HDPA (Greece) - 42/2024

From GDPRhub
HDPA - 42/2024
Authority: HDPA (Greece)
Jurisdiction: Greece
Relevant Law: Article 5(1)(a) GDPR
Article 35 GDPR
Article 38 GDPR
Article 7 Law 4624/2019
Type: Investigation
Outcome: Violation Found
Started: 22.04.2020
Decided: 23.12.2019
Published: 24.11.2018
Fine: 56,000 EUR
Parties: n/a
National Case Number/Name: 42/2024
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Greek
Original Source: HDPA's website (in EL)
Initial Contributor: Iliana Papantoni

The HPDA found that a Nautical Club unlawfully processed biometric data via an access control system and failed to conduct a DPIA, imposed €56,000 in fines, and ordered suspension of processing until a DPIA is completed.

English Summary

Facts

A companion of a member asked the HDPA how to object to biometric processing at a private nautical club, which triggered the HDPA’s investigation. On 6 April 2022, members were told access would henceforth be possible only via a new facial-recognition system, and the existing RFID card system would be disabled. The club asserted multiple Article 6 bases and Article 9 exceptions, circulated vendor assurances about encryption and non-reconstructability, and claimed the system did not process “sensitive” data, while also communicating that refusal could jeopardise membership. After objections, the club amended its internal rules to state that, upon withdrawal of consent, members could use a card, yet communications simultaneously suggested the card system had been discontinued and refusal could affect membership. The HDPA convened a hearing to assess alleged infringements including the lack of a DPIA and concerns over DPO independence. The biometric system processed special category data through facial recognition for roughly 3,500 data subjects (members and companions), indicating large-scale processing with heightened risk.

Holding

The HDPA confirmed that facial-recognition data are biometric data under Article 4 (14) and thus special category data under Article 9(1), requiring strict compliance with the principles of lawfulness, necessity, proportionality, and data minimisation. The controller failed to demonstrate necessity and proportionality, as less intrusive access-control methods were reasonably available, so the processing violated Article 5(1)(a) and the assessment of Article 6 and Article 9 bases was unnecessary once unlawfulness was established. The HDPA emphasised that consent cannot cure non-compliance with other controller obligations, and does not validate processing that breaches core principles. Given the large-scale special category processing using innovative technology and the potential high risk, a DPIA was required but not properly conducted. The HDPA ordered the controller to carry out a DPIA and to suspend biometric processing until completion, and imposed administrative fines totalling €56,000: €28,000 for unlawfulness under Article 5(1)(a), €14,000 for failing to conduct a DPIA (Article 35), and €14,000 for violating DPO independence (Article 38(3)).

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Greek original. Please refer to the Greek original for more details.

Athens, 18-11-2024
No. Prot.: 3211

DECISION 42/2024

The Personal Data Protection Authority met following

the invitation of its President in a meeting on Tuesday 28-07-2023 at 10:00 a.m. and

in a second meeting on Tuesday 19-12-2023 at 10:00 a.m., in order to examine

the case referred to in the history of this case. The President of the

Authority, Konstantinos Menudakos, the regular members Spyridon Vlachopoulos, Konstantinos

Lambrinoudakis, Charalambos Anthopoulos, Aikaterini Iliadou, Grigorios Tsolias and

Christos Kalloniatis, as rapporteur, were present. Present, without the right to vote, were Ioannis

Lykotrafitis, specialist scientist-informatics, Stefania Plota, specialist scientist

-lawyer, as assistants to the rapporteur and Irini Papageorgopoulou, employee of the

administrative affairs department, as secretary.

The Authority took into account the following:

With his request under no. prot. C/EIS/6282/20-04-2022, A addressed the Personal Data Protection Authority (hereinafter referred to as the “Authority”), asking how he can object as an escort of a member of the Vouliagmeni Nautical Club

(hereinafter referred to as “NOB” or “Group”) to the processing of his biometric data, about which he was informed by NOB by e-mail. According to this

information, the controlled entry-exit system will no longer be carried out by

showing, at the entrance to a guard, the member’s escort card but by

processing his biometric characteristics, without providing further

information and justification for the said measure.

1 The above question, interpreted either as a request for information to exercise a right of the subject, or as a question of the lawfulness of processing, falls outside the competences of the Authority. However, due to the importance of the issue, the Authority considered that it should be dealt with ex officio and, with its document No. C/ΕΣΕ/1226/20-05-2022

taking into account the renewed Operating Regulations of the group,

which, as posted on its website (last checked 19-05-

2022), state, in provision 2.1, the following: “Biometric characteristics are used for the entry of Members (main and protected) into the N.O.B. After their registration in the biometric features system, the plastic cards are cancelled. On the first visit of the member and his family to the Club, a short visit to the N.O.B. Secretariat is required to register the member in the system.”, called on N.O.B. to provide clarifications on the processing of biometric data for the control of its members’ access to the Club, including, among others, the legal basis and other characteristics of the intended processing, as well as whether an impact assessment study has been carried out on the effects of the processing on the protection of personal data. N.O.B. with the document no. C/ΕΙΣ/7663/02-06-2022, responded to the Authority

that “…until recently, only the entry system using an individual

magnetic card for each member, which also carried the photograph of the face

of each member, was used. Today, an entry system using an individual card for

each member, which also carries the photograph of the face, and is identified by the
display of a police ID or other public identification document. Finally,

an identification system is also used in parallel, which is based on

the geometry of the face, which is unique for each person. The

coordinates of each person are therefore processed by a very sophisticated algorithm, which

creates for each person a code like the one that an RFID card would have”. Specifically

for the technical specifications of this new system, the NOB states that “the

biometric authentic devices of ZKTeco, which concern access control (Access

Control) and time attendance (Time Attendance), are in accordance with personal

data, meaning that the biometric data of their users belong to them, because they are

1
2See Decision 52/2018 of the Data Protection Authority

https://nov.gr/wp-content/uploads/2021/06/Κανονισμός-Λειτυργίας-final-2022.pdf

2appropriately secured and stored with encryption methods within the

devices….With ZKTecoTimeAttendanceorAccessControl systems, images are never

stored. Photographs are taken and distinct

characteristics known as data elements are collected from the image. A studied algorithm is used to convert the data into a biometric template in the form of a digital code. ZKTeco Biometric Algorithms and Templates: As an additional security measure, the biometric template is then encrypted and the authentication process is carried out on ZK's palm and face recognition machines, which takes place inside the devices without an external factor. The necessary data is compared with the data on the terminal and the comparison result is exported. The comparison result is stored locally and sent to the client via the SSL/TSL encryption algorithm. The encryption algorithm for the data sent is random. The result is a system that provides the highest level of protection for biometric data, ensuring compliance with the GDPR personal data. Biometric templates can only be

recognized by the ZKTeco algorithm and cannot be converted into biometric images other than

this algorithm. ZKTeco Biometric templates cannot

be recognized by other biometric algorithms.” As for the legal basis of

processing, N.O.B. states that: “In this case, the lawfulness of the

processing pursuant to Article 6, paragraph 1 of the GDPR and the exceptions of Article 9, paragraph 2 of the GDPR both apply, if

it is considered that the data in question are sensitive personal data”, noting that first of all

the legal basis for the intended processing is based on Article 6, paragraph 1 of the GDPR and specifically

in paragraphs a, b, c, d, f and further that the exception to their processing

based on Article 9, in paragraphs a, b, c and d is permissible. Finally, the N.O.B. states that its members and

athletes, upon registration, have provided their explicit consent for

the processing of their personal data, which is freely revocable, i.e.

each member is entitled, at any time, to enter the Club with the alternative method of entry (identification with an individual card) that is still in force and that

"it is a primary duty and right, a vital interest, a statutory and legal

obligation of the Club to ensure a safe and healthy environment for our members

and athletes within our facilities. This is achieved primarily by

excluding third parties, who, for example, have stolen the entrance card, have

3 forged it, have borrowed it from an active member, etc. The absolutely Correct identification of those entering the Club is our primary responsibility and obligation, given that both through our statutes, the sports law and the Civil Code, we have a corresponding obligation and it is our duty to provide those entitled to enter with the safest and healthiest environment. And this taking into account that most hours of the day the majority of those entering consist of minors, for whose health and integrity their parents have entrusted the Club and the absolutely controlled environment of its facilities. The control of entry to the Club's facilities is the first and last line of defense against would-be thieves, pickpockets, demonstrators, rapists, pedophiles, kidnappers, etc., in order to avoid and prevent related criminal behavior. Also, in this way, the overcrowding that had previously occurred during the control of those entering with the individual entry card, which posed risks to public health, e.g. outbreaks of covid19 transmission, is being addressed. Finally, we must inform you that the above new entry system was chosen after the request of most members, who on the one hand felt a strong insecurity for third parties illegally entering the Group, and on the other hand were subject to the daily hassle of identification, especially when they forgot their entry card. 

Subsequently, the Authority, with the document no. Γ/ΕΣΕ/1441/10-06-2022, called on the N.O.B. to provide additional clarifications regarding, among others, the

documentation of the application of the exception of Article 9(2)(a) of the GDPR, the technical

characteristics of the system in question, the relevant technical and organizational

security measures that have been put in place, any recipients of the personal

data that are being processed, the time of the decision to

install the system in question and the installation and start of operation of the

system, and the issue of whether an impact assessment study of

the effects of the processing on the protection of personal data has been carried out.

ON.O.B. with document no. Γ/ΕΙΣ/8383/29-06-2022 replied informing the Authority that, as regards the legal basis of the processing, multiple paragraphs of Article 6, paragraph 1 and Article 9, paragraph 2 of the GDPR apply, although it considers that “the system in question does not concern sensitive personal data” and clarifies that “our athletes enter through a special entrance only with the magnetic card procedure, i.e. the system in question does not apply to them. The only exception is when the athlete is also a child of a member’s family, in which case the athlete has also provided his or her data in question. Both our old and new members have been informed - are being informed (about the said login system and their right of withdrawal) and ultimately provide their explicit consent during the process of obtaining their required images (note: not photographs but a representation of distinct geometric elements of each person). Specifically, each member (old and new) must enter the special space of the Group in order to obtain the necessary data for their integration into the said system. During this process, the operation of the said login system as well as the alternative way of entering the Group is analyzed by our competent employee. After this, the member grants his explicit consent and is immediately informed of the possibility of revoking it. The

N.O.B. also states that the current sports law requires the maintenance of a register of members

with specific personal data and that any withdrawal of consent for

the legally required personal data may lead to the deletion of the

member and that the members, in addition to the above information, are informed of the

alternative method of entry by the members of the Board of Directors, the employees of the Group, as well as

the security guards at the entrances. In support of this, the Group states that all

the aforementioned procedures are also described in the current regulations of the Group, and

submits the relevant information forms to the Authority. Regarding the technical specifications

of the system, the Group adds that “During the process of registering a new user

(enrollment phase) the system collects the coordinates of the geometry of the person.
It does NOT photograph and does NOT store photos of the face. Then these

coordinates are processed by a very sophisticated algorithm which

creates a code for each user. The user is connected with this code and

therefore all the information recorded in the system's database is

the same as that which would be recorded by an RFID card identification system,

since the algorithm itself cannot create information that
represents a person. That is, at no time does the system photograph

and/or videotape faces, whether someone is in front of the identification device

or is near it. The above data is kept for as long as the member of the Group is

active. The said data is stored on a server in the offices of the Group's

5secretariat, in a secured area, within the private, fenced and

guarded area of the Group. The following

security systems are also active: IDS/IPS & Firewall. The detection of external online threats and

attacks is covered by …with the following services activated until 11/2/2023:

a)…b)…c)…d)…e)…,….The recipient and controller is the legal representative

of the Group and its president, Mr. B”. Regarding the decision to install the

controversial system, the Group states that it was taken unanimously by the Board of Directors. during the

meeting of 9 June 2021 and submits to the Authority the relevant minutes, from which

it emerges that the project in question was assigned to the company “NousPratlT”, while its operation is scheduled to start around mid-May 2022.

Finally, the NOB clarifies that no impact assessment study has been carried out for the system in question, this because, as

it was informed by the partner company, the processing in question does not pose a high

risk to the rights and freedoms of its members, given that it is not

a systematic and extensive assessment of personal aspects relating to natural persons

or large-scale processing or systematic monitoring of a publicly
accessible space on a large scale.

Moreover, while the ex officio inspection procedure of the case had been initiated in accordance with

the above, the Authority was submitted to the complaint under no. C/ΕΙΣ/8072/18-06-

2022 by A, whose … is a member of N.O.B., and he is her companion

, against N.O.B., in which the complainant states that on 06-04-2022 the members

of the Group were informed by email that access to the Group will now be

possible only by using the new access mechanism using biometric

face characteristics and the previously in operation entry card system (RFID)

will no longer function. The complainant notes that until the introduction of the new

system, “entry to the Club was possible either through entry cards for members

and their companions (1 companion for each member, […]), or by identification at the

entrance of the visitors’ identity details and their entry through a process that

presupposes the simultaneous personal presence of the member, who would have

reported at the entrance gate the name of the visitor he was expecting. That is, there was

identification of the visitor’s identity that had been declared with the person who

appeared by showing his Police Identity Card. Following

identification, the visitor was issued with an RFID card, which operated on

the corresponding card readers at the entry/exit turnstiles and was returned by the

visitor to the entry checkpoint upon exit. It is noted that the personalized member and companion ID cards have printed on them both the details of the member (name and surname), as well as the member number, the card number, and also include a photograph of the holder, so that quick identification by the NOB security staff is possible. In addition, when the card is read by the entrance card reader, both the photograph of the holder that is in the Group's file and the other details of the card are automatically displayed on an adjacent screen in the security office. Therefore, the validity is ensured and the forgery of the card is prevented, while allowing quick (either by showing it by the holder, or electronically) confirmation of the holder's identity when used for entry/exit to NOB. Following the email of 06-04-2022 from

N.O.B., the complainant and his … sent on 16-04-2022 electronically to the Group

a statement of objection to the processing of their personal data, regarding the

use/processing of any biometric data. On 28-04-2022, N.O.B.
responded electronically only to the complainant's ... regarding the statement of objection, stating as the reason for abolishing the use of the contactless access card that it "posed risks to public health" due to overcrowding during the control of those entering with an access card and that "for reasons of completeness of this, we must inform you that any refusal to comply may constitute a reason for not maintaining your status as a member of the Group". The complainant states that
the Group never responded to him as a subject, while regarding the argument for
avoidance of crowding, he states that any "crowding" results only from the
simultaneous arrival, for example, of two large families, and does not last more than
a few seconds for each person to access through the turnstiles, and, because the
subject must take a position motionless facing the reader of the biometric
characteristics, the time is identical or perhaps a little additional in relation to
the use of an RFID card, and further argues that from the response of N.O.B. it follows

that no alternative way of access (entry/exit) to

the Group's premises is provided, other than the use of biometric characteristics and any

objection to the said processing may constitute a reason for the deletion of the member.

7Also, the complainant states that in the new Operating Regulation of the N.O.B., which came into force on 04-05-2022, there is no mention of the parallel use of access cards, nor has there been any information regarding the rights of the subjects and the exercise of these, while exclusively and only biometric characteristics are proposed as a method of entry/exit, and from the beginning to mid-May 2022, a letter from the N.O.B. was sent to the parents of children who are engaged in various activities of the Group to visit the Group Secretariat immediately to renew the access cards, as “from Monday, May 16, they will not operate, regardless of financial status, due to a change in the access system”, namely from 16-5-2022 and from now on the only way to enter/exit the Club by
members/accompanists/family members (children), who until then had personalized
entry cards with a photo, is through the use of biometric facial features.

Also, the complainant states that on 09-06-2022, through the Group's electronic newsletter, members were informed that they are now required to use the new system for entry, while visitors to the Group's members can, without any identification, such as by showing and recording their ID at the entrance and the required additional personal presence of the member, enter its premises at any time they wish, without the necessary simultaneous presence of the member, by simply using a combination of numbers (6+7 digits), which is quite easy to leak in any form, such as verbally, and/or its correct use based on the wishes of the subject/member cannot be checked, putting the other biometrically identified persons at an immediate security risk. characteristics
present. Finally, the complainant states that, as several members oppose the

use/processing of their biometric characteristics, the N.O.B.'s B.O.C.

temporarily accepted and gave directions to the security personnel to allow entry to

members who do not wish their biometric data to be processed to enter

side by side, with the mediation of the security personnel (door opening). Entry will be allowed upon presentation of the existing entrance card, which can be easily and

directly identified for its validity from the electronic files maintained by the N.O.B., a terminal (PC) of which is connected on-line to the

entrance gate. Specifically, as the complainant claims, during his visit to the N.O.B. on 13-06-2022, he was asked by security personnel in addition to the member's ID

and his police ID for identity verification, although there is

a printed photograph of the member on the entry ID. Another example

of the obstacle presented to those who do not wish to use biometrics, as

reported by the complainant, is that after 8 p.m. there is no staff at the entry/exit checkpoint, so if a member wants to enter at 6 p.m. and

wants to leave after 8 p.m., the only alternative is to call an

emergency telephone number and have one of the staff who is

"on call" come to open the door next door - at least 45 minutes with a 1-hour wait

to arrive - while the visitor enters or leaves by simply using a

number combination. The same applies to entering the N.O.B. premises after 8 p.m., since there is no security guard present and the previous

procedure must be followed, namely the emergency telephone number. With the no. prot. C/ΕΙΣ/10657/03-

10-2022 supplementary document, the complainant submits to the Authority the initial electronic message from 06-04-

2022 with the electronic newsletter of the N.O.B., in which the

Group informs its members, among other things, about the upcoming change in the incoming control system

.Specifically, this email states that:
“Now the controlled entry-exit system at N.O.B. has been modernized with new

technologies for security and the best experience for members. All that is needed

is 3 minutes of your time to obtain your biometric characteristics: go

to the N.O.B. Secretariat to complete your registration and then…

get rid of the card!”. Also, the complainant, with the same document, informs the Authority

that in an announcement that the Club had posted on its website on 09-03-2022
regarding the new controlled access system, it states, among other things, that: “The

Vouliagmeni Nautical Club is upgrading its systems with the aim of providing the best

possible experience for its Members, athletes and employees. The controlled access system at the N.O.B. facilities is being modernized and now the entry of Members and their families is carried out using their biometric characteristics. […] All you need to do is look steadily at the special registration screen in the new system for 3 seconds during your visit to the N.O.B. Secretariat. […] During this transitional stage that we are going through until the transition is completed, the card from the previous system will continue to operate. However, this will be abolished during the summer, so it is essential that all our Members have registered in the new system so that they can enter the N.O.B. […]The measurement and coding of the biometric characteristics of the geometry

of a person carried out by the system does not create a file of personal data that

could subsequently be reproduced in some way. In this context, your

personal data is safe.”

Subsequently, the complaint under no. Γ/ΕΙΣ/8648/08-07-2022

was submitted to the Authority, as supplemented by the document no. Γ/ΕΙΣ/8669/08-07-2022

by G, a member of N.O.B., against N.O.B., in which he also complains that

the new system was introduced, without N.O.B. notifying to the members that they have the option of choosing between the current electronic card system and that of biometric characteristics, without informing them about the characteristics of the new system, without informing them that there is the possibility of objection and revocation and without signing the relevant consent document, as well as that the installation of the new system was sudden and caught the members by surprise, while in accordance with the explicit and absolute statement of the, at the behest of the President of the N.O.B. and specific members who follow her, entrance control officers, misleadingly forced the incoming members to mandatory provide their biometric data, "in order to have the possibility of entering the N.O.B. from now on", as they constantly stated. No information sign has been posted, nor has an e-mail been sent to members informing them of the necessity of introducing the new system, or of the alternative use of the old system, or of the possibility of withdrawing consent to the processing of biometric data. The complainant states that in the new Operating Regulations of the N.O.B. approved in May 2022, there is no

reference to the alternative possibility of using the old control system

for incoming visitors, but according to the documents sent by the Authority to N.O.B. in June 2022,

the Group supplemented provision 2.1 of the said Regulation, as follows:

“We remind you that in the event of withdrawal of the Member’s explicit consent for

the use of his biometric data, he may enter the Group with the identification system with his personal membership card.” Finally, the complainant states that members

who disagree with the processing of their data by the new system cannot

have direct access to the N.O.B. facilities, at any time they wish, since

they cannot enter using the old cards, but they are obliged to

10call the caretaker by phone, to reach the entrance, and check

their identity and their card in relation to a handwritten list of members

who have refused to provide their biometric data, and considers that this

constitutes a particularly unequal treatment, a systematic coercion to violate

the regulations concerning the protection of personal data without any

necessity, while there is a perfectly functional system of electronic cards that

gives the possibility of controlling those who are inside the N.O.B. simply by showing

the card.

In view of the above, the Authority invited, with the documents No. Γ/ΕΣΕ/3165/07-12-2022,

Γ/ΕΣ/3163/07-12-2022 and Γ/ΕΣ/3164/07-12-2022, i. N.O.B., as legally represented, ii. complainant C, and iii. complainant A, respectively, to

attend the Plenary Session of the Authority on 13-12-2022, in order to

hold a hearing on the possible violation of the applicable legislation on the protection of personal data. With the above document, both relevant complaints in the case in question were forwarded

to N.O.B. At this meeting,

the request for postponement submitted by N.O.B. was discussed, which was accepted by the Plenary Session of the Authority and a new date for discussion was set for 07-02-2023. The meeting in question was attended by the complainants C with his attorney-in-fact

Dimitris Kampouramalis (AMDSA …) and D, who attended to provide

information, and A and on behalf of N.O.B. B, Chairman of the Board of Directors of the Group, E

and F, members of the Board of Directors of the Group with the attorneys-in-fact Dimitrios Vervesos

(AMDSA …) and Christina Panagoulea (AMDSA …), G, CEO of the company
Atermon Systems S.A. and H, General Manager of the company NousPratIT. The parties, after

expressing their views, received from the President of the Plenary a deadline to

submit memoranda.

With the no. prot. C/ΕΙΣ/1780/09-03-2023 memoranda, the first complainant,

in addition to what he stated during the discussion and in the documents he had submitted

to the Authority, pointed out that from the hearing and from the admissions of

the lawyer of N.O.B. he found the following significant violations on the part of

the Group:i. Violation of the principles of proportionality and necessity of the purpose

of processing, given that there are other milder forms of controlled access. The

alternative entry method for a member who has objected to the current method of control,

11is the demonstration of the identification documents carried by the member to the guard who

is at the gate between 8:00 a.m. and 8:00 p.m., and for the remaining hours or when the guard is absent for more hours during the

winter months, the member must call

the guard on duty from his/her mobile phone, a process that is time-consuming compared to the
use of the magnetic card. Responding to the claim of the NOB lawyer regarding the fact that the system was installed in order to minimize the personal data collected, since the member had to show his identity, the complainant states that identity was never requested, except that when the card was swiped, the member's photograph was displayed, unless the card had been cancelled or was counterfeit, and points out that the simple display of an identification document does not constitute the collection of personal data. ii. Violation of Articles 6 para. 1 GDPR and 5 para. 1a

and c for establishing the legal basis of legitimate interest for the processing of biometric data in question. iii. Regarding accountability, N.O.B., as a controller, violates Article 37 GDPR, as it has not appointed a Data Protection Officer (hereinafter referred to as the “DPO”) in the Authority, Articles 37 para. 1, 38 para. 3 and 39 para. 1 GDPR and Directive 243/2016 of the Article 19 Working Party, as its President performs the duties of an informal DPO, thus circumventing the functional independence of the DPO, Article 57 para. 1c GDPR and Directive 2016/680, as it did not previously request the Authority’s opinion to introduce a restriction on the protection of personal data, and finally Articles 35 GDPR, 27 of the Directive 2016/680 and 65 L.4624/2019, as no impact assessment study has been

prepared for the effects of the processing in question. iv.

The N.O.B. does not have the required documentation in relation to the processing in question
regarding the informing of its members and obtaining relevant consent, as the

information provided in the latest Internal Regulations is less than that

required by the GDPR, is not in an understandable and easily accessible form and does not

use clear and simple wording, while it has not drawn up a privacy policy

and has not posted it on its website. The method of obtaining consent from its members is particularly problematic given the dominant position of the Group over its members, who believe that they will be denied access to the Group's premises if they object to this processing. Finally, the complainant states that the President and the Secretary General, responsibly and under signature, stated that an alternative system, the card system, is in operation, a fact that is completely untrue, because this system has never coexisted with biometric data, and during the discussion before the Plenary Session of the Authority, the lawyer for N.O.B. clearly admitted that the card did not work as an alternative, nor was the appropriate

information provided before the new measure was imposed. v. The supplier did not clarify
a. what the “facial recognition” of the systems is (the biometric data that is

collected reveals racial origin or health issues and this comes into

conflict with fundamental human rights), b. what guarantees did N.O.V.

request and receive from the supplier regarding the protection of privacy

from the design and during the operation of these devices, c. whether any

contract was signed as a processor in the context of the supply of these

systems, and d. whether the supplier has been certified with a “privacy

seal” or “privacy audit assessment” standard.

With the memorandum no. C/ΕΙΣ/1842/13-03-2023, the N.O.B., in addition to

what it stated during the discussion before the Plenary and in the documents it has submitted

to the Authority, pointed out, with the request to recognize as permissible and lawful the

installation and operation of the ProFace system for the entry exclusively of the N.O.B. members, under the terms and conditions that may be dictated by the

Authority, that:

i. There is increased privacy of the N.O.B. with respect to the subjects on whom

the disputed entry control system is applied, namely because the N.O.B. is

a sports club and does not carry out commercial and professional activities and

the system under consideration processes data of a narrow circle of persons,

who have chosen to have the control carried out with the facial recognition system,

as there is a relationship of trust and intimacy between them and

the processing that takes place is limited, instantaneous, spatially defined

and no third party gains access to it and therefore the processing in question

even if it does not fall under the exception of Article 2, paragraph 2c of the GDPR (domestic or

personal activity), solely and solely due to the large number of

members of N.O.B., should be subject to legal assessment taking into account

the fact that the said processing meets all the criteria for the exception to the application

of the GDPR,

13ii. Despite the fact that N.O.B. presented a negative financial result for a

decade, the revenue in 2022 amounts to 3.5 million euros and the total revenue

is channeled to cover the Group's operational needs,

iii. Because, among other things, there were in the past many cases of card lending
and the practical inability to check identification during the summer months, with

the result that extremely worrying incidents have been observed, such as damage

to equipment, uncontrolled stay in the Club of unknown individuals, as in

the past the security guard recorded the name of a guest who indicated

a member or showed his identity without further control, while now each

member can use a code for the guests he is entitled
to invite and therefore bears responsibility for them, the system in question

was chosen as more secure in terms of data and guest protection.

