The privacy of customers is in the spotlight again. More and more companies use biometric systems as facial recognition or fingerprint detectors, and the first consequences have not taken long to arrive.
The Spanish Agency for Data Protection (AEPD) has resolved a sanctioning procedure against Loro Parque SA de Tenerife. The owners of this theme park will have to pay a fine of no less than 250,000 euros.
First fines for the processing of biometric data
The use of recognition systems such as fingerprints begins to be popular among companies to control customer access, but the General Data Protection Regulation (GDPR) is clear regarding user privacy.
Article 9 of the GDPR considers the use of fingerprints of millions of people by Loro Parque. The theme park used this system to verify the identity of the clients that reached the enclosurecompletely ignoring that these personal data are especially protected.
This space has become One of the main attractions of the Canary Island with more than 1.3 million customers in 2024as confirmed by Grupo Loro Parque in the Fitur 2025 edition. The theme park opened its doors in 1972 and has accumulated more than 55 million visitors throughout its history.
Claims for the use of data since 2022
The case began to jump into the media in 2022 when three clients of the center filed two claims against Loro Parque before the Spanish Agency for Data Protection. Visitors criticized that, to use the “Twin Ticket” bond that gives access to Loro Parque and Siam Park they were required to use their fingerprint.
Customers said at that time that they were forced to use that recognition method. The Loro Park Group did not offer prior information and it was not possible to use an alternative method to validate its inputs.
The complainants had to register their fingerprints if they wanted to access Siam Park. The aquatic park had a specific reader that only activated the lathe if customers had previously recorded this recognition system.
The Loro Parque group defended itself at that time ensuring that this registration system did not store images, but only mathematical values. The template with the fingerprint was encrypted on the device and was eliminated when the date of validity of the double tickets.
The Spanish data protection agency has finally issued a sentence and Loro Parque will have to pay a fine of 250,000 euros. This system can only be used under specific exceptions, none of which they could demonstrate.
Know How we work in NoticiasVE.
Tags: Privacy, security