The Spanish authority sanctions GESTORA CLUBS DIR, S.L. for failures in the data protection impact assessment of biometric data

The Spanish Data Protection Authority (AEPD) has sanctioned a sports club manager for conducting a non-compliant data protection impact assessment (DPIA) for its fingerprint access control system, affecting 95,000 users.

Facts and context

The Spanish Data Protection Authority (AEPD) today published a sanction decision against GESTORA CLUBS DIR, S.L. (including the imposition of a fine of €35,000, reduced to €21,000) for failures related to the conduct of a data protection impact assessment for a fingerprint access control system.

The case originated from a complaint filed on 3 July 2024 concerning the use of biometric data for access to sports centers managed by the company, a system in place since 2013 and affecting 95,000 users.

Grounds for the decision

The authority found a main infringement against the company:

  • Obligation to carry out a data protection impact assessment (Article 35 of the GDPR): The authority found that the processing of biometric data (fingerprints) for access control constituted processing of special categories of data within the meaning of Article 9 of the GDPR, requiring a prior impact assessment. The assessment provided by the company, created in 2019 and updated in 2025, was deemed non-compliant with the requirements of Article 35, paragraph 7, of the GDPR. The authority noted the absence of a systematic description of processing operations, an insufficient assessment of the necessity and proportionality of the system, omission of an analysis of less intrusive alternatives, an incomplete risk assessment, and the absence of a description of measures planned to address these risks. The authority notably relied on the European Data Protection Board (EDPB) Guidelines 5/2022 to recall that biometric identification and authentication constitute processing of special categories of data.

Authority's decision

Consequently, the authority imposed a fine of €35,000 on GESTORA CLUBS DIR, S.L., reduced to €21,000 after applying reductions for acknowledgment of responsibility and voluntary payment.

Furthermore, the authority ordered the company to provide, within three months, a valid and compliant data protection impact assessment meeting the requirements of Article 35 of the GDPR for its biometric data processing system.

Lessons learned

This decision reminds that:

  • The mere formal existence of an impact assessment is insufficient; its content must materially and rigorously meet all the detailed requirements of Article 35, paragraph 7, of the GDPR.
  • An impact assessment concerning biometric data processing must imperatively include a thorough evaluation of necessity and proportionality, including a documented analysis of less intrusive alternative solutions.
  • The risk assessment must be sufficiently detailed to identify specific threats and differentiate the inherent risks of various types of biometric processing, such as authentication (1:1) and identification (1:N).
  • Any biometric data processing for the unique identification of a person, including for simple authentication, falls under the special categories of data regime of Article 9 of the GDPR and requires enhanced safeguards.
  • The obligation to carry out an impact assessment is a prior obligation that must be fulfilled before the start of high-risk processing, not years after its implementation.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire