UODO - ZSZZS.440.768.2018

From GDPRhub
Revision as of 15:38, 9 March 2020 by AL (talk | contribs)
UODO - ZSZZS.440.768.2018
Authority: UODO (Poland)
Jurisdiction: Poland
Relevant Law: Article 5(1)(c) GDPR
Article 9(1) GDPR
Article 58(2)(f) GDPR
Article 58(2)(g) GDPR
Article 58(2)(i) GDPR
Article 83(2) GDPR
Article 83(3) GDPR
Article 83(5)(a) GDPR
Article 83(7) GDPR
Type: Investigation
Outcome: Violation found
Decided: 18. 2. 2020
Published: 5. 3. 2020
Fine: 20.000 PLN
Parties: Szkoła Podstawowa nr 2 w Gdańsku (Primary School in Gdańsk)
National Case Number/Name: ZSZZS.440.768.2018
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Polish
Original Source: UODO (in PL)
Initial Contributor: {{{Initial_Contributor}}}

President of the Personal Data Protection Office (pol. PUODO) imposed a fine of PLN 20.000 (€4.700) in connection with the breach consisting in the processing of biometric data of children when using the school canteen.

English Summary


The school processed special categories of data (biometric data) of 680 children without a legal basis, whereas in fact it could use other forms of students identification. (...) Following an ex officio administrative proceedings, the President of the UODO has established that the school is using a biometric reader at the entrance to the school canteen that identifies the children in order to verify the payment of the meal fee.

The proceedings has shown that the school obtains the data and processes them on the basis of the written consent of the parents or legal guardians. The solution has been in place since 1 April 2015. In the school year 2019/2020, 680 pupils use a biometric reader and four pupils - an alternative identification system.[1]