The old system was the use of a magnetic RFID card and the member entered

from more than one entrance to the Group, by showing an identification document

that was often not applied and when applied it was

irrelevant because the photo did not correspond to reality due to its
oldness. For these reasons, it was unanimously chosen, without any

reaction from the members, at the Annual General Meeting of the Group's members in March 2022

to install at the entrance of the Group the "access control" system using

biometric data of the facial geometry for the purpose of the security of

persons and the facilities. In April 2022, a newsletter was sent to

all members to inform them of the installation of the new system, in

May 2022, the new Operating Regulation of N.O.B. for members with

reference to the way of using the new system and obtaining their biometric

data and in June 2022, after Mr. A's complaint, the

relevant article in the Regulation was amended and the possibility of disagreement/revocation

of the members' consent to the new system was provided for,

iv. Regarding the technical characteristics of ZKTeco's ProFace system,
it is noted that the coordinates of each person create a unique code through a

very sophisticated algorithm, and the device each time a member

enters does not recognize faces or biometric characteristics but

the code and the measurement and coding of biometric characteristics does

14 create a file of personal data in the system that could

be reproduced in some way. Also, the software complements the above

system in terms of security and has been installed together with ProFace on a different

server from the one that serves the rest of the Group's IT, is the
"Soft1 ERP" software, which is used for the commercial-accounting

IT of the members and from which, the ZKTeco system extracts information,

such as whether a member is financially aware in order to allow him

entry, in the following way: A member is created in the ERP (his details,

the billing details, which group he belongs to - whether he is a member or an attendant or other), with

a photograph of the person, from which the financial card of each

member is obtained, and if he is financially aware, the ERP informs ProFace that he

is allowed to enter. In the ERP there are also visitor cards with

a specific number of passes, while each financially aware member is entitled

to 2 cards. Each natural person is opened in the ERP and receives a 6-digit

code, and the user updates a flag field if he wants this

6-digit code to be opened in the ZKTeco system and the member is opened as a ZKTeco registration with
the same 6-digit code. The ERP is only updated with the number of passes that

the members' visitors make using the cards. The

access rights of each person are managed by N.O.B. Therefore, the ERP, as

N.O.B. claims, has no relation whatsoever to ProFace, nor is the

encrypted code used for identification

recorded/stored/archived anywhere in the ERP.
v. The controller of the biometric identification system is N.O.B.

and there is no processor, as, as reported by N.O.B., the company

NousPratIT that installed the system provides adhoc support services when

a technical issue arises and only gains access to the encrypted

data of ProFace. The DPO of N.O.B. has been appointed by the President of the Board of Directors of the Group,

while the Group intends to contract with a certified DPO. The subjects
whose data are processed with the new access control system

are the members and their companions, who amount to 3,500, while the employees,

visitors/fans, athletes and restaurant patrons continue

to use other systems and enter through other entrances. Recipients

15 of any data and, as regards biometrics, exclusively of the unique

code, are the salaried employees of the secretariat, who have access

only to the encrypted data and to those generated from reports of the

ProFace application. Under the assumption that no processing of biometric data takes place by the ProFace access control system, the legal basis for

processing is Article 6, paragraph 1a of the GDPR, since members signed a consent form upon registration, which explicitly states both their

rights and the possibility of revoking it. In addition, the N.O.B.

has a legitimate interest in the protection of persons and goods under

its responsibility, which is based on the case in paragraph 1 of Article 6 GDPR,
while under the assumption that special category data is being processed

Article 9 paragraph 2 paragraph a GDPR applies.

vi. The processing of data is governed by the principles of legality because it has

a legal basis, objectivity and transparency because there is full information about

the system, proportionality because the data are the most appropriate,

necessary and relevant for the intended purpose, as after weighing
the system in question was selected with the least possible interference

with the privacy of the members, in contrast to other technologically proposed

solutions, such as the use of fingerprints.

vii. Regarding the technical and organizational measures, it points out that regarding physical

security, the rack is located in a configured computer room, the backup of the files

of Windows server 2008 R2 is encrypted and is carried out only for the Group's
shared files and the historical data due to volume is 7 days and the

data is kept on 2 external disks, which the General Manager rotates

regularly.

viii. Because NOV. seeks further compliance, it has commissioned the performance

of an Impact Assessment Study and, whatever the result, it is committed to

taking it into account and adjusting, if necessary, its technical and

organizational measures. Since the hearing, it has already proceeded with

procedures for assigning to the company “GDPR Greece IKE” the project of obtaining

an ISO27001 certificate, i.e. the certificate for the security management

of 16 information and personal data processed within the

Group.

The Authority, after examining the information in the file, after hearing the rapporteur and the

clarifications from the assistant rapporteurs, who attended without the right to vote,
following a thorough discussion,

HAS DECIDED IN ACCORDANCE WITH THE LAW

1. Whereas, from the provisions of Articles 51 and 55 of the General Data Protection Regulation

(EU) 2016/679 (hereinafter "GDPR") and Article 9 of Law 4624/2019 (Government Gazette
A'137) it follows that the Authority has the competence to supervise the implementation of the provisions

of the GDPR, this Law and other regulations concerning the protection of individuals

from the processing of personal data.

2. Whereas, in accordance with the definitions of Article 4 item. 1 GDPR “personal data means any information relating to an identified or identifiable natural person (‘data subject’);…” and so on.14 biometric data means “personal data resulting from a specific processing technique relating to the physical, biological or behavioural characteristics of a natural person and which allow or confirm the unambiguous identification of that natural person, such as facial images or dactyloscopic data”.

3. Since biometric data are included in the special categories of personal

data, which are in principle prohibited from being processed, in accordance with
Article 9, paragraph 1 of the GDPR: “The processing of personal data

revealing racial or ethnic origin, political opinions,

religious or philosophical beliefs or trade union membership shall be prohibited,

as well as the processing of genetic data, biometric data for the purpose of

unambiguously identifying a person, data concerning health or data

concerning the sex life of a natural person or sexual orientation”.

Paragraph 2 of the same article provides for the exceptions to the above prohibition, the first of

which is the explicit consent of the subject. In particular, it is stated: “

Paragraph 1 shall not apply in the following cases: (a) the data subject has given explicit consent to the processing of those personal data

17 for one or more specific purposes, unless

Union or Member State law provides that the prohibition referred to in

paragraph 1 may not be lifted by the data subject, […]”.

4. Whereas, Article 5 of the GDPR sets out the processing principles governing the processing of

personal data. Specifically, it is stipulated in paragraph 1 that

personal data, among others: “a) are processed lawfully and fairly

in a transparent manner in relation to the data subject (“lawfulness,

objectivity and transparency”).

b) are collected for specified, explicit and legitimate

purposes and are not further processed in a manner incompatible with

those purposes (…),

c) are adequate, relevant and limited to what is necessary in relation to

the purposes for which they are processed (“data minimisation”) (…) f) are processed in a manner that ensures

appropriate security of personal data, including

their protection against unauthorised or unlawful processing and against accidental loss,

destruction or damage, using appropriate technical or organisational measures

(“integrity and confidentiality”)”, and in paragraph 2 that “the controller

shall be responsible for and shall be in a position to demonstrate compliance

with the principles of processing established in paragraph 1 ("accountability")".

In order for personal data to be lawfully processed, i.e.

processed in accordance with the requirements of the GDPR, the conditions for the application and observance of the principles of Article 5(1) of the GDPR must be cumulatively met

. The collection

and processing of personal data must always take place

in the light of the principles of proportionality and necessity and the

controller, in the context of his observance of the principle of fair or

fair processing of personal data, must inform

the data subject that he is going to process his data in a lawful and

transparent manner and be in a position at any time to demonstrate his compliance

with these principles. Also, as the Authority has already assessed, a

new compliance model was adopted with the GDPR, the central point of which is the principle of accountability, in the

framework of which the controller is obliged to design, implement and generally take the necessary measures and policies, in order for the processing of

data to be in accordance with the relevant legislative provisions.

3See Authority Decisions 36/2021, para. 3, 26/2019, para. 8, 44/2019, para. 19, available on its website.

18 Furthermore, the
controller is charged with the specific duty of proving himself and

at all times his compliance with the principles of Article 5(1) GDPR, both in relation to

the data subject for reasons of transparency of the processing, and, in particular,

before the Supervisory Authority. It is no coincidence that the GDPR integrates accountability (Article 5

para. 2 GDPR) into the regulation of the principles (Article 5 para. 1 GDPR) that govern processing,

giving it the function of a mechanism for their compliance,

essentially reversing the “burden of proof” regarding the lawfulness of processing (and in general, compliance with the principles of Article 5 para. 1 GDPR), shifting it to the controller,

so that it can be reasonably argued that he bears the burden of invoking and

proving the lawfulness of processing. Thus, it is the responsibility of the controller to, on the one hand, take the necessary measures to comply with the requirements of the GDPR, and, on the other hand, to demonstrate at any time the aforementioned compliance, without requiring the Authority, in the context of exercising its investigative and supervisory powers, to submit individual and specialized questions and requests to establish compliance. 5. Because, as recital 51 of the GDPR clarifies, special categories of data require special protection, since the context of their processing could create significant risks to fundamental rights and freedoms. While, therefore, in order for the processing of “simple”

personal data to be lawful, it is sufficient that one of the legal bases of Article 6 is present,

with regard to special categories of data, their processing is, in principle, prohibited and

permitted only if one of the legal bases of Article 6

and one of the exceptions of Article 9, paragraph 2, GDPR is cumulatively present.

6. Because the existence of a legal basis (Article 6, GDPR) does not exempt the controller from the obligation to comply with the principles (Article 5, paragraph 1, GDPR) regarding

legitimacy, necessity and proportionality, and the principle of

minimization. In the event that any of the principles set out in Article 5(1) of the GDPR are violated, the processing in question shall be deemed to be non-

4 See in this regard L. Mitrou, The Principle of Accountability in Obligations of the Controller [G.
Giannopoulos, L. Mitrou, G. Tsolias], Collective Volume L. Kotsalis – K. Menudoukou “The GDPR, Legal

5 Dimension and Practical Application”, 2nd ed. Law Library, 2021, pp. 265 et seq.
See Authority Decision 35/2022, sec. 8.

19 lawful (subject to the provisions of the GDPR) and it is unnecessary to examine the conditions

for the application of the legal bases of Article 6 of the GDPR. Thus, the unlawful collection and processing of personal data in violation of the principles of

Article 5 of the GDPR is not remedied by the existence of a legitimate purpose and legal basis (cf.

ADIPC 38/2004).

7. Because, according to Article 35(1) GDPR: “where a type of processing, in particular using new technologies and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the implications of the envisaged processing operations for the protection of personal data. An assessment may consider a set of similar processing operations which present similar high risks.” The Authority, in application of paragraph 4 of Article 35 GDPR, by its decision

65/2018, has drawn up and published a list of the types of

processing operations that are subject to the requirement to carry out a data protection impact assessment

pursuant to paragraph 1. These operations

include the following:

“1.2 Systematic processing of data for the purpose of taking automated

decisions, which produce legal effects concerning the data subjects

or significantly affect the data subjects in a proportionate manner and

may lead to exclusion or discrimination against the natural person (…).

1.3 Systematic processing of data which may prevent the subject from

exercising his rights or using a service or contract, in particular when

data collected by third parties (…) are taken into account.

2.1 Large-scale processing of special categories of data

(including genetic and biometric data for the purpose of unambiguous

identification of a person) referred to in Article 9(1) and of data referred to

in Article 10 of the GDPR.

3.1 Innovative use or application of new technologies or organizational solutions, which

may involve new forms of data collection and use, with a potential

high risk to the rights and freedoms of natural persons such as

6Government Gazette B 1622/10-5-2019
7See Decision of the DPA 65/2018 available on the Authority’s website

20 combined use of fingerprints and facial recognition for

improved physical access control, or mHealth applications or other “smart” applications,

from which a user profile is created (e.g. daily habits), or

artificial intelligence applications or publicly accessible blockchain technologies that

include personal data.”

8
8. Whereas, according to the EDPB Guidelines 3/2019:

“73. The use of biometric data, and in particular facial recognition, poses

increased risks to the rights of data subjects. These technological means should in any case be used in accordance with the principles of lawfulness, necessity, proportionality and data minimisation as set out in the GDPR. While the use of these technologies can be considered to be particularly effective, controllers should first of all assess the impact of these technological means on fundamental rights and freedoms and consider the use of less intrusive means to achieve the legitimate purpose of the processing. 74. The processing of raw data such as the physical, biological or behavioural characteristics of a natural person, in order to be considered as processing of biometric data as defined in the GDPR, must involve the measurement of those characteristics. Since biometric

data are the result of such measurements”, the GDPR definition in Article

4(14) applies, as set out above, “However, video footage depicting

individuals cannot be considered as biometric data as such pursuant to

Article 9, unless the footage has previously undergone specific technical processing

in order to contribute to the identification of individuals.” 75.

