Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo
Home› News› Croatia Fines Gambling Operator €2.59 Million Over Biometric…
NEWS

Croatia Fines Gambling Operator €2.59 Million Over Biometric Data and Invalid Consent

Croatia’s data protection authority has imposed a €2.59 million GDPR fine on a gambling operator after finding that the company collected excessive biometric data, relied on invalid consent, and gave players incomplete and inconsistent information about how their personal data was being used.

Oct 9, 2026 8 min read

Croatia’s data protection authority has imposed a €2.59 million GDPR fine on a gambling operator after finding that the company collected excessive biometric data, relied on invalid consent, and gave players incomplete and inconsistent information about how their personal data was being used.

The Croatian Personal Data Protection Agency, known as AZOP, launched the investigation on its own initiative and found violations involving Articles 5, 6, 7, 9, 12 and 13 of the GDPR. The regulator has not officially named the operator.

The most significant part of the case involved fingerprint collection.

The operator allowed casino players to identify themselves using an identity card, RFID chip or fingerprints. The biometric option was intended to allow returning customers to move through the identification process more quickly.

The company represented that it collected fingerprints from two fingers.

AZOP found that it actually collected fingerprints from four fingers, two from each hand.

The operator argued that the additional fingerprints were needed as backups in case a player damaged the skin on one finger and the system could no longer reliably authenticate the person.

The regulator was not persuaded.

AZOP concluded that the company had not demonstrated that collecting four fingerprints was necessary to accomplish the identification purpose, particularly where other means of verifying identity remained available.

That finding carries a broader GDPR lesson:

Consent does not give an organization unlimited authority to collect personal data.

Nearly 35,000 players were enrolled in the biometric program

AZOP said biometric consent had been recorded for 34,933 players.

That scale matters because fingerprints are not ordinary identifiers.

Under Article 9 of the GDPR, biometric data processed for the purpose of uniquely identifying an individual falls within the regulation’s special categories of personal data.

That generally creates a much higher compliance threshold.

The operator relied on explicit consent as its basis for biometric processing, but AZOP found problems both with the consent itself and with the amount of biometric information being collected.

The regulator’s reasoning is particularly important because it separates two questions that organizations sometimes collapse into one:

Did the individual consent?

and:

Was the processing itself necessary and proportionate?

Those are not the same question.

A person cannot simply “consent away” the GDPR’s data-minimization requirements.

Article 5 of the GDPR requires personal data to be adequate, relevant and limited to what is necessary for the purpose for which it is processed.

That principle becomes especially important with biometric information.

If a company needs one fingerprint to authenticate someone reliably, collecting four fingerprints creates an obvious question:

Why?

A company needs a defensible answer.

Convenience, redundancy or the possibility that a finger could someday become temporarily unreadable may not automatically justify collecting additional biometric templates.

AZOP specifically rejected the argument that merely describing the additional fingerprints as “backup” fingerprints demonstrated necessity.

The controller needed to show why four fingerprints were required for the purpose and whether the same goal could be achieved using fewer fingerprints combined with alternative identity checks.

That is a good illustration of what data minimization actually requires.

It is not:

Collect whatever might be useful
↓
Get consent
↓
Processing becomes lawful

It is closer to:

Define the purpose
↓
Determine the minimum data necessary
↓
Determine the legal basis
↓
Collect only that data

Consent sits inside that analysis.

It does not replace it.

AZOP also found that the operator’s consent process failed to satisfy GDPR requirements.

During casino registration, players were shown four interactive consent fields.

The regulator concluded that the first two consent statements were defective because they bundled multiple purposes into single consent requests rather than giving individuals meaningful control over each purpose.

The fingerprint consent reportedly covered purposes including:

  • providing services;
  • performing a contract;
  • identity verification;
  • statistical purposes;
  • profiling;
  • service improvement;
  • personalization;
  • protection of rights and property;
  • preventing minors from gambling.

Those are materially different processing activities.

Yet they were grouped together.

That is a classic GDPR consent problem.

For consent to be valid, it must be freely given, specific, informed and unambiguous.

A person should not have to accept profiling and personalization merely because the company also wants permission to use a fingerprint for identity verification.

Imagine a registration screen containing one checkbox:

I consent to fingerprint authentication, fraud prevention, analytics, personalization, profiling, marketing optimization and service improvement.

That may look efficient from a user-interface perspective.

Legally, it creates problems.

The user cannot independently say:

Fingerprint authentication: YES

Profiling: NO

Personalization: NO

Analytics: MAYBE

The controller has turned several separate processing purposes into a single package.

AZOP found that the gambling operator did exactly that with its biometric consent process.

The regulator also found a similar problem involving photographs.

The photo consent combined identity verification with other purposes, including protection of property and preventing minors from participating in gambling, without clearly separating the processing purposes or allowing the individual to choose among them.

For companies designing consent interfaces, this case is another reminder that the number of consent buttons is less important than whether each consent corresponds to a sufficiently specific purpose.

Mandatory processing and optional processing were also blurred

One of the more interesting parts of the case involved the distinction between legally required identification and optional biometric processing.

Casinos may have legitimate legal obligations to verify player identity.

