facilities is being modernized and now the entry of Members and their families is carried out using their biometric characteristics. […] All you need to do is look steadily at the special registration screen in the new system for 3 seconds during your visit to the N.O.B. Secretariat. […] During this transitional stage that we are going through until the transition is completed, the card from the previous system will continue to operate. However, this will be abolished during the summer, so it is essential that all our Members have registered in the new system so that they can enter the N.O.B. […]The measurement and coding of the biometric characteristics of the geometry
of a person carried out by the system does not create a file of personal data that
could subsequently be reproduced in some way. In this context, your
personal data is safe.”
Subsequently, the complaint under no. Γ/ΕΙΣ/8648/08-07-2022
was submitted to the Authority, as supplemented by the document no. Γ/ΕΙΣ/8669/08-07-2022
by G, a member of N.O.B., against N.O.B., in which he also complains that
the new system was introduced, without N.O.B. notifying to the members that they have the option of choosing between the current electronic card system and that of biometric characteristics, without informing them about the characteristics of the new system, without informing them that there is the possibility of objection and revocation and without signing the relevant consent document, as well as that the installation of the new system was sudden and caught the members by surprise, while in accordance with the explicit and absolute statement of the, at the behest of the President of the N.O.B. and specific members who follow her, entrance control officers, misleadingly forced the incoming members to mandatory provide their biometric data, "in order to have the possibility of entering the N.O.B. from now on", as they constantly stated. No information sign has been posted, nor has an e-mail been sent to members informing them of the necessity of introducing the new system, or of the alternative use of the old system, or of the possibility of withdrawing consent to the processing of biometric data. The complainant states that in the new Operating Regulations of the N.O.B. approved in May 2022, there is no
reference to the alternative possibility of using the old control system
for incoming visitors, but according to the documents sent by the Authority to N.O.B. in June 2022,
the Group supplemented provision 2.1 of the said Regulation, as follows:
“We remind you that in the event of withdrawal of the Member’s explicit consent for
the use of his biometric data, he may enter the Group with the identification system with his personal membership card.” Finally, the complainant states that members
who disagree with the processing of their data by the new system cannot
have direct access to the N.O.B. facilities, at any time they wish, since
they cannot enter using the old cards, but they are obliged to
10call the caretaker by phone, to reach the entrance, and check
their identity and their card in relation to a handwritten list of members
who have refused to provide their biometric data, and considers that this
constitutes a particularly unequal treatment, a systematic coercion to violate
the regulations concerning the protection of personal data without any
necessity, while there is a perfectly functional system of electronic cards that
gives the possibility of controlling those who are inside the N.O.B. simply by showing
the card.
In view of the above, the Authority invited, with the documents No. Γ/ΕΣΕ/3165/07-12-2022,
Γ/ΕΣ/3163/07-12-2022 and Γ/ΕΣ/3164/07-12-2022, i. N.O.B., as legally represented, ii. complainant C, and iii. complainant A, respectively, to
attend the Plenary Session of the Authority on 13-12-2022, in order to
hold a hearing on the possible violation of the applicable legislation on the protection of personal data. With the above document, both relevant complaints in the case in question were forwarded
to N.O.B. At this meeting,
the request for postponement submitted by N.O.B. was discussed, which was accepted by the Plenary Session of the Authority and a new date for discussion was set for 07-02-2023. The meeting in question was attended by the complainants C with his attorney-in-fact
Dimitris Kampouramalis (AMDSA …) and D, who attended to provide
information, and A and on behalf of N.O.B. B, Chairman of the Board of Directors of the Group, E
and F, members of the Board of Directors of the Group with the attorneys-in-fact Dimitrios Vervesos
(AMDSA …) and Christina Panagoulea (AMDSA …), G, CEO of the company
Atermon Systems S.A. and H, General Manager of the company NousPratIT. The parties, after
expressing their views, received from the President of the Plenary a deadline to
submit memoranda.
With the no. prot. C/ΕΙΣ/1780/09-03-2023 memoranda, the first complainant,
in addition to what he stated during the discussion and in the documents he had submitted
to the Authority, pointed out that from the hearing and from the admissions of
the lawyer of N.O.B. he found the following significant violations on the part of
the Group:i. Violation of the principles of proportionality and necessity of the purpose
of processing, given that there are other milder forms of controlled access. The
alternative entry method for a member who has objected to the current method of control,
11is the demonstration of the identification documents carried by the member to the guard who
is at the gate between 8:00 a.m. and 8:00 p.m., and for the remaining hours or when the guard is absent for more hours during the
winter months, the member must call
the guard on duty from his/her mobile phone, a process that is time-consuming compared to the
use of the magnetic card. Responding to the claim of the NOB lawyer regarding the fact that the system was installed in order to minimize the personal data collected, since the member had to show his identity, the complainant states that identity was never requested, except that when the card was swiped, the member's photograph was displayed, unless the card had been cancelled or was counterfeit, and points out that the simple display of an identification document does not constitute the collection of personal data. ii. Violation of Articles 6 para. 1 GDPR and 5 para. 1a
and c for establishing the legal basis of legitimate interest for the processing of biometric data in question. iii. Regarding accountability, N.O.B., as a controller, violates Article 37 GDPR, as it has not appointed a Data Protection Officer (hereinafter referred to as the “DPO”) in the Authority, Articles 37 para. 1, 38 para. 3 and 39 para. 1 GDPR and Directive 243/2016 of the Article 19 Working Party, as its President performs the duties of an informal DPO, thus circumventing the functional independence of the DPO, Article 57 para. 1c GDPR and Directive 2016/680, as it did not previously request the Authority’s opinion to introduce a restriction on the protection of personal data, and finally Articles 35 GDPR, 27 of the Directive 2016/680 and 65 L.4624/2019, as no impact assessment study has been
prepared for the effects of the processing in question. iv.
The N.O.B. does not have the required documentation in relation to the processing in question
regarding the informing of its members and obtaining relevant consent, as the
information provided in the latest Internal Regulations is less than that
required by the GDPR, is not in an understandable and easily accessible form and does not
use clear and simple wording, while it has not drawn up a privacy policy
and has not posted it on its website. The method of obtaining consent from its members is particularly problematic given the dominant position of the Group over its members, who believe that they will be denied access to the Group's premises if they object to this processing. Finally, the complainant states that the President and the Secretary General, responsibly and under signature, stated that an alternative system, the card system, is in operation, a fact that is completely untrue, because this system has never coexisted with biometric data, and during the discussion before the Plenary Session of the Authority, the lawyer for N.O.B. clearly admitted that the card did not work as an alternative, nor was the appropriate
information provided before the new measure was imposed. v. The supplier did not clarify
a. what the “facial recognition” of the systems is (the biometric data that is
collected reveals racial origin or health issues and this comes into
conflict with fundamental human rights), b. what guarantees did N.O.V.
request and receive from the supplier regarding the protection of privacy
from the design and during the operation of these devices, c. whether any
contract was signed as a processor in the context of the supply of these
systems, and d. whether the supplier has been certified with a “privacy
seal” or “privacy audit assessment” standard.
With the memorandum no. C/ΕΙΣ/1842/13-03-2023, the N.O.B., in addition to
what it stated during the discussion before the Plenary and in the documents it has submitted
to the Authority, pointed out, with the request to recognize as permissible and lawful the
installation and operation of the ProFace system for the entry exclusively of the N.O.B. members, under the terms and conditions that may be dictated by the
Authority, that:
i. There is increased privacy of the N.O.B. with respect to the subjects on whom
the disputed entry control system is applied, namely because the N.O.B. is
a sports club and does not carry out commercial and professional activities and
the system under consideration processes data of a narrow circle of persons,
who have chosen to have the control carried out with the facial recognition system,
as there is a relationship of trust and intimacy between them and
the processing that takes place is limited, instantaneous, spatially defined
and no third party gains access to it and therefore the processing in question
even if it does not fall under the exception of Article 2, paragraph 2c of the GDPR (domestic or
personal activity), solely and solely due to the large number of
members of N.O.B., should be subject to legal assessment taking into account
the fact that the said processing meets all the criteria for the exception to the application
of the GDPR,
13ii. Despite the fact that N.O.B. presented a negative financial result for a
decade, the revenue in 2022 amounts to 3.5 million euros and the total revenue
is channeled to cover the Group's operational needs,
iii. Because, among other things, there were in the past many cases of card lending
and the practical inability to check identification during the summer months, with
the result that extremely worrying incidents have been observed, such as damage
to equipment, uncontrolled stay in the Club of unknown individuals, as in
the past the security guard recorded the name of a guest who indicated
a member or showed his identity without further control, while now each
member can use a code for the guests he is entitled
to invite and therefore bears responsibility for them, the system in question
was chosen as more secure in terms of data and guest protection.
