The Loro Parque Group on Tenerife has been ordered to pay a fine of 250,000 euros. This is due to a breach of data protection regulations affecting visitors to several of the group’s theme parks. Three visitors had lodged a complaint regarding the storage of their biometric data.
Spain’s data protection authorities subsequently carried out an investigation lasting three years. The outcome has now been confirmed. Anyone who visits Loro Parque and Siam Park with a so-called „Twin Ticket“ – that is, anyone who chooses to visit both parks on a discounted combined ticket – must provide a fingerprint. The same applies to anyone who decides to return to one of the theme parks whilst visiting the Canary Islands.
The theme park argues that this is the only way to ensure that the guest is the same person and not a new visitor with a ticket that has been passed on. The Spanish data protection authority nevertheless classifies this practice as a serious breach. And so it is now set to prove costly for Tenerife’s most famous zoo. The zoo had put forward counter-arguments, but the data protection authorities did not accept them. What this means now is:
Loro Parque must pay a fine
According to the Loro Parque Group, there is no alternative to this practice. Furthermore, it claims that it is not the fingerprints themselves that are stored, but encrypted mathematical data derived from the fingerprint. Consequently, no biometric data as such is stored.
The park states that this data would be deleted as soon as the ticket ceases to be valid – that is, either once the validity period has expired or once the ticket has been validated. Furthermore, data is not linked together, meaning that a fingerprint cannot be linked to any specific individual. In addition, no name is stored on a ticket.
Data protection authorities, on the other hand, do not regard the current practice as the only option. Furthermore, according to Article 4(14) of the General Data Protection Regulation, biometric data encompasses all technical procedures that establish or verify a person’s identity on the basis of physical characteristics. Since, in the present case, the fingerprint was used to verify whether a person had access to the parks, this constitutes the storage of biometric data under the law.
The Spanish data protection authorities also found that, for online purchases, a guest’s name, email address and telephone number were required. During the visit, depending on the type of ticket, a fingerprint was also taken. They considered this information to be disproportionate for the purpose of visiting the parks. Furthermore, the operator had failed to provide evidence that there were no alternatives to the practice in question.
Data protection investigation: Loro Parque must take corrective action
The Loro Parque Group is the largest employer in the Canary Islands. In addition to the zoo, it operates Siam Park, Europe’s largest water slide park, and the Botanico, one of the most luxurious hotels on Tenerife. On Gran Canaria there is also a large seawater aquarium.
The group must now pay a fine of a quarter of a million euros for data protection offences. It has also been ordered to implement corrective measures regarding admission to Loro Parque and Siam Park.











No comments on this article yet.