Investigative Journalism
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
The Face as Attendance Register: Biometric Recognition in a University Course
Acquired Record: garanteprivacy.it

The Face as Attendance Register: Biometric Recognition in a University Course

garanteprivacy.itItalia2026public
#riconoscimento facciale#dati biometrici#garante privacy#universita#sorveglianza

Verified Primary Investigative Source: garanteprivacy.it — Italia

Share:

Editorial Transparency & Fair Use Notice

Investigative dossier curated and structured by the Unclessify editorial team based on official disclosures, court filings and declassified records published by garanteprivacy.it. Historical context, analytical synthesis, and editorial commentary are provided by Unclessify under Public Interest, Freedom of the Press, and Fair Use principles.

Read Full Editorial Policy & Source Transparency →

Official Records & Declassified Dossier

Taking the register by face

The decision of 29 January 2026 concerns a practice that, described in a single line, says almost everything: to check that students were present in class, a university used biometric recognition of their faces.

The reconstruction begins with the justification the university itself supplied. By a note of 29 July 2024 the institution supplements and clarifies its reply, stating that «in the course of each lesson the lecturer is required to verify the presence of the students». This is the argument from necessity: there is an obligation, and the system exists to discharge it.

The remainder of the decision is, in substance, an explanation of why an obligation to verify attendance does not authorise verifying it in that manner.

What was processed, and for how long

The finding is unambiguous. On the basis of what emerged from the investigation, «it is established that the University carried out processing of personal data relating to the biometric characteristics of the faces of participants in a course for teaching qualification».

The context matters: this is not an entrance gate or a restricted laboratory, but a training course for future teachers. The people subjected to recognition were there to obtain a professional qualification.

The chronology is reconstructed precisely. The processing was carried out from March to July 2024, «first by the methods set out in the aforementioned note of 24 June 2024 and then by those described in the note of 29 July 2024»: two different configurations within the same period. From 23 September 2024 the biometric recognition system remained «partially in use», and its use ceased definitively on 11 November 2024, according to the table produced by the university with its note of 20 May 2025.

That table arrived late, and through a lawyer: the Authority had made a final request for information by note protocol number 0049433 of 10 April 2024, and the reply came more than a year later. The controller was nonetheless invited to submit written defences or documents, or to request a hearing, under Article 166(6) and (7) of the Code and Article 18(1) of Law No 689 of 24 November 1981.

The prohibition, and its exceptions

The legal starting point is not a balancing exercise: it is a prohibition. In this framework, the Garante writes, «the processing of biometric data is as a rule prohibited, unless one of the conditions in Article 9 of the Regulation applies “and in conformity with the safeguard measures laid down by the Garante”».

These are two requirements, not one, and both must be met, and the order between them is not accidental. Finding an Article 9 exception is not enough: the safeguard measures the Authority has laid down must also be observed. It is an architecture designed precisely for data that cannot be changed — a person’s face cannot be revoked like a password.

The consent that was not free

The university’s defence rests on consent, and on reasoning that at first sight looks solid. In the note of 24 June 2024 it argues that consent was «free, since in the event of refusal students may enrol in one of the many courses for obtaining the 30 credits held by other centres in person».

In other words: nobody was compelled — anyone unwilling to have their face recognised could enrol elsewhere.

The Garante dismisses this without hesitation — «this is not relevant in that regard» — and the reason deserves to be understood, because it goes to the heart of what makes consent valid. The freedom of consent is not measured by the theoretical existence of alternatives elsewhere, but by the absence of detriment to whoever refuses within the relationship already under way. A student already enrolled, who chose that course and arranged their schedule and travel around it, is not on an equal footing when told the alternative is to start again at another centre.

It is the same imbalance the law recognises in the employment relationship, transposed to the educational one. And the competition argument — «there are many other courses» — if accepted, would render any consent free in any market: it would suffice that a competitor exists.

Public and private, the same measure

A substantial part of the decision is devoted to establishing that the university’s legal form does not change the applicable rules, and the reasoning is careful.