The processing of biometric data, in order to be considered as processing of special categories

personal data (Article 9), must be “for the purpose of unambiguous

identification of a person”.

76. In summary, in the light of Article 4(14) and Article 9, three criteria should be

taken into account:

- Nature of the data: data relating to the metaphysical, biological or behavioural

characteristics of a natural person,

- Means and method of processing: data which “result from a specific technique

8 Guidelines 3/2019 on the processing of personal data by means of video devices, 29-01-2020, pp. 20 and 21.

21 processing”,

- Purpose of the processing: the data must be used for the purpose of

unambiguously identifying a natural person.

77. The use of video surveillance systems including biometric recognition functions installed by private entities for their own purposes (e.g. for marketing, statistical or even security purposes) most often requires the explicit consent of all data subjects (Article 9

(2)(a)), although in this case another legitimate exception to Article 9 may apply.”

9. Since, according to the case-law of the Court of Justice of the European Union, 9 “as is clear from recital 39 of the GDPR, the requirement of necessity is not met if the general interest objective pursued can reasonably be achieved in an equally effective manner by other means which are less intrusive to the fundamental rights of data subjects, in particular the rights to respect for private life and to the protection of personal data as enshrined in Articles 7 and 8 of the Charter, taking into account that derogations and limitations to the principle of the protection of such data must not go beyond what is strictly necessary” and “the requirement of necessity of the processing must be considered in conjunction with the so-called principle of ‘data minimisation’, as laid down in Article 6(1)(c) of the Charter, of

Directive 95/46, as well as Article 5, paragraph 1, letter cʹ, of the GDPR, according to which

personal data must be adequate, relevant and limited
10
to what is necessary in relation to the purposes for which they are processed”.

This decision essentially accepts that processing is lawful only for

necessary data.

10. Whereas, in the Opinion of the Advocate General of the CJEU of 06-10-2022, submitted

in the context of the procedure for issuing the CJEU decision of 04-05-2023 in case
C-300/2021, it is stated, among other things, that “73. The consent of the data subject, as the highest expression of control, constitutes only one of the legal bases for lawful processing, but is not capable of validating the non-compliance with the other obligations and conditions incumbent on the controller and the processor. 74. It is not, in my opinion, easy to infer from the GDPR that the purpose of the latter is to provide the data subject with control over personal data as an independent value. Nor that the data subject should have the greatest possible control over his or her data. 75. This finding is not surprising. On the one hand, it is not

obvious that control, in the sense of data ownership, forms part of the

essence of the fundamental right to the protection of personal data.

On the other hand, the recognition of this right as a right to informational self-determination is otherwise unanimous: Article 8 of the

Charter does not use these terms.

For the record, the final

text of the GDPR did not include a recital stating that “the right to the

protection of personal data is based on the right of the

data subject to exercise control over the personal data

which are processed”.

11. Whereas, with regard to the data protection officer, in accordance with Article 38paragraph 3 GDPR “The controller and the processor shall ensure that the data protection officer does not receive instructions in order to carry out these tasks. He shall not be dismissed or penalised by the controller or the processor for carrying out his tasks. The data protection officer shall be directly accountable to the highest management level of the controller or the processor”, paragraph 5 “The data protection officer shall be bound by the secrecy or confidentiality of the performance of his tasks, in accordance with Union or Member State law” and paragraph 6 “The data protection officer may also perform other tasks and obligations. The controller or processor

shall ensure that these tasks and obligations do not give rise to a conflict of

interests.” Furthermore, the OA 29 Guidelines 11 state that “the

data protection officer shall not hold a position within the organization

from which he or she can determine the purposes and means of the

processing of personal data. Since each organization has a different organizational

structure, this issue should be examined on a case-by-case basis.”

11 OA 29 Guidelines on Data Protection Officers, WP 243 rev.01,
Chap. 3.5

2312. Whereas, in the case under consideration, it appears from the information in the file, the hearing of the

parties involved, and the submissions submitted that:

i. N.O.B., in accordance with the “N.O.B. Operating Regulations for Members -2022”, has

installed and is operating, at least since mid-May 2022, at the entrance to its

premises a “biometric features system”, as it

describes it, which identification system is based on facial geometry

which is unique for each person. For the operation of this system,

the subject must enter the special area of N.O.B. in order to make the

required image of distinct geometric elements of each

person. The system collects the coordinates of the facial geometry

which are processed through an algorithm, which creates a

code for each user and the above data are stored digitally on the N.O.B. server

for as long as the data subject is an active member of

the Group.

Therefore, the Authority finds that with the said login identification system, a special category of personal data is processed and N.O.B. becomes the controller of such data.

ii. At the time the complaints against N.O.B. were filed, N.O.B. members

did not have the option of using another login system to the Group,

other than the system under examination, as for some time, this

constituted their only way of logging in.

iii. In the “N.O.B. Operating Regulations for Members - 2022”, submitted by N.O.B. with its
document no. Γ/ΕΙΣ/8383/29-06-2022, it is stated that “For

the login to N.O.B. of Members (main and protected)

biometric characteristics are used. After their registration in the biometric system, the plastic cards are cancelled. […] We remind you that in the event of a Member’s withdrawal of their explicit consent for the use of their biometric data, they may enter the Group using the identification system with their personal membership card.” However, the form available to N.O.B. members at the same time, “Information Form for Registered Members Regarding Their Personal Data,” provides information on the processing of personal data, without reference to the data that is processed with the biometric system in question and the legal basis for consent for special category data. With the memorandum submitted to the Authority by N.O.B. after the

hearing before the Plenary under no. prot. C/EIS/1842/13-03-2023

presented the “Consent Form for
the ProFace biometric identification system as an Access Control method at NOB”, which states that “It is expressly assured by the Group,

that the biometric/geometric (not imaging) data used for identification/identification are not collected in a file,

nor stored on a PC unit” and “I expressly declare that I HAVE BEEN INFORMED of

the above processing of biometric data that takes place by
the Vouliagmeni Nautical Club and I AGREE to said processing”, and

a relevant selection field is given to the subject. Finally, in the response email from NOB dated 28-04-2022

to … the first

complainant, following their statement of opposition to the

processing of their personal data dated 16-04-2022, it was stated that “any refusal

to comply [i.e. granting consent for the new login system],
may constitute a reason for not maintaining your status as a member of the

Group”.

iv. The subjects whose data are processed with the new

access control system are the members and their companions, who amount to

3,500, while the employees, visitors/fans, athletes and restaurant patrons

continue to use other systems and enter from other entrances.

v. Regarding the impact assessment, the initial response of the N.O.B. to the

Authority was that it was not deemed necessary to prepare it, while after the hearing

before the Plenary, the N.O.B. informed the Authority that it has commissioned the

conduct of this study and, whatever the result, it undertakes to

take it into account and to adjust, if necessary, the technical and

organizational measures it has already implemented. N.O.B. has not submitted to the Authority

an impact assessment for the system under examination.

vi. N.O.B. has appointed the President of the Board of Directors of the

Group as Data Protection Officer.

2513. Whereas, in view of the above, the Authority finds that N.O.B. has installed and

put into operation the biometric features system under examination, for which,

as follows from the above paragraph 12.i., the processing of a special category

of personal data of the subjects is required, and N.O.B. becomes responsible for

their processing. This processing relates to the systematic processing of data using new technology and automated data processing, with a potential high risk to the rights and freedoms of natural persons (facial recognition), as large-scale processing of special categories of data of approximately 3,500 subjects takes place, as it concerns all members of the Group and their companions. From the case file, it appears
that the controller has not documented that the use of the new system is necessary and proportionate
and in particular that it is not possible for the purpose of the processing
to implement softer forms of controlled entry into the space, by processing
simple data, while for some time it implemented the said
biometric characteristics system, without having provided appropriate information to
the subjects about the processing of their data, without having obtained their consent
and without providing an alternative method of controlled entry. Therefore, if the controller, who is required to demonstrate compliance with the principles of Article 5(1)(a) of the GDPR, has not demonstrated the necessity of the purpose of the processing in question, the principle of lawfulness (Article 5(1)(a)) has been infringed and the processing of special categories of personal data in question is deemed unlawful, in accordance with the provisions of paragraph 6, it is unnecessary to examine the existence of a legal basis for processing under Article 6 of the GDPR and the application of the exceptions to the prohibition of processing special categories of personal data under Article 9(2) of the GDPR.

14. Since, although, according to what is set out in paragraph 7, NOV as controller

was obliged, pursuant to Article 35(3)(c) GDPR and the aforementioned Decision 65/2018 of the Authority, to carry out an impact assessment

12
See i. Guidelines on Data Protection Impact Assessment (DPIA)
determining whether the processing is “likely to result in a high risk” for the purposes of
Regulation 2016/679, OM no. 29 WP 248 rev. 01, ii. Opinion 7/2018 EDPB, and iii. Decision 65/2018 DPA
"List of types of processing operations subject to the request for a data protection impact assessment in accordance with Article 35(4) of the GDPR

26regarding the protection of a special category of data, did not document before the
Authority, in accordance with the principle of accountability (Article 5(2) of the GDPR), its compliance

with this obligation, the breach of which constitutes an independent breach under

Article 35 of the GDPR.

15. Since, according to the GDPR and the OE29 Guidelines, the Data Protection Officer (hereinafter referred to as the “DPO”) must exercise his or her duties independently and is therefore not allowed to hold a position within the controller from which he or she can determine the purposes and means of the processing of personal data. In this specific case, the President of the Board of Directors of the N.O.B., as the legal representative of the controller, determines the purposes and means of the processing of personal data and by assigning her the duties of DPO, objective supervision of compliance with the GDPR is not ensured. Therefore, according to the above Guidelines, the position of

Chairman of the Board of Directors comes into a material conflict of interest and is incompatible with

the position of DPO, and, consequently, the coincidence of these two capacities in the same person

comes into conflict with the provision of Article 38(3) of the GDPR.

16. Because, based on the above, the Authority considers that there is a case to exercise the corrective powers of imposing fines under

Articles 58 par. 2 i’ and 83 GDPR, with regard to the violations established above, as well as the corrective powers under Article 58 par. 2 d’

and in order to impose on the controller the

obligation to prepare an impact assessment study for the processing of personal data of the subjects through the system under examination and the

suspension of this processing until the study is prepared. In order to determine the

fines, so that they are effective, proportionate and dissuasive, the measurement criteria set out in Article 83(2) of the GDPR, which are

applicable to the present case, as specifically interpreted by the

Guidelines 4/2022 of the EDPB on the calculation of administrative
14
fines, are taken into account.

17. Whereas, when assessing the data, the Authority takes particular account of:

13See supra footnote 11.

14https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-042022-calculation-

administrative-fines-under_en - version 2.1

27 i. the nature and gravity of the infringement, which concerns the basic principles

of lawfulness of processing which are fundamental for the protection of personal data, in accordance with the GDPR, taking into account that,

regardless of the fact that compliance with the principles provided for by

the provision of Article 5 of the GDPR is of paramount importance, primarily, the

principle of lawfulness, so that, if it is absent, the

processing becomes unlawful from the outset, even if the other principles of processing have been complied with, in

this case it was established that unlawful processing was carried out using

the system under examination,

ii. that the processing in question concerns a special category of personal data
of a large number of subjects,

iii. that the controller considered the possibility of carrying out an impact assessment

and decided that it was not required

iv. the fact that the violation of the provisions relating to the basic principles for

processing falls, in accordance with the provisions of Article 83, paragraph 5, paragraphs a and b

GDPR, into the highest category of the grading system
of administrative fines,

v. that the revenues of NOV amount to 3.5 million for the year 2022

Based on the above, the Authority unanimously decides that the

complained Group, as controller, should be imposed the

administrative sanctions referred to in the operative part

, which are deemed proportionate to the gravity of the violations.

FOR THESE REASONS

The Authority

A. Imposes on the Vouliagmeni Nautical Club, as controller, based on
Article 58, paragraph 2, subparagraph i’ of the GDPR, a fine of twenty-eight thousand euros (28,000 €)

euro for the violation of the principle of lawfulness (Article 5, paragraph 1, subparagraph a’ of the GDPR).

B. Imposes on the Vouliagmeni Nautical Club, as controller, based on

Article 58, paragraph 2, subparagraph i’ of the GDPR, a fine of fourteen thousand euros (14,000

€28) euros for the failure to carry out an impact assessment of the biometric features

controlled entry system (Article 35 of the GDPR).

C. Orders the Vouliagmeni Nautical Club, as controller, on the one hand, on the basis of

Article 58, paragraph 2, subparagraph d’ of the GDPR, to prepare, in accordance with Article 35 of the GDPR,

a study assessing the impact of the processing operations through the biometric

features controlled entry system on the protection of personal data

and on the other hand, on the basis of Article 58, paragraph 2, subparagraph f’ of the GDPR, to discontinue the processing

of personal data through the aforementioned biometric

features controlled entry system, until it has prepared an impact assessment study,

according to the above and to inform the Authority regarding the above actions,

at the latest within three (3) months from the notification of this.

D. Imposes on the Vouliagmeni Nautical Club, as controller, based on

article 58 par. 2 sub. i’ of the GDPR, a fine of fourteen thousand euros (14,000

€) euros for the violation of article 38 par. 3 of the GDPR.

The President The Secretary

Konstantinos Menuudakos Irini Papageorgopoulou

29