Home » Comunicat_Presa_12.03.2026
 Română | English | Francais

12.03.2026

Warning: Potential GDPR Violation

 

The National Supervisory Authority for Personal Data Processing has completed an investigation into ARRISE LIVE SRL and issued a warning pursuant to Article 58(2)(a) of Regulation (EU) 2016/679.

The investigation was initiated following complaints indicating that ARRISE LIVE SRL intended to implement a security system based on facial recognition for employees’ access to the company’s premises/work locations.

As part of the investigation, it was established that the processing of biometric data was intended to serve the purpose of ensuring secure access to the company’s premises, while the controller was already using an access control system based on cards.

Therefore, the biometric access control system had not yet been implemented, meaning that the controller had not processed biometric data relating to employees, suppliers, or visitors.

Furthermore, the investigation established that the facial biometric recognition system had been designed to prevent unauthorized access by accurately verifying individuals’ identities and to address the misuse of access cards.

It was also found that the situation presented by the controller did not meet the requirements of lawfulness, necessity, and proportionality applicable to the processing of biometric data relating to its own employees, suppliers, and visitors. Such processing could have adversely affected the right to privacy and the right to the protection of personal data of the data subjects who were expected to access the controller’s premises/locations.

In this context, the controller was advised to use less intrusive means to achieve the purpose of the processing, which would not involve the processing of biometric data.

Accordingly, a warning was issued to ARRISE LIVE SRL, as the processing operations involving the personal data of data subjects through the facial recognition system could have violated the provisions of Article 5(1)(a) and (c) of Regulation (EU) 2016/679, read in conjunction with Article 6 of the GDPR.

 

Legal and Communication Department

A.N.S.P.D.C.P