Fingerprint authentication, however, was an optional convenience mechanism.

According to AZOP, the operator’s notices created the impression that the registration activities broadly relied on consent without clearly separating legally required identity verification from optional biometric processing.

That distinction matters.

Organizations frequently have several lawful bases operating simultaneously.

For example:

Identity verification
→ legal obligation

Contract information
→ contract necessity

Fraud monitoring
→ legitimate interests

Biometric identification
→ explicit consent

A privacy notice should identify those distinctions.

Otherwise, individuals may believe they are consenting to something they cannot actually refuse or may believe a legally required activity is optional.

Both situations undermine transparency.

The privacy notices contradicted each other

AZOP found a third category of violations involving the information presented to players.

The operator provided several documents during registration, but those documents contained incomplete and inconsistent explanations of:

  • why personal data was processed;
  • which legal bases applied;
  • what fingerprint information was used for.

One document, for example, connected fingerprint processing not just to entry identification but also to monitoring entry into branches, protecting minors, participating in gambling, administering bonus programs and other purposes.

The regulator concluded that players could not clearly determine what their information was being used for or which legal basis applied to each activity.

This violated GDPR transparency obligations.

That is another common compliance problem.

Companies often have:

Privacy Policy
Registration Notice
Consent Screen
Terms and Conditions
Internal Data Map
Marketing Notice

Each document may have been written at a different time by a different person.

Over several years, they drift apart.

One says biometric data is collected for authentication.

Another says security.

A third says personalization.

A fourth says profiling.

Eventually the organization no longer has one coherent explanation of what it actually does.

Biometric systems deserve stricter governance

Fingerprint systems create a particularly serious risk because biometric identifiers are difficult or impossible to replace.

If a password is compromised, the user can reset it.

If a credit card is compromised, the bank can issue another one.

A person cannot meaningfully replace their fingerprints.

That is one reason organizations should apply a higher bar before collecting biometric information.

Before deploying a biometric system, companies should be able to explain:

  • why biometric authentication is necessary;
  • whether a less intrusive method would work;
  • which biometric characteristics are collected;
  • how many biometric samples are required;
  • whether raw images or templates are stored;
  • how long the information is retained;
  • who can access it;
  • where it is stored;
  • whether vendors receive it;
  • how consent is obtained and withdrawn.

The analysis should happen before collection begins.

Convenience is not necessity

Perhaps the clearest lesson from the Croatian case is the distinction between convenience and necessity.

The fingerprint system was apparently designed in part to let returning casino customers identify themselves more quickly.

That may provide a legitimate user benefit.

But convenience alone does not establish that every piece of biometric data collected is necessary.

An organization cannot simply say:

More biometric samples improve reliability.

The GDPR asks a harder question:

Could you accomplish the purpose while collecting less personal data?

For the additional two fingerprints, AZOP concluded the operator had not adequately demonstrated otherwise.

That principle reaches far beyond casinos.

Companies increasingly deploy:

facial recognition
voice recognition
fingerprint authentication
behavioral biometrics
gait analysis
iris recognition

Every deployment should begin with necessity and proportionality.

The case also illustrates why consent governance cannot be limited to websites and advertising technology.

Most privacy teams now understand cookie consent.

Biometric consent is more complicated.

Organizations need to preserve evidence showing:

What data was involved?

What purpose was disclosed?

Which version of the notice was shown?

When did the person consent?

Was the consent optional?

Could individual purposes be accepted separately?

Could consent be withdrawn?

What happened after withdrawal?

For higher-risk processing, “consent = yes” is not an adequate audit record.

The organization needs enough context to establish that the consent itself was valid.

Data maps should match reality

There is another lesson buried in the regulator’s investigation.

The operator said it collected two fingerprints.

AZOP found four.

That discrepancy is important.

A privacy program is only as good as its understanding of the actual technology.

Documentation may say:

Fingerprint data collected: 2 fingers

But the application, scanner or biometric terminal may collect:

Fingerprint data collected: 4 fingers

From a regulator’s perspective, the system wins that argument.

Technical validation should therefore be part of privacy assessments involving sensitive data.

Do not rely exclusively on questionnaires.

Inspect the implementation.

The GDPR fine is about more than fingerprints

Croatia’s €2.59 million enforcement action is ultimately about three connected failures:

Too much data was collected.

Consent was not sufficiently specific.

The explanations given to consumers did not accurately describe the processing.

Those failures reinforced one another.

The organization could not rely on consent to justify unnecessary collection.

The bundled consent language did not provide granular control.

And inconsistent notices made it difficult for players to understand what was happening.

That is why the case has relevance far beyond the gambling sector.

Biometric systems are spreading through workplaces, financial services, retail, hospitality, security, healthcare and consumer applications.

Companies deploying them should not begin with:

Can we get the user to agree?

They should begin with:

Why are we collecting this biometric information at all?

Then:

What is the minimum amount we actually need?

Then:

What legal basis permits the processing?

And only after those questions are resolved:

What must the consent experience look like?

The Croatian regulator’s message is straightforward.

A checkbox cannot cure unnecessary processing.

And with biometric data, regulators are likely to expect companies to prove why every element they collect is necessary.