The Croatian data protection authority (AZOP) imposed a €2.59 million fine on a casino company for collecting fingerprints and photographs in violation of the GDPR. The authority found that the company violated the principle of data minimization by collecting four fingerprints without demonstrating that doing so was necessary. It also found that the company’s consent was invalid because multiple processing purposes were bundled together.

What happened, and why does it matter for U.S.-based companies in the gaming industry and beyond?

What Happened

At issue was the collection of players’ fingerprints as an optional method of expedited identification at the casino. Players could also be identified using an identification card or RFID chip.

The fact that fingerprint identification was optional did not change the authority’s conclusion that the practice was unlawful.

There were two principal issues: data minimization and consent.

Data Minimization

By collecting four fingerprints, the controller collected more personal data than was necessary for the stated purpose of identifying the player.

The controller argued that additional fingerprints were needed because the skin on a player’s fingers could be damaged, resulting in an incorrect or failed reading. The authority concluded, however, that a general reference to the availability of “backup” fingerprints did not, by itself, establish that collecting them was necessary.

The controller needed to demonstrate why four fingerprints were necessary for the specific purpose and whether that purpose could be achieved just as effectively by collecting fewer fingerprints and using additional methods of identity verification. It was unable to do so.

This principle is also reflected in many U.S. state privacy laws, with Maryland imposing a particularly stringent data minimization standard.

Here, however, the authority also found that the consent itself was deficient for several reasons:

  1. When registering at the casino, customers were presented with numerous documents concerning the processing of personal data.
  2. Those documents contained inconsistent and incomplete information about the purposes and legal bases for processing.
  3. The purposes of individual processing activities were not specified or connected to particular processing activities.

Why This Matters

The decision offers the following important takeaways for US-based companies.

First, making biometric processing optional does not eliminate the obligation to limit collection to what is necessary for the stated purpose. A company should be prepared to demonstrate why each data element is needed and why the same purpose cannot be achieved through less extensive collection. U.S. privacy laws impose similar data minimization requirements, and regulators have signaled that they intend to enforce them.

In the US, biometric data is sensitive data under the State privacy laws and would require opt-in consent in many cases. The definition of opt-in consent under many U.S. state privacy laws closely resembles the EU standard, requiring consent to be freely given, specific, informed, unambiguous, and revocable.

Third, privacy disclosures must be accurate, complete, and easy to understand. Each stated purpose should be clearly linked to the relevant processing activity. Regulators, including those in California, have already brought enforcement actions involving noncompliant privacy notices, and companies should expect that scrutiny to continue.