The Spanish authority sanctions the Directorate General of Police for breaches of data protection law in biometric border controls
The Spanish data protection authority has sanctioned the Directorate General of Police for serious breaches concerning the processing of biometric data at border controls, notably insufficient information provided to travelers and the absence of a compliant data protection impact assessment.
Facts and context
The Spanish data protection authority (AEPD) has today published a decision against the Directorate General of Police for breaches related to informing individuals and conducting a data protection impact assessment in the context of biometric border controls.
The case originated from a complaint by a traveler who was subjected, on 15 March 2024, to the use of a biometric control system at Alicante airport without receiving any information about this data processing or about her rights.
Grounds of the decision
The authority found that data processing carried out by competent authorities for the purposes of preventing and detecting criminal offenses, or protecting against threats to public security, does not fall under the GDPR, as specified in its recital 19, but under Directive (EU) 2016/680, transposed into Spanish law by Organic Law 7/2021. The breaches were therefore analyzed under this specific law.
- Obligation to inform data subjects (article 21 of Organic Law 7/2021): The authority found that the complainant received no information about the processing of her biometric data during the border control. It considered that merely publishing the register of processing activities on a website does not fulfill the obligation to inform, which must be effective at the time and place of data collection. The absence of procedures enabling officers to provide this information and the omission of this information prevent individuals from exercising their rights, constituting a very serious violation under article 58, paragraph f), of the same law.
- Obligation to carry out a data protection impact assessment (article 35 of Organic Law 7/2021): The authority judged that the impact assessment provided by the police was incomplete and non-compliant. The document lacked risk analysis, description of the data lifecycle, detailed security measures, and had not been conducted before processing began. Given the large-scale processing (approximately 25 million people) of biometric data, this omission constitutes a serious violation under article 59, paragraph l), of the law.
Authority's decision
Consequently, the authority found that the Directorate General of Police committed a very serious infringement of article 21 and a serious infringement of article 35 of Organic Law 7/2021.
Furthermore, the authority ordered the Directorate General of Police to implement, within three months, the following corrective measures: include the information required by law in documents given to passengers at borders, and carry out a complete and compliant impact assessment for the data processing concerned.
Lessons learned
This decision reminds that:
- Publishing a register of processing activities on a website does not exempt the controller from its obligation to provide clear and accessible information to data subjects at the time and place of data collection.
- A data protection impact assessment must be a substantive and complete document, concretely assessing risks to individuals' rights and freedoms and detailing measures planned to address them; a formal and incomplete document does not meet this legal requirement.
- Data processing carried out by police authorities for the purposes of preventing and detecting criminal offenses, including at borders, does not fall under the GDPR but under a specific legal regime (Directive 2016/680 and its national transposition), which imposes distinct and strict obligations.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire