Investigative Journalism
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
Facial Recognition Attendance Tracking in Municipal Waste Management Exposed
Acquired Record: garanteprivacy.it

Facial Recognition Attendance Tracking in Municipal Waste Management Exposed

garanteprivacy.itItalia2023public
#biometria#riconoscimento facciale#privacy lavoratori#garante privacy#igiene urbana#gdpr#sorveglianza presenze

Verified Primary Investigative Source: garanteprivacy.it — Italia

Share:

Editorial Transparency & Fair Use Notice

Investigative dossier curated and structured by the Unclessify editorial team based on official disclosures, court filings and declassified records published by garanteprivacy.it. Historical context, analytical synthesis, and editorial commentary are provided by Unclessify under Public Interest, Freedom of the Press, and Fair Use principles.

Read Full Editorial Policy & Source Transparency →

Official Records & Declassified Dossier

Public Interest and Systemic Implications

The deployment of biometric surveillance in routine workplace management represents an escalating friction point between corporate oversight technologies and fundamental digital privacy rights. When technological solutions designed for high-security environments are repurposed for daily employee attendance verification, the systemic power imbalance inherent in employment relationships transforms routine management into pervasive automated monitoring.

The enforcement actions surrounding these practices demonstrate that biometric identifiers cannot be treated as ordinary administrative metrics. Physical biometric data, being unalterable and inherently tied to an individual’s permanent physical identity, demands the highest tier of legal justification and technical proportionality before deployment in any operational workplace setting.

This case exposes critical structural vulnerabilities in the procurement, deployment, and legal assessment of automated tracking systems by municipal contractors. It establishes a definitive benchmark regarding the invalidity of employee consent in asymmetric workplace environments and underscores the non-negotiable obligation to perform rigorous data protection impact assessments before deploying biometric hardware.

Historical and Regulatory Context

Over recent years, automated workforce management software vendors have increasingly integrated facial recognition hardware into standard physical timekeeping devices. Promoted as friction-free mechanisms to verify attendance and eliminate badge sharing, these biometric terminals entered routine commercial distribution without adequate scrutiny regarding their compatibility with European Union data protection regulations.

The legal framework governing such technologies was firmly established under European data protection standards, which classify biometric data processed for uniquely identifying a natural person as a special category of data. Under Article 9 of the General Data Protection Regulation, the processing of biometric data is fundamentally prohibited unless specific, strictly interpreted statutory exceptions apply.

Prior enforcement precedents, including regulatory decisions such as Provision No. 16 of 14 January 2021 and Provision No. 369 of 10 November 2022, consistently established that ordinary attendance monitoring does not warrant the capture and algorithmic extraction of biometric features. The European Data Protection Board reaffirmed this principle through Guidelines 3/2019 on the processing of personal data through video devices, specifically highlighting points 4 and 73 regarding facial recognition technologies.

The timeline of field inspections reveals how administrative oversights materialize on the ground. Regulatory inspection activities commenced on 19 January 2023 at the Ardea yard, followed immediately by comprehensive on-site inspections at the administrative headquarters of L’Igiene Urbana Evolution s.r.l. on 26 and 27 January 2023. These inquiries expanded on 30 May 2023 to encompass technical supply entities DM Technology s.r.l. and Unica s.r.l.s.

Formal notifications of alleged violations were officially served to the operating company on 13 September 2023 under Article 166, paragraph 5, of the Italian Privacy Code. The administrative findings cited critical non-compliance with Articles 5(1)(a), 9, 28, and 35 of the General Data Protection Regulation, triggering statutory proceedings subject to the stringent legal standards of Article 168 regarding truthfulness in regulatory declarations.

Entities and Corporate Actors

The operational entity at the core of the investigation is L’Igiene Urbana Evolution s.r.l., a corporate entity providing environmental and waste management services across several municipal territories. As the data controller, the company maintained ultimate operational and legal responsibility for determining the means, purposes, and proportionality of workforce data processing across its regional yards.

The technical architecture and hardware deployment involved key external commercial vendors. Technical supplier DM Technology s.r.l. and contracting counterparty Unica s.r.l.s. were directly tied to the supply chain of the time-tracking ecosystem. Inspections established that the proprietary application Junior Web was made accessible by the vendor pursuant to a specific supply contract executed directly with Unica s.r.l.s.

The administrative oversight body presiding over the enforcement procedure is the Italian Data Protection Authority (Garante per la protezione dei dati personali), acting pursuant to its statutory supervisory powers under national and European Union legislation to investigate unlawful data handling and issue binding compliance orders.

The human perimeter of the biometric tracking operation comprised exactly 157 workers stationed across four separate territorial yards in the Campania region: Scafati, Quarto, Orta di Atella, and San Marzano. These employees constituted the target population subjected to automated facial biometric capture during their daily work shifts.

Critical Analysis of the Evidence

The evidentiary record established across official inspection minutes reveals stark variations in the operational duration and geographical scale of the biometric processing system. At the Scafati operational yard, facial recognition tracking commenced on 1 July 2020 and operated continuously for more than two and a half years before being halted on 26 January 2023, affecting 19 workers throughout that prolonged timeframe.

At the remaining three operational sites, the deployment unfolded during the autumn of 2022. Biometric capture was initiated on 29 September 2022 at Orta di Atella involving 59 employees, on 1 October 2022 at Quarto involving 63 employees, and on 11 November 2022 at San Marzano involving 16 employees. In all four operational yards, the physical capture devices were deactivated between 23 and 26 January 2023, directly following the regulatory on-site inspection activities.

The defense strategy submitted on 7 June 2023 relied heavily on employee consent forms distributed under an information notice dated 12 March 2021. However, European jurisprudence and regulatory authority rulings conclusively invalidate consent as a lawful basis within employment contexts due to the fundamental imbalance of power between employer and employee:

“The processing of biometric data in the context of ordinary employment relationship management is not compliant with the principles of data minimization and proportionality.”

The critical structural failure identified in the proceedings centers on Article 35 of the General Data Protection Regulation. The deployment of innovative technological solutions against vulnerable subjects—such as subordinate employees in an operational waste management facility—mandated an exhaustive Data Protection Impact Assessment prior to system activation, as cataloged under Provision No. 467 of 11 October 2018.

The factual record documents that four biometric facial recognition hardware units were physically deployed across the company’s operational sites. While the company confirmed that these four devices were subsequently turned off and disconnected from the internal network in January 2023, serious systemic questions remain regarding the storage, retention periods, cryptographic hashing, and potential vendor-level replication of the biometric templates collected between July 2020 and January 2023.

Furthermore, the technical interplay between the proprietary software Junior Web and the hardware biometric terminals exposes the persistent opacity of third-party workforce management supply chains. When municipal utility contractors procure commercial tracking platforms through intermediaries without rigorous technical audits, data protection compliance is routinely compromised across every linked operational facility.

Transparency, Public Record, and Legal Basis

The documentation underlying this investigative dossier derives from official administrative enforcement acts published by the national supervisory authority under Provision No. 9995762, adopted on 22 February 2024. The formal administrative record is accessible through the regulatory registry of the Garante per la protezione dei dati personali.

Under Article 5 of Italian Law No. 633 of 22 April 1941, official texts of state acts, administrative decisions, and public authorities are excluded from copyright restrictions and belong fully to the public domain. This legal designation guarantees the unrestricted public access, dissemination, and critical analysis of administrative decisions governing fundamental rights and digital surveillance standards.

Publishing these verified evidentiary records serves an indispensable public accountability function. Documenting regulatory actions against unlawful biometric monitoring ensures that public utility contractors, technology vendors, and municipal workers maintain access to transparent records regarding the legal limits of workplace tracking technologies.

What this piece rests on

The text was checked against the facts listed below, extracted from the act above. It does not yet carry corroboration from independent sources.

