The Spanish authority imposes a €40,000 fine on GSMA LIMITED for excessive data collection at MWC 2023

The Spanish Data Protection Agency sanctions the organizer of the Mobile World Congress for requiring a full copy of participants' identity documents, deeming this collection excessive in light of the data minimization principle, regardless of the existence of a biometric verification option based on consent.

Facts and context

The Spanish Data Protection Agency (AEPD) today published a sanction decision against GSMA LIMITED, including the imposition of a €50,000 fine (reduced to €40,000) for breaches related to excessive collection of identity data during registration for the Mobile World Congress 2023 event.

The case originated from a complaint submitted on August 10, 2023, by the Catalan Data Protection Authority, denouncing the obligation for participants to upload a copy of their identity document and a photograph in order to register and access the event.

Reasons for the decision

The authority analyzed the identity verification processes implemented for the 99,998 people registered for the event. To complete their registration, participants were required to validate their identity by uploading a copy of their passport or national identity card, as well as a photograph of themselves. Two options were then offered: manual validation by agents (taking up to 72 hours) or automated validation by facial recognition (called BREEZ), requiring explicit consent. The authority concluded a violation on the following point:

  • Data minimization obligation (Article 5(1)(c) of the GDPR): The AEPD found that the requirement to upload a full copy of the identity document was excessive and unnecessary in view of the purpose of verifying participants' identity. The authority highlights that data irrelevant to this purpose, such as signature, age, or other information visible on the document, were collected without justification. Relying on the European Data Protection Board (EDPB) Guidelines 01/2022, it recalls that collecting a complete copy of an identity document creates significant security risks and that only the data fields strictly necessary for identification should have been processed. The fact that this collection was a mandatory prerequisite for both validation paths (manual and biometric) constitutes a violation of the minimization principle.

Regarding the potential violation of the obligation to conduct a data protection impact assessment (Article 35 of the GDPR), the authority closed the case. It noted that the data in question (biometric tokens and copies of identity documents) were deleted on March 3 and 13, 2023, shortly after the event. Since the sanction procedure was initiated on April 16, 2025, the AEPD considered the infringement time-barred, the obligation being intrinsically linked to the duration of the processing.

Authority's decision

Consequently, the authority imposed a €50,000 fine on GSMA LIMITED, with the final amount set at €40,000 following a voluntary payment.

Lessons learned

This decision reminds that:

  • Collecting a full copy of an identity document is generally considered excessive if the identity verification purpose can be achieved with a subset of data (e.g., name, first name, document number).
  • Obtaining explicit consent for high-risk data processing, such as biometrics, does not exempt the controller from respecting the minimization principle for upstream data collection steps.
  • The mandatory nature of data collection deemed excessive constitutes a violation, even if robust security measures are implemented and retention periods are short.
  • An alternative to data processing must be presented clearly and easily accessible to the user, which is not the case for an option hidden behind a general help button.
  • The infringement related to the absence of a data protection impact assessment (DPIA) may be considered time-barred if the processing has ceased and the data were deleted well before the authority's sanction procedure was opened.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire