Italy’s Data Protection Authority (DPA or simply “Garante”) has fined Delivery Hero-owned Foodinho 5 million euros (about $5.2 million) for violating privacy laws in its handling of over 35,000 riders’ personal data. The watchdog’s investigation revealed that Foodinho, a unit of Glovo acquired by Delivery Hero in 2022, unlawfully transmitted riders’ geolocation data to third parties without their consent, even when riders were off-duty as recently as August 2023.
Additionally, the authority prohibited the company from using riders’ biometric data, such as facial recognition, for identity verification.
The investigation was prompted by a rider’s account being deactivated after a fatal car accident in 2022 and subsequent findings from IT experts. The regulator uncovered significant privacy breaches despite Foodinho being fined in 2021 for similar violations.
As part of the ruling, Foodinho has been instructed to update its practices, including improving transparency in account deactivation communications and enabling riders to deactivate GPS tracking when not working. Foodinho has not yet issued a response.
Notably, the Italian regulator’s prohibition of the use of facial recognition for driver verification appears to be a preemptive measure. There is no indication that Foodinho has in fact been using facial recognition for this purpose, and the fine and regulatory action were primarily focused on broader data protection issues and breaches related to the company’s handling of rider information.
Garante’s actions in this case suggest that companies that are found to be mishandling personal information may be subject to anticipatory regulations, and perhaps not just in Italy, but in the wider European Union. Garante’s investigation found Foodinho to be in breach of multiple GDPR articles, including those related to transparency, security, and privacy by design and default.
Source: Reuters
–
November 25, 2024 – by Cass Kennedy and Alex Perala
Follow Us