The 20 facts verified in the text
  1. Nel corso di tale attività delegata, sono state effettuate ispezioni, tra l’altro, presso il cantiere di Ardea (19 gennaio 2023), nei confronti di L’Igiene Urbana Evolution s.r.l. (26 e 27 gennaio 2023), nei confronti di DM Technology s.r.l. (30 maggio 2023) e di Unica s.r.l.s. (30 maggio 2023).
  2. Il 27 gennaio 2023, sono proseguite le attività ispettive presso la sede amministrativa di L’Igiene Urbana Evolution s.r.l.
  3. Nel corso dell’ispezione, svoltasi in data 30 maggio 2023, la Società ha dichiarato che: “l’applicativo Junior Web è stato reso disponibile [dal fornitore], in base al contratto sottoscritto con Unica s.r.l.s. […].
  4. Il 13 settembre 2023, l’Ufficio ha effettuato, ai sensi dell’art. 166, comma 5, del Codice, la notificazione alla Società delle presunte violazioni del Regolamento riscontrate, con riferimento agli artt. 5, par. 1, lett. a), 9, 28 e 35 del Regolamento.
  5. Violazione dell’art. 5, par. 1, lett. a) e 9 del Regolamento in relazione ai trattamenti di dati dei propri dipendenti.
  6. In proposito si evidenzia che, salvo che il fatto non costituisca più grave reato, chiunque, in un procedimento dinanzi al Garante, dichiara o attesta falsamente notizie o circostanze o produce atti o documenti falsi ne risponde ai sensi dell'art. 168 del Codice “Falsità nelle dichiarazioni al Garante e interruzione dell’esecuzione dei compiti o dell’esercizio dei poteri del Garante”.
  7. Nel merito, all’esito dell’attività istruttoria, è stato accertato che la Società ha utilizzato un sistema biometrico, basato sul riconoscimento facciale, presso alcuni cantieri, attraverso quattro dispositivi biometrici (v. verbale 30/5/2023, p. 3), disattivati dal mese di gennaio 2023 e allo stato “scollegati dalla rete”.
  8. Come evidenziato dalla Società nelle proprie memorie difensive, in data 7 giugno 2023 quest’ultima ha trasmesso all’Autorità, a scioglimento della riserva effettuata in occasione dell’accertamento ispettivo, un prospetto dal quale si evince che i trattamenti di dati biometrici hanno riguardato un totale di 157 dipendenti (in forza presso le sedi di Scafati, Quarto, Orta di Atella e San Marzano).
  9. Per quanto riguarda la durata del trattamento, relativamente a 19 dipendenti (presso la sede di Scafati), questo è iniziato il 1° luglio 2020 e cessato il 26 gennaio 2023.
  10. I trattamenti relativi agli altri 138 dipendenti sono iniziati il 29 settembre (sede di Orta di Atella, 59 dipendenti), 1° ottobre (sede di Quarto, 63 dipendenti) e 11 novembre 2022 (sede di San Marzano, 16 dipendenti) e cessati tra il 23 e il 26 gennaio 2023, dopo l’avvio delle attività ispettive da parte dell’Autorità.
  11. Il datore di lavoro, inoltre, è tenuto ad applicare i principi generali del trattamento, in particolare quelli di liceità, correttezza e trasparenza, minimizzazione, integrità e riservatezza dei dati (art. 5, par. 1, lett. a), c) e f) del Regolamento).
  12. Ciò è stato ribadito dal Garante con i provvedimenti n. 369 del 10 novembre 2022 (doc. web n. 9832838) e n. 16 del 14 gennaio 2021 (doc. web n. 9542071).
  13. L’utilizzo del dato biometrico nel contesto dell’ordinaria gestione del rapporto di lavoro (quale è l’attività di rilevazione delle presenze) non è pertanto conforme ai principi di minimizzazione e proporzionalità del trattamento (art. 5, par. 1, lett. c) del Regolamento).
  14. Linee guida 3/2019 sul trattamento dei dati personali attraverso dispositivi video, adottate il 29 gennaio 2020, spec. punti 4 e 73; si veda altresì il Provv. del 10 febbraio 2022, n. 50, doc. web n. 9751362, adottato, seppure in un diverso contesto, in materia di riconoscimento facciale).
  15. Né, quale condizione di liceità del trattamento dei dati biometrici, può soccorrere la prestazione del consenso da parte del dipendente, come prevista nel modello di informativa fornita agli interessati ai sensi dell’art. 13 del Regolamento, datata 12/3/2021 e acquisita in atti (v. verbale ispettivo 30/5/2023, All. 5).
  16. In base ai suesposti motivi il trattamento di dati biometrici dei propri dipendenti effettuato dalla Società risulta pertanto essere stato effettuato in assenza di un’idonea base giuridica, in violazione degli artt. 5, par. 1, lett. a) e 9 del Regolamento. 4.2 Violazione dell’art. 35 del Regolamento.
  17. In base all’art. 35 del Regolamento, in relazione a trattamenti che prevedono “l'uso di nuove tecnologie, considerati la natura, l'oggetto, il contesto e le finalità del trattamento, [tali da] presentare un rischio elevato per i diritti e le libertà delle persone fisiche”, il titolare è tenuto ad effettuare una valutazione dell'impatto sulla protezione dei dati personali prima dell’inizio dei trattamenti previsti.
  18. III, B, n. 4), il trattamento effettuato nei confronti di interessati “vulnerabili” (ad es. in quanto parti di un rapporto di lavoro; v. cap.
  19. III, B, n. 7) nonché i trattamenti che realizzano un “uso innovativo o [l’]applicazione di nuove soluzioni tecnologiche od organizzative” (v. cap.
  20. Ulteriori indicazioni sono state fornite in proposito con il provvedimento del Garante dell’11 ottobre 2018, n. 467 (“Elenco delle tipologie di trattamenti soggetti al requisito di una valutazione d'impatto sulla protezione dei dati ai sensi dell’art. 35, comma 4, del Regolamento (UE) n. 2016/679”, in G.U., S.
Click to switch theme:

Comments (0)