The old system was the use of a magnetic RFID card and the member entered
from more than one entrance to the Group, by showing an identification document
that was often not applied and when applied it was
irrelevant because the photo did not correspond to reality due to its
oldness. For these reasons, it was unanimously chosen, without any
reaction from the members, at the Annual General Meeting of the Group's members in March 2022
to install at the entrance of the Group the "access control" system using
biometric data of the facial geometry for the purpose of the security of
persons and the facilities. In April 2022, a newsletter was sent to
all members to inform them of the installation of the new system, in
May 2022, the new Operating Regulation of N.O.B. for members with
reference to the way of using the new system and obtaining their biometric
data and in June 2022, after Mr. A's complaint, the
relevant article in the Regulation was amended and the possibility of disagreement/revocation
of the members' consent to the new system was provided for,
iv. Regarding the technical characteristics of ZKTeco's ProFace system,
it is noted that the coordinates of each person create a unique code through a
very sophisticated algorithm, and the device each time a member
enters does not recognize faces or biometric characteristics but
the code and the measurement and coding of biometric characteristics does
14 create a file of personal data in the system that could
be reproduced in some way. Also, the software complements the above
system in terms of security and has been installed together with ProFace on a different
server from the one that serves the rest of the Group's IT, is the
"Soft1 ERP" software, which is used for the commercial-accounting
IT of the members and from which, the ZKTeco system extracts information,
such as whether a member is financially aware in order to allow him
entry, in the following way: A member is created in the ERP (his details,
the billing details, which group he belongs to - whether he is a member or an attendant or other), with
a photograph of the person, from which the financial card of each
member is obtained, and if he is financially aware, the ERP informs ProFace that he
is allowed to enter. In the ERP there are also visitor cards with
a specific number of passes, while each financially aware member is entitled
to 2 cards. Each natural person is opened in the ERP and receives a 6-digit
code, and the user updates a flag field if he wants this
6-digit code to be opened in the ZKTeco system and the member is opened as a ZKTeco registration with
the same 6-digit code. The ERP is only updated with the number of passes that
the members' visitors make using the cards. The
access rights of each person are managed by N.O.B. Therefore, the ERP, as
N.O.B. claims, has no relation whatsoever to ProFace, nor is the
encrypted code used for identification
recorded/stored/archived anywhere in the ERP.
v. The controller of the biometric identification system is N.O.B.
and there is no processor, as, as reported by N.O.B., the company
NousPratIT that installed the system provides adhoc support services when
a technical issue arises and only gains access to the encrypted
data of ProFace. The DPO of N.O.B. has been appointed by the President of the Board of Directors of the Group,
while the Group intends to contract with a certified DPO. The subjects
whose data are processed with the new access control system
are the members and their companions, who amount to 3,500, while the employees,
visitors/fans, athletes and restaurant patrons continue
to use other systems and enter through other entrances. Recipients
15 of any data and, as regards biometrics, exclusively of the unique
code, are the salaried employees of the secretariat, who have access
only to the encrypted data and to those generated from reports of the
ProFace application. Under the assumption that no processing of biometric data takes place by the ProFace access control system, the legal basis for
processing is Article 6, paragraph 1a of the GDPR, since members signed a consent form upon registration, which explicitly states both their
rights and the possibility of revoking it. In addition, the N.O.B.
has a legitimate interest in the protection of persons and goods under
its responsibility, which is based on the case in paragraph 1 of Article 6 GDPR,
while under the assumption that special category data is being processed
Article 9 paragraph 2 paragraph a GDPR applies.
vi. The processing of data is governed by the principles of legality because it has
a legal basis, objectivity and transparency because there is full information about
the system, proportionality because the data are the most appropriate,
necessary and relevant for the intended purpose, as after weighing
the system in question was selected with the least possible interference
with the privacy of the members, in contrast to other technologically proposed
solutions, such as the use of fingerprints.
vii. Regarding the technical and organizational measures, it points out that regarding physical
security, the rack is located in a configured computer room, the backup of the files
of Windows server 2008 R2 is encrypted and is carried out only for the Group's
shared files and the historical data due to volume is 7 days and the
data is kept on 2 external disks, which the General Manager rotates
regularly.
viii. Because NOV. seeks further compliance, it has commissioned the performance
of an Impact Assessment Study and, whatever the result, it is committed to
taking it into account and adjusting, if necessary, its technical and
organizational measures. Since the hearing, it has already proceeded with
procedures for assigning to the company “GDPR Greece IKE” the project of obtaining
an ISO27001 certificate, i.e. the certificate for the security management
of 16 information and personal data processed within the
Group.
The Authority, after examining the information in the file, after hearing the rapporteur and the
clarifications from the assistant rapporteurs, who attended without the right to vote,
following a thorough discussion,
HAS DECIDED IN ACCORDANCE WITH THE LAW
1. Whereas, from the provisions of Articles 51 and 55 of the General Data Protection Regulation
(EU) 2016/679 (hereinafter "GDPR") and Article 9 of Law 4624/2019 (Government Gazette
A'137) it follows that the Authority has the competence to supervise the implementation of the provisions
of the GDPR, this Law and other regulations concerning the protection of individuals
from the processing of personal data.
2. Whereas, in accordance with the definitions of Article 4 item. 1 GDPR “personal data means any information relating to an identified or identifiable natural person (‘data subject’);…” and so on.14 biometric data means “personal data resulting from a specific processing technique relating to the physical, biological or behavioural characteristics of a natural person and which allow or confirm the unambiguous identification of that natural person, such as facial images or dactyloscopic data”.
3. Since biometric data are included in the special categories of personal
data, which are in principle prohibited from being processed, in accordance with
Article 9, paragraph 1 of the GDPR: “The processing of personal data
revealing racial or ethnic origin, political opinions,
religious or philosophical beliefs or trade union membership shall be prohibited,
as well as the processing of genetic data, biometric data for the purpose of
unambiguously identifying a person, data concerning health or data
concerning the sex life of a natural person or sexual orientation”.
Paragraph 2 of the same article provides for the exceptions to the above prohibition, the first of
which is the explicit consent of the subject. In particular, it is stated: “
Paragraph 1 shall not apply in the following cases: (a) the data subject has given explicit consent to the processing of those personal data
17 for one or more specific purposes, unless
Union or Member State law provides that the prohibition referred to in
paragraph 1 may not be lifted by the data subject, […]”.
4. Whereas, Article 5 of the GDPR sets out the processing principles governing the processing of
personal data. Specifically, it is stipulated in paragraph 1 that
personal data, among others: “a) are processed lawfully and fairly
in a transparent manner in relation to the data subject (“lawfulness,
objectivity and transparency”).
b) are collected for specified, explicit and legitimate
purposes and are not further processed in a manner incompatible with
those purposes (…),
c) are adequate, relevant and limited to what is necessary in relation to
the purposes for which they are processed (“data minimisation”) (…) f) are processed in a manner that ensures
appropriate security of personal data, including
their protection against unauthorised or unlawful processing and against accidental loss,
destruction or damage, using appropriate technical or organisational measures
(“integrity and confidentiality”)”, and in paragraph 2 that “the controller
shall be responsible for and shall be in a position to demonstrate compliance
with the principles of processing established in paragraph 1 ("accountability")".
In order for personal data to be lawfully processed, i.e.
processed in accordance with the requirements of the GDPR, the conditions for the application and observance of the principles of Article 5(1) of the GDPR must be cumulatively met
. The collection
and processing of personal data must always take place
in the light of the principles of proportionality and necessity and the
controller, in the context of his observance of the principle of fair or
fair processing of personal data, must inform
the data subject that he is going to process his data in a lawful and
transparent manner and be in a position at any time to demonstrate his compliance
with these principles. Also, as the Authority has already assessed, a
new compliance model was adopted with the GDPR, the central point of which is the principle of accountability, in the
framework of which the controller is obliged to design, implement and generally take the necessary measures and policies, in order for the processing of
data to be in accordance with the relevant legislative provisions.
3See Authority Decisions 36/2021, para. 3, 26/2019, para. 8, 44/2019, para. 19, available on its website.
18 Furthermore, the
controller is charged with the specific duty of proving himself and
at all times his compliance with the principles of Article 5(1) GDPR, both in relation to
the data subject for reasons of transparency of the processing, and, in particular,
before the Supervisory Authority. It is no coincidence that the GDPR integrates accountability (Article 5
para. 2 GDPR) into the regulation of the principles (Article 5 para. 1 GDPR) that govern processing,
giving it the function of a mechanism for their compliance,
essentially reversing the “burden of proof” regarding the lawfulness of processing (and in general, compliance with the principles of Article 5 para. 1 GDPR), shifting it to the controller,
so that it can be reasonably argued that he bears the burden of invoking and
proving the lawfulness of processing. Thus, it is the responsibility of the controller to, on the one hand, take the necessary measures to comply with the requirements of the GDPR, and, on the other hand, to demonstrate at any time the aforementioned compliance, without requiring the Authority, in the context of exercising its investigative and supervisory powers, to submit individual and specialized questions and requests to establish compliance. 5. Because, as recital 51 of the GDPR clarifies, special categories of data require special protection, since the context of their processing could create significant risks to fundamental rights and freedoms. While, therefore, in order for the processing of “simple”
personal data to be lawful, it is sufficient that one of the legal bases of Article 6 is present,
with regard to special categories of data, their processing is, in principle, prohibited and
permitted only if one of the legal bases of Article 6
and one of the exceptions of Article 9, paragraph 2, GDPR is cumulatively present.
6. Because the existence of a legal basis (Article 6, GDPR) does not exempt the controller from the obligation to comply with the principles (Article 5, paragraph 1, GDPR) regarding
legitimacy, necessity and proportionality, and the principle of
minimization. In the event that any of the principles set out in Article 5(1) of the GDPR are violated, the processing in question shall be deemed to be non-
4 See in this regard L. Mitrou, The Principle of Accountability in Obligations of the Controller [G.
Giannopoulos, L. Mitrou, G. Tsolias], Collective Volume L. Kotsalis – K. Menudoukou “The GDPR, Legal
5 Dimension and Practical Application”, 2nd ed. Law Library, 2021, pp. 265 et seq.
See Authority Decision 35/2022, sec. 8.
19 lawful (subject to the provisions of the GDPR) and it is unnecessary to examine the conditions
for the application of the legal bases of Article 6 of the GDPR. Thus, the unlawful collection and processing of personal data in violation of the principles of
Article 5 of the GDPR is not remedied by the existence of a legitimate purpose and legal basis (cf.
ADIPC 38/2004).
7. Because, according to Article 35(1) GDPR: “where a type of processing, in particular using new technologies and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the implications of the envisaged processing operations for the protection of personal data. An assessment may consider a set of similar processing operations which present similar high risks.” The Authority, in application of paragraph 4 of Article 35 GDPR, by its decision
65/2018, has drawn up and published a list of the types of
processing operations that are subject to the requirement to carry out a data protection impact assessment
pursuant to paragraph 1. These operations
include the following:
“1.2 Systematic processing of data for the purpose of taking automated
decisions, which produce legal effects concerning the data subjects
or significantly affect the data subjects in a proportionate manner and
may lead to exclusion or discrimination against the natural person (…).
1.3 Systematic processing of data which may prevent the subject from
exercising his rights or using a service or contract, in particular when
data collected by third parties (…) are taken into account.
2.1 Large-scale processing of special categories of data
(including genetic and biometric data for the purpose of unambiguous
identification of a person) referred to in Article 9(1) and of data referred to
in Article 10 of the GDPR.
3.1 Innovative use or application of new technologies or organizational solutions, which
may involve new forms of data collection and use, with a potential
high risk to the rights and freedoms of natural persons such as
6Government Gazette B 1622/10-5-2019
7See Decision of the DPA 65/2018 available on the Authority’s website
20 combined use of fingerprints and facial recognition for
improved physical access control, or mHealth applications or other “smart” applications,
from which a user profile is created (e.g. daily habits), or
artificial intelligence applications or publicly accessible blockchain technologies that
include personal data.”
8
8. Whereas, according to the EDPB Guidelines 3/2019:
“73. The use of biometric data, and in particular facial recognition, poses
increased risks to the rights of data subjects. These technological means should in any case be used in accordance with the principles of lawfulness, necessity, proportionality and data minimisation as set out in the GDPR. While the use of these technologies can be considered to be particularly effective, controllers should first of all assess the impact of these technological means on fundamental rights and freedoms and consider the use of less intrusive means to achieve the legitimate purpose of the processing. 74. The processing of raw data such as the physical, biological or behavioural characteristics of a natural person, in order to be considered as processing of biometric data as defined in the GDPR, must involve the measurement of those characteristics. Since biometric
data are the result of such measurements”, the GDPR definition in Article
4(14) applies, as set out above, “However, video footage depicting
individuals cannot be considered as biometric data as such pursuant to
Article 9, unless the footage has previously undergone specific technical processing
in order to contribute to the identification of individuals.” 75.
The processing of biometric data, in order to be considered as processing of special categories
personal data (Article 9), must be “for the purpose of unambiguous
identification of a person”.
76. In summary, in the light of Article 4(14) and Article 9, three criteria should be
taken into account:
- Nature of the data: data relating to the metaphysical, biological or behavioural
characteristics of a natural person,
- Means and method of processing: data which “result from a specific technique
8 Guidelines 3/2019 on the processing of personal data by means of video devices, 29-01-2020, pp. 20 and 21.
21 processing”,
- Purpose of the processing: the data must be used for the purpose of
unambiguously identifying a natural person.
77. The use of video surveillance systems including biometric recognition functions installed by private entities for their own purposes (e.g. for marketing, statistical or even security purposes) most often requires the explicit consent of all data subjects (Article 9
(2)(a)), although in this case another legitimate exception to Article 9 may apply.”
9. Since, according to the case-law of the Court of Justice of the European Union, 9 “as is clear from recital 39 of the GDPR, the requirement of necessity is not met if the general interest objective pursued can reasonably be achieved in an equally effective manner by other means which are less intrusive to the fundamental rights of data subjects, in particular the rights to respect for private life and to the protection of personal data as enshrined in Articles 7 and 8 of the Charter, taking into account that derogations and limitations to the principle of the protection of such data must not go beyond what is strictly necessary” and “the requirement of necessity of the processing must be considered in conjunction with the so-called principle of ‘data minimisation’, as laid down in Article 6(1)(c) of the Charter, of
Directive 95/46, as well as Article 5, paragraph 1, letter cʹ, of the GDPR, according to which
personal data must be adequate, relevant and limited
10
to what is necessary in relation to the purposes for which they are processed”.
This decision essentially accepts that processing is lawful only for
necessary data.
10. Whereas, in the Opinion of the Advocate General of the CJEU of 06-10-2022, submitted
in the context of the procedure for issuing the CJEU decision of 04-05-2023 in case
C-300/2021, it is stated, among other things, that “73. The consent of the data subject, as the highest expression of control, constitutes only one of the legal bases for lawful processing, but is not capable of validating the non-compliance with the other obligations and conditions incumbent on the controller and the processor. 74. It is not, in my opinion, easy to infer from the GDPR that the purpose of the latter is to provide the data subject with control over personal data as an independent value. Nor that the data subject should have the greatest possible control over his or her data. 75. This finding is not surprising. On the one hand, it is not
obvious that control, in the sense of data ownership, forms part of the
essence of the fundamental right to the protection of personal data.
On the other hand, the recognition of this right as a right to informational self-determination is otherwise unanimous: Article 8 of the
Charter does not use these terms.
For the record, the final
text of the GDPR did not include a recital stating that “the right to the
protection of personal data is based on the right of the
data subject to exercise control over the personal data
which are processed”.
11. Whereas, with regard to the data protection officer, in accordance with Article 38paragraph 3 GDPR “The controller and the processor shall ensure that the data protection officer does not receive instructions in order to carry out these tasks. He shall not be dismissed or penalised by the controller or the processor for carrying out his tasks. The data protection officer shall be directly accountable to the highest management level of the controller or the processor”, paragraph 5 “The data protection officer shall be bound by the secrecy or confidentiality of the performance of his tasks, in accordance with Union or Member State law” and paragraph 6 “The data protection officer may also perform other tasks and obligations. The controller or processor
shall ensure that these tasks and obligations do not give rise to a conflict of
interests.” Furthermore, the OA 29 Guidelines 11 state that “the
data protection officer shall not hold a position within the organization
from which he or she can determine the purposes and means of the
processing of personal data. Since each organization has a different organizational
structure, this issue should be examined on a case-by-case basis.”
11 OA 29 Guidelines on Data Protection Officers, WP 243 rev.01,
Chap. 3.5
2312. Whereas, in the case under consideration, it appears from the information in the file, the hearing of the
parties involved, and the submissions submitted that:
i. N.O.B., in accordance with the “N.O.B. Operating Regulations for Members -2022”, has
installed and is operating, at least since mid-May 2022, at the entrance to its
premises a “biometric features system”, as it
describes it, which identification system is based on facial geometry
which is unique for each person. For the operation of this system,
the subject must enter the special area of N.O.B. in order to make the
required image of distinct geometric elements of each
person. The system collects the coordinates of the facial geometry
which are processed through an algorithm, which creates a
code for each user and the above data are stored digitally on the N.O.B. server
for as long as the data subject is an active member of
the Group.
Therefore, the Authority finds that with the said login identification system, a special category of personal data is processed and N.O.B. becomes the controller of such data.
ii. At the time the complaints against N.O.B. were filed, N.O.B. members
did not have the option of using another login system to the Group,
other than the system under examination, as for some time, this
constituted their only way of logging in.
iii. In the “N.O.B. Operating Regulations for Members - 2022”, submitted by N.O.B. with its
document no. Γ/ΕΙΣ/8383/29-06-2022, it is stated that “For
the login to N.O.B. of Members (main and protected)
biometric characteristics are used. After their registration in the biometric system, the plastic cards are cancelled. […] We remind you that in the event of a Member’s withdrawal of their explicit consent for the use of their biometric data, they may enter the Group using the identification system with their personal membership card.” However, the form available to N.O.B. members at the same time, “Information Form for Registered Members Regarding Their Personal Data,” provides information on the processing of personal data, without reference to the data that is processed with the biometric system in question and the legal basis for consent for special category data. With the memorandum submitted to the Authority by N.O.B. after the
hearing before the Plenary under no. prot. C/EIS/1842/13-03-2023
presented the “Consent Form for
the ProFace biometric identification system as an Access Control method at NOB”, which states that “It is expressly assured by the Group,
that the biometric/geometric (not imaging) data used for identification/identification are not collected in a file,
nor stored on a PC unit” and “I expressly declare that I HAVE BEEN INFORMED of
the above processing of biometric data that takes place by
the Vouliagmeni Nautical Club and I AGREE to said processing”, and
a relevant selection field is given to the subject. Finally, in the response email from NOB dated 28-04-2022
to … the first
complainant, following their statement of opposition to the
processing of their personal data dated 16-04-2022, it was stated that “any refusal
to comply [i.e. granting consent for the new login system],
may constitute a reason for not maintaining your status as a member of the
Group”.
iv. The subjects whose data are processed with the new
access control system are the members and their companions, who amount to
3,500, while the employees, visitors/fans, athletes and restaurant patrons
continue to use other systems and enter from other entrances.
v. Regarding the impact assessment, the initial response of the N.O.B. to the
Authority was that it was not deemed necessary to prepare it, while after the hearing
before the Plenary, the N.O.B. informed the Authority that it has commissioned the
conduct of this study and, whatever the result, it undertakes to
take it into account and to adjust, if necessary, the technical and
organizational measures it has already implemented. N.O.B. has not submitted to the Authority
an impact assessment for the system under examination.
vi. N.O.B. has appointed the President of the Board of Directors of the
Group as Data Protection Officer.
2513. Whereas, in view of the above, the Authority finds that N.O.B. has installed and
put into operation the biometric features system under examination, for which,
as follows from the above paragraph 12.i., the processing of a special category
of personal data of the subjects is required, and N.O.B. becomes responsible for
their processing. This processing relates to the systematic processing of data using new technology and automated data processing, with a potential high risk to the rights and freedoms of natural persons (facial recognition), as large-scale processing of special categories of data of approximately 3,500 subjects takes place, as it concerns all members of the Group and their companions. From the case file, it appears
that the controller has not documented that the use of the new system is necessary and proportionate
and in particular that it is not possible for the purpose of the processing
to implement softer forms of controlled entry into the space, by processing
simple data, while for some time it implemented the said
biometric characteristics system, without having provided appropriate information to
the subjects about the processing of their data, without having obtained their consent
and without providing an alternative method of controlled entry. Therefore, if the controller, who is required to demonstrate compliance with the principles of Article 5(1)(a) of the GDPR, has not demonstrated the necessity of the purpose of the processing in question, the principle of lawfulness (Article 5(1)(a)) has been infringed and the processing of special categories of personal data in question is deemed unlawful, in accordance with the provisions of paragraph 6, it is unnecessary to examine the existence of a legal basis for processing under Article 6 of the GDPR and the application of the exceptions to the prohibition of processing special categories of personal data under Article 9(2) of the GDPR.
14. Since, although, according to what is set out in paragraph 7, NOV as controller
was obliged, pursuant to Article 35(3)(c) GDPR and the aforementioned Decision 65/2018 of the Authority, to carry out an impact assessment
12
See i. Guidelines on Data Protection Impact Assessment (DPIA)
determining whether the processing is “likely to result in a high risk” for the purposes of
Regulation 2016/679, OM no. 29 WP 248 rev. 01, ii. Opinion 7/2018 EDPB, and iii. Decision 65/2018 DPA
"List of types of processing operations subject to the request for a data protection impact assessment in accordance with Article 35(4) of the GDPR
26regarding the protection of a special category of data, did not document before the
Authority, in accordance with the principle of accountability (Article 5(2) of the GDPR), its compliance
with this obligation, the breach of which constitutes an independent breach under
Article 35 of the GDPR.
15. Since, according to the GDPR and the OE29 Guidelines, the Data Protection Officer (hereinafter referred to as the “DPO”) must exercise his or her duties independently and is therefore not allowed to hold a position within the controller from which he or she can determine the purposes and means of the processing of personal data. In this specific case, the President of the Board of Directors of the N.O.B., as the legal representative of the controller, determines the purposes and means of the processing of personal data and by assigning her the duties of DPO, objective supervision of compliance with the GDPR is not ensured. Therefore, according to the above Guidelines, the position of
Chairman of the Board of Directors comes into a material conflict of interest and is incompatible with
the position of DPO, and, consequently, the coincidence of these two capacities in the same person
comes into conflict with the provision of Article 38(3) of the GDPR.
16. Because, based on the above, the Authority considers that there is a case to exercise the corrective powers of imposing fines under
Articles 58 par. 2 i’ and 83 GDPR, with regard to the violations established above, as well as the corrective powers under Article 58 par. 2 d’
and in order to impose on the controller the
obligation to prepare an impact assessment study for the processing of personal data of the subjects through the system under examination and the
suspension of this processing until the study is prepared. In order to determine the
fines, so that they are effective, proportionate and dissuasive, the measurement criteria set out in Article 83(2) of the GDPR, which are
applicable to the present case, as specifically interpreted by the
Guidelines 4/2022 of the EDPB on the calculation of administrative
14
fines, are taken into account.
17. Whereas, when assessing the data, the Authority takes particular account of:
13See supra footnote 11.
14https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-042022-calculation-
administrative-fines-under_en - version 2.1
27 i. the nature and gravity of the infringement, which concerns the basic principles
of lawfulness of processing which are fundamental for the protection of personal data, in accordance with the GDPR, taking into account that,
regardless of the fact that compliance with the principles provided for by
the provision of Article 5 of the GDPR is of paramount importance, primarily, the
principle of lawfulness, so that, if it is absent, the
processing becomes unlawful from the outset, even if the other principles of processing have been complied with, in
this case it was established that unlawful processing was carried out using
the system under examination,
ii. that the processing in question concerns a special category of personal data
of a large number of subjects,
iii. that the controller considered the possibility of carrying out an impact assessment
and decided that it was not required
iv. the fact that the violation of the provisions relating to the basic principles for
processing falls, in accordance with the provisions of Article 83, paragraph 5, paragraphs a and b
GDPR, into the highest category of the grading system
of administrative fines,
v. that the revenues of NOV amount to 3.5 million for the year 2022
Based on the above, the Authority unanimously decides that the
complained Group, as controller, should be imposed the
administrative sanctions referred to in the operative part
, which are deemed proportionate to the gravity of the violations.
FOR THESE REASONS
The Authority
A. Imposes on the Vouliagmeni Nautical Club, as controller, based on
Article 58, paragraph 2, subparagraph i’ of the GDPR, a fine of twenty-eight thousand euros (28,000 €)
euro for the violation of the principle of lawfulness (Article 5, paragraph 1, subparagraph a’ of the GDPR).
B. Imposes on the Vouliagmeni Nautical Club, as controller, based on
Article 58, paragraph 2, subparagraph i’ of the GDPR, a fine of fourteen thousand euros (14,000
€28) euros for the failure to carry out an impact assessment of the biometric features
controlled entry system (Article 35 of the GDPR).
C. Orders the Vouliagmeni Nautical Club, as controller, on the one hand, on the basis of
Article 58, paragraph 2, subparagraph d’ of the GDPR, to prepare, in accordance with Article 35 of the GDPR,
a study assessing the impact of the processing operations through the biometric
features controlled entry system on the protection of personal data
and on the other hand, on the basis of Article 58, paragraph 2, subparagraph f’ of the GDPR, to discontinue the processing
of personal data through the aforementioned biometric
features controlled entry system, until it has prepared an impact assessment study,
according to the above and to inform the Authority regarding the above actions,
at the latest within three (3) months from the notification of this.
D. Imposes on the Vouliagmeni Nautical Club, as controller, based on
article 58 par. 2 sub. i’ of the GDPR, a fine of fourteen thousand euros (14,000
€) euros for the violation of article 38 par. 3 of the GDPR.
The President The Secretary
Konstantinos Menuudakos Irini Papageorgopoulou
29




