Executive Summary and Core Findings
The unauthorized deployment of biometric recognition systems across public educational facilities represents a structural breach of European data governance and fundamental privacy rights. In a formal enforcement action, national data protection authorities intervened against unlawful employee attendance tracking inside a state educational facility, reaffirming the strict prohibitions surrounding sensitive identifier processing.
Public institutions that capture and store physical identifiers create irreversible systemic vulnerabilities for their personnel. When biometric attendance mechanisms operate without an explicit statutory mandate or strict proportionality safeguards, they violate foundational European Union regulations designed to protect worker dignity and sensitive personal data from systemic overreach.
This investigation examines the legal collapse of public sector biometric tracking, tracing how administrative inertia led an educational body to maintain illicit biometric control infrastructure years after parliamentary legislation abolished statutory authorizations for automated employee scanning in civil administration workplaces.
Historical and Legislative Context
The operational trajectory of workplace biometric surveillance within Italian public administration underwent a decisive legislative reversal between 2019 and 2020. Under the initial framework established by Law 19 June 2019, n. 56, lawmakers introduced provisions within Article 2, paragraphs 1 through 4, that envisioned widespread biometric verification systems to combat absenteeism across state offices.
That initial legislative experiment encountered immediate constitutional friction and regulatory resistance due to severe privacy risks. Recognizing the disproportionate nature of harvesting bodily metrics for routine administrative attendance, the Italian Parliament formally dismantled this mechanism through Law 30 December 2020, n. 178, completely repealing the biometric surveillance provisions of the earlier statute.
Despite this clear statutory repeal, legacy implementation projects and commercial vendor momentum left numerous public administrations in legal limbo. Local institutions continued acquiring, activating, or maintaining fingerprint and facial recognition terminals, ignoring the reality that no valid statutory basis existed under domestic or European law to justify such processing.
The institutional friction culminated when three public employees, designated in official records as XX, XX, and XX, retained legal counsel to formally challenge their school employer’s physical tracking apparatus under Article 77 of Regulation (EU) 2016/679, initiating a comprehensive oversight proceeding into institutional non-compliance.
The resulting inquiry brought national regulatory scrutiny to the administrative seat of the public school, triggering defense procedures and technical assessments regarding the deployment of digital fingerprint terminals across secondary school campuses.
Institutional Actors and Administrative Targets
The primary entity subject to regulatory sanction is the Istituto di Istruzione Superiore “P. Galluppi” Tropea, located at viale Coniugi Crigna snc, 89861 Tropea (VV), operating under tax identification code 96012510796. As an autonomous secondary education complex, the institute acts as the formal data controller under European privacy frameworks.
The administrative oversight body directing the enforcement proceeding is the Italian Data Protection Authority, known as the [[Garante per la protezione dei dati personali|Q3758364]]. Operating under independent statutory powers, the authority serves as the supervisory body empowered to investigate unlawful processing, apply administrative sanctions, and enforce binding corrective measures across the national territory.
At the international regulatory level, the enforcement methodology adheres strictly to the unified oversight benchmarks articulated by the [[European Data Protection Board|Q54958988]]. Specifically, the calculation and characterization of punitive measures directly reflect the official EDPB Guidelines 4/2022 on the calculation of administrative fines under the General Data Protection Regulation.
The complaining parties—identified in supervisory records under procedural anonymity safeguards as employees XX, XX, and XX—acted through designated legal counsel to enforce their rights under European privacy statutes, seeking an immediate cessation of illicit physiological data processing within their workplace.
Administrative records indicate that the legal representative pro-tempore of the educational institute was formally summoned to provide defense submissions and evidentiary documentation pursuant to Article 166, paragraphs 6 and 7 of the Italian Privacy Code and Article 18, paragraph 1 of Law 24 November 1981, n. 689.
Critical Analysis of Evidence and Systemic Violations
Technical verification of the attendance system confirmed that the infrastructure extracted physiological markers directly linked to unique identification codes assigned to each worker. Under Article 4, items 1 and 14 of the General Data Protection Regulation, data resulting from specific technical processing relating to physical characteristics constitutes special category biometric data requiring absolute legal justification.
