Croatian Privacy Regulator Fines Gambling Operator €2.59 Million Over Fingerprint Collection
Key Takeaways
- €2.59 Million Fine: Croatia’s data protection authority fined an unnamed gambling operator over violations involving biometric data, consent and transparency.
- Four Fingerprints Collected: The operator said it collected two fingerprints, but inspectors found it collected four, which the regulator determined went beyond what was necessary for player identification.
- Consent Fell Short: Consent covering fingerprints and photographs bundled multiple processing purposes together without giving players meaningful separate choices.
- Nearly 35,000 Players: Consent to biometric data processing had been recorded for 34,933 players.
- Privacy Information Conflicted: The regulator found that documents provided to players contained incomplete, inaccurate and contradictory information about processing purposes and legal bases.
Deep Dive
A gambling operator in Croatia offered its casino customers a shortcut. Instead of producing an identity card on every visit, players could use an RFID chip or their fingerprints to identify themselves more quickly. For 34,933 players, consent to biometric processing was recorded. But when Croatia’s Personal Data Protection Agency examined how that system actually worked, it found that the operator was collecting more than it said it was collecting.
The company maintained that it took fingerprints from two fingers. Inspectors found four were being collected, two from each hand, and used to identify players. The explanation was practical enough on its face. Fingers can be damaged. Prints can fail to read. Having additional fingerprints available gave the system a backup. The regulator’s answer was that convenience does not establish necessity.
In supervisory proceedings opened on its own initiative, the agency found that the operator had not demonstrated why four fingerprints were needed to identify a player, or why the same job could not be done with fewer prints backed by another method of identity verification. That failure became part of a broader case over how the company handled some of the most sensitive information it held.
The result was a €2.59 million administrative fine for violations of the General Data Protection Regulation. Croatian law allows biometric data to be processed for the secure identification of service users when the individual has given explicit consent that satisfies the GDPR. But consent does not cure excessive collection. Personal data must still be adequate, relevant and limited to what is necessary for the purpose for which it is being processed.
That requirement carries particular force with biometric information. A person may agree to provide a fingerprint. The controller still has to justify how much biometric data it takes.
The agency concluded that the operator had failed on both fronts. It found that players’ biometric data had been processed without valid consent and beyond what was necessary for the stated purpose, violating Article 6(1) and Article 9(1), read together with Article 9(2)(a), as well as the lawfulness and data-minimization requirements under Article 5(1)(a) and (c). The fingerprints, though, were only where the trouble became easiest to see.
Consent Without Much Choice
At registration, casino customers were shown a document containing interactive fields for four consents. The regulator examined the first two and found that neither met the GDPR requirement that consent be freely given, specific, informed and unambiguous.
The first concerned fingerprint scans. Rather than asking players to make separate choices about separate uses, the operator folded several purposes into a single declaration. Those purposes included providing services and performing contracts, establishing identity, statistical purposes, profiling, improving and personalizing services, protecting rights and property, and enforcing the prohibition on minors participating in gambling.
There was another problem buried in the same language. According to the agency, the information presented to players created the impression that processing during registration rested on consent without clearly separating identification processing required by law from the optional use of biometric data.
That left the player facing what looked like one decision where, under the GDPR, there needed to be meaningful choices.
The second declaration dealt with photographs and again combined different purposes. The agency found that a player could not clearly determine whether a photograph would be used solely to establish identity or for other stated purposes, nor could the player consent separately to those uses.
The regulator concluded that the company had combined different processing purposes without giving players the ability to choose between them and had failed to present the consent requirements with sufficient clarity. That amounted to an infringement of Article 7 of the GDPR in conjunction with Article 4(11).
When the Paperwork Stops Agreeing With Itself
The investigation then moved beyond what players were asked to accept and into what they were told. Casino registration came with a substantial collection of documents explaining the processing of personal data. Those documents did not consistently describe the same system. The regulator found incomplete and conflicting information about why data was being processed and the legal grounds relied upon to process it. Some purposes were not specified. In other places, legal bases were not clearly tied to particular processing operations.
The operator’s general rules provided one of the clearest examples. There, fingerprints were connected not simply with identifying someone entering the casino but with controlling and monitoring entry to branches, protecting minors, participation in gambling, use of the bonus rewards program and other purposes.
For a player trying to understand what would happen to a fingerprint after providing it, the problem was no longer the amount of information available. It was whether the information could be relied upon.
The agency found that it could not. The material given to players was incomplete, inaccurate and mutually contradictory when describing the purposes and legal bases for individual processing operations. As a result, data subjects could not clearly understand why their information was being used or which legal basis supported each use.
That breached Articles 12(1) and 13 of the GDPR and the transparency principle contained in Article 5(1)(a), the regulator found. The agency imposed a total administrative fine of €2.59 million across the violations identified in the proceeding. Its published notice does not name the gambling operator.
The case leaves behind a fairly unforgiving record of how an identification system can go wrong without any single spectacular failure. Four fingerprints were collected where the necessity of four had not been established. Several purposes were placed behind a single consent. Mandatory and optional processing were not cleanly separated. Different documents gave players different accounts of what their information was being used for.
By the time the regulator put those pieces beside one another, the problem was no longer confined to a fingerprint scanner at the casino door. It was the operator’s inability to give a consistent, legally sufficient account of why it was collecting the data in the first place.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.