As a preliminary point, the Garante observes, academic freedom — citing Article 33 of the Constitution and Article 1 of Law No 240 of 30 December 2010 — «including at university level, may be exercised by public or private entities, irrespective of their legal form».

And among the points of analogy with the rules governing state universities «there is, first of all, the pursuit of public interest purposes», with reference to Article 1(1) of that same Law 240 of 2010, which applies «both to state and to non-state universities».

The Garante also cites domestic case law, with judgment No 12967 of 13 May 2024 and, most recently, the Court of Milan, No 8872 of 19 November 2025. A non-state university awarding qualifying titles performs a public interest function, and cannot invoke its private form to place itself under a more permissive regime.

The impact assessment that did not exist

The final infringement established is the most instructive, because it concerns a judgment the university passed on itself.

The Regulation requires an impact assessment where processing presents a high risk, and the typical cases include biometric data and processing involving an «innovative use or application of new technological or organisational solutions».

The investigation found instead that the university «did not identify any high risk to the rights and freedoms of individuals and therefore did not consider it necessary to set out the considerations described above in a further document, that is, an impact assessment». The reasoning is circular: the assessment exists to establish the risk, and it cannot be skipped by asserting that one has already concluded there is none.

Only during the investigation, by note of 16 December 2024, did the university place on file a copy of an impact assessment — that is, when the system had already been switched off for more than a month. «It must therefore be concluded that the University acted in breach of Article 35 of the Regulation.»

The penalty, and how it is calculated

There follows the adoption of the injunction order for the application of the administrative fine and ancillary penalties, under Article 58(2)(i) and Article 83 of the Regulation, and Article 166(7) of the Code.

Having regard to Article 83(3), the infringement attracts the fine provided for in Article 83(5) — the tier reserved for breaches of the principles and of the rights of data subjects. The amount «is to be determined with due regard to the elements listed in Article 83(2)», and the Garante cites the European Data Protection Board’s «Guidelines 4/2022 on the calculation of administrative fines under the GDPR» of 24 May 2023, at point 60.

As with every injunction order, the chapter containing it is published on the Garante’s website, under Article 166(7) of the Code and Article 16(1) of the Garante’s Regulation No 1/2019.

What this case teaches

The sequence of facts describes a path that repeats itself: a technology is adopted because it solves a practical problem; the adopter judges for itself that no high risk arises; a consent that looks voluntary on paper is collected; and when the authority asks for an account, the documentation that should have existed beforehand is produced.

The system was switched off on 11 November 2024, before the decision arrived. But the finding concerns the months in which it operated, and the people whose faces were measured in order to sign an attendance register.

That those people were future teachers on a qualification course gives the case a symmetry nobody sought. They learned, before ever entering a classroom, what it means to be identified by a machine simply for being in a place.

What this piece rests on

The text was checked against the facts listed below, extracted from the act above. It does not yet carry corroboration from independent sources.

The 20 facts verified in the text
  1. Con una successiva nota del 29 luglio 2024, l’Ateneo ha integrato e precisato il proprio riscontro, dichiarando, in particolare, che: “nel corso di ciascuna lezione il docente è tenuto a verificare la presenza degli studenti.
  2. A fronte di un’ultima richiesta d’informazioni formulata dall’Autorità (v. nota prot. n. 0049433 del 10 aprile 2024), l’Ateneo, con nota del 20 maggio 2025 inviata dal proprio avvocato, ha dichiarato, in particolare, che: “il sistema di riconoscimento [oggetto di istruttoria] è stato utilizzato nelle prime due edizioni e nella terza solo parzialmente.
  3. Con la medesima nota, il predetto titolare è stato invitato a produrre al Garante scritti difensivi o documenti ovvero a chiedere di essere sentito dall’Autorità (art. 166, commi 6 e 7, del Codice, nonché art. 18, comma 1, della l. 24 novembre 1981, n. 689).
  4. In via preliminare, deve osservarsi che la libertà di insegnamento (cfr. artt. 33 Cost. e 1 della l. 30 dicembre 2010, n. 240), anche a livello universitario, può essere esercitata da soggetti pubblici o privati, indipendentemente dalla forma giuridica degli stessi (enti pubblici, fondazioni, società di capitali).
  5. Tra i profili di analogia rispetto alla disciplina delle università statali (pubbliche), ricorre, anzitutto, il perseguimento di finalità di interesse pubblico (cfr. art. 1, co. 1, della l. 30 dicembre 2010, n. 240, riferito sia alle università statali sia alle università non statali).
  6. I, n. 12967 del 13 maggio 2024 e, da ultimo, Tribunale di Milano, n. 8872 del 19 novembre 2025). 3.2.
  7. Sulla base di quanto è emerso a seguito dell’istruttoria, risulta accertato che l’Ateneo ha posto in essere un trattamento di dati personali, relativi alle caratteristiche biometriche del volto dei partecipanti a un corso per l’abilitazione all’insegnamento, svoltosi ai sensi dell’art. 13 del d.P.C.M. 4 agosto 2023.
  8. Tale trattamento è stato posto in essere da marzo a luglio 2024, prima con le modalità illustrate nella citata nota del 24 giugno 2024 e poi con quelle di cui alla nota del 29 luglio 2024.
  9. Dal 23 settembre 2024, il sistema di riconoscimento biometrico è rimasto “parzialmente in uso” e il suo impiego è definitivamente cessato in data 11 novembre 2024 (v. la tabella riportata nella nota dell’Ateneo del 20 maggio 2025).
  10. In tale quadro il trattamento dei dati biometrici è di regola vietato, salvo che sussista una delle condizioni di cui all’art. 9 del Regolamento “ed in conformità alle misure di garanzia disposte dal Garante”.
  11. Non rileva, a tal riguardo, che, come sostenuto dall’Ateneo, “il consenso [… è] libero in quanto, in caso di rifiuto, gli studenti possono accedere a uno dei molti corsi per l’ottenimento dei 30 CFU tenuto da altri centri in presenza” (nota del 24 giugno 2024).
  12. III, B, n. 4), nonché i trattamenti che realizzano un “uso innovativo o [l’]applicazione di nuove soluzioni tecnologiche od organizzative” (v. cap.
  13. Dall’istruttoria è, invece, emerso che l’Ateneo “non ha rinvenuto alcun rischio elevato per i diritti le libertà delle persone e non ha quindi ritenuto necessario riversare le considerazioni sopra illustrate all’interno di un documento ulteriore, ossia di una valutazione di impatto sulla protezione dei dati ai sensi dell’art. 35 [del Regolamento]” (nota del 24 giugno 2024).
  14. Soltanto nel corso dell’istruttoria, con la nota del 16 dicembre 2024, l’Ateneo ha prodotto in atti copia di una valutazione di impatto sulla protezione dei dati.
  15. Deve, pertanto, concludersi che l’Ateneo ha agito in violazione dell’art. 35 del Regolamento. 4.
  16. Adozione dell’ordinanza ingiunzione per l’applicazione della sanzione amministrativa pecuniaria e delle sanzioni accessorie (artt. 58, par. 2, lett. i e 83 del Regolamento; art. 166, comma 7, del Codice).
  17. Al riguardo, tenuto conto dell’art. 83, par. 3, del Regolamento, nel caso di specie la violazione delle disposizioni citate è soggetta all’applicazione della sanzione amministrativa pecuniaria prevista dall’art. 83, par. 5, del Regolamento.
  18. La predetta sanzione amministrativa pecuniaria inflitta, in funzione delle circostanze di ogni singolo caso, va determinata nell’ammontare tenendo in debito conto gli elementi previsti dall’art. 83, par. 2, del Regolamento.
  19. Comitato europeo per la protezione dei dati, “Linee guida 4/2022 sul calcolo delle sanzioni amministrative pecuniarie ai sensi del GDPR” del 24 maggio 2023, punto 60).
  20. Si ritiene, altresì, che, ai sensi dell’art. 166, comma 7, del Codice e dell’art. 16, comma 1, del Regolamento del Garante n. 1/2019, si debba procedere alla pubblicazione del presente capo contenente l'ordinanza ingiunzione sul sito Internet del Garante.
Click to switch theme:

Comments (0)