The regulatory evaluation established that the school operated without a lawful exception under Article 9, paragraph 2 of the Regulation. Processing special categories of personal data is explicitly prohibited unless an exceptional condition applies in strict conformity with public interest guarantees and specific supervisory measures established by the competent data protection authority.
“La norma prevede che è lecito il trattamento di tali categorie di dati al ricorrere di una delle condizioni di cui all’art. 9, par. 2, del Regolamento ‘ed in conformità alle misure di garanzia disposte dal Garante’, in relazione a ciascuna categoria dei dati.”
The institutional defense attempted to ground its operations within general administrative management mandates. However, Article 6, paragraph 3, letter b of the Regulation requires that any legal basis claimed by a public authority must pursue a specific public interest objective and remain strictly proportionate to the legitimate aim pursued.
The data protection authority established that routine workplace attendance monitoring can readily be accomplished through conventional, non-invasive digital or card-based mechanisms. Deploying immutable biological metrics to verify staff arrival represents a disproportionate intrusion that fails the European proportionality test entirely.
“Ciò in quanto, la base giuridica del trattamento, per poter essere considerata una valida condizione di liceità del trattamento, deve, tra l’altro, ‘perseguire un obiettivo di interesse pubblico ed essere proporzionato all’obiettivo legittimo perseguito’.”
Following the repeal of national public sector biometric authorization statutes by Law n. 178/2020, no general public interest mandate remained in the Italian legal system to permit school administrators to collect biometric templates from staff members. The processing therefore operated in direct violation of basic processing principles set forth in Articles 5, 6, and 9 of the Regulation.
Pursuant to Article 57, paragraph 1, letter f, and Article 58, paragraph 2, letter i of the Regulation, the supervisory authority formally declared the illegality of the processing operations conducted by the school administration, subsequently initiating mandatory financial sanction proceedings under Article 83.
In determining the financial sanction, the supervisory body applied the analytical framework established under EDPB Guidelines 4/2022, point 60, evaluating the nature, gravity, and duration of the infringement alongside mitigating and aggravating criteria listed in Article 83, paragraph 2 of the Regulation.
The authority imposed an administrative pecuniary fine of exactly 4,000.00 euros against the educational institute. Under European legal standards, this amount was determined to be effective, proportionate, and dissuasive, taking into account the public nature of the institution and the operational context of the violation.
Under domestic procedural law governed by Article 166, paragraph 8 of the Privacy Code, the sanctioned educational institute was granted the statutory option to settle the dispute by paying an amount equal to half of the imposed fine within a strict 30-day statutory window.
Should the institute fail to utilize the simplified settlement mechanism, an injunction requires payment of the full 4,000.00 euros within 30 days of official notification, under penalty of compulsory administrative debt enforcement pursuant to Article 27 of Law n. 689/1981.
The formal ruling also activated accessory transparency measures. Pursuant to Article 166, paragraph 7 of the Code and Article 16, paragraph 1, alongside Article 17 of Garante Regulation n. 1/2019, the full injunction was ordered to be published on the authority’s permanent public digital register.
The administrative determination remains subject to judicial appeal under Article 78 of the Regulation, Article 152 of the Code, and Article 10 of Legislative Decree n. 150/2011. The sanctioned party may initiate proceedings before ordinary judicial courts within 30 days of official service, extended to 60 days for entities residing abroad.
Transparency, Provenance, and Legal Basis
The evidentiary record underpinning this dossier originates from official administrative enforcement ruling Provvedimento del 27 marzo 2025 [10138981], issued by the Italian Data Protection Authority. The public documentation serves as a permanent administrative precedent governing biometric limits across the European educational sector.
In accordance with Article 5 of Italian Law 22 April 1941, n. 633, official acts and legislative texts of state administrations are entirely excluded from copyright restrictions and belong strictly within the public domain. This institutional transparency enables independent journalistic analysis and investigative scrutiny of state compliance with European data privacy standards.
The published supervisory documentation provides conclusive legal proof that public institutions cannot circumvent European privacy standards through administrative inertia or commercial tracking solutions, establishing that technological deployment in public education must remain subordinated to basic legal rights.

