The Croatian data protection authority (AZOP) imposed a €2.59 million fine on a casino company for collecting fingerprints and photographs in violation of the GDPR. The authority found that the company violated the principle of data minimization by collecting four fingerprints without demonstrating that doing so was necessary. It also found that the company’s consent was invalid because multiple processing purposes were bundled together.
What happened, and why does it matter for U.S.-based companies in the gaming industry and beyond?
What Happened
At issue was the collection of players’ fingerprints as an optional method of expedited identification at the casino. Players could also be identified using an identification card or RFID chip.
The fact that fingerprint identification was optional did not change the authority’s conclusion that the practice was unlawful.
There were two principal issues: data minimization and consent.
The relevant consent language stated:
“I give my consent to the collection and processing of biometric data, i.e. fingerprint scans, which data are collected for the purpose of providing services/execution of contracts, determining the identity of parties, statistical purposes, profiling, improvement and personalization of the service, protection of rights and property, enforcement of the ban on participation in games of chance for minors.”
Data Minimization
By collecting four fingerprints, the controller collected more personal data than was necessary for the stated purpose of identifying the player.
The controller argued that additional fingerprints were needed because the skin on a player’s fingers could be damaged, resulting in an incorrect or failed reading. The authority concluded, however, that a general reference to the availability of “backup” fingerprints did not, by itself, establish that collecting them was necessary.
The controller needed to demonstrate why four fingerprints were necessary for the specific purpose and whether that purpose could be achieved just as effectively by collecting fewer fingerprints and using additional methods of identity verification. It was unable to do so.
Consent Cannot Cure Excessive Collection
Even valid consent would not cure the collection of data that is not adequate, relevant, and necessary for the stated purposes of the processing.
This principle is also reflected in many U.S. state privacy laws, with Maryland imposing a particularly stringent data minimization standard.
Here, however, the authority also found that the consent itself was deficient for several reasons:
- When registering at the casino, customers were presented with numerous documents concerning the processing of personal data.
- Those documents contained inconsistent and incomplete information about the purposes and legal bases for processing.
- The purposes of individual processing activities were not specified or connected to particular processing activities.
- The legal bases were not clearly linked to specific processing activities.
- Consent was bundled, and individuals could not separately select the purposes to which they agreed. In other words, the company did not provide players with a meaningful opportunity to decide which uses of their biometric data they would accept.
Why This Matters
The decision offers the following important takeaways for US-based companies.
First, making biometric processing optional does not eliminate the obligation to limit collection to what is necessary for the stated purpose. A company should be prepared to demonstrate why each data element is needed and why the same purpose cannot be achieved through less extensive collection. U.S. privacy laws impose similar data minimization requirements, and regulators have signaled that they intend to enforce them.
Second, consent is not a workaround for data minimization. Even carefully drafted consent cannot make excessive data collection lawful. Where consent is relied upon, each purpose must be clearly identified and presented in a way that allows individuals to make a specific and meaningful choice.
In the US, biometric data is sensitive data under the State privacy laws and would require opt-in consent in many cases. The definition of opt-in consent under many U.S. state privacy laws closely resembles the EU standard, requiring consent to be freely given, specific, informed, unambiguous, and revocable.
Third, privacy disclosures must be accurate, complete, and easy to understand. Each stated purpose should be clearly linked to the relevant processing activity. Regulators, including those in California, have already brought enforcement actions involving noncompliant privacy notices, and companies should expect that scrutiny to continue.