Taking the register by face
The decision of 29 January 2026 concerns a practice that, described in a single line, says almost everything: to check that students were present in class, a university used biometric recognition of their faces.
The reconstruction begins with the justification the university itself supplied. By a note of 29 July 2024 the institution supplements and clarifies its reply, stating that «in the course of each lesson the lecturer is required to verify the presence of the students». This is the argument from necessity: there is an obligation, and the system exists to discharge it.
The remainder of the decision is, in substance, an explanation of why an obligation to verify attendance does not authorise verifying it in that manner.
What was processed, and for how long
The finding is unambiguous. On the basis of what emerged from the investigation, «it is established that the University carried out processing of personal data relating to the biometric characteristics of the faces of participants in a course for teaching qualification».
The context matters: this is not an entrance gate or a restricted laboratory, but a training course for future teachers. The people subjected to recognition were there to obtain a professional qualification.
The chronology is reconstructed precisely. The processing was carried out from March to July 2024, «first by the methods set out in the aforementioned note of 24 June 2024 and then by those described in the note of 29 July 2024»: two different configurations within the same period. From 23 September 2024 the biometric recognition system remained «partially in use», and its use ceased definitively on 11 November 2024, according to the table produced by the university with its note of 20 May 2025.
That table arrived late, and through a lawyer: the Authority had made a final request for information by note protocol number 0049433 of 10 April 2024, and the reply came more than a year later. The controller was nonetheless invited to submit written defences or documents, or to request a hearing, under Article 166(6) and (7) of the Code and Article 18(1) of Law No 689 of 24 November 1981.
The prohibition, and its exceptions
The legal starting point is not a balancing exercise: it is a prohibition. In this framework, the Garante writes, «the processing of biometric data is as a rule prohibited, unless one of the conditions in Article 9 of the Regulation applies “and in conformity with the safeguard measures laid down by the Garante”».
These are two requirements, not one, and both must be met, and the order between them is not accidental. Finding an Article 9 exception is not enough: the safeguard measures the Authority has laid down must also be observed. It is an architecture designed precisely for data that cannot be changed — a person’s face cannot be revoked like a password.
The consent that was not free
The university’s defence rests on consent, and on reasoning that at first sight looks solid. In the note of 24 June 2024 it argues that consent was «free, since in the event of refusal students may enrol in one of the many courses for obtaining the 30 credits held by other centres in person».
In other words: nobody was compelled — anyone unwilling to have their face recognised could enrol elsewhere.
The Garante dismisses this without hesitation — «this is not relevant in that regard» — and the reason deserves to be understood, because it goes to the heart of what makes consent valid. The freedom of consent is not measured by the theoretical existence of alternatives elsewhere, but by the absence of detriment to whoever refuses within the relationship already under way. A student already enrolled, who chose that course and arranged their schedule and travel around it, is not on an equal footing when told the alternative is to start again at another centre.
It is the same imbalance the law recognises in the employment relationship, transposed to the educational one. And the competition argument — «there are many other courses» — if accepted, would render any consent free in any market: it would suffice that a competitor exists.
Public and private, the same measure
A substantial part of the decision is devoted to establishing that the university’s legal form does not change the applicable rules, and the reasoning is careful.
As a preliminary point, the Garante observes, academic freedom — citing Article 33 of the Constitution and Article 1 of Law No 240 of 30 December 2010 — «including at university level, may be exercised by public or private entities, irrespective of their legal form».
And among the points of analogy with the rules governing state universities «there is, first of all, the pursuit of public interest purposes», with reference to Article 1(1) of that same Law 240 of 2010, which applies «both to state and to non-state universities».
The Garante also cites domestic case law, with judgment No 12967 of 13 May 2024 and, most recently, the Court of Milan, No 8872 of 19 November 2025. A non-state university awarding qualifying titles performs a public interest function, and cannot invoke its private form to place itself under a more permissive regime.
The impact assessment that did not exist
The final infringement established is the most instructive, because it concerns a judgment the university passed on itself.
The Regulation requires an impact assessment where processing presents a high risk, and the typical cases include biometric data and processing involving an «innovative use or application of new technological or organisational solutions».
The investigation found instead that the university «did not identify any high risk to the rights and freedoms of individuals and therefore did not consider it necessary to set out the considerations described above in a further document, that is, an impact assessment». The reasoning is circular: the assessment exists to establish the risk, and it cannot be skipped by asserting that one has already concluded there is none.
Only during the investigation, by note of 16 December 2024, did the university place on file a copy of an impact assessment — that is, when the system had already been switched off for more than a month. «It must therefore be concluded that the University acted in breach of Article 35 of the Regulation.»
The penalty, and how it is calculated
There follows the adoption of the injunction order for the application of the administrative fine and ancillary penalties, under Article 58(2)(i) and Article 83 of the Regulation, and Article 166(7) of the Code.
Having regard to Article 83(3), the infringement attracts the fine provided for in Article 83(5) — the tier reserved for breaches of the principles and of the rights of data subjects. The amount «is to be determined with due regard to the elements listed in Article 83(2)», and the Garante cites the European Data Protection Board’s «Guidelines 4/2022 on the calculation of administrative fines under the GDPR» of 24 May 2023, at point 60.
As with every injunction order, the chapter containing it is published on the Garante’s website, under Article 166(7) of the Code and Article 16(1) of the Garante’s Regulation No 1/2019.
What this case teaches
The sequence of facts describes a path that repeats itself: a technology is adopted because it solves a practical problem; the adopter judges for itself that no high risk arises; a consent that looks voluntary on paper is collected; and when the authority asks for an account, the documentation that should have existed beforehand is produced.
The system was switched off on 11 November 2024, before the decision arrived. But the finding concerns the months in which it operated, and the people whose faces were measured in order to sign an attendance register.
That those people were future teachers on a qualification course gives the case a symmetry nobody sought. They learned, before ever entering a classroom, what it means to be identified by a machine simply for being in a place.

