Spanish supermarket chain Mercadona fined for facial recognition privacy violations
Supermarket chain Mercadona was fined EUR 2.5m by AEPD, Spain's data protection regulator, for illegally collecting and processing childrens' and employees' biometric data. The stated aim of the programme was to detect known criminals and people with restraining orders issued against them for attacking Mercadona employees, with cameras equipped with facial recognition identifying relevant transgressors, who would then be reported to the police. AEPD ruled, under the EU's General Data Protection Act (GDPR), that Mercadona had failed to appreciate that its system processed sensitive data of anyone who entered its supermarkets, including childen and its own employees. The regulator also found that Mercadona had violated GDPR Article 12 and 13 transparency requirements, including the ability of those affected to complain or appeal. Mercadona's facial recognition system was supplied by Israeli company AnyVision ( since renamed Oosto) . System 🤖 Unknown Operator: Mercadona Developer: AnyVision (Oosto) Country: Spain Sector: Retail Purpose: Identify criminal suspects Technology: Facial recognition Issue: Accountability; Privacy/surveillance ; Transparency Legal, regulatory 👩🏼⚖️ AEPD (2021). RESOLUCIÓN DE TERMINACIÓN DEL PROCEDIMIENTO POR PAGO VOLUNTARIO
- Date it happened
- 2021-07-01
- Organisation involved
- Mercadona
This incident was imported from AIAAIC and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.