Croatia's data protection regulator has fined an unnamed gambling operator nearly €2.6 million for collecting four fingerprints from each casino player. The casino fingerprint data GDPR fine, reported by MLex, turns on a simple point: the operator did not show that taking all four fingerprints was necessary to identify players. The regulator also found the biometric processing lacked valid consent under the GDPR.
The summary available to us is brief, so this post sticks to what has been reported and explains the wider legal principles involved.
What Croatia's Regulator Found
According to the MLex summary, the operator collected four fingerprints per player for identification purposes. The regulator's concerns, as reported, were twofold:
- Necessity was not demonstrated. The operator did not show that all four fingerprints were required to identify a player.
- Consent was not valid. The biometric processing lacked valid consent under the GDPR.
The fine came to nearly €2.6 million. The operator has not been named in the reporting we have seen, and we do not have further details on how players were enrolled or how the data was stored. We will not speculate on those points.
The case is notable because the regulator did not simply say fingerprints are off limits. The criticism was about proportion: collecting more biometric data than the operator could justify.
Why Biometric Consent Under GDPR Is Hard to Meet
Under the GDPR, biometric data used to uniquely identify a person is treated as special category data. That means processing it faces a higher bar than ordinary personal data such as an email address or a name. Organizations generally need a valid legal basis and an additional condition for handling this kind of information.
Consent is the route many businesses reach for, but it is demanding. In general terms, consent must be freely given, specific, informed and unambiguous. Several things can undermine it:
- Pressure or lack of alternatives. If a player must hand over fingerprints to enter or play, the choice may not be genuinely free.
- Vague explanations. People need to understand what is collected, why, and for how long.
- Excess collection. Even with consent, data minimization still applies. Collecting four fingerprints when fewer would do invites the kind of challenge seen in Croatia.
The necessity point is worth underlining. Regulators expect organizations to justify each data element they collect. If a lighter method can achieve the same goal, a heavier one is hard to defend.
What This Means For You
Fingerprints are different from passwords. You can change a compromised password, but you cannot change your fingers. That permanence is why regulators treat biometrics as high-risk, and why a gambling platform asking for them deserves scrutiny.
If you gamble in person or online, consider the following:
- Ask why. If a venue or platform requests biometrics, ask what exactly is collected, why it is needed, and who can access it.
- Look for alternatives. Under GDPR principles, a genuine choice should exist. Ask whether another form of identification is accepted.
- Check retention. Ask how long the data is kept and how you can request deletion.
- Know your rights. In the EU, you can generally request access to your data, ask for its erasure in certain circumstances, and complain to your national data protection authority.
This case also shows regulators are willing to impose substantial penalties over biometric collection, which may encourage operators to review their own practices.
What a VPN Can and Cannot Protect
It is tempting to think a VPN solves privacy problems around gambling. In this scenario, it mostly does not. A VPN encrypts the traffic between your device and the VPN server, which can limit what your internet provider or someone on public Wi-Fi sees. Protocol choice matters here; for example, SSTP wraps traffic in SSL/TLS encryption, which can help it pass through restrictive firewalls.
But a VPN cannot reach data you give directly to a company. If you scan your fingerprint at a casino terminal, or submit a biometric check to a platform, that information goes straight to the operator. No tunnel changes what the operator holds or how it processes it. The Croatian case involved exactly that kind of direct collection.
A VPN is one layer of protection for network traffic. It is not a substitute for scrutinizing what personal data you hand over in the first place. If you do use one, our Surfshark setup guide shows what configuring a client involves, though this is a walkthrough and not an endorsement.
Key Takeaways
The casino fingerprint data GDPR fine in Croatia sends a clear message: biometric data needs a strong justification, a valid legal basis, and no more collection than necessary. For players, the practical response is to question any biometric request from a gambling platform before agreeing.
- Ask what is collected and why, and whether a non-biometric option exists.
- Remember that fingerprints cannot be changed if they are exposed.
- Use a VPN for what it does well, protecting network traffic, but do not expect it to protect data you hand over directly.
- If you believe your data was handled unlawfully, contact your national data protection authority.




